Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
articulate-360.exe

Overview

General Information

Sample name:articulate-360.exe
Analysis ID:1539190
MD5:f1d670108f566db99dfbc0b91c2ad2a2
SHA1:fb758a61a196de45a42c781fad5f77dd6f21bdcd
SHA256:9c4c3f2396efcf50c10ff0f162626635058bd9e26b03249474097a61b61e492f
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Compliance

Score:50
Range:0 - 100

Signatures

Installs Task Scheduler Managed Wrapper
Yara detected Generic Downloader
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for available system drives (often done to infect USB drives)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates or modifies windows services
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the application program directory (C:\ProgramData)
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Enables debug privileges
Enables security privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
HTML body contains low number of good links
HTML page contains hidden javascript code
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Stores files to the Windows start menu directory
Uses 32bit PE files
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64_ra
  • articulate-360.exe (PID: 6960 cmdline: "C:\Users\user\Desktop\articulate-360.exe" MD5: F1D670108F566DB99DFBC0B91C2AD2A2)
    • articulate-360.exe (PID: 6984 cmdline: "C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe" -burn.clean.room="C:\Users\user\Desktop\articulate-360.exe" -burn.filehandle.attached=520 -burn.filehandle.self=528 MD5: 27A052A559D18C7A5823AA55D41A1A14)
      • Articulate.360.Bundle.exe (PID: 6280 cmdline: "C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe" -q -burn.elevated BurnPipe.{2F0C2B53-B19F-40D3-85E6-CA669222AE1F} {FCE9E140-D8F2-4827-9147-38CAF241950C} 6984 MD5: 27A052A559D18C7A5823AA55D41A1A14)
        • vc_redist.x86.exe (PID: 3820 cmdline: "C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" /quiet /norestart MD5: 9882A328C8414274555845FA6B542D1E)
          • vc_redist.x86.exe (PID: 6160 cmdline: "C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe" -burn.clean.room="C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" -burn.filehandle.attached=536 -burn.filehandle.self=532 /quiet /norestart MD5: 7BD0B2D204D75012D3A9A9CE107C379E)
            • VC_redist.x86.exe (PID: 1164 cmdline: "C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{8FA64B99-084F-4A69-A6FF-A0E7A184ECCB} {DC705CDD-8D74-4A36-AC9D-66771471949A} 6160 MD5: 7BD0B2D204D75012D3A9A9CE107C379E)
      • Articulate 360 Desktop Service.exe (PID: 3420 cmdline: "C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe" MD5: 19F3A3EF1A887820D421BA01C8CD6CF3)
      • Articulate 360 Desktop App.exe (PID: 3584 cmdline: "C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe" MD5: 53A59069B2CC644D2AA1DAEEC9AF9B3B)
        • chrome.exe (PID: 4412 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://id.articulate.com/oauth2/default/v1/authorize?response_type=code&nonce=fa078e7de1bf0818227aa6437c33d7f9&state=3651676f97588deec52d1b7d0a6c34c0&code_challenge=p6zXwn-8zxC48gaGjk10u0AOD5wVSruex4K3YTcewj0&code_challenge_method=S256&client_id=0oaajzcsjphvmDtIW356&scope=openid offline_access email profile profile_name user_subscription staff&redirect_uri=http%3A%2F%2F127.0.0.1%3A49360%2F&response_mode=form_post&data=eyJ2ZXJzaW9uIjoiMS44OS4zMjYxOC4wIiwic3RhdGUiOiI2MDI2Y2RiMjIyMTI3NmZjZTVhNjI0ODBkMjY3ZjI3YSIsImluc3RhbGxhdGlvbklkIjoiMjYwZjIxNTU5YTgzNGQzMDllYjg4MGZkOTFkNGI0NTEifQ%3D%3D MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
          • chrome.exe (PID: 5144 cmdline: "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1888,i,13776261870539790963,7267718473941381716,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8 MD5: 83395EAB5B03DEA9720F8D7AC0D15CAA)
  • SrTasks.exe (PID: 6696 cmdline: C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1 MD5: 2694D2D28C368B921686FE567BD319EB)
    • conhost.exe (PID: 6668 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • SrTasks.exe (PID: 1428 cmdline: C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:2 MD5: 2694D2D28C368B921686FE567BD319EB)
    • conhost.exe (PID: 6816 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • msiexec.exe (PID: 1576 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 5828 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 41CDB22C6A61E7016A5A2564D9C06BBF MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 3040 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 0AB85726319CC19B2F88681BE96BEC66 E Global\MSI0000 MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • rundll32.exe (PID: 5296 cmdline: rundll32.exe "C:\Windows\Installer\MSI4FBA.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5656531 18 Articulate.CustomActions!Articulate.CustomActions.CustomActions.CreateRegistryValuesAction MD5: 889B99C52A60DD49227C5E485A016679)
      • rundll32.exe (PID: 1160 cmdline: rundll32.exe "C:\Windows\Installer\MSI5AC7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5659359 27 Articulate.CustomActions!Articulate.CustomActions.CustomActions.RegisterScheduledTaskAction MD5: 889B99C52A60DD49227C5E485A016679)
  • Articulate 360 Installer Service.exe (PID: 1484 cmdline: "C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe" MD5: 161D9B1A3B37D56D15F53591B2478382)
  • cleanup
SourceRuleDescriptionAuthorStrings
C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dllJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
    C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dllJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
      Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\ProgramData\Package Cache\{b7197944-fc91-43ad-bcc0-233e39733206}\Articulate.360.Bundle.exe" /burn.runonce, EventID: 13, EventType: SetValue, Image: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe, ProcessId: 6280, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\{b7197944-fc91-43ad-bcc0-233e39733206}
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Number of links: 0
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Base64 decoded: {"typ":"JWT","alg":"HS256"}
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-K9R2NB
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Iframe src: https://td.doubleclick.net/td/rul/663970415?random=1729587437881&cv=11&fst=1729587437881&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be4ah0v872251761z871205897za201zb71205897&gcd=13l3l3l3l1l1&dma=0&tag_exp=101686685~101823848~101836706&u_w=1280&u_h=1024&url=https%3A%2F%2Fid.articulate.com%2F&hn=www.googleadservices.com&frm=0&tiba=Articulate%20-%20Sign%20In&npa=0&us_privacy=1-N-&pscdl=noapi&auid=1169443646.1729587436&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Iframe src: https://td.doubleclick.net/td/ga/rul?tid=G-FX3HXD9SHZ&gacid=729542289.1729587438&gtm=45je4ah0h1v881450918z871205897za200zb71205897&dma=0&gcd=13l3l3l3l1l1&npa=0&pscdl=noapi&aip=1&fledge=1&frm=0&tag_exp=101686685~101823848~101836706&z=689602308
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Iframe src: https://www.googletagmanager.com/ns.html?id=GTM-K9R2NB
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Iframe src: https://td.doubleclick.net/td/rul/663970415?random=1729587437881&cv=11&fst=1729587437881&fmt=3&bg=ffffff&guid=ON&async=1&gtm=45be4ah0v872251761z871205897za201zb71205897&gcd=13l3l3l3l1l1&dma=0&tag_exp=101686685~101823848~101836706&u_w=1280&u_h=1024&url=https%3A%2F%2Fid.articulate.com%2F&hn=www.googleadservices.com&frm=0&tiba=Articulate%20-%20Sign%20In&npa=0&us_privacy=1-N-&pscdl=noapi&auid=1169443646.1729587436&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Iframe src: https://td.doubleclick.net/td/ga/rul?tid=G-FX3HXD9SHZ&gacid=729542289.1729587438&gtm=45je4ah0h1v881450918z871205897za200zb71205897&dma=0&gcd=13l3l3l3l1l1&npa=0&pscdl=noapi&aip=1&fledge=1&frm=0&tag_exp=101686685~101823848~101836706&z=689602308
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: Iframe src: https://td.doubleclick.net/td/ga/rul?tid=G-0LXMVHBMX2&gacid=729542289.1729587438&gtm=45je4ah0v878369553za200&dma=0&gcd=13l3l3l3l2l1&npa=0&pscdl=noapi&aip=1&fledge=1&frm=0&tag_exp=101686685~101794736~101823848~101836706&z=891387343
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: No favicon
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: No <meta name="author".. found
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: No <meta name="author".. found
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: No <meta name="copyright".. found
      Source: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=HTTP Parser: No <meta name="copyright".. found

      Compliance

      barindex
      Source: articulate-360.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore SRInitDone
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeFile created: C:\ProgramData\Articulate\360\Logs\InstallerService_STABLE_20241022_045641.log
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1028\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1029\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1031\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1036\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1040\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1041\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1042\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1045\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1046\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1049\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1055\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\2052\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\3082\license.rtf
      Source: articulate-360.exeStatic PE information: certificate valid
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49707 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49708 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49709 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 54.81.144.153:443 -> 192.168.2.17:49711 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49710 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49712 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49713 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49715 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49716 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 34.202.68.135:443 -> 192.168.2.17:49717 version: TLS 1.2
      Source: articulate-360.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
      Source: C:\Windows\System32\msiexec.exeFile opened: z:
      Source: C:\Windows\System32\msiexec.exeFile opened: x:
      Source: C:\Windows\System32\msiexec.exeFile opened: v:
      Source: C:\Windows\System32\msiexec.exeFile opened: t:
      Source: C:\Windows\System32\msiexec.exeFile opened: r:
      Source: C:\Windows\System32\msiexec.exeFile opened: p:
      Source: C:\Windows\System32\msiexec.exeFile opened: n:
      Source: C:\Windows\System32\msiexec.exeFile opened: l:
      Source: C:\Windows\System32\msiexec.exeFile opened: j:
      Source: C:\Windows\System32\msiexec.exeFile opened: h:
      Source: C:\Windows\System32\msiexec.exeFile opened: f:
      Source: C:\Windows\System32\msiexec.exeFile opened: b:
      Source: C:\Windows\System32\msiexec.exeFile opened: y:
      Source: C:\Windows\System32\msiexec.exeFile opened: w:
      Source: C:\Windows\System32\msiexec.exeFile opened: u:
      Source: C:\Windows\System32\msiexec.exeFile opened: s:
      Source: C:\Windows\System32\msiexec.exeFile opened: q:
      Source: C:\Windows\System32\msiexec.exeFile opened: o:
      Source: C:\Windows\System32\msiexec.exeFile opened: m:
      Source: C:\Windows\System32\msiexec.exeFile opened: k:
      Source: C:\Windows\System32\msiexec.exeFile opened: i:
      Source: C:\Windows\System32\msiexec.exeFile opened: g:
      Source: C:\Windows\System32\msiexec.exeFile opened: e:
      Source: C:\Windows\System32\msiexec.exeFile opened: c:
      Source: C:\Windows\System32\msiexec.exeFile opened: a:
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\NULL
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL

      Networking

      barindex
      Source: Yara matchFile source: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dll, type: DROPPED
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
      Source: unknownTCP traffic detected without corresponding DNS query: 199.232.214.172
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownTCP traffic detected without corresponding DNS query: 204.79.197.200
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
      Source: global trafficDNS traffic detected: DNS query: metrics.articulate.com
      Source: global trafficDNS traffic detected: DNS query: api.articulate.com
      Source: global trafficDNS traffic detected: DNS query: id.articulate.com
      Source: global trafficDNS traffic detected: DNS query: cmp.osano.com
      Source: global trafficDNS traffic detected: DNS query: cdn.articulate.com
      Source: global trafficDNS traffic detected: DNS query: www.google.com
      Source: global trafficDNS traffic detected: DNS query: consent.api.osano.com
      Source: global trafficDNS traffic detected: DNS query: snap.licdn.com
      Source: global trafficDNS traffic detected: DNS query: scout-cdn.salesloft.com
      Source: global trafficDNS traffic detected: DNS query: sessions.bugsnag.com
      Source: global trafficDNS traffic detected: DNS query: geo.articulate.com
      Source: global trafficDNS traffic detected: DNS query: rum.browser-intake-datadoghq.com
      Source: global trafficDNS traffic detected: DNS query: scout.salesloft.com
      Source: global trafficDNS traffic detected: DNS query: stats.g.doubleclick.net
      Source: global trafficDNS traffic detected: DNS query: px.ads.linkedin.com
      Source: global trafficDNS traffic detected: DNS query: googleads.g.doubleclick.net
      Source: global trafficDNS traffic detected: DNS query: analytics.google.com
      Source: unknownNetwork traffic detected: HTTP traffic on port 49708 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49744
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49742
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49741
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49740
      Source: unknownNetwork traffic detected: HTTP traffic on port 49800 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49766 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49746 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49781 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49769 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49803 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49795 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49826 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49739
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49738
      Source: unknownNetwork traffic detected: HTTP traffic on port 49717 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49735
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49734
      Source: unknownNetwork traffic detected: HTTP traffic on port 49772 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49733
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49732
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49730
      Source: unknownNetwork traffic detected: HTTP traffic on port 49732 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49691
      Source: unknownNetwork traffic detected: HTTP traffic on port 49784 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49728 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49749 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49806 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49823 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49729
      Source: unknownNetwork traffic detected: HTTP traffic on port 49752 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49728
      Source: unknownNetwork traffic detected: HTTP traffic on port 49777 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49714 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49727
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49726
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49725
      Source: unknownNetwork traffic detected: HTTP traffic on port 49735 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49790 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49723
      Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49712 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49787 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49729 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49748 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49760 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49745 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49828 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49805 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49719
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49718
      Source: unknownNetwork traffic detected: HTTP traffic on port 49751 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49717
      Source: unknownNetwork traffic detected: HTTP traffic on port 49715 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49716
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49715
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49714
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49713
      Source: unknownNetwork traffic detected: HTTP traffic on port 49774 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49712
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49799
      Source: unknownNetwork traffic detected: HTTP traffic on port 49734 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49797
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49796
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49795
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49794
      Source: unknownNetwork traffic detected: HTTP traffic on port 49814 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49822 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49726 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49790
      Source: unknownNetwork traffic detected: HTTP traffic on port 49740 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49723 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49796 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49825 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49708
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49707
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49828
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49827
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49826
      Source: unknownNetwork traffic detected: HTTP traffic on port 49754 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49825
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49824
      Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49823
      Source: unknownNetwork traffic detected: HTTP traffic on port 49771 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49822
      Source: unknownNetwork traffic detected: HTTP traffic on port 49733 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49821
      Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49787
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49786
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49785
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49784
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49783
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49781
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49780
      Source: unknownNetwork traffic detected: HTTP traffic on port 49727 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49691 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49785 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49818
      Source: unknownNetwork traffic detected: HTTP traffic on port 49776 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49799 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49810 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49713 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49814
      Source: unknownNetwork traffic detected: HTTP traffic on port 49759 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49753 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49778
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49777
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49810
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49776
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49775
      Source: unknownNetwork traffic detected: HTTP traffic on port 49707 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49774
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49773
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49772
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49771
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49770
      Source: unknownNetwork traffic detected: HTTP traffic on port 49742 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49780 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49794 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49827 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49809
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49806
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49805
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49804
      Source: unknownNetwork traffic detected: HTTP traffic on port 49773 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49803
      Source: unknownNetwork traffic detected: HTTP traffic on port 49718 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49769
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49801
      Source: unknownNetwork traffic detected: HTTP traffic on port 49739 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49756 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49800
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49766
      Source: unknownNetwork traffic detected: HTTP traffic on port 49758 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49783 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49760
      Source: unknownNetwork traffic detected: HTTP traffic on port 49821 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49725 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49741 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49770 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49719 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49797 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49801 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49824 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49809 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49759
      Source: unknownNetwork traffic detected: HTTP traffic on port 49778 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49758
      Source: unknownNetwork traffic detected: HTTP traffic on port 49738 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49755 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49756
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49755
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49754
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49753
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49752
      Source: unknownNetwork traffic detected: HTTP traffic on port 49730 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49751
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49750
      Source: unknownNetwork traffic detected: HTTP traffic on port 49818 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49786 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49747 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49804 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49744 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49775 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49716 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 49750 -> 443
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49749
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49748
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49747
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49746
      Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49745
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49707 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49708 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49709 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 54.81.144.153:443 -> 192.168.2.17:49711 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49710 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49712 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49713 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49715 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 108.138.7.72:443 -> 192.168.2.17:49716 version: TLS 1.2
      Source: unknownHTTPS traffic detected: 34.202.68.135:443 -> 192.168.2.17:49717 version: TLS 1.2
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612ba.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7}
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI149F.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\concrt140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_1.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_2.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_atomic_wait.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_codecvt_ids.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcamp140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vccorlib140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcomp140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcruntime140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcruntime140_threads.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612c6.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612c6.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612c7.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{9C19C103-7DB1-44D1-A039-2C076A633A38}
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI1933.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140chs.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140cht.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140deu.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140enu.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140esn.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140fra.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140ita.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140jpn.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140kor.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140rus.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140u.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfcm140.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfcm140u.dll
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612ce.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612ce.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612cf.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3170.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI321C.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI3366.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}\DesktopAppIcon.exe
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612d2.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5612d2.msi
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4F3C.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4FBA.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI5AC7.tmp
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6E9E.tmp
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeFile deleted: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
      Source: C:\Windows\System32\SrTasks.exeProcess token adjusted: Security
      Source: articulate-360.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
      Source: classification engineClassification label: mal48.troj.evad.winEXE@27/335@58/110
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\Public\Desktop\Articulate 360.lnk
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeMutant created: NULL
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6668:120:WilError_03
      Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6816:120:WilError_03
      Source: C:\Users\user\Desktop\articulate-360.exeFile created: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\
      Source: articulate-360.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile read: C:\Users\user\Desktop\desktop.ini
      Source: C:\Users\user\Desktop\articulate-360.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
      Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI4FBA.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5656531 18 Articulate.CustomActions!Articulate.CustomActions.CustomActions.CreateRegistryValuesAction
      Source: C:\Users\user\Desktop\articulate-360.exeFile read: C:\Users\user\Desktop\articulate-360.exe
      Source: unknownProcess created: C:\Users\user\Desktop\articulate-360.exe "C:\Users\user\Desktop\articulate-360.exe"
      Source: C:\Users\user\Desktop\articulate-360.exeProcess created: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe "C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe" -burn.clean.room="C:\Users\user\Desktop\articulate-360.exe" -burn.filehandle.attached=520 -burn.filehandle.self=528
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe "C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe" -q -burn.elevated BurnPipe.{2F0C2B53-B19F-40D3-85E6-CA669222AE1F} {FCE9E140-D8F2-4827-9147-38CAF241950C} 6984
      Source: C:\Users\user\Desktop\articulate-360.exeProcess created: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe "C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe" -burn.clean.room="C:\Users\user\Desktop\articulate-360.exe" -burn.filehandle.attached=520 -burn.filehandle.self=528
      Source: unknownProcess created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
      Source: C:\Windows\System32\SrTasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe "C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe" -q -burn.elevated BurnPipe.{2F0C2B53-B19F-40D3-85E6-CA669222AE1F} {FCE9E140-D8F2-4827-9147-38CAF241950C} 6984
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeProcess created: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe "C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" /quiet /norestart
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeProcess created: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe "C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe" -burn.clean.room="C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" -burn.filehandle.attached=536 -burn.filehandle.self=532 /quiet /norestart
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeProcess created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe "C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{8FA64B99-084F-4A69-A6FF-A0E7A184ECCB} {DC705CDD-8D74-4A36-AC9D-66771471949A} 6160
      Source: unknownProcess created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:2
      Source: C:\Windows\System32\SrTasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
      Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeProcess created: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe "C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" /quiet /norestart
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeProcess created: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe "C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe" -burn.clean.room="C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" -burn.filehandle.attached=536 -burn.filehandle.self=532 /quiet /norestart
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeProcess created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe "C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{8FA64B99-084F-4A69-A6FF-A0E7A184ECCB} {DC705CDD-8D74-4A36-AC9D-66771471949A} 6160
      Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 41CDB22C6A61E7016A5A2564D9C06BBF
      Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 0AB85726319CC19B2F88681BE96BEC66 E Global\MSI0000
      Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI4FBA.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5656531 18 Articulate.CustomActions!Articulate.CustomActions.CustomActions.CreateRegistryValuesAction
      Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI5AC7.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5659359 27 Articulate.CustomActions!Articulate.CustomActions.CustomActions.RegisterScheduledTaskAction
      Source: unknownProcess created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe "C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe"
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe "C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe"
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe "C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe"
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --start-maximized --single-argument https://id.articulate.com/oauth2/default/v1/authorize?response_type=code&nonce=fa078e7de1bf0818227aa6437c33d7f9&state=3651676f97588deec52d1b7d0a6c34c0&code_challenge=p6zXwn-8zxC48gaGjk10u0AOD5wVSruex4K3YTcewj0&code_challenge_method=S256&client_id=0oaajzcsjphvmDtIW356&scope=openid offline_access email profile profile_name user_subscription staff&redirect_uri=http%3A%2F%2F127.0.0.1%3A49360%2F&response_mode=form_post&data=eyJ2ZXJzaW9uIjoiMS44OS4zMjYxOC4wIiwic3RhdGUiOiI2MDI2Y2RiMjIyMTI3NmZjZTVhNjI0ODBkMjY3ZjI3YSIsImluc3RhbGxhdGlvbklkIjoiMjYwZjIxNTU5YTgzNGQzMDllYjg4MGZkOTFkNGI0NTEifQ%3D%3D
      Source: C:\Program Files\Google\Chrome\Application\chrome.exeProcess created: C:\Program Files\Google\Chrome\Application\chrome.exe "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1968 --field-trial-handle=1888,i,13776261870539790963,7267718473941381716,262144 --disable-features=OptimizationGuideModelDownloading,OptimizationHints,OptimizationHintsFetching,OptimizationTargetPrediction /prefetch:8
      Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 41CDB22C6A61E7016A5A2564D9C06BBF
      Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 0AB85726319CC19B2F88681BE96BEC66 E Global\MSI0000
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: kernel.appcore.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: cryptbase.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: msi.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: version.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: cabinet.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: msxml3.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: windows.storage.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: wldp.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: profapi.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: feclient.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: iertutil.dll
      Source: C:\Users\user\Desktop\articulate-360.exeSection loaded: apphelp.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: kernel.appcore.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: cryptbase.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: msi.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: version.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: cabinet.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: msxml3.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: windows.storage.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: wldp.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: profapi.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: feclient.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: iertutil.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: uxtheme.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: textinputframework.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: coreuicomponents.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: coremessaging.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: ntmarta.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: mscoree.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: vcruntime140_clr0400.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: cryptsp.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: rsaenh.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: dwrite.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: msvcp140_clr0400.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: windowscodecs.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: dwmapi.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: d3d9.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: d3d10warp.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: wtsapi32.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: winsta.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: powrprof.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: umpdc.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: textshaping.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: dataexchange.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: d3d11.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: dcomp.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: dxgi.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: twinapi.appcore.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: resourcepolicyclient.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: dxcore.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: urlmon.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: srvcli.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: netutils.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: uiautomationcore.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: propsys.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: msctfui.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: d3dcompiler_47.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: edputil.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: windows.staterepositoryps.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: sspicli.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: appresolver.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: bcp47langs.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: slc.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: userenv.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: sppc.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: onecorecommonproxystub.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: onecoreuapcommonproxystub.dll
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeSection loaded: apphelp.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: kernel.appcore.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: cryptbase.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: msi.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: version.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: cabinet.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: msxml3.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: windows.storage.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: wldp.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: profapi.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: uxtheme.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: textinputframework.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: coreuicomponents.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: coremessaging.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: ntmarta.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: srclient.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: spp.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: powrprof.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: vssapi.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: vsstrace.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: umpdc.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: usoapi.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: sxproxy.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: cryptsp.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: rsaenh.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: feclient.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: iertutil.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: apphelp.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: spp.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: srclient.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: srcore.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vssapi.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vssapi.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vsstrace.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: ktmw32.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: wer.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: bcd.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: powrprof.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: umpdc.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: kernel.appcore.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: ntmarta.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: dsrole.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: msxml3.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vss_ps.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: kernel.appcore.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: cryptbase.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: msi.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: version.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: cabinet.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: msxml3.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: windows.storage.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: wldp.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: profapi.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: feclient.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: iertutil.dll
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeSection loaded: apphelp.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: kernel.appcore.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: cryptbase.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: msi.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: version.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: cabinet.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: msxml3.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: windows.storage.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: wldp.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: profapi.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: feclient.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: iertutil.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: uxtheme.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: textinputframework.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: coreuicomponents.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: coremessaging.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: ntmarta.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: msimg32.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: windowscodecs.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: explorerframe.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: riched20.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: usp10.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: msls31.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: textshaping.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: propsys.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: edputil.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: urlmon.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: srvcli.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: netutils.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: windows.staterepositoryps.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: sspicli.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: appresolver.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: bcp47langs.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: slc.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: userenv.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: sppc.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: onecorecommonproxystub.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: onecoreuapcommonproxystub.dll
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeSection loaded: apphelp.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: kernel.appcore.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: cryptbase.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: msi.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: version.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: cabinet.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: msxml3.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: windows.storage.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: wldp.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: profapi.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: uxtheme.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: textinputframework.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: coreuicomponents.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: coremessaging.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: ntmarta.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: wintypes.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: srclient.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: spp.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: powrprof.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: vssapi.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: vsstrace.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: umpdc.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: usoapi.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: sxproxy.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: srpapi.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: tsappcmp.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: netapi32.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: wkscli.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeSection loaded: netutils.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: cryptsp.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: rsaenh.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: feclient.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: iertutil.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: srpapi.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: tsappcmp.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: netapi32.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: wkscli.dll
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeSection loaded: netutils.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: spp.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: srclient.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: srcore.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vssapi.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: ktmw32.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vssapi.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vssapi.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: wer.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: bcd.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vsstrace.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: powrprof.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: umpdc.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: kernel.appcore.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: ntmarta.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: dsrole.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: msxml3.dll
      Source: C:\Windows\System32\SrTasks.exeSection loaded: vss_ps.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
      Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: mscoree.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: kernel.appcore.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: version.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: vcruntime140_clr0400.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: cryptsp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: rsaenh.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: cryptbase.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: windows.storage.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: wldp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: profapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: shfolder.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: vcruntime140.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: msvcp140.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: iphlpapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: dnsapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: dhcpcsvc6.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: dhcpcsvc.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: winnsi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: wbemcomn.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: amsi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: userenv.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: rasapi32.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: rasman.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: rtutils.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: mswsock.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: msasn1.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: winhttp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: ondemandconnroutehelper.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: rasadhlp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: fwpuclnt.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: secur32.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: sspicli.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: schannel.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: mskeyprotect.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: ntasn1.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: ncrypt.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: ncryptsslp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeSection loaded: gpapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: mscoree.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: kernel.appcore.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: version.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: vcruntime140_clr0400.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: ucrtbase_clr0400.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: uxtheme.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: cryptsp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: rsaenh.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: cryptbase.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: windows.storage.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: wldp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: profapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: shfolder.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: vcruntime140.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: msvcp140.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: iphlpapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: dnsapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: dhcpcsvc6.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: dhcpcsvc.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: winnsi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: wbemcomn.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: amsi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: userenv.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: secur32.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: sspicli.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: mswsock.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: rasapi32.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: rasman.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: rtutils.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: winhttp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: ondemandconnroutehelper.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: rasadhlp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: fwpuclnt.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: schannel.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: mskeyprotect.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: ntasn1.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: ncrypt.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: ncryptsslp.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: msasn1.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: gpapi.dll
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeSection loaded: rstrtmgr.dll
      Source: C:\Users\user\Desktop\articulate-360.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
      Source: articulate-360.exeStatic PE information: certificate valid
      Source: articulate-360.exeStatic file information: File size 36620184 > 1048576
      Source: articulate-360.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
      Source: articulate-360.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
      Source: articulate-360.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
      Source: articulate-360.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
      Source: articulate-360.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
      Source: articulate-360.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
      Source: articulate-360.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
      Source: articulate-360.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
      Source: articulate-360.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
      Source: articulate-360.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
      Source: articulate-360.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
      Source: articulate-360.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
      Source: articulate-360.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
      Source: articulate-360.exeStatic PE information: section name: .wixburn
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Svg.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140esn.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.VisualStudio.Validation.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.DependencyInjection.Abstractions.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Interactivity.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\YurlDotNet.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\System.Windows.Interactivity.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140deu.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcamp140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Bridgewater.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.IO.Pipelines.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.ThreeSixty.Facade.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140jpn.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\ICSharpCode.SharpZipLib.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfcm140u.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Platform.DirectWrite.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\es\Articulate.ContentLibrary.Resources.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\es\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\ResvgNet.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Core.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.ThreeSixty.App.View.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate 360 Desktop App.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Net.Http.Formatting.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.Common.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Reflection.Metadata.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Xaml.Behaviors.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.IdentityModel.Logging.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.IntelPrimitives.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Buffers.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.ValueTuple.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbapreq.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140cht.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.PubSubEvents.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate 360 Desktop App.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Bcl.AsyncInterfaces.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Ribbon.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Characters.Rendering.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\de-DE\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Reactive.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.ThreeSixty.Facade.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Configuration.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.ThreeSixty.App.ViewModel.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vccorlib140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Options.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.IdentityModel.Tokens.Jwt.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Text.Encodings.Web.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Remoting.Client.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.SharedInterfaces.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Collections.Immutable.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140u.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Windows.Forms.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.App.ViewModel.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.EventLog.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Win32.TaskScheduler.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.ThreeSixty.Facade.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Analytics.NET.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Text.Json.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\StreamJsonRpc.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.App.View.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate 360 Desktop App.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\resvg_net.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140enu.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcruntime140_threads.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.DataModel.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\MessagePack.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.MemoryManagement.Platform.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.Desktop.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbahost.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Doubles.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4FBA.tmpJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Castle.Core.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140ita.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.ThreeSixty.App.ViewModel.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.VisualStudio.Threading.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6E9E.tmpJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\de-DE\Articulate.ContentLibrary.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140chs.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.Wpf.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.Wpf.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Drawing.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Bootstrapper.Application.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.ThreeSixty.App.ViewModel.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\concrt140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Memory.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.ThreeSixty.App.View.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_1.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.IdentityModel.Tokens.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Forms.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140fra.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Ben.Demystifier.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Diagnostics.DiagnosticSource.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.Wpf.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\fr-FR\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcomp140.dllJump to dropped file
      Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\MSI5AC7.tmp-\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Core.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\MessagePack.Annotations.dllJump to dropped file
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140rus.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Nerdbank.Streams.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfcm140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\de-DE\Articulate.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Remoting.Server.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Desktop.InstalledPackages.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\BootstrapperCore.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.NET.StringTools.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Threading.Tasks.Extensions.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.CustomActions.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Logging.Abstractions.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Runtime.CompilerServices.Unsafe.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_atomic_wait.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}\DesktopAppIcon.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Core.XmlSerializers.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Composition.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.TraceSource.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\fr-FR\Articulate.ContentLibrary.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.ThreeSixty.App.View.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Remoting.Model.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcruntime140.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Desktop.InstalledPackages.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140kor.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_codecvt_ids.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Win32.Registry.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Autofac.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Facade.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Wpf.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Model.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.ServiceLocation.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\IdentityModel.OidcClient.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\fr-FR\Articulate.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_2.dllJump to dropped file
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\wixstdba.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\VisualCPlusPlusRedistributablex86Jump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Api.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Platform.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\es\Articulate.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Numerics.Vectors.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Threading.Tasks.Dataflow.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\BouncyCastle.Cryptography.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\Newtonsoft.Json.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\IdentityModel.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Articulate\360\Desktop Service\de-DE\Articulate.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exePE file moved: C:\ProgramData\Package Cache\.unverified\VisualCPlusPlusRedistributablex86
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140esn.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140ita.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Interactivity.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\System.Windows.Interactivity.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140deu.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6E9E.tmpJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcamp140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140jpn.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140chs.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfcm140u.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\es\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Bootstrapper.Application.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\concrt140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_1.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140fra.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\fr-FR\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcomp140.dllJump to dropped file
      Source: C:\Windows\SysWOW64\rundll32.exeFile created: C:\Windows\Installer\MSI5AC7.tmp-\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140rus.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbapreq.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140cht.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.PubSubEvents.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfcm140.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\de-DE\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\BootstrapperCore.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vccorlib140.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.CustomActions.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}\DesktopAppIcon.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_atomic_wait.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Composition.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.SharedInterfaces.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140u.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcruntime140.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Desktop.InstalledPackages.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Win32.TaskScheduler.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140kor.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_codecvt_ids.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.ServiceLocation.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\msvcp140_2.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\VisualCPlusPlusRedistributablex86Jump to dropped file
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\wixstdba.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\mfc140enu.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\vcruntime140_threads.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.Desktop.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbahost.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4FBA.tmpJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\VisualCPlusPlusRedistributablex86Jump to dropped file
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeFile created: C:\ProgramData\Articulate\360\Logs\InstallerService_STABLE_20241022_045641.log
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1028\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1029\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1031\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1036\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1040\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1041\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1042\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1045\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1046\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1049\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\1055\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\2052\license.rtf
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeFile created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\3082\license.rtf

      Boot Survival

      barindex
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeFile created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Win32.TaskScheduler.dll
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeRegistry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
      Source: C:\Windows\System32\SrTasks.exeRegistry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
      Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Articulate 360.lnk
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {b7197944-fc91-43ad-bcc0-233e39733206}
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {b7197944-fc91-43ad-bcc0-233e39733206}
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {b7197944-fc91-43ad-bcc0-233e39733206}
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {b7197944-fc91-43ad-bcc0-233e39733206}
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {46c3b171-c15c-4137-8e1d-67eeb2985b44}
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {46c3b171-c15c-4137-8e1d-67eeb2985b44}
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {46c3b171-c15c-4137-8e1d-67eeb2985b44}
      Source: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {46c3b171-c15c-4137-8e1d-67eeb2985b44}
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeProcess information set: NOOPENFILEERRORBOX
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeMemory allocated: 2BF0000 memory reserve | memory write watch
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeMemory allocated: 3CC0000 memory reserve | memory write watch
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeMemory allocated: 2EC0000 memory reserve | memory write watch
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeMemory allocated: 1070000 memory reserve | memory write watch
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeMemory allocated: 11E0000 memory reserve | memory write watch
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeMemory allocated: 31E0000 memory reserve | memory write watch
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeMemory allocated: 1460000 memory reserve | memory write watch
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeMemory allocated: 3450000 memory reserve | memory write watch
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeMemory allocated: 3250000 memory reserve | memory write watch
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeThread delayed: delay time: 922337203685477
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeThread delayed: delay time: 922337203685477
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 922337203685477
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 922337203685477
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeWindow / User API: threadDelayed 9681
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeWindow / User API: threadDelayed 6933
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeWindow / User API: threadDelayed 2781
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Svg.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140esn.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.VisualStudio.Validation.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Interactivity.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.DependencyInjection.Abstractions.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\YurlDotNet.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\System.Windows.Interactivity.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140deu.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\vcamp140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Bridgewater.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140jpn.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.ThreeSixty.Facade.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.IO.Pipelines.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\ICSharpCode.SharpZipLib.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfcm140u.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Platform.DirectWrite.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\ResvgNet.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\es\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Core.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\es\Articulate.ContentLibrary.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.ThreeSixty.App.View.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate 360 Desktop App.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Net.Http.Formatting.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.Common.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Reflection.Metadata.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Xaml.Behaviors.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.IntelPrimitives.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.IdentityModel.Logging.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Buffers.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.ValueTuple.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbapreq.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140cht.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.PubSubEvents.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate 360 Desktop App.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Bcl.AsyncInterfaces.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Ribbon.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Characters.Rendering.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\de-DE\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Reactive.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.ThreeSixty.Facade.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Configuration.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.ThreeSixty.App.ViewModel.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\vccorlib140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Options.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Text.Encodings.Web.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.IdentityModel.Tokens.Jwt.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Remoting.Client.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.SharedInterfaces.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Collections.Immutable.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\msvcp140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140u.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.App.ViewModel.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Windows.Forms.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.EventLog.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Win32.TaskScheduler.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.ThreeSixty.Facade.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Analytics.NET.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Text.Json.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\StreamJsonRpc.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.App.View.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate 360 Desktop App.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140enu.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\resvg_net.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.DataModel.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\vcruntime140_threads.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\MessagePack.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.MemoryManagement.Platform.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.Desktop.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbahost.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Doubles.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI4FBA.tmpJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Castle.Core.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140ita.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.ThreeSixty.App.ViewModel.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.VisualStudio.Threading.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI6E9E.tmpJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\de-DE\Articulate.ContentLibrary.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140chs.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\fr-FR\Articulate.Wpf.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.Wpf.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Drawing.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Bootstrapper.Application.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.ThreeSixty.App.ViewModel.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\concrt140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Memory.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate.ThreeSixty.App.View.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\msvcp140_1.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.IdentityModel.Tokens.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Forms.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140fra.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Ben.Demystifier.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Diagnostics.DiagnosticSource.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.Wpf.resources.dllJump to dropped file
      Source: C:\Windows\SysWOW64\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\MSI5AC7.tmp-\Microsoft.Win32.TaskScheduler.resources.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\fr-FR\Articulate.Bootstrapper.Application.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\vcomp140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Core.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140rus.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\MessagePack.Annotations.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Nerdbank.Streams.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfcm140.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\de-DE\Articulate.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Remoting.Server.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Desktop.InstalledPackages.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\BootstrapperCore.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.NET.StringTools.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Threading.Tasks.Extensions.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.CustomActions.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Runtime.CompilerServices.Unsafe.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Logging.Abstractions.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\WixToolset.Dtf.WindowsInstaller.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}\DesktopAppIcon.exeJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\msvcp140_atomic_wait.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Core.XmlSerializers.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Composition.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.TraceSource.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\es\Articulate.ThreeSixty.App.View.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\fr-FR\Articulate.ContentLibrary.Resources.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Remoting.Model.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\vcruntime140.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Desktop.InstalledPackages.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\mfc140kor.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\msvcp140_codecvt_ids.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Win32.Registry.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Autofac.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Facade.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Wpf.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Model.dllJump to dropped file
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeDropped PE file which has not been started: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.ServiceLocation.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\IdentityModel.OidcClient.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\fr-FR\Articulate.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\msvcp140_2.dllJump to dropped file
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeDropped PE file which has not been started: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\wixstdba.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Api.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Platform.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\es\Articulate.resources.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Numerics.Vectors.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Threading.Tasks.Dataflow.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\BouncyCastle.Cryptography.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\Newtonsoft.Json.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\IdentityModel.dllJump to dropped file
      Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Articulate\360\Desktop Service\de-DE\Articulate.resources.dllJump to dropped file
      Source: C:\Windows\System32\SrTasks.exe TID: 6700Thread sleep time: -290000s >= -30000s
      Source: C:\Windows\System32\SrTasks.exe TID: 6784Thread sleep time: -280000s >= -30000s
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe TID: 7056Thread sleep time: -922337203685477s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe TID: 2516Thread sleep time: -9223372036854770s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe TID: 2516Thread sleep time: -30000s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe TID: 1928Thread sleep count: 87 > 30
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe TID: 1928Thread sleep count: 9681 > 30
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -10145709240540247s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -100000s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -99872s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 5912Thread sleep count: 6933 > 30
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 5912Thread sleep count: 2781 > 30
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -99762s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -99650s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -99542s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -99475s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 2116Thread sleep time: -30000s >= -30000s
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe TID: 4832Thread sleep time: -922337203685477s >= -30000s
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile Volume queried: C:\Windows FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeThread delayed: delay time: 922337203685477
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeThread delayed: delay time: 922337203685477
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeThread delayed: delay time: 30000
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 922337203685477
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 100000
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 99872
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 99762
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 99650
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 99542
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 99475
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 30000
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeThread delayed: delay time: 922337203685477
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\NULL
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL
      Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess token adjusted: Debug
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeProcess token adjusted: Debug
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeMemory allocated: page read and write | page guard
      Source: C:\Users\user\Desktop\articulate-360.exeProcess created: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe "C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe" -burn.clean.room="C:\Users\user\Desktop\articulate-360.exe" -burn.filehandle.attached=520 -burn.filehandle.self=528
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeProcess created: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe "C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe" -q -burn.elevated BurnPipe.{2F0C2B53-B19F-40D3-85E6-CA669222AE1F} {FCE9E140-D8F2-4827-9147-38CAF241950C} 6984
      Source: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exeProcess created: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe "C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" /quiet /norestart
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeProcess created: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe "C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe" -burn.clean.room="C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" -burn.filehandle.attached=536 -burn.filehandle.self=532 /quiet /norestart
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeProcess created: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe "C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{8FA64B99-084F-4A69-A6FF-A0E7A184ECCB} {DC705CDD-8D74-4A36-AC9D-66771471949A} 6160
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeProcess created: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe "c:\windows\temp\{902f5521-81a4-4ea4-b59e-2dd7517c3955}\.cr\vc_redist.x86.exe" -burn.clean.room="c:\programdata\package cache\ab4a97610b127d68c45311deabfbcd8aa7066f4b\vc_redist.x86.exe" -burn.filehandle.attached=536 -burn.filehandle.self=532 /quiet /norestart
      Source: C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exeProcess created: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe "c:\windows\temp\{902f5521-81a4-4ea4-b59e-2dd7517c3955}\.cr\vc_redist.x86.exe" -burn.clean.room="c:\programdata\package cache\ab4a97610b127d68c45311deabfbcd8aa7066f4b\vc_redist.x86.exe" -burn.filehandle.attached=536 -burn.filehandle.self=532 /quiet /norestart
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\BootstrapperCore.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Bootstrapper.Application.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.CustomActions.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Desktop.InstalledPackages.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ObjectModel\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ObjectModel.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.PubSubEvents.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.SharedInterfaces.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Threading.Tasks\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Threading.Tasks.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Linq.Expressions\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Linq.Expressions.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Reflection\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Reflection.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Threading\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Threading.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Resources.ResourceManager\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Resources.ResourceManager.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Collections\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Collections.dll VolumeInformation
      Source: C:\Windows\System32\SrTasks.exeQueries volume information: C:\ VolumeInformation
      Source: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exeQueries volume information: C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\logo.png VolumeInformation
      Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
      Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
      Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.Abstractions.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Options.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ValueTuple\v4.0_4.0.0.0__cc7b13ffcd2ddd51\System.ValueTuple.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Configuration.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Autofac.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\netstandard\v4.0_2.0.0.0__cc7b13ffcd2ddd51\netstandard.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Bcl.AsyncInterfaces.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Threading.Tasks.Extensions.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Doubles.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Model.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.TraceSource.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Diagnostics.DiagnosticSource.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.DataModel.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.MemoryManagement.Platform.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.MemoryManagement.Platform.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.MemoryManagement.Platform.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.VisualStudio.Threading.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.VisualStudio.Validation.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Reactive.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Analytics.NET.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Newtonsoft.Json.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.Common.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exe VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Logging.Abstractions.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Logging.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Options.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ValueTuple\v4.0_4.0.0.0__cc7b13ffcd2ddd51\System.ValueTuple.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Configuration.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Autofac.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\netstandard\v4.0_2.0.0.0__cc7b13ffcd2ddd51\netstandard.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Bcl.AsyncInterfaces.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Threading.Tasks.Extensions.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Remoting.Model.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Remoting.Server.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.VisualStudio.Threading.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Model.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Doubles.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.Extensions.Logging.TraceSource.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Diagnostics.DiagnosticSource.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Api.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ThreeSixty.Core.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.DataModel.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.MemoryManagement.Platform.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.MemoryManagement.Platform.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.MemoryManagement.Platform.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Mindscape.Raygun4Net.NetCore.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Mindscape.Raygun4Net.NetCore.Common.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Reactive.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Analytics.NET.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Newtonsoft.Json.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.VisualStudio.Validation.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Management\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Core.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.IdentityModel.Tokens.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\IdentityModel.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Net.Http.WebRequest\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Net.Http.WebRequest.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Net.Http.Formatting.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\YurlDotNet.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Remoting\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Memory.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Runtime.CompilerServices.Unsafe.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Buffers.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\StreamJsonRpc.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Characters.Rendering.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\MessagePack.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Nerdbank.Streams.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.IO.Pipelines.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Collections.Immutable.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Microsoft.NET.StringTools.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\MessagePack.Annotations.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Reflection.Emit\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Reflection.Emit.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Reflection.Emit.ILGeneration\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Reflection.Emit.ILGeneration.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Reflection.Emit.Lightweight\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Reflection.Emit.Lightweight.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.Resources.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate.ContentLibrary.Resources.dll VolumeInformation
      Source: C:\Program Files (x86)\Articulate\360\Desktop Service\Articulate 360 Desktop Service.exeQueries volume information: C:\Program Files (x86)\Articulate\360\Desktop Service\System.Numerics.Vectors.dll VolumeInformation
      Source: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire Infrastructure1
      Drive-by Compromise
      1
      Command and Scripting Interpreter
      2
      Windows Service
      2
      Windows Service
      32
      Masquerading
      OS Credential Dumping1
      Process Discovery
      Remote ServicesData from Local System2
      Encrypted Channel
      Exfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomains1
      Replication Through Removable Media
      1
      Scheduled Task/Job
      1
      Scheduled Task/Job
      11
      Process Injection
      1
      Disable or Modify Tools
      LSASS Memory31
      Virtualization/Sandbox Evasion
      Remote Desktop ProtocolData from Removable Media1
      Non-Application Layer Protocol
      Exfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAt11
      Registry Run Keys / Startup Folder
      1
      Scheduled Task/Job
      31
      Virtualization/Sandbox Evasion
      Security Account Manager1
      Application Window Discovery
      SMB/Windows Admin SharesData from Network Shared Drive2
      Application Layer Protocol
      Automated ExfiltrationData Encrypted for Impact
      Employee NamesVirtual Private ServerLocal AccountsCron1
      DLL Side-Loading
      11
      Registry Run Keys / Startup Folder
      11
      Process Injection
      NTDS11
      Peripheral Device Discovery
      Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
      DLL Side-Loading
      1
      Rundll32
      LSA Secrets2
      File and Directory Discovery
      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
      DLL Side-Loading
      Cached Domain Credentials13
      System Information Discovery
      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
      File Deletion
      DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      articulate-360.exe0%ReversingLabs
      SourceDetectionScannerLabelLink
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Bootstrapper.Application.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.CustomActions.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Articulate.Desktop.InstalledPackages.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\BootstrapperCore.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Deployment.WindowsInstaller.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Composition.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Interactivity.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.Desktop.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.Mvvm.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.PubSubEvents.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.Prism.SharedInterfaces.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Practices.ServiceLocation.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\Microsoft.Win32.TaskScheduler.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\System.Windows.Interactivity.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\de-DE\Articulate.Bootstrapper.Application.resources.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\es\Articulate.Bootstrapper.Application.resources.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\fr-FR\Articulate.Bootstrapper.Application.resources.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbahost.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.ba\mbapreq.dll0%ReversingLabs
      C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe0%ReversingLabs
      C:\ProgramData\Package Cache\.unverified\VisualCPlusPlusRedistributablex86 (copy)0%ReversingLabs
      C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.ba\wixstdba.dll0%ReversingLabs
      C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe0%ReversingLabs
      5612bd.rbf (copy)0%ReversingLabs
      5612be.rbf (copy)0%ReversingLabs
      5612bf.rbf (copy)0%ReversingLabs
      5612c0.rbf (copy)0%ReversingLabs
      5612c1.rbf (copy)0%ReversingLabs
      5612c2.rbf (copy)0%ReversingLabs
      5612c3.rbf (copy)0%ReversingLabs
      5612c4.rbf (copy)0%ReversingLabs
      5612c5.rbf (copy)0%ReversingLabs
      5612ca.rbf (copy)0%ReversingLabs
      5612cb.rbf (copy)0%ReversingLabs
      5612cc.rbf (copy)0%ReversingLabs
      5612cd.rbf (copy)0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Installer Service.exe0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Bridgewater.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Configuration.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Doubles.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Drawing.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Resources.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Ribbon.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Forms.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Platform.DirectWrite.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.Platform.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Text.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.App.View.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.App.ViewModel.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Facade.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Model.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Remoting.Client.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.ThreeSixty.Remoting.Model.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Windows.Forms.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate.Wpf.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Autofac.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Ben.Demystifier.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\BouncyCastle.Cryptography.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Castle.Core.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\ICSharpCode.SharpZipLib.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\IdentityModel.OidcClient.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.EventLog.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.TraceSource.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.Extensions.Logging.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.NET.StringTools.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Microsoft.VisualStudio.Threading.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.Common.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Mindscape.Raygun4Net.NetCore.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\Nerdbank.Streams.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\System.Collections.Immutable.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\System.Reactive.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\System.Runtime.CompilerServices.Unsafe.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\System.Text.Encodings.Web.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\System.Text.Json.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\System.Threading.Tasks.Dataflow.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\WixToolset.Dtf.WindowsInstaller.dll0%ReversingLabs
      C:\Program Files (x86)\Articulate\360\Desktop Application\de-DE\Articulate 360 Desktop App.resources.dll0%ReversingLabs
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      NameIPActiveMaliciousAntivirus DetectionReputation
      kong.360.prod.art-internal.com
      54.81.144.153
      truefalse
        unknown
        ax-0001.ax-dc-msedge.net
        150.171.30.10
        truefalse
          unknown
          sessions.bugsnag.com
          35.190.88.7
          truefalse
            unknown
            scout.us1.salesloft.com
            54.196.48.215
            truefalse
              unknown
              ax-0001.ax-msedge.net
              150.171.28.10
              truefalse
                unknown
                fp2e7a.wpc.phicdn.net
                192.229.221.95
                truefalse
                  unknown
                  d3bv7d5w6owffv.cloudfront.net
                  18.173.205.103
                  truefalse
                    unknown
                    stats.g.doubleclick.net
                    74.125.71.156
                    truefalse
                      unknown
                      googleads.g.doubleclick.net
                      216.58.212.130
                      truefalse
                        unknown
                        d2i2rs86fcfw2m.cloudfront.net
                        13.33.187.86
                        truefalse
                          unknown
                          d2gt2ux04o03l1.cloudfront.net
                          18.245.31.35
                          truefalse
                            unknown
                            consent.api.osano.com
                            18.245.60.30
                            truefalse
                              unknown
                              l4-logs-http-rum-pub-s1-6386d34262e59173.elb.us-east-1.amazonaws.com
                              3.233.158.34
                              truefalse
                                unknown
                                360-okta-proxy.360.prod.art-internal.com
                                34.202.68.135
                                truefalse
                                  unknown
                                  www.google.com
                                  142.250.186.100
                                  truefalse
                                    unknown
                                    analytics.google.com
                                    216.58.206.78
                                    truefalse
                                      unknown
                                      metrics.articulate.com
                                      108.138.7.72
                                      truefalse
                                        unknown
                                        scout.salesloft.com
                                        unknown
                                        unknownfalse
                                          unknown
                                          id.articulate.com
                                          unknown
                                          unknownfalse
                                            unknown
                                            scout-cdn.salesloft.com
                                            unknown
                                            unknownfalse
                                              unknown
                                              px.ads.linkedin.com
                                              unknown
                                              unknownfalse
                                                unknown
                                                api.articulate.com
                                                unknown
                                                unknownfalse
                                                  unknown
                                                  cmp.osano.com
                                                  unknown
                                                  unknownfalse
                                                    unknown
                                                    snap.licdn.com
                                                    unknown
                                                    unknownfalse
                                                      unknown
                                                      rum.browser-intake-datadoghq.com
                                                      unknown
                                                      unknownfalse
                                                        unknown
                                                        cdn.articulate.com
                                                        unknown
                                                        unknownfalse
                                                          unknown
                                                          geo.articulate.com
                                                          unknown
                                                          unknownfalse
                                                            unknown
                                                            NameMaliciousAntivirus DetectionReputation
                                                            https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9ENXdWU3J1ZXg0SzNZVGNld2owIiwiY29kZV9jaGFsbGVuZ2VfbWV0aG9kIjoiUzI1NiIsImNsaWVudF9pZCI6IjBvYWFqemNzanBodm1EdElXMzU2Iiwic2NvcGUiOiJvcGVuaWQgb2ZmbGluZV9hY2Nlc3MgZW1haWwgcHJvZmlsZSBwcm9maWxlX25hbWUgdXNlcl9zdWJzY3JpcHRpb24gc3RhZmYiLCJyZWRpcmVjdF91cmkiOiJodHRwOi8vMTI3LjAuMC4xOjQ5MzYwLyIsInJlc3BvbnNlX21vZGUiOiJmb3JtX3Bvc3QiLCJkYXRhIjoiZXlKMlpYSnphVzl1SWpvaU1TNDRPUzR6TWpZeE9DNHdJaXdpYzNSaGRHVWlPaUkyTURJMlkyUmlNakl5TVRJM05tWmpaVFZoTmpJME9EQmtNalkzWmpJM1lTSXNJbWx1YzNSaGJHeGhkR2x2Ymtsa0lqb2lNall3WmpJeE5UVTVZVGd6TkdRek1EbGxZamc0TUdaa09URmtOR0kwTlRFaWZRPT0ifX0=false
                                                              unknown
                                                              • No. of IPs < 25%
                                                              • 25% < No. of IPs < 50%
                                                              • 50% < No. of IPs < 75%
                                                              • 75% < No. of IPs
                                                              IPDomainCountryFlagASNASN NameMalicious
                                                              18.245.60.30
                                                              consent.api.osano.comUnited States
                                                              16509AMAZON-02USfalse
                                                              142.250.185.206
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              216.58.206.74
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              2.18.64.220
                                                              unknownEuropean Union
                                                              6057AdministracionNacionaldeTelecomunicacionesUYfalse
                                                              216.58.206.78
                                                              analytics.google.comUnited States
                                                              15169GOOGLEUSfalse
                                                              74.125.71.156
                                                              stats.g.doubleclick.netUnited States
                                                              15169GOOGLEUSfalse
                                                              18.245.31.78
                                                              unknownUnited States
                                                              16509AMAZON-02USfalse
                                                              52.2.87.7
                                                              unknownUnited States
                                                              14618AMAZON-AESUSfalse
                                                              35.190.88.7
                                                              sessions.bugsnag.comUnited States
                                                              15169GOOGLEUSfalse
                                                              34.202.68.135
                                                              360-okta-proxy.360.prod.art-internal.comUnited States
                                                              14618AMAZON-AESUSfalse
                                                              74.125.206.154
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              18.245.31.35
                                                              d2gt2ux04o03l1.cloudfront.netUnited States
                                                              16509AMAZON-02USfalse
                                                              52.204.181.23
                                                              unknownUnited States
                                                              14618AMAZON-AESUSfalse
                                                              150.171.30.10
                                                              ax-0001.ax-dc-msedge.netUnited States
                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                              13.33.187.86
                                                              d2i2rs86fcfw2m.cloudfront.netUnited States
                                                              16509AMAZON-02USfalse
                                                              150.171.28.10
                                                              ax-0001.ax-msedge.netUnited States
                                                              8075MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                              52.55.2.94
                                                              unknownUnited States
                                                              14618AMAZON-AESUSfalse
                                                              18.173.205.103
                                                              d3bv7d5w6owffv.cloudfront.netUnited States
                                                              3MIT-GATEWAYSUSfalse
                                                              216.58.212.130
                                                              googleads.g.doubleclick.netUnited States
                                                              15169GOOGLEUSfalse
                                                              142.250.186.136
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              54.81.144.153
                                                              kong.360.prod.art-internal.comUnited States
                                                              14618AMAZON-AESUSfalse
                                                              3.233.158.34
                                                              l4-logs-http-rum-pub-s1-6386d34262e59173.elb.us-east-1.amazonaws.comUnited States
                                                              14618AMAZON-AESUSfalse
                                                              104.16.72.105
                                                              unknownUnited States
                                                              13335CLOUDFLARENETUSfalse
                                                              1.1.1.1
                                                              unknownAustralia
                                                              13335CLOUDFLARENETUSfalse
                                                              54.196.48.215
                                                              scout.us1.salesloft.comUnited States
                                                              14618AMAZON-AESUSfalse
                                                              74.125.133.84
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              2.16.164.10
                                                              unknownEuropean Union
                                                              20940AKAMAI-ASN1EUfalse
                                                              216.58.206.66
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              142.250.185.110
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              13.107.42.14
                                                              unknownUnited States
                                                              8068MICROSOFT-CORP-MSN-AS-BLOCKUSfalse
                                                              3.214.192.165
                                                              unknownUnited States
                                                              14618AMAZON-AESUSfalse
                                                              13.33.187.127
                                                              unknownUnited States
                                                              16509AMAZON-02USfalse
                                                              104.16.71.105
                                                              unknownUnited States
                                                              13335CLOUDFLARENETUSfalse
                                                              239.255.255.250
                                                              unknownReserved
                                                              unknownunknownfalse
                                                              142.250.185.131
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              3.216.122.29
                                                              unknownUnited States
                                                              14618AMAZON-AESUSfalse
                                                              108.138.7.72
                                                              metrics.articulate.comUnited States
                                                              16509AMAZON-02USfalse
                                                              142.250.186.100
                                                              www.google.comUnited States
                                                              15169GOOGLEUSfalse
                                                              142.250.184.238
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              142.250.186.168
                                                              unknownUnited States
                                                              15169GOOGLEUSfalse
                                                              IP
                                                              192.168.2.17
                                                              Joe Sandbox version:41.0.0 Charoite
                                                              Analysis ID:1539190
                                                              Start date and time:2024-10-22 10:55:14 +02:00
                                                              Joe Sandbox product:CloudBasic
                                                              Overall analysis duration:
                                                              Hypervisor based Inspection enabled:false
                                                              Report type:full
                                                              Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                              Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                              Number of analysed new started processes analysed:38
                                                              Number of new started drivers analysed:0
                                                              Number of existing processes analysed:0
                                                              Number of existing drivers analysed:0
                                                              Number of injected processes analysed:0
                                                              Technologies:
                                                              • EGA enabled
                                                              Analysis Mode:stream
                                                              Sample name:articulate-360.exe
                                                              Detection:MAL
                                                              Classification:mal48.troj.evad.winEXE@27/335@58/110
                                                              Cookbook Comments:
                                                              • Found application associated with file extension: .exe
                                                              • Exclude process from analysis (whitelisted): dllhost.exe, VSSVC.exe, svchost.exe
                                                              • Excluded IPs from analysis (whitelisted): 184.28.90.27
                                                              • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, e16604.g.akamaiedge.net, ctldl.windowsupdate.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, fe3cr.delivery.mp.microsoft.com
                                                              • Not all processes where analyzed, report is missing behavior information
                                                              • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                              • Report size getting too big, too many NtOpenKeyEx calls found.
                                                              • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                              • Report size getting too big, too many NtQueryValueKey calls found.
                                                              • Report size getting too big, too many NtReadVirtualMemory calls found.
                                                              • Report size getting too big, too many NtSetInformationFile calls found.
                                                              • Report size getting too big, too many NtSetValueKey calls found.
                                                              • Timeout during stream target processing, analysis might miss dynamic analysis data
                                                              • VT rate limit hit for: articulate-360.exe
                                                              InputOutput
                                                              URL: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9E Model: claude-3-haiku-20240307
                                                              ```json
                                                              {
                                                                "contains_trigger_text": true,
                                                                "trigger_text": "Sign In",
                                                                "prominent_button_name": "Continue",
                                                                "text_input_field_labels": [
                                                                  "Email"
                                                                ],
                                                                "pdf_icon_visible": false,
                                                                "has_visible_captcha": false,
                                                                "has_urgent_text": false,
                                                                "has_visible_qrcode": false
                                                              }
                                                              URL: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9E Model: claude-3-haiku-20240307
                                                              ```json
                                                              {
                                                                "brands": [
                                                                  "Articulate"
                                                                ]
                                                              }
                                                              URL: https://id.articulate.com/#eyJhdXRob3JpemVRdWVyeSI6eyJyZXNwb25zZV90eXBlIjoiY29kZSIsIm5vbmNlIjoiZmEwNzhlN2RlMWJmMDgxODIyN2FhNjQzN2MzM2Q3ZjkiLCJzdGF0ZSI6IjM2NTE2NzZmOTc1ODhkZWVjNTJkMWI3ZDBhNmMzNGMwIiwiY29kZV9jaGFsbGVuZ2UiOiJwNnpYd24tOHp4QzQ4Z2FHamsxMHUwQU9E Model: gpt-4o
                                                              ```json{  "legit_domain": "articulate.com",  "classification": "known",  "reasons": [    "The URL 'id.articulate.com' is a subdomain of 'articulate.com', which is the legitimate domain for the brand Articulate.",    "Articulate is a known brand, primarily associated with e-learning software.",    "The URL does not contain any suspicious elements such as misspellings, extra characters, or unusual domain extensions.",    "The presence of an 'Email' input field is typical for login or account-related pages, which aligns with the subdomain 'id' suggesting identity or login services."  ],  "riskscore": 1}
                                                              URL: id.articulate.com
                                                                          Brands: Articulate
                                                                          Input Fields: Email
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3D0EA6BA3551AEC4717AB2827319A741
                                                              SHA1:E1273BA1B3D6CDBF93C99B115EF8ACCD84568718
                                                              SHA-256:1573721C06F70D779F5AEBA175C039202069DA15D8526C3CE0C19B8C7FA985B1
                                                              SHA-512:BADE3D768BF435C0ADD77BA377866A59146D22E102932FBEAB08FC10B27B9F5BCC5375ED26EE48847FB57649D706FF2AD6192895780C6924E34CAA7FCCA3514A
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........z[.s)[.s)[.s)..r(Y.s)R..)Q.s)].r(^.s)[.r).s)].w(P.s)].p(\.s)].v(..s)].s(Z.s)]..)Z.s)].q(Z.s)Rich[.s)........PE..L...+............."!...&.&...x..............@......................................Jc....@A.............................K.. ...........................PP.......*...;..T...........................(;..@............................................text...\$.......&.................. ..`.data....4...@...2...*..............@....idata...............\..............@..@.rsrc................n..............@..@.reloc...*.......,...r..............@..B........................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C766CA0482DFE588576074B9ED467E38
                                                              SHA1:5AC975CCCE81399218AB0DD27A3EFFC5B702005E
                                                              SHA-256:85AA8C8AB4CBF1FF9AE5C7BDE1BF6DA2E18A570E36E2D870B88536B8658C5BA8
                                                              SHA-512:EE36BC949D627B06F11725117D568F9CF1A4D345A939D9B4C46040E96C84159FA741637EF3D73ED2D01DF988DE59A573C3574308731402EB52BAE2329D7BDDAC
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........O.$...w...w...w.\.v...w.V@w...w..v...w...w...w..v...w..v...w..vD..w..v...w.,w...w..v...wRich...w........................PE..L....4.w.........."!...&.....z...............0.......................................=....@A.........................S......8c..........................xO.......4...U..T...........................8U..@............`..0............................text...b........................... ..`.data....&...0......................@....idata..0....`.......0..............@..@.rsrc................H..............@..@.reloc...4.......6...L..............@..B........................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B262A68778D6117D77DFD88A7F43CA44
                                                              SHA1:839DE1D7BCFB4D91736707194B5F94BFF9285AFC
                                                              SHA-256:A7ED4A417F0C50578F2CA2C5106004DD82F78DD3658A852B37147FC362716667
                                                              SHA-512:4F417D12A86D19773D47BDD50D97BF975EADDF1DBBDFF72EA6EA9BA164E47503CD4BB4FFD9C308567EC1CE0A23C024C24BD8647AAFB68CEC4F747CE668296E28
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........B.I.,.I.,.I.,.-.K.,.@...M.,.OP(.C.,.OP/.H.,.I.-.a.,.OP-.L.,.OP).].,.OP,.H.,.OP..H.,.OP..H.,.RichI.,.................PE..L......+.........."!...&............@........0...............................p.......b....@A.........................*..J....@..x....P...............2..PP...`..x.......T...........................X...@............@...............................text............................... ..`.data........0....... ..............@....idata.......@.......$..............@..@.rsrc........P.......*..............@..@.reloc..x....`......................@..B................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:60BF20C3CC7A98169465CD85EE833D67
                                                              SHA1:D562FD487CDBA1EEBAD05D39DF4E143ACD9A50F1
                                                              SHA-256:3EEE52D6389E9F12FA38F71247656C414BA675A96F7FA9987ED598F5963711DB
                                                              SHA-512:D7A7859A86EECAADFDF6F5001595A331F5FDEC16112C5B9B6A314EB55C9EF49966A74F45E4EAA9912B0F2FD76E867C2AAAD4698B396989EB6532AFE53E4E8F67
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........>H..P...P...P.u.Q...P.......P..sT...P..sS...P...Q...P..sQ...P..sU...P..sP...P..s....P..sR...P.Rich..P.................PE..L...~.b.........."!...&.....~............... ......................................q.....@A............................@....Q.......`...................P...p...A...N..T........................... N..@............P...............................text...P........................... ..`.data...H&... ...$..................@....idata..6....P......................@..@.rsrc........`.......>..............@..@.reloc...A...p...B...B..............@..B................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C1FF4738F68A0570720F695B5A4837B9
                                                              SHA1:C7BA41BA8049409D2EA5A3B4DABC2499837CD60F
                                                              SHA-256:1B940CE6E0791B41538F475FF97FCD04156C2CAB924557199B57736D7EA510D5
                                                              SHA-512:EDB1FD8EFB8B45474F43472A88A404329C0E756E1EFD9F3FB1EF2C800CDF64BA705CC7A339650CF0E2978E8D38FE42A16CCC86FAAF6630986E3E2E01BB03E632
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........u.:...i...i...iJf.h...i.l.i...i...h...i...h...i...i...i...h...i...h...i...h...i..ei...i...h...iRich...i................PE..L....9..........."!...&.J.......... E.......`............................... ............@A........................`S..D............................f..PP......\.......T...............................@............................................text....H.......J.................. ..`.data...<....`.......N..............@....idata...............P..............@..@.rsrc................Z..............@..@.reloc..\............`..............@..B................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D90414F90993F195846C25140D47566B
                                                              SHA1:3D3EF684D63BC62EEF8CBE09EAF0EE88159FC17C
                                                              SHA-256:AF5645D93635823702F00E12C0C8D68EEA5D2F20EDCEBFDCF5E076E50A9CB64A
                                                              SHA-512:BD4D3E4681D766449F743A924783154A5916A85FFB72F2F0EF43EBBF8380869D58CED6F56E31534F8B70FEBD4EF5DE47A9B1760478966C5D26ACCD7173FDE45F
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A..[.....................\......i...............i.......i.......i.......i.......i0......i......Rich............PE..L.....8.........."!...&............@........0...............................p.......=....@A........................."../...p@..P....P...............&..PP...`..L.......T...........................H...@............@..h............................text............................... ..`.data........0......................@....idata..x....@......................@..@.rsrc........P......................@..@.reloc..L....`.......$..............@..B........................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:934C75ADFF9036378FD34F526C6641A1
                                                              SHA1:0B9572EBE4FC49EF2DEF824327EFCAF9C9B90DAF
                                                              SHA-256:B4652ED190EEBF59D4CA8BB340CADFBCFBB7A32ABB893D57AC49B1F22CFA0861
                                                              SHA-512:A00B1BF0F10437A680C332E2FCE287C194B3CF666E985ACF047CEBE755596B15F99BAD5252B6A2244AE8805E24218ACA2A898E63C28CCF515D75232410ADD6E2
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........s...........j&........................N`......................J.........Rich....................PE..L...~..w.........."!...&.*.......... ........@...............................@......=.....@A........................p....=..............................pP......xY.. K..T...........................`J..@............................................text....).......*.................. ..`.data....p...@...n..................@....idata..............................@..@.rsrc...............................@..@.reloc..xY.......Z..................@..B........................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1BB877A36D2FCF866A79433D318A38C7
                                                              SHA1:ADF05679B78D0B15342CDFB4B5FA03C6FD7A140B
                                                              SHA-256:2FA5C0FA42036A1891A4824C41842869820BA6251D9BA39631B2F41636CC474F
                                                              SHA-512:B89BBCEBF968FD8D8038C4D61664ABF0AEDA77D15C1E8DD7083347272A1BBB22178A5DC6EFC20D428A38A7625B702C9BEE922A10C3BDE3F20A2DD043506152EF
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........3.5.R.f.R.f.R.fX .g.R.fX .g.R.fX .g.R.f..g.R.f..g.R.f..g.R.fX .g.R.f.R.f.R.f..g.R.f..g.R.f..hf.R.f..g.R.fRich.R.f........................PE..L.....'..........."!...&.....L...............................................p......Z.....@......................... .......`!..(....0...............(..pP...P..L....p..T...........................Po..@............ ..X............................text............................... ..`.data...T...........................@....idata..$.... ......................@..@.rsrc........0......................@..@.reloc..L....P......................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9C133B18FA9ED96E1AEB2DA66E4A4F2B
                                                              SHA1:238D34DBD80501B580587E330D4405505D5E80F2
                                                              SHA-256:C7D9DFDDBE68CF7C6F0B595690E31A26DF4780F465D2B90B5F400F2D8D788512
                                                              SHA-512:D2D588F9940E7E623022ADEBEBDC5AF68421A8C1024177189D11DF45481D7BFED16400958E67454C84BA97F0020DA559A8DAE2EC41950DC07E629B0FD4752E2F
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................2........I..............o.......o.......o.......o.......o%......o......Rich............PE..L....s............"!...&............P........................................P...........@A........................@........ .......0...................O...@.......$..T............................#..@............ ...............................text...T........................... ..`.data...d...........................@....idata....... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:968006878A0703C6D528C315AAA64E92
                                                              SHA1:EDCC9FBA54F81ABB6162C6FEC2A56AE0472EDF68
                                                              SHA-256:20F9A3BDBE5981EE42E2665623BFE342BFAC18BA7209E889ABDA2FE88AD7EC3D
                                                              SHA-512:961D49A5529F833A03FC3A117EE4379D9AD8F17C2780A42796D9C775577CA31A5CFD4E66C0FDDE6DA3E41AF0E0B2DB655ADAB32E5041107EE31F169FF1C45CFB
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......I.....y...y...y..|...y..~...y..}...y.......y..ix...y..i}...y..iz...y..x...y...x...y..i|...y..ip..y..iy...y..i....y..i{...y.Rich..y.........PE..L...v............"!...&.^/..n........*......p/...............................J.......J...@A.................................]0.......0.`.............I..O...`F.....?..T...........................@4..@............P0.....h|.......................text....\/......^/................. ..`.data...$....p/......b/.............@....idata...T...P0..V....0.............@..@.didat........0......Z0.............@....rsrc...`.....0......^0.............@..@.reloc......`F.......E.............@..B................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:EC9829B23C2E5A7029AC2F9F81924EFA
                                                              SHA1:9B7400EE4282E4655C0CD5F54C41D3AE14095434
                                                              SHA-256:28EB2E4DE14C90B303E13EAFF2E65A4D57E4F5E220BD34CEB858D745A02BDF94
                                                              SHA-512:7B2831CA2CDE03F3F12240AE5F18386BBC1D6DA2B66A550515800E8A1947BC64F077EAF498E63CC3E1CAF39986CFEEB886F43562C0D451D8C54C196F4AF58662
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........W.M.9.M.9.M.9..<.L.9..>.L.9..=.W.9.D...Y.9.Ki8.O.9.Ki=.A.9.Ki:.G.9..8.^.9.M.8..9.Ki<.Z.9.Ki0...9.Ki9.L.9.Ki..L.9.Ki;.L.9.RichM.9.........PE..L...z............."!...&../..p.......*+......./...............................J.....V.J...@A........................P...L.....0......@1.`.............I.xO....F.\.......T............................5..@.............0..............................text...../......./................. ..`.data........./......./.............@....idata..JS....0..T...p0.............@..@.didat.......01.......0.............@....rsrc...`....@1.......0.............@..@.reloc..\.....F......`F.............@..B................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:ABF14CC1A720FF3968911F6FD2E6DD7E
                                                              SHA1:175ADE2E220DE9BF6C1595F9FF4A1E910F9B8C99
                                                              SHA-256:B6C3F35ABC2ED9B44CAEFEF8846A26C05D10B3619E298625B4D7891B16D8A539
                                                              SHA-512:AF0C6BEB089365A19181B27AA6C45656F409AFC36E1C76DCDB74DFDE70DFA75C8AD66442C4F94482A0BEBE96CCA4297E58FAABE2E92B77CEF77BBB1A1C538AAE
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........qT.}...}...}.......}.../...}.......}.......}.......}.......}.......}...}..~}.......}.......}.......}.......}..Rich.}..........................PE..L.....!..........."!...&.@...........N.......P...............................0............@.........................p.......0...........................pP... ..P...pU..T............................T..@............P..(............R..H............text...U?.......@.................. ..`.rdata..d....P.......D..............@..@.data...L...........................@....rsrc...............................@..@.reloc..P.... ......................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F0CE2D4BE2A728B2767E3F5100DDE8CA
                                                              SHA1:124CFABF98D386F47E3D73EBDD4960DFF8B20864
                                                              SHA-256:EEA420619FBDCA1468DFA825E832BA14A21DC0402EBE90E75DDF3903DF4B8C61
                                                              SHA-512:67543A966A31163D78C23BE4B83300F211A23F3B0DB61A6E3707F6106FEC0462C67D1898C8D086A1B7A59F89A0E089140AB163B666A21E9A7311DD0C5F856D7F
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........qT.}...}...}.......}.../...}.......}.......}.......}.......}.......}...}..~}.......}.......}.......}.......}..Rich.}..........................PE..L....3.+.........."!...&.@...........N.......P...............................0......t*....@.........................p.......0...........................PP... ..P...pU..T............................T..@............P..(............R..H............text...U?.......@.................. ..`.rdata..d....P.......D..............@..@.data...L...........................@....rsrc...............................@..@.reloc..P.... ......................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):19650
                                                              Entropy (8bit):5.418203322428527
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:71AA1A4F5D4475F39AC3FB1466FF0DA9
                                                              SHA1:900A783029A70118B139E7EF700F7731400331F3
                                                              SHA-256:880AD817CC3A1B2F92DA1438858BBD89084886E9E643C9F244149E1BA91D59D2
                                                              SHA-512:42970F6C17A4F9C5E7180F4B9F6D8F7299CE1FBCBBC6A35F37E70222BDA080789445F21D12B45BD74ECA43462AC22F31BC1F3D09FAD9E73A6FB6C78092BA927A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7};.Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135..vc_runtimeMinimum_x86.msi.@.....@o.&..@.....@........&.{83CEF352-ED74-4B1D-B0E7-96CDF4DA1C2D}.....@.....@.....@.....@.......@.....@.....@.......@....;.Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{E3819B64-3C56-3DD7-921D-00B011AD31DE}&.{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7}.@......&.{E8E39D3B-4F35-36D8-B892-4B28336FE041}&.{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7}.@......&.{F4F89385-AC80-4040-ADA6-06D37B69832E}&.{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7}.@......&.{A2AA960C-FD3C-3A6D-BD6F-14933011AFB3}&.{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7}.@......&.{A2E7203F-60C2-3D7E-8A46-DB3D381A2CE6}&.{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7}.@......&.{BC0399EF-5E9D-3C7C-BFF5-5E9A95C96DAF}&
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):20971
                                                              Entropy (8bit):5.329040474835542
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E83E14695F1D6D74DD57DFA1BC455A39
                                                              SHA1:43AB16C686FF2E23D0C3245E24F4DF7B3AF9AF4C
                                                              SHA-256:3C0CAB5C22E0E5E1E732624FCBA2EB5D73594FA752B89F299B745504E666446E
                                                              SHA-512:B88420BD4F5A7EF0D7C596777DB69A73AD1714BA98904295A197D39DAE2221F7AF82C95FDC3064227645AEDCCAA3D10FA05CB9B5B62B778995419FB0D2BA5F89
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{9C19C103-7DB1-44D1-A039-2C076A633A38}>.Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135..vc_runtimeAdditional_x86.msi.@.....@o.&..@.....@........&.{29E9ACD5-6C1B-48C9-A316-358656F83B42}.....@.....@.....@.....@.......@.....@.....@.......@....>.Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{E3819B64-3C56-3DD7-921D-00B011AD31DE}&.{9C19C103-7DB1-44D1-A039-2C076A633A38}.@......&.{4FD4AB8C-C57F-3782-9230-9CCA22153AD3}&.{9C19C103-7DB1-44D1-A039-2C076A633A38}.@......&.{46A1EA6B-3D81-3399-8991-127F7F7AE76A}&.{9C19C103-7DB1-44D1-A039-2C076A633A38}.@......&.{C94DDE19-CC70-3B9A-A6AF-5CA7340B9B9A}&.{9C19C103-7DB1-44D1-A039-2C076A633A38}.@......&.{946D6FA6-49BB-3415-AD2D-4D634C432CF0}&.{9C19C103-7DB1-44D1-A039-2C076A633A38}.@......&.{E533B148-A83A-3788-A763-0C6C4
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):48782
                                                              Entropy (8bit):5.858626416079435
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6F263D88BB43B41BC2A13BADFACFCAE8
                                                              SHA1:DEF7BB542EBCD517FD7B0316D07CFC2632451F1D
                                                              SHA-256:0E8BE8285E1C88A48A97B38AFBC5338EFB1F3B8016F523E2E72CF6671BA7D7AE
                                                              SHA-512:7A997CF1BA808EFFF5EDB2CC74A290941B6E25789AA6F8463A408AD07CEE11A205B3F83242C90F078ED2E241DA38D6B276AF59D87E1C03EB707B29322982FE37
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}..Articulate 360..Articulate.360.Package.msi.@.....@j.Y..@.....@........&.{C5D0A98E-A4FF-4ADA-8410-5E4BAF9F113F}.....@.....@.....@.....@.......@.....@.....@.......@......Articulate 360......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....WixCloseApplicationsDeferred....ProcessComponents..Updating component registration..&.{21121F44-691A-5083-8E96-D8F73FE91444}&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}.@......&.{A7E3FD72-8B67-5630-A386-F107B120C3EA}&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}.@......&.{A6E171AA-25D9-5B4E-B933-9AC492F17C64}&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}.@......&.{141C87D7-0345-5466-B7F1-DB37BD75DFEC}&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}.@......&.{96D730A7-3EBD-547C-AEF6-1152065EBD8E}&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}.@......&.{808B93DB-79BF-5505-BCA7-02A736B7C6E4}&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}.@......&.{1A7F2DB
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):455
                                                              Entropy (8bit):5.182981220355661
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:60AEA56641C5B6CED42D3A14AD325322
                                                              SHA1:2F3489A909FA69E6E40A19DE375A9000F75DCE55
                                                              SHA-256:01BC18EB6151A0C1BD4693BD9851B9722C6C0E10D2E2A3D1DAE4495411924BAD
                                                              SHA-512:A4BEB04273E3F1267DD324D76125DD5D3B9DAAC908706779E68F07D058CAA790EE6E5CEBA8E1C359D5A161EB79DAA36A3B4FDA1C0AC935FB23E8F233E4F24F3E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}..Articulate 360..Articulate.360.Package.msi.@.....@j.Y..@.....@........&.{C5D0A98E-A4FF-4ADA-8410-5E4BAF9F113F}.....@.....@.....@.....@.......@.....@.....@.......@......Articulate 360......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....CreateRegistryValuesAction....RegisterScheduledTaskAction...@.....@.....@....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text
                                                              Category:dropped
                                                              Size (bytes):341
                                                              Entropy (8bit):5.375486852343577
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B3FDE1C14B4DA2C1591624E6402C6162
                                                              SHA1:5E3295FB2CE512F6EAB88E778F424F728C3802AF
                                                              SHA-256:B4F719AED1FC3E9EE0CD61DFB9290A751DCE05A942BEE24ACAEA640D03813AFD
                                                              SHA-512:DA44CB236FA7C016FD2BB239A1D8DF7C0E074662ECB306471867B9CCB9AD63394756465909E7978471E9DD90B6EDB043ACC8562A9333B7A01075AF4EC652DC11
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.<?xml version="1.0" encoding="utf-8"?>.<Application xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">. <VisualElements ForegroundText="light" BackgroundColor="#4FBDF4" ShowNameOnSquare150x150Logo="on" Square150x150Logo="StartMenu\ThreeSixtyMedium.png" Square70x70Logo="StartMenu\ThreeSixtySmall.png"></VisualElements>.</Application>
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):455784
                                                              Entropy (8bit):5.469265754324763
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:53A59069B2CC644D2AA1DAEEC9AF9B3B
                                                              SHA1:79620B702710962840E89465D949363BD95FFEFC
                                                              SHA-256:1F8AAF7DA916B2BDB1919389A12391951369316131FF42AB09C018BB368DC6D8
                                                              SHA-512:8323F369B007F31233FCFA3CF95DC63340FC6BAFC208B75159CCD32BC5D3E4C506B14972F7A3B10BE7335F11FF6B7AFB3DB30C788F68DB9D06AB734FAC93A3C6
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf..............0.................. ........@.. ....................... ......&1....`.................................t...O.......................h(..........<................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......h'..D*...........Q................................................(....*^.(.......F...%...}....*:.(......}....*:.(......}....*2.{....o....*2.{....o....*.0..[........~....%-.&~......$...s....%.....s....}.....~....%-.&~......%...s....%.....s....}.....(....*^.. (......}......}....*..0..P.........(.....s ...(!...&.s"...(!...&.s#...(!...&.s$...(!...&..{.....{....s....(!...&*:.(......}....*..0..&.......s&......}......}.......'...s%...(&...*..(......}......}......}.......}..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):6435
                                                              Entropy (8bit):5.034793799707034
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A44A893B87DC144844989984DBB50F04
                                                              SHA1:95DF39EFBF5DB5CE40F9B2E632A4C8C7B0209EEC
                                                              SHA-256:9B3E95499E119F91ED6E472CA00F6E55D02F2B2708FD38D9B109BD3E789CCE3B
                                                              SHA-512:360DB69346B55863469A07755BEC9DBC99ED83659776D7A74C76A7B3E9AF8DB52E1A17C21BA10EA66FF4C830B459F2F7D01B96088E831E677EC68635C4DEBBA9
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <system.diagnostics>.. <sources>.. <source name="ApplicationLog" switchValue="Information"></source>.. <source name="Configuration" switchValue="Information"></source>.. <source name="ErrorReporting" switchValue="Error"></source>.. <source name="Installation" switchValue="Information"></source>.. <source name="ThreeSixtyClient" switchValue="Warning"></source>.. <source name="ThreeSixtyDesktopApplication" switchValue="Information"></source>.. <source name="ThreeSixtyInstallation" switchValue="Information"></source>.. <source name="ThreeSixtyRemoting" switchValue="Information"></source>.. <source name="ThreeSixtyOidcClient" switchValue="Verbose"></source>.. </sources>.. </system.diagnostics>.. <system.net>.. <defaultProxy useDefaultCredentials="true" />.. </system.net>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.8" />.. </startup>.. <r
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:MS Windows shortcut, Item id list present, Has Relative path, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
                                                              Category:dropped
                                                              Size (bytes):2481
                                                              Entropy (8bit):2.5813302613142404
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9998E645A8C1B4C8EFD1A0EE35DFA29F
                                                              SHA1:1E70178A43804D6ACC18422BD0562E131D2D83FA
                                                              SHA-256:088D4AEDF470641E5E534260352DBD70C1D6C4C2229ABCEDEC4A1AECEACCDA74
                                                              SHA-512:C7DD5EB1FB3529062D7FBB18C889E0A62C3F56B2A948E56394BA2BE5871ADF8B994A8D448D2A2852582F469501120BD73EDDACA168D6A9C6CB4AF0742E87826E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.P...........................................................P.O. .:i.....+00.../C:\...................V.1.....VY.F..Windows.@......OwHVY.G....3.....................}/8.W.i.n.d.o.w.s.....\.1.....VY.G..Installer.D......O.IVY.G...........................'..I.n.s.t.a.l.l.e.r.......1.....VY.G..{1D482~1..~......VY.GVY.G..............................{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.....r.2.h&..VY.G!.DESKTO~1.EXE..V......VY.GVY.G..............................D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.......W.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.N.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.........(LyJ,d[Q}96FN{74yHvfDesktopApp>[}JsY8X@QBqp9g2'0e@3........................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):256104
                                                              Entropy (8bit):5.371906006634162
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:161D9B1A3B37D56D15F53591B2478382
                                                              SHA1:A1D270C2B8DA784270A49CF92D9D6F51A4E36F74
                                                              SHA-256:E52182D1B2B722E4C044D01EB9EAD5426BEFDD0178FCCFC4D85909217A9A60FF
                                                              SHA-512:74A16399A05187B97C27BB1CF448C34162FB2012679C9F9621BAB9C02ED2575BEA6446E29D840153E44869A294C213F386EDD53D5AEAAE977B9B5AEDC2066B4F
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf..............0.................. ........@.. ....................... ............`.................................d...O.......................h(..........,................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........F.........'.....................................................(....*:.(......}....*:.(......}....*6.{.....o....*2.{....o....*2.{....o....*:.(......}....*....0...........{....o......&.{....o......*................6.{.....o....*2.{....o....*2.{....o....*v.s....%~....o ...%~....o!...*R#......^@("........*V.(......}......}....*.~#...r...pr...p($...~0...oV...,.~#...r#..p(...+(&...*('...*r.{.....{....o(...r...p()...*...0..d........{.....3.*~#...r...pr...p......%...s....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):4067
                                                              Entropy (8bit):5.0324369188590135
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3FB1A5E76D6B5A1587BFEDDDE154E387
                                                              SHA1:F1F7DE9A011E81E71B13A4C070C4636A81A6824E
                                                              SHA-256:B513C25BEE95900A56258056AD271C94D6F1F73CB1C75E3150D44231F3416402
                                                              SHA-512:A135FBCE2FAD3466D43F6221DFC92B783284C1FF098A0D099A06E563517626C0DB363F761F805946C0E3C049387484BA6A577ACD99B3D39E7CFBF9528B88BCDD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <system.diagnostics>.. <sources>.. <source name="ApplicationLog" switchValue="Information"></source>.. <source name="Configuration" switchValue="Information"></source>.. <source name="ErrorReporting" switchValue="Error"></source>.. <source name="Installation" switchValue="Information"></source>.. <source name="ThreeSixtyInstallation" switchValue="Information"></source>.. </sources>.. </system.diagnostics>.. <system.net>.. <defaultProxy useDefaultCredentials="true" />.. </system.net>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.8" />.. </startup>.. <runtime>.. <enforceFIPSPolicy enabled="false" />.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="Microsoft.Bcl.AsyncInterfaces" publicKeyToken="cc7b13ffcd2ddd51" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-7.0
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):842344
                                                              Entropy (8bit):5.874248302707682
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F318CB9DF66F66E514B684A68A63132F
                                                              SHA1:18696E86044BC996E16C382E5E02B65B4C254F84
                                                              SHA-256:632B9E79C195693F7539D474F3FF0EF86D9799D00599A00D0FB1C913F220DCD9
                                                              SHA-512:1EDF92FC387511F6DB3D4DDAEB43D5293A1568E25BDE14AF1AA5D3D88AC7EC2B23B4803C54A54D562914F127A96625DAFAFB3DBA9F7EE716E7058D9F710ED169
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...,..............!..0.................. ........... ....................... .......B....`.....................................O.......@...............h(..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...@...........................@..@.reloc..............................@..B........................H........R..pr..................0.........................................{?...*..{@...*V.(A.....}?.....}@...*...0..A........u........4.,/(B....{?....{?...oC...,.(D....{@....{@...oE...*.*.*. ..M )UU.Z(B....{?...oF...X )UU.Z(D....{@...oG...X*...0..b........r...p......%..{?......%q.........-.&.+.......oH....%..{@......%q.........-.&.+.......oH....(I...*..(J...*:.(J.....}....*....0...........(....,..(....,..*.(....,..(....,..*.o.....o....3..o........o....(K...*.u2...,..u2...,..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):112744
                                                              Entropy (8bit):6.11989198572612
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:15DD89014EFE966051329C27032DB9D6
                                                              SHA1:08A357612596B8404ADA90FFDF340A1BD119D396
                                                              SHA-256:C3AD59BE720F67FA02D4A4B03F2C26DD481C87DF48F01264EF297FBB5E784304
                                                              SHA-512:1808949D9FAF187857EB9C82A472A901E9A507AD45693BC8E654217C03D1D870E734A397D084CBBF5376648A295E00414BC56C6F08367F7CC177D0B65BA62E31
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..._.V..........." ..0.............^.... ........... ...............................Z....`.....................................O.......H...............h(..............T............................................ ............... ..H............text...d.... ...................... ..`.rsrc...H...........................@..@.reloc..............................@..B................=.......H........m...3..................|.........................................(....*^.(.......Q...%...}....*:.(......}....*:.(......}....*..{....*:.(......}....*:.( .....}....**.{.......*..0..*.......r...p.{...........(.......(!...o"...(#...*..~....3.*~.....($...,.*.......o%...(&...(....*f~.....($...,.~....*('...*.(....(....*.(....(....*.(....o%...*B(....o(...o)...*.0...........(*...&....&.....*....................*..*.(....*.(....*..( ...*.0..F........-..+..(+.....rC..p(,...-..r
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):42088
                                                              Entropy (8bit):6.266327471426039
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:2AA1B165F1A60DC691AB3D56044B80B0
                                                              SHA1:20BFA81CDA8D45082E3C34A8CF1F98ECDA82C964
                                                              SHA-256:325B5AC102B1F37F9EBCE82891BE429774D47F4A5F58B5D7CDCBE42FEE2D281D
                                                              SHA-512:3777D93BFB62806FC7D0B20F243BAD572E02283D2F39CEE839AC8A1F91D05A80FC775442D8EDD1941A0656346BA75AFC066D50008814F25F1D652FE92781D90A
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...\..............!..0..r..........R.... ........... ..............................D.....`.....................................O.......0............|..h(..............T............................................ ............... ..H............text...Xp... ...r.................. ..`.rsrc...0............t..............@..@.reloc...............z..............@..B................4.......H........-...`............................................................(....*:.(......}....*2(.....o....*2(.....o....*..(....*..()...*Fr...p(....(*...&*..(....*..(....*.(....*.(....*..(....*..{....*.(....*.(....*.(....*.(....*.(....*J.(.....s/...}....*..(....*..(....*.(....o ...*.(....o!...*.(....o"...*.(....o#...*..(....*"..($...*"..(%...*&...(&...**....('...*2......((...*:.(......})...*N.{)..........o*...*J.{)....o+........*2(,....o-...*2(,....o....*.(,...o/...*2(,....o0
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):452712
                                                              Entropy (8bit):6.579209109994679
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7907C6D9EA31F6C63E51BE64C1FC2711
                                                              SHA1:8A38301E00E0504520F99000AA4011A58B7122FF
                                                              SHA-256:929606BC8CC0AFE871369DF629FE7E1C759688292B419A57CCF7293930182BEC
                                                              SHA-512:D38B9BBE76B756F5E5D9C0BE09563541EE4D22612F57A0FABE221C90E2B38B6FBAE26013C2779B0679ECA638201BD2243E67E3E85243F204A0E4ECA8CA29F7A5
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...'.V............!..0...... ......*.... ........... ....................................`....................................O.......0...............h(..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...0...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):4196456
                                                              Entropy (8bit):6.276668211926548
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:BD10B6FDF7CAD44033368679EFF05831
                                                              SHA1:6BF95056D714578A44522E44BF635A1C7D309A59
                                                              SHA-256:50BF915B54C54FC265A0DF492001E729F926AA474C4B9536F042762279A05A5B
                                                              SHA-512:BF4882CD14CD5623962E028C3F5BF1D92F8260FB39AFC5FE9222B44FF666CCD7FE81A79D34C1D6E0D31B6335A16F5ADCD05D56C6EFE0BB97D3937E19B24F4356
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....5.............!..0...?...........?.. ....@...... .......................@@.......@...`.................................L.?.O.....@.8.............?.h(... @.....P.?.T............................................ ............... ..H............text.....?.. ....?................. ..`.rsrc...8.....@.......?.............@..@.reloc....... @.......?.............@..B..................?.....H.......(................b.. .;...?.......................................(....*:.(......}....*..0..<........(.....(....o..........(.....(.....o....t........,..(......*.........0.......0..6........(.....(....o..........(.....(......o.......,..(.....*...........+.......0..6........(.....(....o..........(.....(......o.......,..(.....*...........+.......0..1........(....o..........(.....(.....o .......,..(......*............%.......*J.(!....(....}....*:..(.....("...*.0..n.......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):439912
                                                              Entropy (8bit):6.127191409183356
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F85954989637D42EBE99A20F0DB7042A
                                                              SHA1:7B778177C3A5D097B76080C14A0890CE55CFBA0E
                                                              SHA-256:20E69105EFC76A494EED54C98A48E38F10CBCBA35A888FA35DC55071AD9E0C83
                                                              SHA-512:05A568E60F16A4E7DECE2472988B74317C43F500EE30DBCC6EB2E75A015A2E541544EC976608601551C2D2F246F5A2988EB1DE65EAEF4147F0A52DF48A2201C8
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....i............!..0.............N.... ........... ....................................`.....................................O.......(...............h(..............T............................................ ............... ..H............text...T.... ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B........................H........^...............|...#............................................(<...*^.(<..........%...}....*:.(<.....}....*:.(<.....}....*V.(=.....}......}....*..{.....3..{....o>...*.{.....3..{....o>...*.*....0...........{....-'..}.....{....,...{....o?...}.....(....*.{.....36.{....,..{....o@...,..*..}......{....oA...}.....(....*.{.....3..{....o@...,..*.*.*"..}....*V.(=.....}......}....*....0../........{.....o#...,..*.{.......+.....3..*..X....i2..*..0..,........{.....o$......3..{.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):72296
                                                              Entropy (8bit):6.324170084442499
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8FEF2B87B14E1019A422971E6386E265
                                                              SHA1:C3B71E28BEC9596CEC0FB1A360D0AF9C9E07B141
                                                              SHA-256:F576C3C9C3B4C113ED3DE3406D6C8A9CEACDD24F94424974C592B6F3CEF34ADC
                                                              SHA-512:5951ECC943BFABE251F64758CD4E4FE76B3E41A38D88610AD79372D7C3A9A932A84A53CB05F76C44CD294A1CB63ACC0D82EBF2934226A591188BEF1A4C5F4CC2
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!..0.................. ... ....... .......................`............`.....................................O.... ..8...............h(...@..........T............................................ ............... ..H............text........ ...................... ..`.rsrc...8.... ......................@..@.reloc.......@......................@..B........................H........l..T...........T.................................................(....*:.(......}....*..(....*.~....o....*..*..*.(....o....*.( ...o....*....0..........~....o!......("...*..0.. .......~....o#......($......(%...(&...*.('...*.~....((...*..*..*....0..........~)...o*......(+...*..*...0..........~)...o,......("...*..0..........~)...o-......(....*..0..........~)...o/......("...*..0..........~)...o0......("...*..0..........~)...o1......("...*..0..........~)...o2......("...*"
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):137320
                                                              Entropy (8bit):6.270412282239485
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F67043DBFC315340DC84120FC0530AB8
                                                              SHA1:7BB894513802AB9A50E7E0E2674F187E29C73F3A
                                                              SHA-256:E878EF78AC88D24EC60D875943170B19F86F643235D03E6883F5BB3C235AB41E
                                                              SHA-512:313A109622CE72FF3155CB48DDE739C0FB38F0D4A867927BD9D63CD6B765B6001807B6ACD562BAC89134B14E498021303D20F9CAB8C7BD8F72369C9C8216092A
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!..0.................. ... ....... .......................`......Fs....`.....................................O.... ..x...............h(...@......t...T............................................ ............... ..H............text........ ...................... ..`.rsrc...x.... ......................@..@.reloc.......@......................@..B........................H............"............................................................(&...*:.(&.....}....*..{....*..{....*>..}......}....*2.(....o....*..{....*.0...........(.......('...*..{....*2.(....o(...*..{....*..{....*..{....*..(....o)...o*....../...s+...(...+...0...s-...(...+*..(....o.....(....o/......1...s0...(...+*n.(....,..(.....o1...*"....*>..(.....Y( ...*....0.. ........(.....+....Y(#...-..*..Y...2..*Z.(......(.....Y( ...Y*..0...........(.......(2...*J.(.....(....o....*N.(...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):301672
                                                              Entropy (8bit):6.320480306295889
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:305B3C770335BC5CBBEC82C76B6ECFC5
                                                              SHA1:5D49E9F4C378EF88579C485B2ED782276BCCF2E5
                                                              SHA-256:DE53C15923108BB5BDFFAD2C1E0472E4FB47D7E21F4DE0D53AEE1019D480D8DA
                                                              SHA-512:96668F7050895460FB40A3DFDC92843F21C4C4011108535FAFBBA3B8670E7AAAF4565BDAE8CC51ADFE911D4D9ADAB36832C235DD1715F3F387FFB96ED94099F6
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............L...L...L..aL...L..aL...L..M...L..M...L..M...L..M...L..M...L..M...L...L...Lz..M...Lz..L...L..eL...Lz..M...LRich...L........................PE..L....%kf...........!.....r...........x....................................................@..................................f..........H............r..h(..............T...........................@...@...........................`...H............text....q.......r.................. ..`.rdata...............v..............@..@.data................Z..............@....rsrc...H............b..............@..@.reloc...............h..............@..B................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):397416
                                                              Entropy (8bit):6.2335327300685055
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7E50A72E4F7DB3912AAF32680D0BDF74
                                                              SHA1:6C1C0DDE6305C917E4C60708307D8AD9478F5348
                                                              SHA-256:C825E4FB12D483ABC121908DDD4B05C978BE66ED319D637D5DAF67F5E0D6BA6F
                                                              SHA-512:B624A3597911463F860E9CAEA8367A20B072C1BF40F38C4DDD14472735F78315CA274D995F8883D8308D0CAB4529AB4CF60DE5436714E07C714FACE959683D00
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...L.[............!..0.................. ........... .......................@......7.....`.....................................O....... ...............h(... ..........T............................................ ............... ..H............text........ ...................... ..`.rsrc... ...........................@..@.reloc....... ......................@..B........................H...........pm..........p.......(.........................................{I...*..{J...*V.(K.....}I.....}J...*...0..A........u;.......4.,/(L....{I....{I...oM...,.(N....{J....{J...oO...*.*.*. .... )UU.Z(L....{I...oP...X )UU.Z(N....{J...oQ...X*...0..b........r...p......%..{I......%q>....>...-.&.+...>...oR....%..{J......%q?....?...-.&.+...?...oR....(S...*..{T...*..{U...*V.(K.....}T.....}U...*.0..A........u@.......4.,/(L....{T....{T...oM...,.(N....{U....{U...oO...*.*.*. .@T. )UU.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):637544
                                                              Entropy (8bit):5.924399321429543
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5735BDFAD37949943BB7750560F9E854
                                                              SHA1:1878B5C5371B8D7579F47FCD4808B510A00997DB
                                                              SHA-256:6EFA93F7EAFC198CCC8D1C96B7AEB92C1E3F01E599B62A6F404BD710547DB0CC
                                                              SHA-512:5D82FF4811F82570D1054CAB87C9F8ECA332AFFA114FB33D9EFF5356128F3FFB314F8CC20362AB5760427C1E86166F5AC0731714FDC8BBCA5776CB6302F26A7E
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf...........!..0.............2.... ........... ..............................A.....`....................................O.......................h(........................................................... ............... ..H............text...8.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........K..l...................(.........................................(....*^.(.......v...%...}....*:.(......}....*:.(......}....*>. 4......(....*2......o....*:........o....*...0..,........o ...r...p $...........%...%....o!...t....*&...o"...*..(#...*...0..Z.........($....(...+(...+o'...&.(...+(...+&.(...+o(...(...+~w...%-.&~v.....O...s)...%.w...o*...&*..(+...*..*F.~....(,....~...*J.~......~...(-...*F.~....(,....~...*J.~......~...(-...*..0..........sP......}y....(......}x.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):644200
                                                              Entropy (8bit):6.773226514045122
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:856071692376D0177080B94DEF3A5014
                                                              SHA1:4B639ECDAE96A9FCF8A2516C2FE48ED7B450A2C5
                                                              SHA-256:111C86D895548BBA50E663D4B027B7570D916B5C59C17E722C04FFA297DD060D
                                                              SHA-512:D3AD6050E813EBE952F7265F3664C8C7E0274287993B25D38A35EC31FC81F4A5DF19A8EB12B28C15861333D5149D57AAD084C7110D1C0D585BDC13C14C50CC99
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!..0.................. ........... ....................... .......&....`.................................t...O.......................h(..........<................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H...........t{...............*............................................{-...*..{....*V.(/.....}-.....}....*...0..A........u........4.,/(0....{-....{-...o1...,.(2....{.....{....o3...*.*.*. ..8K )UU.Z(0....{-...o4...X )UU.Z(2....{....o5...X*...0..b........r...p......%..{-......%q.........-.&.+.......o6....%..{.......%q.........-.&.+.......o6....(7...*..{8...*:.(/.....}8...*....0..)........u..........,.(0....{8....{8...o1...*.*.*v |S.. )UU.Z(0....{8...o4...X*..0..:........rG.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):31848
                                                              Entropy (8bit):6.413024106409615
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6B1FEE5541F9696B371859ABC36D6D4B
                                                              SHA1:904DCD1469350771ED8BD77D5626C60C9C5DF522
                                                              SHA-256:BF05F72A7F35486DAE07DA5CAE6F7667C1AD6BDE92F51F8981EBEC1298C08F1E
                                                              SHA-512:C03344B09EC57140BDD5168DDF484B2F7FC60B96EA3F5503C79EA070A706AE0B6ABD4EE684BEE31E69D48D86974971056802B79DA90C43D7FA50A17A22D5FC01
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!..0..J...........h... ........... ....................................`..................................h..O.......X............T..h(..........lg............................................... ............... ..H............text....H... ...J.................. ..`.rsrc...X............L..............@..@.reloc...............R..............@..B.................h......H........(...6..........T_.......f........................................(....*:.(......}....*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*.~....*.......*..(....*..0..A.......(....,.r...ps....z.sG.....(....}....(.....{....o:...-.........(....(...+}.....(....(...+}....(....(...+...H...s....(...+(....(...+...I...s....(...+.{....o....~....%-.&~......F...s....%
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):153192
                                                              Entropy (8bit):6.226505565277279
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:63E73366F7BF6445EF3D7B442A74BC92
                                                              SHA1:2F25E091AF96B99773268697D341FE05063D64D8
                                                              SHA-256:6007EA53354240D239001B45FDDB40E0F3E760195975DD16CFD1E2EF74A1235D
                                                              SHA-512:889AF4815426B6618067EDA8291DFE435C26C4A87813596A3649300CB330D5141DEC46BAECB4AD2C77C87CAEF467CF6ACF2F2A10840952518B0CA97CDA316ADC
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....9.............!..0..$...........B... ...`....... ..............................0.....`..................................A..O....`..P...............h(...........@..T............................................ ............... ..H............text...$"... ...$.................. ..`.rsrc...P....`.......&..............@..@.reloc...............,..............@..B.................A......H........|......................@@........................................(....*^.(.......x...%...}....*:.(......}....*:.(......}....*:.(......}....*..{....*"..}....*..{....*"..}....*..( ...*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..( ...*..(...+*..(...+*..(...+*..(...+%-.&.+.("...%-.&....O...o#...*....0..2.........($...k..(%...k[...(....Y(&.....(....Y(&...4..*.*r........+."...?*"9..?*s'...z&...((...*....0..)........{9........()...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):86120
                                                              Entropy (8bit):6.3760845519882
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:89D8D0DFDCFD9DF218F6CB34FD1FC4F8
                                                              SHA1:A140C0E1B105D35C4AE6C874FCB75A46060EEDC2
                                                              SHA-256:97DF710892725756444A2BB094004EE06AB4E2EBC92DF1A2CC33D46B3F7F08D7
                                                              SHA-512:2333B096902F5C09E4B5B1D75F8B81E14774921873F06E6E69D5D993B019F6BD372EDAB15B25368525AE8939E4AFC40A2454CE1907094197C9CDCEE36988F074
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...8.............!..0..............<... ...@....... ...................................`.................................v<..O....@..x............(..h(...`......X;..T............................................ ............... ..H............text........ ...................... ..`.rsrc...x....@....... ..............@..@.reloc.......`.......&..............@..B.................<......H.......lr..l....................:........................................(....*^.(...........%...}....*:.(......}....*:.(......}....*:.(......}....*V.(......}......}....*2.{....o....*6.{.....o....*.~....*.......*.(....o....*....0............( ...(!...-.s"...z.(...+&~$...(%...,..(...+(...+o(...(...+&.(...+&.(...+&.(...+&.(...+(...+(...+&.~I...%-.&~H.........s+...%.I...(...+&.(...+o-...(...+&.(...+(...+o....&.(...+(...+(...+o/...&.(...+.(...+.(...+.(...+.(...+.(...+.(...+.(...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):381
                                                              Entropy (8bit):4.997072360809177
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:33419992E4132F91F8692BA56E433A33
                                                              SHA1:3A774567BD40E9CAB0CC2A12CF4D271A313099FA
                                                              SHA-256:C8197C7BD1E9F315D1812211EA96A99EAD30ED84045CA6905D18EAF80B995EA7
                                                              SHA-512:32A35B292D58D463340CD22CA149F5D631996F4E9976375443562CDBC07EF14C526F34CA6030618AB8B52CF89977F13A6E0B3BC6295E42E31D53AC0A35EE5336
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.<?xml version="1.0" encoding="utf-8" ?>..<appSettings>.. <add key="ConnectionMaxRetryCount" value="10" />.. <add key="ServiceExclusiveLockTimeoutMilliseconds" value="5000" />.. <add key="ServiceStartMaxRetryCount" value="40" />.. <add key="ServiceStartRetryIntervalMilliseconds" value="250" />.. <add key="ServiceReadyTimeoutMilliseconds" value="10000" />..</appSettings>..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):134760
                                                              Entropy (8bit):6.150054438854623
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D2CE550F79000B87B0B19F9C4B309B43
                                                              SHA1:E7BAF52E2064ABDEBAEBDAA6ACC5FF051EBF9CCC
                                                              SHA-256:03892E2F21F1BFC8585C74A6B419804D46F9E4F4F3127F4D27D6276B31DF6155
                                                              SHA-512:EDB88B16A8F6FFD578DDBE9653B3F69BE43C037F3FB976D0F548DAAA3D0C6C38E73B1A17441BC3A0D0BD00F34BF1A26D7F75CD3A5CF7726C33BCF60E282EAF1F
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.../.............!..0.............J.... ........... .......................@.......`....`.....................................O.......x...............h(... ..........T............................................ ............... ..H............text...P.... ...................... ..`.rsrc...x...........................@..@.reloc....... ......................@..B................,.......H............b..................\.........................................(0...*^.(0..........%...}....*:.(0.....}....*:.(0.....}....*:.(0.....}....*"..(1...*...0..*.......s.......}.....(2...(3..........s4...o5...*...0../..............%..,.o6.......r...po7...-..r...po8...*.*.......%.r7..p.%.ro..p.%.r...p......*..{....*"..}....*..{....*"..}....*...0..c.........(&.....o9...(......o'...~....%-.&~..........s:...%.....~....%-.&~..........s;...%.....(...+(....*&...('...*"..((...*..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):3049576
                                                              Entropy (8bit):7.033227230038466
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:DA131385E4B13158729845731D626BA9
                                                              SHA1:CE7ECB523781BA9928BACA3A1C803310C76FA25D
                                                              SHA-256:3F30E26C9203A0E57868A5E7C30B2CD3388369E003D759D93B7E76BE14B3FD0E
                                                              SHA-512:288B23B1D62B96BCC58BCE91E379EB6FED2CEAE57A4B62BD0D9933DDF3915DA45A1160B30BFBB595539A0303DFC44C5F9F7957CA267DAC27D2748130E765D043
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?.{............!..0..0... .......H... ...`....... ..............................9Q/...`.................................4H..O....`..H............`..h(..........0G..T............................................ ............... ..H............text....)... ...0.................. ..`.rsrc...H....`.......@..............@..@.reloc...............P..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1633384
                                                              Entropy (8bit):6.413516248745208
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:262E1F69E6AE10F4A3748CB27BBD8E27
                                                              SHA1:D262FA08005558529CD4834AF2442C5DA4D9D7A3
                                                              SHA-256:E678394E83141EC8052C2AE3683A6945A89FE68691A364A6A89894C82E5312A9
                                                              SHA-512:84B234E51490373BB4C725230BAB287A2F54C4C3D57E8C5E3DB83172E99D795CA25F0881D7A5802ECC88C672C8B7533A79A934FA1BB2FEDC7D40E12EBE5F9FC5
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ntv............!..0.................. ........... ....................... ............`.................................|...O....... ...............h(..............T............................................ ............... ..H............text....... ...................... ..`.rsrc... ...........................@..@.reloc..............................@..B........................H........................_..xw............................................(*...*^.(*..........%...}....*:.(*.....}....*:.(*.....}....*...0..)........{.........(+...t......|......(...+...3.*....0..)........{.........(-...t......|......(...+...3.*"..(....*b.{....%-.&*..s....o/...*N.{....%-.&*..o/...*..(0...*j....(1......}.......(....*z.{...........s2...o3....(4...*N........s2...o5...*j..o6....s7...(8.....o9...*:.(0.....}....*.(:....{....o....o;....{....o....(<...*...0..).......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):383592
                                                              Entropy (8bit):6.203511932263794
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:83A0CDC68372A42F793E739CD173A7B1
                                                              SHA1:D3812F1729B563642C9563CCEFC62498646A88DB
                                                              SHA-256:03A8215DCCAD2F6902DC0A63D8A3F5190816530755EFD29CE609BFBE29C8DBA1
                                                              SHA-512:A8C0AEF369AC3BDDB90E67B4715178BB26AAC645BC40828E293C0D0FF8EF41B362ED324B1C81D0EA18AE0E21FFF5614FC124B9FBBFE0E06D19EC8C36B1B18AA3
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....KZ..........." ..0.................. ........... ....................... ......C.....`.....................................O.......................h(..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......$................Z..xj..l.........................................{;...*..{<...*V.(=.....};.....}<...*...0..A........u4.......4.,/(>....{;....{;...o?...,.(@....{<....{<...oA...*.*.*. Wd.. )UU.Z(>....{;...oB...X )UU.Z(@....{<...oC...X*...0..b........r...p......%..{;......%q7....7...-.&.+...7...oD....%..{<......%q.........-.&.+.......oD....(E...*..{F...*..{G...*V.(=.....}F.....}G...*.0..A........u8.......4.,/(>....{F....{F...o?...,.(@....{G....{G...oA...*.*.*. .B`v )UU.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):52328
                                                              Entropy (8bit):6.688351883260309
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C22408B0D76C8602E3FD7C230F633FB2
                                                              SHA1:176C44CADD6B5B3E272A98F1B92CD2255E951D8E
                                                              SHA-256:E94576A1154E12A6AE94E3FC7DAF776E37C37057AD61F3D5920D97300B820839
                                                              SHA-512:E9956F313B34DD4D07F0FFBA90D61B95FEAD537331DAC09F459BE6710B03BA876819BF993C11AAE9E6BB905FCE5917B2385B036D25FF4C17FB93B4546238C0EF
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...m.Z..........." ..0.................. ........... ....................................`....................................O.......................h(..............p............................................ ............... ..H............text...4.... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........F..DW..................8.........................................s....*"..}....*2.{....s....*..s....*..s....*6.{.....o....*:.{......o....*2.{....o....*2.{....o....*6.{.....o....*2.{....o....*6.{.....o....*:.{......o....*6.{.....o ...*:.{......o!...*6.{.....o"...*6.{.....o#...*2.($........*2.($........*.*>..}%.....}&...*J.{&....{%...o....*...{%....X}%....{%....{&...%-.&.+.o......*.*2.('........*"..}%...*..{....*..{....*.......((.....}......}......}.......}.......}....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):6966688
                                                              Entropy (8bit):7.362517080971882
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B4809419FE5E7902BBB0873D296070D9
                                                              SHA1:C1F1DD2968CFAE6AFEF1060BCC52A93D99713F60
                                                              SHA-256:9585563412E6A0A1BB104F89B3F107A976BE9725EB4705545C932D35B72D127C
                                                              SHA-512:68E6AE894A4F0AD0ED2E1B6062D0AEC44B8DF07BDEDE9470DE81A5313B860DF57F2C2231852063A37065439270CA56734BE77A1AB5180E3528B6074C8346555C
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....[..........." ..0...i...........g.. ... j...... .......................`j......`j...`...................................g.O.... j...............i..Q...@j.......g.T............................................ ............... ..H............text...X.i.. ....i................. ..`.rsrc........ j.......i.............@..@.reloc.......@j.......i.............@..B..................g.....H........................f2.X.5.T.g.....................................V!.....n...s1........*N.(2.....(.C..}....*..(2......(.....sX@..s4C..s"C..}....*..(2......oE...(.....oD...sX@..s4C..s"C..}....*f.(2......(....s%C..}....*.0../........(2....s.@..s0B........(....s`C.....s'C..}....*..0...........{....o*C....,..obC..o.?..*.*..{....o*C..%-.&.*(dC..o3B..o.@..*r.{....o*C..%-.&.*(eC..o.?..*r.{....o*C..%-.&.*(cC..o.@..*2.s.B..s.C..*...0..B........o.C.....+-.....o.C...3..o.C..(}D...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):434280
                                                              Entropy (8bit):5.917165890191457
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:83699066EDBD5E2DEB0D9ABEC9EB46ED
                                                              SHA1:67C55ACE611F6A4FF454954AB99D6B414699D2F6
                                                              SHA-256:2E96AB6270D6BAA4804C443A1A5C0854AB9FECC74EB3336A22A50DD94674C0F6
                                                              SHA-512:D99013CDF219DB5AD575A9AA70C236F087CEB1E844B7CBB186729C48C9A66DE8A712398AE4AF65E714690523F5E32A35B749698DC5B4AE004B65100D3155CA29
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..n............... ........... ..............................x.....`.................................K...O....................x..h(..........t...T............................................ ............... ..H............text...Hm... ...n.................. ..`.rsrc................p..............@..@.reloc...............v..............@..B........................H........(...`..............X............................................{....*..{....*V.(......}......}....*...0..A........uD.......4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. .... )UU.Z(.....{....o....X )UU.Z(.....{....o....X*...0..b........r...p......%..{.......%qG....G...-.&.+...G...o.....%..{.......%qH....H...-.&.+...H...o.....(....*..{....*..{....*V.(......}......}....*.0..A........uI.......4.,/(.....{.....{....o....,.(.....{.....{....o....*.*.*. O... )UU.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):258152
                                                              Entropy (8bit):6.078595029793906
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FE829DD32864E9B3721F02AA61E53B4A
                                                              SHA1:451274E6BE5861A220E56E7970C50DEEF53FA4BF
                                                              SHA-256:82BD74C7F33BB66890F8F4B111819EF21C5382379EA93ECA000D7A6857B4A9F4
                                                              SHA-512:C68A9A1275055CEFE4E691253C7610540D87CF22A71142BA0C3CC995E72DE132FCB636A2C1A21EC7AEA4B9C9D5CE9B07B095F45242CC8875C648891A9611E607
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....0z..........." ..0.............>.... ........... ....................... .......Y....`.....................................O.......t...............h(..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...t...........................@..@.reloc..............................@..B........................H.......8...H.............................................................($...*"..(%...*&...(&...*&...('...*2.r...p(....*"..(....*&...(....*&...(....*2.rE..p(....*"..(....*&...(....*&...(....*2.r...p(....*"..(....*&...(....*&...(....*J..r...p((...(....*v....().....().....()...(....*....h...%...%.r...p.%...%.r...p.%....%.r+..p.%...(*...(....*..(....*&...(....*&...(....*.0..)........{.........(+...t......|......(...+...3.*....0..)........{.........(-...t......|......(...+...3.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):67688
                                                              Entropy (8bit):6.191872566202956
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:755D41B2A3A0F731F9651A610EFE85B4
                                                              SHA1:F3948287201B0386E3AB30DA835D92C45793127E
                                                              SHA-256:C3216AF23B1C4FAAD9F38B7C0A71D779BA02CECCFA4A69E371776A86EE15B25F
                                                              SHA-512:DD2AF51ABF64DE118DB1A4693BB21A45BFC17D0B44065E8EDFCEC4F9C76A18AA9AF9BEA8138E4ECD94ED3742212E2EC39197282094D8093852D6129EDCEDCD41
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....T.............!..0.............n.... ........@.. .......................@......+.....`.....................................W.......H...............h(... ....................................................... ............... ..H............text...t.... ...................... ..`.rsrc...H...........................@..@.reloc....... ......................@..B................P.......H........a......................pa........................................(......}......o....(...+}......s....}....*.0..Q..........}.......}.......}.......}......(....}.......}.....{.........(...+..|....(....*....0..A..........}.......}......(....}.......}.....{.........(...+..|....(....*....0...........{....r...p......(.....{....o.....s....%.{....o....o....%.{....o....o....%.{....oq...o....%.o....o........o.....o.....o ....(....o.....{.....(..........(.....*..0..>........{..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:HTML document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):5586999
                                                              Entropy (8bit):4.867547681370863
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9B00281A022D0FDB921E86F6D64B962A
                                                              SHA1:455240DA1483E8CE909DC5D23E318D2194BAF782
                                                              SHA-256:23EF8B0199496C6030A313FD8625D84B5648D04F82796E5C189CBFDED36E5978
                                                              SHA-512:9BD1E00C51CDE6371033C3DB85906943320CAC32C4D0B68C9EEEEB426C1DBF2E0EB199958ACFDA3466A55B7B560E95B69AFB5446F13F9B694E2D9BE8D4BC5737
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview: Generated by licenses.py; do not edit. --><!doctype html>..<html>..<head>..<meta charset="utf-8">..<meta name="viewport" content="width=device-width">..<meta name="color-scheme" content="light dark">..<title>Credits</title>..<link rel="stylesheet" href="chrome://resources/css/text_defaults.css">..<style>..html {.. --google-blue-50: rgb(232, 240, 254);.. --google-blue-300: rgb(138, 180, 248);.. --google-blue-600: rgb(26, 115, 232);.. --google-blue-900: rgb(23, 78, 166);.. --google-grey-200: rgb(232, 234, 237);.. --google-grey-800: rgb(60, 64, 67);.. --google-grey-900: rgb(32, 33, 36);.... --interactive-color: var(--google-blue-600);.. --primary-color: var(--google-grey-900);.... --product-background: var(--google-blue-50);.. --product-text-color: var(--google-blue-900);.... background: white;..}....@media (prefers-color-scheme: dark) {.. html {.. --interactive-color: var(--google-blue-300);.. --primary-color: var(--google-grey-200);.... --product-background: v
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):22878
                                                              Entropy (8bit):4.872322583286523
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:045B6EC8B13D0DD2ECC1490A4FED71CA
                                                              SHA1:172008B66C4CF26E6028170B9E88592761B9C779
                                                              SHA-256:02A439E6181B64C746C3BAFB3CFE292090C018829C4DA5A0BA798EA04E6A05A9
                                                              SHA-512:186193F0B8556649590769D3DE3620006403AC8FF9C0B2CC104B54073D0FB9A48BD13009014ECF29823150C4F0651A81769E05E31A6B02167CB80A3CD216C5EC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:Intel(R) Integrated Performance Primitives Third Party Programs File....This file is the "third-party-programs.txt" file specified in the associated Intel end user license..agreement for the Intel software you are licensing...Third party programs and their corresponding required notices and/or license terms are listed..below.....-------------------------------------------------------------....1. Intel(R) Intelligent Storage Acceleration Library.. .. Copyright(c) 2011-2017 Intel Corporation All rights reserved. .... BSD 3-Clause "New" or "Revised" License.... Redistribution and use in source and binary forms, with or without.. modification, are permitted provided that the following conditions.. are met:.. * Redistributions of source code must retain the above copyright.. notice, this list of conditions and the following disclaimer... * Redistributions in binary form must reproduce the above copyright.. notice, this list of conditions and the following disclaim
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:HTML document, Unicode text, UTF-8 text, with very long lines (466), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):645625
                                                              Entropy (8bit):5.0234178255701725
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:83F7777B89F346F626B6F5100A271DAD
                                                              SHA1:5DBFBA8F644949593730376D640C4D6BEE961270
                                                              SHA-256:42981DE51B3856C3092666B37327CB289DB4FDFA90A7A58596E831866D702E43
                                                              SHA-512:89AFAD95D04E529369993492FEF371C847DF8B8E6CD4068D1493646DF00E5AA81EBAE6D2415CE9C4B85154E4E4770B913AFEAA71288024F982DB5C012CAEC66A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<html>..<head>..<title>3rd-Party Software Report For Articulate 360</title>..<style>....h1, h2, h3, h4, p {.. font-family: 'Segoe UI', Helvetica, Arial, sans-serif;.. color: #55676E;..}....a {.. color: #1486D6;..}.....title-card {.. padding: 60px 20px;.. border: 1px solid black;..}.....license-card {.. padding: 20px 20px;.. border: 1px solid #55676E;..}.....license-text {.. height:100px;.. overflow: auto;.. border: 1px solid #55676E;.. background: #F5F5F5;..}....pre {.. padding: 10px;.. word-break: break-word;.. white-space: pre-wrap;..}....</style>..</head>..<body>..<div class='title-card'>..<h1>3rd-Party Software Report For Articulate 360</h1>..<p>The following sets forth attribution notices for third-party software components that may be contained or used in portions of the Articulate 360 application.</p>..<p>Generated on 6/13/2024</p>..</div>..<p></p>..<div class='license-card'>..<h3><a href='https://anglesharp.github.io/' target='_blank' rel='noopener noreferrer'>Ang
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):39680
                                                              Entropy (8bit):6.870684598138585
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D00F9CFB752A684AED4B65EA66A128FB
                                                              SHA1:0C9123E8B88276C488BD15F74DCB132C22898971
                                                              SHA-256:46956EE5246C4076FDD6963A8F9BAD1080017F83D155A5E63F6042D72EE6B923
                                                              SHA-512:16ED4C0AFA5AB0B2162CA288ADB7E26904F2B48AD502E30A909E7FCCDFE405DA140A79A14AE175AE8E6F196EECA50E3E78ABD6601D983DD66059789AC4235790
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....z}..........." ..0..@...........^... ...`....... ..............................0x....`.................................S^..O....`..`............J...Q..........P]..T............................................ ............... ..H............text....>... ...@.................. ..`.rsrc...`....`.......B..............@..@.reloc...............H..............@..B.................^......H.......T)..|3...................\........................................(....*^.(.......2...%...}....*:.(......}....*:.(......}....*:.(......}....*:.(......}....**.-..(....*..s....z..(....*..(....*..(....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*..(....*:.(......}....*..{....*^.(.......4...%...}....*:.(......}....*..{....*z.(......}.......4...%...}....*V.(......}......}....*..{....*..{....*:.(......}....*..{....*"..(....*"..(....*"..(....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):35072
                                                              Entropy (8bit):6.934461550929986
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:50C2383BC46CC018A05C540559B2A559
                                                              SHA1:8EA7F532E89F9F179509D06996D0D27C8F2CAACC
                                                              SHA-256:B8D4C5B3F9F551F4031121B30627BA0E0401BCD78C8C6BECE15928E98EFEAD28
                                                              SHA-512:1EB742D4678FB1C381D4C2C4DFBD2E914BD4DAAD1A91B56560FE79E91263521C43D6FC13B6B8C026867FC27C03E127D3AC47E3249DC9463E29AC230BCEEFA486
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..,...........K... ...`....... ....................................`..................................K..O....`..T............8...Q..........xJ..T............................................ ............... ..H............text....+... ...,.................. ..`.rsrc...T....`......................@..@.reloc...............6..............@..B.................K......H.......t&...#...................I........................................(....*^.(.......*...%...}....*:.(......}....*:.(......}....*:.(......}....*:.(......}....**.-..(....*..s....z..(....*..(....*..(....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*..(....*:.(......}....*..{....*^.(.......,...%...}....*:.(......}....*..{....*z.(......}.......,...%...}....*V.(......}......}....*..{....*..{....*:.(......}....*..{....*..{....*"..}....*..{....*"
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):60168
                                                              Entropy (8bit):6.676765494837987
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:10B736D77D1F586389B9ED8A83B778AD
                                                              SHA1:B621A7DBAB776E4C6BD802B41DCCF8E313264C98
                                                              SHA-256:7D09942E538A1921EC4EF3CD2E53843A50FCAF638ECA725C60A41325A192662B
                                                              SHA-512:814CDDD86383031D95386CF22BDA883F9869A0E415B067DF821B7BEF754B461D8CE1F384B8581AD68CE152FFF448E26325A53515DCC9FF3E2674EAFC6DEA8EC6
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ........... ..............................9.....`.................................9...O.......(................Q..........H...T............................................ ............... ..H............text........ ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B................m.......H........?...j...........................................................("...*..("...*^.("......Q...%...}....*:.(".....}....*:.(".....}....*:.(".....}....*:.(".....}....**.-..(....*..s#...z.~....*...0..........(....,..*..(.....o$......&...*...................0...........(.......(%...-..,..*.*.(....,.r...p......%...%...(&...*..('...*.(....,.r...p......%...%...%...(&...*...((...*.(....,!r...p......%...%...%...%...(&...*....()...*..,&(....,..r...pr...p.(&...(*...*..(+...*.*.(.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):40712
                                                              Entropy (8bit):6.847915108131539
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F0948798F7623261B90161B29B8C94D5
                                                              SHA1:A5949D64C88BEBED965EA6BB2F5CAC6924330299
                                                              SHA-256:FB302254034AF4E3A1100E1D7D499D58D6D115C7F0A11E3B84DF2065D0E2D55D
                                                              SHA-512:6C0C0706F84A50DBD51954AAE3724CB8159B774984CE619E46CC88665167C2A212F35F9076CEC89254A5C85F674828443881992029CD05714DA076A93D350D12
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....-..........." ..0..D..........^c... ........... ..............................{A....`..................................c..O....................N...Q..........,b..T............................................ ............... ..H............text...dC... ...D.................. ..`.rsrc................F..............@..@.reloc...............L..............@..B................=c......H.......D2..h/...................a........................................(....*^.(......./...%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*r..}......}.......(....(....*..-.r...ps....z..(....}......}......o....(....*..|............o....}......o....(....*..{....*"..}....*..s9...*.0...........o.....(.......*.{.......|....(....(....(...+,..*.{....,e.|....(......{....o!....+2..("......(#.......($...(....(...+,....%...($...X...(%...-...........o&.....*.*........Q.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):742392
                                                              Entropy (8bit):5.790276669062503
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:14470C63B8C5ADBBE814FF74C6101F7B
                                                              SHA1:F778A3ADAFE8A44CDF64E3D305A5784FC41C2A4A
                                                              SHA-256:C023AC9390F117501832CDC65280EDA2DCAEEE7C029D8FE463AE823A5405D897
                                                              SHA-512:045F91EA3D72766B7EEC3A28389C89DC84D2AB2B229A914D09941CEA137CB77AE7600D04BFFC558F51F5E9106B440F26EFA5512E057E9080CFCBAD6A96F03B6A
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...T.1..........." ..0..Z...........x... ........... .......................`.......|....`..................................w..O.......,................M...@.......v..T............................................ ............... ..H............text....X... ...Z.................. ..`.rsrc...,............\..............@..@.reloc.......@......................@..B.................w......H........................h......Dv........................................(9...*^.(9..........%...}....*:.(9.....}....*:.(9.....}....*:.(9.....}....*V!..q..q...s:........*..0..s............,....o;....o<...(.....+.r...ps=...z.,....o;....o<...(&....+..js>...(&..........(.........,..o?....,..o?......*.........Y].......0............(@.........(A......(....*"..}....*.0...................*:.{......(B...*..{....*..s....*J.{.....{....(B...*...(.......*J.{.....{....(B...*..0..........
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):117864
                                                              Entropy (8bit):6.731256251335476
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7C77567D7DA1C3DA4424ADA361F03D01
                                                              SHA1:CC03B3FF46174EB92095B758A3D69858D03F1ED7
                                                              SHA-256:0843FDB68EA0CECE731B0FD2F61F988CAF0A67559A0865503007443756A5F387
                                                              SHA-512:9A0F68C1D951C5BCAAFA3BB871EB3D25CF6AFD9FFBCF22C9DBAF684CC55031511ADD92CAAC50C25772C721947BBF1DBAC3206B3B4D0857A91D5E1D4BD469EBC3
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ........... ....................................`.................................U...O.......................h(..........Xn..p............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......x...`....................m........................................(%...*^.(%......z...%...}....*:.(%.....}....*:.(%.....}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*....0...........{....%-.&.s&...%.}.....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*...0..0........r...p}.....('...~....((......()...j}.....(*...*Z ..........s+........*..0..........~....('......#........(,...(-...,y~....o....~....~/...(0...,.(.....(....('......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):20072
                                                              Entropy (8bit):7.227069260567178
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:23D34FE505300883E353ACAEFDF06D5A
                                                              SHA1:83A5B4555C1F9D526B2048F32C9B32D976113DD6
                                                              SHA-256:7753CB17E79D94C5CDE908C10E11D64C474BAF59E91BEC837F9825224F18702A
                                                              SHA-512:B753B4B51BC2B0B7D158612ED52D6F6C32E00DC961C0A535AB4797621518E0DC3A67D6DAD29687F31F5A753D84CE571874E257A12D9290C7471DE83ABC887D25
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...5DZ..........." ..0..............;... ...@....... ....................................`..................................;..O....@..\............&..h(...`......d*..p............................................ ............... ..H............text........ ...................... ..`.rsrc...\....@......................@..@.reloc.......`.......$..............@..B.................;......H........ ..8....................)......................................N.s....%.o....(....*R.s....%.o.....(....*"..(....*&...(....*&...(....**....(....*..(....*...BSJB............v4.0.30319......l.......#~......$...#Strings....(.......#US.,.......#GUID...<.......#Blob...........G..........3....................................................F...........q...................................).................f...........W.....F.............I...Y.....3.........................=.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):238400
                                                              Entropy (8bit):6.249705202866407
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:00FE6CE6631A963E91A67D80BF24C56C
                                                              SHA1:E011CDC507C4DAE530133BD5C1441F3633B24443
                                                              SHA-256:866090A606327427E685E028F374614B71721FC0D898DF59B1DAF47573662D93
                                                              SHA-512:526E1CE9E572A33E51CA70190E3E732EBB17A639905E494A454EE935B4FEFAE73FAE7B0C6D665BB25F823F00A5860BD64DE359ACD09D1DC514B7B233BC14B75A
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@_............" ..0..B..........._... ........... ....................................`.................................]_..O....................L..@W..........|^..T............................................ ............... ..H............text....A... ...B.................. ..`.rsrc................D..............@..@.reloc...............J..............@..B................._......H.......L...h............V..H....]........................................()...*..()...*..()...*..()...*^.()..........%...}....*:.().....}....*:.().....}....*:.().....}....*V!..y..g...s*........*..0..e.........}......j}......%-.&r...ps+...z}......}.....|......J....{.....(...+..(,....|....(...+&...(....}....*....0..V.........}......j}......%-.&r...ps+...z}.....|......J.....}......s/...}......{....(...+}....*..{....*..{....*..{....*..{....*:..(.....(....*....0..C.........(.....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):2648
                                                              Entropy (8bit):2.9877916744372337
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E81289181DD4319992B7703C1A8EE1C5
                                                              SHA1:54A5F394BDE8D78B15D37079B31300661B537C78
                                                              SHA-256:1279B340BBD37BA36D7F75686FC27D20FE31EA5FB225663B9807848DEFCCC675
                                                              SHA-512:49EE04F34D433EF5E97940B683FD415D585A6B364B63B2110E75B8A35B43AF4F65B702ABDEED4F578B1D922A9C1A7CDD4382F356316FF1CE88EC29F6848D553B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:mrm_pri1....X... ... ...........[mrm_decn_info].................[mrm_pridescex].............P...[mrm_hschema] .........8.......[mrm_res_map__].................[mrm_dataitem] .................[mrm_dataitem] .................[mrm_dataitem] .........h.......[mrm_dataitem] .........H.......[mrm_decn_info]................................................................................. .......X...........................................................................................1.0.0...1.4.0...1.8.0...............[mrm_pridescex].........P...................................................P...[mrm_hschema] ...................................>`........m.s.-.a.p.p.x.:././.T.h.r.e.e.S.i.x.t.y./...T.h.r.e.e.S.i.x.t.y.....$...............J.......................F...........S.........$.T.........#.T...&.................................F.i.l.e.s...S.t.a.r.t.M.e.n.u...T.h.r.e.e.S.i.x.t.y.M.e.d.i.u.m...p.n.g...T.h.r.e.e.S.i.x.t.y.S.m.a.l.l...p.n.g..............................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 150 x 150, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):16096
                                                              Entropy (8bit):2.320671502348941
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8FA4D0A9DF363E86A737A8B2269649AF
                                                              SHA1:40BA9A19A0D8FAAD73AAC5D77387E3D6366D0B1A
                                                              SHA-256:7F8DE8F2C5E212930FF838203F0609815A9D4C871860C97BA47DA0056632876F
                                                              SHA-512:F575E320D7AD851027013F0E282FE69C42DF39D0941B11E56EA9F2E30F754C6749CB2ACE66473F58D2613C07259C21DDE956A69799E388FCCE00EB9833B5CF49
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR.............<.q.....pHYs...............9.iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:a0329022-d10b-4a28-91bd-dce8df03be88</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:1951DDA3502D11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 210 x 210, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):16674
                                                              Entropy (8bit):2.5923623131130573
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B50E628867070DBF29ACB86C5B05B796
                                                              SHA1:9EF57DBAAC6461A6F593FBF74AF8C0156509AE44
                                                              SHA-256:99A569D60DF5BDE2B4E5A679219FD784C38E2998B9C399B0815352073854BD08
                                                              SHA-512:C228F0C58AADC797F1F862FB525B8AE35793C72A6FDEFFFBB8969EB62131A6754B3C3EFA75B21BD3F12321D6D1677A17D82F3B3DA64320FC1A818500B7F6FF5A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR.............?..B....pHYs...............9.iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:a0329022-d10b-4a28-91bd-dce8df03be88</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:D6DCF6F4502B11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 270 x 270, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):17445
                                                              Entropy (8bit):2.9082182864829447
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3BF7D0F52DC10A2451E3789B52BB5D64
                                                              SHA1:5DC6F623FF60342D6F890CC1E0E705860F2A860C
                                                              SHA-256:864E00BE7CFF934A9FB46855782CEDCF7A79651FD6FBCE2889092433A331E609
                                                              SHA-512:439C7EF5F019688AA3B7EFAE91E1133863718DAA0EC58A635FDCB000F00C0EB830CEC9B5A24710032ED2101DF9D6E3AE1DA3F293548BDF3B624330561F2CC2A7
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR.............x.......pHYs...............9.iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:a0329022-d10b-4a28-91bd-dce8df03be88</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:CB85C18E502D11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 120 x 120, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):15741
                                                              Entropy (8bit):2.12330547313144
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5D54629C8DF41BD81E110AB04948DBFE
                                                              SHA1:A8F59F3F3F497BDA644BC5B5D04DB024FB52443E
                                                              SHA-256:26D4FB0324F9298FE5AD09FBF7D95B4F797E1D1B94421F3954A9885DBE47A696
                                                              SHA-512:12B804638AE3A5BEC4E2D37685EE7B8303E7B0DC92ADBC82E77A2DE8A7219921FA3F80FF258F0C69C2EA5BCA9A031F051378EF9937307FA9F75EEE1D1C1F6963
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...x...x.....9d6.....pHYs...............9.iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:a0329022-d10b-4a28-91bd-dce8df03be88</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:1951DDAB502D11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 70 x 70, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):15534
                                                              Entropy (8bit):2.01352862456016
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:25ECD54E6572601497856F2D6038CD27
                                                              SHA1:22BBAE3F7D59E33472E2F548D4B74416E78F2AAF
                                                              SHA-256:A0075738D3F16C6B5FDA40A65E7ED48E824B9C0DDE636F2A5DC3320AD7A36899
                                                              SHA-512:81D8DDFDFBDEA31E541667B6A378BE09FA9EA32938F067BA8803D7C52AAB8E62C2199199B99703BC308C236EE1A3FEED2FD44E966C054879F7DE11C75E95CD7A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...F...F.....q......pHYs...............9.iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:b6d79f29-4f58-473e-96d7-4eeadf27ef9e</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:3A6EE230502F11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 98 x 98, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):15929
                                                              Entropy (8bit):2.2335863153699727
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5D4D0BE1D5968CCB318566554517F690
                                                              SHA1:31562B8BB3FCE1CADD34EE889C03C5FB9D590A7B
                                                              SHA-256:5838EE0F2242AEA66EF26EF774152A8DD3DC74390B423E20E97E9ACC791A49D2
                                                              SHA-512:0061BFBA72FB31C98BFD633365B2FA4D9E640446D03DFCD5AECAC4AE14CC6033A05F86AAD0B537084936591C48E343AD329ADDFD77F5740D8614FFFBA7A744F7
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...b...b.............pHYs...............9.iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:b6d79f29-4f58-473e-96d7-4eeadf27ef9e</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:3A6EE234502F11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 126 x 126, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):16735
                                                              Entropy (8bit):2.5188432644442913
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:564CD74CC0B47CEC0635031E9A3059F7
                                                              SHA1:7E5716C81A3A78CA38FE62C80028183631247CEF
                                                              SHA-256:A48AE31729FEA6777D309ED9318489EA922CCA53E020680161030CAE535AA6B0
                                                              SHA-512:DFB3D89D09238A8EEA193C6DD6DC4CEABF37257E533FB4541D44E83756D5AD4FDF964BB2D7D430FB0829CFFD63223FCEB25FDC7E644FA43D5ECC6DEF79CAEE77
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...~...~......#......pHYs...............;liTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:b6d79f29-4f58-473e-96d7-4eeadf27ef9e</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:3A6EE238502F11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PNG image data, 56 x 56, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):15419
                                                              Entropy (8bit):1.9346695932198532
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:157590D29DF19DBE0C336093C396C88C
                                                              SHA1:87897A9096D6087243FD88AEE1044C4DAF1FD88E
                                                              SHA-256:C49FB4316CDA98E851F1581F6D14F3A13BD8E36FF2279A77EA29AE6F85A8A637
                                                              SHA-512:B3796663F6138948EAFA290790352660F8F0BB079CA9B8D89DE5D44A6DECD32ECFB151F4E0CE1E7FB939C5307BFDF92534581C8D35C6CFB8DF7E168825812914
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...8...8.......;.....pHYs...............9.iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stRef="http://ns.adobe.com/xap/1.0/sType/ResourceRef#". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmpMM:OriginalDocumentID>xmp.did:b6d79f29-4f58-473e-96d7-4eeadf27ef9e</xmpMM:OriginalDocumentID>. <xmpMM:DocumentID>xmp.did:0E939311502E11
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):209160
                                                              Entropy (8bit):6.28154063319408
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:CAD4B3DF5F7DFD7A2B5468103F53FA25
                                                              SHA1:430928DCBD2652202037F6BB357FA627689A0175
                                                              SHA-256:7BE5C37F8A471CF716F7EAFAD0C4CCF231FD0E3482364CBEDA4B12954DE31EDA
                                                              SHA-512:EE7D27AA3D8F4941B9BC412E6EEDB6D9282632925E0EA0E182C2B2F061E680D88F7F7402C74E7B4E99EEF0EBA6A581CF942DD19427F1DD9CDEFC228919E86DF0
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.............Z.... ........... .......................@......@.....`.....................................O........................Q... ..........T............................................ ............... ..H............text...`.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................9.......H........!..............T...@.............................................(....*..(....*^.(.......Z...%...}....*:.(......}....*:.(......}....*:.(......}....*:.(......}....*.~....*..0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):7164520
                                                              Entropy (8bit):5.717908911752026
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:16C36C40D987A36096B6000050994F6C
                                                              SHA1:EB8AD13DAEDCCCCA43D4D749275E57B9C9626F14
                                                              SHA-256:ABE4BEBF0240265037051DC25A0FB618F8688947A98F816C0C821D2227841F18
                                                              SHA-512:2FC2B9D5F2659BF845C363C1E37182EF37E3A9D61534875EFC58DEBBB866FEC52E7BCB99C2BC41151BE12BDE26B3D164B89106F55B0A1F600AA12C7EB92EC685
                                                              Malicious:true
                                                              Yara Hits:
                                                              • Rule: JoeSecurity_GenericDownloader_1, Description: Yara detected Generic Downloader, Source: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dll, Author: Joe Security
                                                              • Rule: JoeSecurity_GenericDownloader_1, Description: Yara detected Generic Downloader, Source: C:\Program Files (x86)\Articulate\360\Desktop Application\System.Management.Automation.dll, Author: Joe Security
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....2V.........."!......]..\........].. ....^...S . ........................m.......m...`.................................d.].W.....^..Y...........*m.h(...`m.....,.].............................................. ............... ..H............text.....].. ....]................. ..`.rsrc....Y....^..Z....].............@..@.reloc.......`m......(m.............@..B..................].....H.........(.p/5...........!.....P .......................................Y.QA.>T..G.$p.....R,.p.X.M....G\R...:...P.....}.h~l8..H9.9.....U.7.P._.Pj5.V.t...-G..a.........f.......B.L..zU.{>_,...6^+..(F...*..(F...*..(F....-.r...p(}S..z..}......oQ...o....}....*r.(F....-.r...p(}S..z..}....*..0...........{....................o-N..*N.{...........o-N..*6.......(....*F.{.........o.N..*>.{.......o1N..*.0...........{.....................o4N..*R.{............o4N..*V.{.............o4
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1480792
                                                              Entropy (8bit):6.163046324443291
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8EC7CCA97C2552585F28AB4CFD7D4B47
                                                              SHA1:A67C30AB737D7111A42AA395DC2C30C04EDE3E0B
                                                              SHA-256:19E7B6F23AAD9CA6D94A283761BE05DD27CD1A3D8105007B659E3C1823DB6457
                                                              SHA-512:38F04977009D4E324C4FA26189ACB979CEE5E5EC5F9DA291A29715C059DB9565ECD759AFEA0900E2A37577203390EA3211CE6A3B4C6B919D713B42B61F4D1609
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..F...........d... ........... ...............................C....`.................................Dd..O.......`............P..XH..............p............................................ ............... ..H............text....D... ...F.................. ..`.rsrc...`............H..............@..@.reloc...............N..............@..B................xd......H.......ln..............Tt......$.........................................(=...*^.(=..........%...}....*:.(=.....}....*:.(=.....}....*V!..4.....s>........*..-.r...ps?...z.~@...~q...~p...sA...oB...*..-.r...ps?...z.-.r...ps?...z..~q...~p...sA...oB...*..-.r...ps?...z.-.r...ps?...z.-.r...ps?...z...~p...sA...oB...*..-.r...ps?...z.-.r...ps?...z.-.r-..ps?...z..~q....sA...oB...*...0..G........-.r...ps?...z.-.r...ps?...z.-.r...ps?...z.-.r-..ps?...z....sA...oB...*..-.r...ps?...z.-.rE.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):28400
                                                              Entropy (8bit):6.940054943050567
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:975151C1180A17260A249DCF703CD391
                                                              SHA1:51C8E377D9314C4A845C4DE97E4196369796D8CB
                                                              SHA-256:C7528EF2E3A64C4F3EFAA894E4C75A7A8B3D7527EF7F92104BDD903B46D99F13
                                                              SHA-512:BF9814DBDF779BE13E771586165FF5C0145A240D2860102B271A6560265139B56E5F1A4EBFD2C457C7950A8A9A734AAD009C74FC6763E4056249CACABA00DA75
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Ksa...........!.................6... ...@....@.. ....................................@..................................6..K....@..............."...L...`.......$............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B.................6......H.......D%..<...................P ......................................_...+.'g.......x2..}}...B.O....T...e..?.M..R"M.~pg..c..LD#..y.....y....:u.v*...#.;.-.h.......0..#.....a5|T%W...].!.%'..9.0...........q....*..0..............q....*...0..............q....*...0.................*.0....................*..0....................*..0............q.........*....0............q.........*....0............*..0..........*....0................*..0...............*...0..............
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):89352
                                                              Entropy (8bit):6.365567780296158
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:67550EAFC9309D82432C53F952B8C4C2
                                                              SHA1:8075509CE4F9C8A67E5DA1FDF62E4A3708BC9624
                                                              SHA-256:6EDD82BF89E91CC0121BA8AEA58EC727587D510323B0120CBB3E0B5185ACDFDC
                                                              SHA-512:1E452B787A1B08A8D4EDCE7FAA8235523B147A4BF96C96DF6213F4F3BD8B200F94AD9E74061CE2D7E7AF0160CB96AEFAA6B9CAB1EADB82FC49F058E410AB843A
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....u............" ..0.................. ... ....... .......................`......=.....`.....................................O.... ...................Q...@..........T............................................ ............... ..H............text...0.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H........m......................H.........................................('...*..('...*..('...*^.('......8...%...}....*:.('.....}....*:.('.....}....*:.('.....}....*^.('......9...%...}....*:.('.....}....*:.('.....}....*..0..E........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X((.....R...((.....d.R*....0..K........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X().... ...._.S...().....d.S*..0..&.........+....(*...G...Z.(......X....(+...2.*...0............(+.....1...(+....Z.:..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):592696
                                                              Entropy (8bit):6.035760539079814
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:AA351A78C6F2A3FE689FF188AA04F28D
                                                              SHA1:C73697042F208181EF1D113BFB164D99A1B1747D
                                                              SHA-256:814C013D1A1A6D96DFC9E316EBF8E11CB64969CF5231B86B5EC687AC30A14C15
                                                              SHA-512:62C0A95FC65CD47ADFCFE5BBC2FE4D2290CEC30FCB745889A267649A606BFF086F6A3A2842E24FCC668978DF328AEB1A16AA75B7A56740EF727819B886DE3A9D
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.................. ........... ....................... ......e.....`.................................i...O.......................8Q..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........S..............`O...w............................................(J...*..(J...*..(J...*..(J...*^.(J..........%...}....*:.(J.....}....*:.(J.....}....*:.(J.....}....*..(J...*:.(J.....}....*.0..E........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X(K.....R...(K.....d.R*....0..K........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X(L.... ...._.S...(L.....d.S*..0..&.........+....(M...G...Z.(......X....(N...2.*...0............(N.....1...(N....Z.....(...+.+...(N....Z......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):191752
                                                              Entropy (8bit):6.3698487697261825
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:BCAA4E32CB65CCBC9370E24FD4DD0DF0
                                                              SHA1:04A8538096E0E853F19B514538C87C6F05B05480
                                                              SHA-256:C26DBA5E28E97CD89E7477EFC870881D0CB8E898B414604779E4EA4EE38671A0
                                                              SHA-512:42CCB96F147980B9C982BF95E2CE2EDC740280BEDDFDB32BD1676F4B3E6C9388611296430C16419F5C7FA1F0FDCF5CB739282C41CB73E5377CC40A024BF939C5
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0.................. ........... ....................................`.....................................O.......l................Q..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...l...........................@..@.reloc..............................@..B.......................H.......<.............. .......8.........................................(H...*..(H...*^.(H......j...%...}....*:.(H.....}....*:.(H.....}....*:.(H.....}....*:.(H.....}....*.~....*..0..........(....,..*..(.....oI......&...*...................0...........(.......(J...-..,..*.*.(....,.r...p......%...%...(K...*..(L...*.(....,.r...p......%...%...%...(K...*...(M...*.(....,!r...p......%...%...%...%...(K...*....(N...*..,&(....,..r...pr...p.(K...(O...*..(P...*.*.(....,.r...p......%...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):208280
                                                              Entropy (8bit):6.658390715394582
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3686D608628DB3C49395D40F59CA6ECC
                                                              SHA1:6E72578A2BFCE6A45EF9B3933D3D7CD9F0625B69
                                                              SHA-256:D548100E2B8B81B6FD67294B393BD667B2584AB33CC35FF510A187A0A88ECD91
                                                              SHA-512:4765DAF276077B694F2EA330ED03A4AF9E3773670384BF53141E4A909B40747F62D72193DFC388CF095DCB847132ABA0D6759831546B8A8EEF29F0791268F2B8
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....~............" ..0.................. ........... .......................@......Cr....@.....................................O........................W... ......d...p............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......`....G...............z...........................................(;....-.r...ps<...z..s=...}....*..(;....-.r...ps<...z..(....}....*2.{....o>...*..*...2...{....o>.../..{.....o?...*r...ps@...z..0..[........(A...,.r3..ps<...z.{....oB....+..oC.....o.....(D...,......o....-....,..o.....r3..ps@...z.*.........%D.......sE...z.sE...z:..(..........*6..o....(....*..0..F........(A...,.r3..ps<...z..+..{.....o?...o.....(D...,..*......{....o>...2..*r.-.rI..ps<...z.{......oF...*.sE..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):14952
                                                              Entropy (8bit):6.885872719976307
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C6616EABD023F09374A265BB14E4DA1F
                                                              SHA1:91A8AF11A3D82F6416EEE147437FAB4EB55A4B9A
                                                              SHA-256:A72EE59050B016EA52F867F5B609271BA0D85FD8E7AEC978CE4A5D58A99028F8
                                                              SHA-512:77A6657C09AD005EADFBD4258E0D3A05D053D8CC5562A04AED1DEACE1A695BC07319107BE5651157BE24DC31C977733E2C54C6FF92AC9F9011D305E7CC84810C
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf...........!.................&... ...@....... ...................................@.................................4&..W....@..................h(...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H........!............... ......P ........................................a.....>J.I.W.A#..].+.$...c.P.b..`.4.5.C~%y.....g.7X.:.2.....W.AMW.`.Wn.bk:.....-.....U....q..6a.3ul....V.. .o i.....3..................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...\...#Strings............#US.........#GUID.......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):21608
                                                              Entropy (8bit):6.549468708298116
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:54B70F10B75D32B53C611D05997AA9FB
                                                              SHA1:00C8D489874F06778901EE48146D5FD14EB8E6A5
                                                              SHA-256:64A0BBA9530F18880BFB0AE4088058E929FF54C44EE7875F8ED7CD3B03EDA4B6
                                                              SHA-512:D6B8DB64045911916E1CBC1002EE8DFC3B6AFF4AD88522DD2F9990C4B633DCE9411E6AF3E6FF9A19530A3EDF13BA67D28C16B324B2D0172F75E1A14291667E94
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf...........!....."...........@... ...`....... ....................................@..................................@..S....`...............,..h(........................................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................@......H........;............... ..,...P .......................................J.T/j.....k.....<....C..8C."....1.....Eh.......V`g%...h.....n.u".U..rh.x....i].w{..Y.z.{..pDb.........f.h.:......(/...)...(..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....^.......PADPADP........V.....o.Y.@.......+.......`.1/.......V...&.}..T[.....d.R.[...{.O.=...M..3..c..Q...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):39528
                                                              Entropy (8bit):6.009720419473838
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6875B2C05D2253C2CA04D229AE1856DD
                                                              SHA1:B8CC8C70F70BC9626917DC0BF21E933A502611D7
                                                              SHA-256:7A8A86F90CA963E1D78E3F4D4A846E3CA6D2C27E94CECF549FAC65FCAC36A3B6
                                                              SHA-512:737887825D7C34B473700BBA213E53ED9ECDCDA27888853E266B27C9CF5DDD46D4395EDCFEEAB4D2066702A635C14C204318130E554CFCBD70C8724797D75456
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.....h............... ........... ...............................1....@.....................................K....................r..h(........................................................... ............... ..H............text....g... ...h.................. ..`.rsrc................j..............@..@.reloc...............p..............@..B........................H....................... .."a..P .......................................5..c..l%.<. o.........I]..1'ZOB...1~ETL...5Z.99)Ft._"....j.nV>.........+.`..r..T".3x..i"....s......t3.4....*/...+k..')?d.,b>.a.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....."..v.......&.Q.R..p..>._..|.......s,.[.<.T............^...n............mB.9..<...j...x.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):17000
                                                              Entropy (8bit):6.7395894141355415
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A4C249692482B1959A10AA5FA9D9BE65
                                                              SHA1:FEDCD8D18A2EDF60D6E626779A056613EC5164B2
                                                              SHA-256:DE0484F5CDA5D40A0A652FB52760BE8360C5EB32ACDBB65BF161D289D73ADB4E
                                                              SHA-512:C99FF2C9D57C2BF3869FDF2B7141B6CF07443263C246F965B540B9E7DB7507AF5E3F8770A68BA8FC77E1D77964158138F724AB368F5B39236AB501A07333EEFE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!................N.... ...@....... ..............................v.....@..................................-..S....@..`...............h(...`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B................0.......H.......t)............... ......P .......................................R....q..~t.\.KQ...AL.......Gl..Q.).L....:q.%.....r.=...5.7q.E.#.<\#n..4...[<`C....@.l.^.......r?|.......AA.}.'k.J.H...M.=..]...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....hp...M..Sk..6-...m#..kZ`.3]$.w^,.......t...]...........................XA.r.t.i.c.u.l.a.t.e.3.6
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):16488
                                                              Entropy (8bit):6.820602130011184
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9B952710C2032F644C516683364E9B08
                                                              SHA1:AA6834E67F835607C7D356AEA96D966F6F761702
                                                              SHA-256:136F74D8551EF2D9C9D66F6D5A6946A6947FEE810D6F5F1CC69FDB6AACB2D4FA
                                                              SHA-512:ED2A863706733D00E77E836244514CCC186E15A151273D43EBEB335B08230169B63A293FD9628BBD8851C6739BBA05C4061DB759B84386B48C6133853ECC7AFB
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!................N-... ...@....... ..............................].....@..................................-..K....@..(...............h(...`....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...(....@......................@..@.reloc.......`......................@..B................0-......H........(..\............ ......P .........................................n....=#R.J"R........!..W'......z.}..1.F&...<4^.a.....+....)m.Nqp...F...*..#*\i'.1.I/v.v....4.....m0.lp..-..,....1Y.q$W...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP...|M......T.|.3.q...BU,..ls.$sY.J.......K...2.....H6...>?.->=.Q>...>.E.O..<c!..u~..|...|...~M...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):14952
                                                              Entropy (8bit):6.889316499272346
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4FED1B1C3A7217EE0639D07EF9F3BB28
                                                              SHA1:87BED259701426CB761D670D3F1E38ADCE1D825D
                                                              SHA-256:59003CE94C4938D22578F331A23CBDD1A8BCA6900ECF8E8B6E5FE6E9AE682A2C
                                                              SHA-512:5F161008D2EFEF504624284D2440CF1260B36496E66E5D1923F6F13288D09354F6ED4977CAD21FADFAD3987C34E24A56D2416C0E72D3820EBC391006B1ED046D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf...........!................~&... ...@....... ..............................\.....@.................................,&..O....@..................h(...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`&......H........!............... ......P ...........................................{..C.c ...X.._$.I...:,}U.m........:._..A..f..e...B....I6^.n~..!y.......VZm.;.......K.-....J..;.{.i..x...."J.q.h.:..;m................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...T...#Strings............#US.........#GUID.......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):130664
                                                              Entropy (8bit):5.482829191526948
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6BEF8D0F8BF260B2FC891FEAF68F24E9
                                                              SHA1:1212FBB9CE60D47BD819B4A45C4C0CCCBA8B2DFD
                                                              SHA-256:F6760BB73124651D55C1A94ECE9DBFC7B7FDAA8D168EBC069204719D3E56AF0F
                                                              SHA-512:0C66CD1306DC69DAC0225308CF10581E93EA599EADBCD1C02830DF630BB347DC0ED4959C8F8F07821131B74BAB29CDA345264AF486CB5940515A84071F3B05E5
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...t%kf...........!..................... ........... .......................@.......@....@.................................l...O.......@...............h(... ....................................................... ............... ..H............text........ ...................... ..`.rsrc...@...........................@..@.reloc....... ......................@..B........................H...........h............ ..3...P ........................................:V...i....Z..Q^.*y.\.6..zs.T.A..7..D..'.\.....d....7.#~..2&|K..Uqd. ..X@...e.Z.....E.....M...3.i.`?..tQ.P...5?r..}N["e{M../..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.S,.../..aZ..........g=B........(3.....-N...|..........}......F.^.........%K.>.W..l...g..P..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):21608
                                                              Entropy (8bit):6.557771196472087
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6F67C6A8FF82E31EABA248ED95F067CF
                                                              SHA1:2F26378521478DB1EE911A72AE8A0BCAA587E287
                                                              SHA-256:BFB6FE58CBAC08C9576D4807A6A6CC750F8EE1B286D9C8D279CC20D862287DE3
                                                              SHA-512:B701795D8E7C538051A8D0A88B7A647CA2B51FEB097590930ED949BACD74760F8B9E8F67C2631E8128D5119DBBD60FDA2DD459979A8C541FC9A452D19AEC0D8C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf...........!....."...........A... ...`....... ...............................]....@.................................lA..O....`...............,..h(........................................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................A......H........<............... ......P .........................................IF...[..h..F.c.D.j...Ln.y......S...........9...L.z..Dl'.7_....v.g..`.,./.K...F..D.....B]..3.f.(.w...0*...2....O1.Q...[..................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet...._.......PADPADP........V.....o.Y.@.......+.......`.1/.......V...&.}..T[.....d.R.[...{.O.=...M..3..c..Q...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):38504
                                                              Entropy (8bit):5.979022248096841
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3984AC6E995200D4940E9F350EE166AA
                                                              SHA1:AB972232ABDB2D4A05EA462E7EE75B2C261502F0
                                                              SHA-256:4303223BBDFB63EB5D7092E19450CB927B88BA32C3F9D4684E8949C123037FF3
                                                              SHA-512:39D35B569A7C7D96F4BDA34018549B4E45B1FE0F6C535B7E3ACBB8223060C4F7C356DCB3FBCF4CCEACB4881933BB5F7C60025F31A632B033B59CA59BD1793C56
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.....d..........N.... ........... ...............................-....@....................................W....................n..h(........................................................... ............... ..H............text...Tb... ...d.................. ..`.rsrc................f..............@..@.reloc...............l..............@..B................0.......H.......@}............... ..n\..P ......................................>..^...~$.vJ.C.E....._..%.....|..E.......*?..(....W.....2?..Ha........@.*.f.b..:....qk.5.. .y.cM.."..f..f$h....7..9.4.j\.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....."..v.......&.Q.R..p..>._..|.......s,.[.<.T............^...n............mB.9..<...j...x.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):17000
                                                              Entropy (8bit):6.723705988474288
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:33FAD2C157BA19C4F33D4DB11EFC9AD9
                                                              SHA1:D1EB05EB6B77A65910A91742AAE0E8A497CB1319
                                                              SHA-256:6381298E27710287C81ED99AD2347CB82FFEA45F4F7F5EF65AF31315F10CB9CE
                                                              SHA-512:673621BFAE837CF66F7755A9E45996F54394F0DF9CF627B95FAF8C29D19F53ACAA412399C960B70DE853E69DD4765EDB0CD1338EE7720A0EE0E15A129092CACC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!..................... ...@....... ...............................r....@..................................-..S....@..`...............h(...`....................................................... ............... ..H............text...$.... ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B........................H.......H)............... ..v...P ........................................tc.la"..@...*..7..25....*.G..?z.xHu.'...u.M.}...hL.[..GUr.............Sx....2x......;o.Mh....-*V.jyU...p..L..xm..E.r..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....hp...M..Sk..6-...m#..kZ`.3]$.w^,.......t...]...........................XA.r.t.i.c.u.l.a.t.e.3.6
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):16488
                                                              Entropy (8bit):6.803756453810723
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C127027660298E4E3E78B4A291414363
                                                              SHA1:48FD55F89BB9C617D7125B596DA55540BE9C8C49
                                                              SHA-256:D702BCDC3EC748A34A2C7938903A02F45FAAB5CE22FCFFE3A3D2F62D886D665E
                                                              SHA-512:CD1BFE9F0FD1E5343EB3B73F324A16B88A15A5C193AC4531F113F0348BAB28F68C05697BAF4CAE8F026DE35040E7828368992D14A55D5A83EF9A967300457E2A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.................,... ...@....... ....................................@..................................,..K....@..(...............h(...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...(....@......................@..@.reloc.......`......................@..B.................,......H.......\(..T............ ......P ......................................[A.CD...O..={.1.........1.9.J\6...,"..:..xnNf..s.Mw.1...&d:Ie,..p....z{....F03a.+..).x.#.[....G.!...SO.@&..<..D+..%.....................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP...|M......T.|.3.q...BU,..ls.asY.J.......K...2.....H6...>?.->=.Q>...>.E.O..<c!..u~..|...|...~M...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):14952
                                                              Entropy (8bit):6.8935119239632865
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:503523BC36DA06A19E26553563C11F6B
                                                              SHA1:8B4D1073BE35F7B9CDE5981040134A1F7914BBCF
                                                              SHA-256:508415A5791D2FF003E8D1A866670BF4A681A098B756A6347044696EFC1657DC
                                                              SHA-512:BF8B9B71EB70F47C14F7A7327FEA8ECECA931F5B7319C7C413594C423B41F0A235F01B90B6A99F5BF4678ACE517545F90BF7A0E1456B791C0588BC1CDAD9438C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf...........!.................&... ...@....... ..............................+a....@.................................4&..W....@..................h(...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p&......H........!............... ......P .........................................(.....'..".p...#.VR3..}[.._...WbN.6q.....x.,...u.@j.+5../...R.F.Q..1>\V.....t.b,."..#.t..%EC..j.492.9....r...}.-f.K(3.{}...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....BSJB............v4.0.30319......l.......#~..`...\...#Strings............#US.........#GUID.......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):130152
                                                              Entropy (8bit):5.521265528803377
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4180EFC11A592826B1DCD1A69874D4FF
                                                              SHA1:01BE0E1F2954FF8ACB6784DE0CC7341F277BB84D
                                                              SHA-256:B9254C334DA0967C1FA0EABD0F7E3A9764C37A4D88E730B694B84DF02706994A
                                                              SHA-512:195193EB1668F6BA7F628A1682072EDA28C0E619C97E6BE2D807504D0BDF9977D5DB49C07EB3B1747F5F16510AEECE7FE606E37A3E34F1DE809D4ECB5F865986
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...t%kf...........!................N.... ........... .......................@............@.....................................K.......@...............h(... ....................................................... ............... ..H............text...T.... ...................... ..`.rsrc...@...........................@..@.reloc....... ......................@..B................0.......H...........l............ ......P ......................................y.`.{.j....==gQ.=.|j+'.........t.z..Je.F...~.^3x...v.L...C+...c.p9K.G.x.....x......v(.qk.^GO.r.p....q%j....7.y.+{a..?:.LlI.V...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.S,.../..aZ........g=B........(3.....-N...|..........}......F.^.........%K.>.W..l...g..P..6...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):22120
                                                              Entropy (8bit):6.518781513754287
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:302D8BFF20790E845803DF693BED1BAE
                                                              SHA1:58A81617D1758A86455FDBB4E7E2E7A138A96DAC
                                                              SHA-256:6CF67AF088FF79E1F37C52CA097A66235C1081C8F388B4B11675737101A17F1A
                                                              SHA-512:F0A1A056BD45482CB26291B65D7C92E5CC4498F036E32158F803CC61D401B656D71D57C24F518BFE5A8B9650669B94582D8F07D1DF641F02562BA3868C300DB6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....&kf...........!.....$...........B... ...`....... ....................................@.................................HB..S....`..................h(........................................................... ............... ..H............text...."... ...$.................. ..`.rsrc........`.......&..............@..@.reloc...............,..............@..B.................B......H........=............... ......P ......................................a..8....$..Z\....'.[...Kbo..Q7.....Q?..g.i....X.@.]..Y.7.K=...@.c~..O.Y.i.}.K..."..-...Cb....B....?.....Z ...|.T..cpm.D.................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....^.......PADPADP........V.....o.Y.@.......+.......`.1/.......V...&.}..T[.....d.R.[...{.O.=...M..3..c..Q...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):39528
                                                              Entropy (8bit):6.009964199490928
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:77EA470549B6B02B1EDC4BD71A4B444E
                                                              SHA1:DE798E513F5E5B482A8555760007E5DC525CEE96
                                                              SHA-256:1BAED2AC84CD06EE6D7CE106E4B4C9F5E79F674461D5B84C364880CF539BB709
                                                              SHA-512:3F732CDE42D32E24EB2C8136A490CF33B4AD1DA0D144ADE62F82BB5CD039C7C3D7211B1FBC36B5F6A79966E932DB512D9468F40D0F8CCE5E9AAB2CC44B9FBB0E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.....h..........n.... ........... ..............................[.....@................................. ...K....................r..h(........................................................... ............... ..H............text...tf... ...h.................. ..`.rsrc................j..............@..@.reloc...............p..............@..B................P.......H.......d................ ...`..P ...........................................os...J.nw.i. ..B....^6..d/....&.....^.x.h.`:..8O.=...].....l..b..R...[{..<..1...@U.'.@.H.......`%..B.....z.}.....l.`.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....."..v.......&.Q.R..p..>._..|.......s,.[.<.T............^...n............mB.9..<...j...x.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):17000
                                                              Entropy (8bit):6.731553948835644
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6F5D7E4685F1052AB77E7F9D8F6C49DE
                                                              SHA1:DD3AFC7E378E1C962952280BAAC7A9C25B2C2115
                                                              SHA-256:ED34FB654558C83EA9C4546910841B0C318CB0AE0733FBC07209E78E940DCAAB
                                                              SHA-512:4C130B53FE4C02C69A9FAFC858B7533D042607EA941DCC6A5BEAA8D1393DAE20A9A2E4DFA5DF224BFFFC198F6FF6A4C920F94E96441AF38588512FB910AF5FDE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.................-... ...@....... ....................................@..................................-..W....@..`...............h(...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B.................-......H....... )............... ..M...P ......................................7.B......`w.....s.d.|I......9..~..........^a...%.....3.....n>..Il1........W.\X...2..Z.\4.H...|..(..S...`..c.)]i.......tqI..............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP....hp...M..Sk..6-...m#..kZ`.3]$.w^,.......t...]...........................XA.r.t.i.c.u.l.a.t.e.3.6
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):16488
                                                              Entropy (8bit):6.820282625278445
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C0F5842E92E8CB85A0827B0FAEA097E6
                                                              SHA1:0DCF1C8D821B3B8E5B03DD9C9CE52B9783BD0E4D
                                                              SHA-256:5538E2424BD1D3874A5742161F7CFA7FF7E4CABA0C218605D5DDF7A36439DAE6
                                                              SHA-512:EFEF3E661068025BB2CF122CF95B3E8EE086C4AFCBB560CE2E584E1CF31607DF6182D544326D8CB5556945A37E61434B34174AD308051265E267F9D4B9DBE3BD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!................>-... ...@....... ..............................B.....@..................................,..O....@..(...............h(...`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc...(....@......................@..@.reloc.......`......................@..B................ -......H........(..\............ ......P .......................................+als....;..@O_.E5..53.R.W.N...X.......LR.....*.^...i...4Z..G@.....*X.vD.?.b.~..e$ m..(..@P.\mx.e~1..).M....@N......*.................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP...|M......T.|.3.q...BU,..ls.$sY.J.......K...2.....H6...>?.->=.Q>...>.E.O..<c!..u~..|...|...~M...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):37480
                                                              Entropy (8bit):6.2421189237264425
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:66A2F1551C55A87B801AC2D6B0118CD9
                                                              SHA1:40C0FCD0096B3193A1FB3D58580288A0E28D3422
                                                              SHA-256:E8ADDBE122659719599418E4F758EEEF9A5F82337633122DF4E5C39852C0AF4B
                                                              SHA-512:0C52BE4C80EB7AEC38B66AE4939B9BC8EBAF060EA5F17F6EA4A21CECA6B002C9CA8BB5DA4D1E0648B7017833EE32AAEFB2FA9CC0D3B917573E28AC80AC68DA0B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0..`..........R.... ........... ...................................`.....................................O.......L............j..h(.......... ~..T............................................ ............... ..H............text...X_... ...`.................. ..`.rsrc...L............b..............@..@.reloc...............h..............@..B................4.......H.......(6..xG...................}.......................................~....*.......*..0../.......~..........(....(....-..s....(.......,..(.....*..........$.......0..0.......~..........(....(....-...s....(.......,..(.....*.........%.......0..4.......~..........(....(....,.(....o*....(.......,..(.....*........!)........(....*Vr...p.....s.........*..{....*"..}....*..0..)........{.........(....t!.....|......(...+...3.*....0..)........{.........(....t!.....|......(...+...3.*...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):218216
                                                              Entropy (8bit):5.257021511871449
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:19F3A3EF1A887820D421BA01C8CD6CF3
                                                              SHA1:B019659EC5532174A4E4968A2AD1CEA96F8D26B4
                                                              SHA-256:2795EE4F0B800D5E5EA055A36E095EAE229CD126868BB809CC961C8E9F423107
                                                              SHA-512:D2A26DD204F4B19ECE5E4C6C9A082EE15F1E8FE4B320B81305DADDF67FBD4FE97CA47A9BA71E2491CF910CB579259BDCEDEBD7275D3ED94D3F04AB1E3885C7F7
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf..............0..0..........vO... ...`....@.. ....................................`.................................$O..O....`...............,..h(...`.......M............................................... ............... ..H............text...|/... ...0.................. ..`.rsrc........`.......2..............@..@.reloc.......`.......*..............@..B................XO......H.......|'...%..................lM........................................(....*^.(.......8...%...}....*:.(......}....*:.(......}....*...0...........(....~........(....(....(....r...prC..ps....s......o....,..o.....(....r...p.s.....s....o........(....~....r...p(...+( ...s!.......o".....o#.....o$...s%.....s&.....~....%-.&~..........s'...%.....((...().....(...+....(...+&..(...+&..(...+&..(...+&..(...+&..(...+&..(...+&..(...+&~+....(,...,...(...+&..(...+&..(...+&..(...+&..(...+&.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):6247
                                                              Entropy (8bit):5.041268739159272
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D52F58A3E699640D429CD35E2661EB5A
                                                              SHA1:089B76B73B3C4265CC1B5617EE6E3FEEA11B4F25
                                                              SHA-256:1CD0CB3F85D9362CDCA8139DF2FFAC2D7240C470FA766D43B811A4D43143526B
                                                              SHA-512:BC395633BCAE1A0BF5FBFFAA5D8F15454C7D7AB2BFC9AF90380A0BC92CC5C69235823ED90E7CFE24B54D6B4BC49611B269D908AB06158954888CF6B10BB95611
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <section name="http" type="Articulate.ThreeSixty.Core.Internal.HttpConfigurationSection, Articulate.ThreeSixty.Core" />.. </configSections>.. <system.diagnostics>.. <sources>.. <source name="ApplicationLog" switchValue="Information"></source>.. <source name="Configuration" switchValue="Information"></source>.. <source name="ErrorReporting" switchValue="Error"></source>.. <source name="Installation" switchValue="Information"></source>.. <source name="ThreeSixtyApi" switchValue="Information"></source>.. <source name="ThreeSixtyAuthorization" switchValue="Information"></source>.. <source name="ThreeSixtyDesktopService" switchValue="Information"></source>.. <source name="ThreeSixtyDownloads" switchValue="Information"></source>.. <source name="ThreeSixtyRemoting" switchValue="Information"></source>.. <source name="ThreeSixtySerialization" switchValue="Infor
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:MS Windows shortcut, Item id list present, Has Relative path, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
                                                              Category:dropped
                                                              Size (bytes):2481
                                                              Entropy (8bit):2.6232005143987753
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:096014CEB2F06BFF079D18152A56A5FB
                                                              SHA1:4267ED2BA84F7D306BC2B3487F7D1BB9076705F3
                                                              SHA-256:0915287943B8C002E4A5B466F015DB8A2783878530A9D692DDBE62403C54B02A
                                                              SHA-512:780481A2B1FA4EEA1908727C6E9FF13EC592D36161BD51E78022408FA94EA72DA52342557C667E500C52D2C85D08BD7A519FDF9D7D065863F8C6E905712A28BF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.P...........................................................P.O. .:i.....+00.../C:\...................V.1.....VY.F..Windows.@......OwHVY.G....3.....................}/8.W.i.n.d.o.w.s.....\.1.....VY.G..Installer.D......O.IVY.G............................&.I.n.s.t.a.l.l.e.r.......1.....VY.G..{1D482~1..~......VY.GVY.G...........................'..{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.....r.2.h&..VY.G!.DESKTO~1.EXE..V......VY.GVY.G..............................D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.......W.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.N.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.........(LyJ,d[Q}96FN{74yHvfDesktopService>oolPXJu&1C,_(HB)iQsU....................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):27752
                                                              Entropy (8bit):6.588382559801127
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8D957058B1D6C04347E32BC849C5DA66
                                                              SHA1:85C8C539D5E6C3B07E3E6E0E320D5A081F72A544
                                                              SHA-256:A4B28A4CAF07A27D457F7B817ACCB301D3B515DF76E3B8A478AFE5DED4C5AA36
                                                              SHA-512:8EC109FE31E53FAF42F68B77280E1D854448C68470D01F69810885278A07F4A783EA76FC34B232E0EE487F02FF63F7B155831055AA983507F6F751D330116A9D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%b............!..0..:...........Y... ...`....... ....................................`..................................X..O....`..`............D..h(...........W..T............................................ ............... ..H............text....9... ...:.................. ..`.rsrc...`....`.......<..............@..@.reloc...............B..............@..B.................X......H........0...'..................(W........................................(....*:.(......}....*6..s....s....*"..s....*r.(......}......}......}....*..0..O..........(.........(......{.....o.....s.......(......jo.........,..o......,..o......*....... ..9..........0C.......0..Q..........(...........(......{.....o.....s.......(......jo.........,..o......,..o......*........."..;..........0E.......0..V..........(.........(......{.......o.....s.......(....o......jo.........,..o......,
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):38504
                                                              Entropy (8bit):6.119593477643397
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:50530BDD1D21F076F2D2BE1E8ABA202F
                                                              SHA1:4C278E9B5B28B40A344AD3CBE773B17524597550
                                                              SHA-256:4C38F9D34AAA91F8F612F374CBC71AAB715EFAE3D10A2E79C55618A187CCA690
                                                              SHA-512:83A9CCA4BC99A93694A4ECED198C2F93D1FBB5BCF16C1D0A1CB1D8D391AFCAF213B4A25AC83221DFD28D272CC1646B24C874417F21637C3A41089344824394AB
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.....f.............. ........... ..............................>`....@.....................................K.......X............n..h(........................................................... ............... ..H............text....d... ...f.................. ..`.rsrc...X............h..............@..@.reloc...............l..............@..B.......................H........N...5..................P ........................................=i...p.>5.rh8.......,v1.#g.p...nE..6.j./....._.r>/32...:w ..q[Y...k.[7....'...+..@.W?..0).C.........J.R......_.#.{4:.......(.....-..r...pr5..p(....*.(.....r...pr5..p.t......(....*...0..~........(.....-..r7..pr5..p(....*.(.....t......-..r7..pr5..p(....*.r7..pr5..p..(......+..r...pr5..p..o......(......X...o....2..(....*..(.....-..ry..pr5..p(....*.(.....ry..pr5..p.t......(....*..(.....-..r...pr5..p(..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):136808
                                                              Entropy (8bit):5.999178307056221
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D435B00695A4E004C30005E9067C2BD1
                                                              SHA1:31B6BF4412481E8E75876A84EE26A9DFC5B321A1
                                                              SHA-256:FA63EE9748652A4CA33780781E880410A009A6F8A89188D8BC68ADA2E76B7180
                                                              SHA-512:8701BD62F849758C60B41162B43926C9C11AEA2655C24A1426EC8CE03B9719D45B5581BDC4DDF10DFD26C6A52E3E9C623E1F818CFA4C991FE215927FFE2E38F0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!..0.............J.... ... ....... .......................`............`.....................................O.... ..`...............h(...@..........T............................................ ............... ..H............text...`.... ...................... ..`.rsrc...`.... ......................@..@.reloc.......@......................@..B................,.......H...........Lm..................h.........................................(!...*:.(!.....}....*..0..)........{"........(#...t......|".....(...+...3.*....0..)........{"........(%...t......|".....(...+...3.*..{&...*"..}&...*..{'...*"..}'...*..((.....})....s*...(+.......,...s-...o....*..(/...*..0..M........{)...o0...-.*...{)...o1...o2.......u....-..u....-..u....,.......(3....(4...*............"......R.....4...o5...(+...*2.~6...(7...*...0...........{".....,....o8...*..(/...*..0..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):108648
                                                              Entropy (8bit):6.356165613669871
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7008E210A1551C18D8E66C3BA9DAA1BB
                                                              SHA1:E40772FDF8493B3FB181C90C6DAA6403DC6F5E39
                                                              SHA-256:7A726AE3840D6F93AD85753093156B94A8DA091CA39B3652B9ECDD9022710679
                                                              SHA-512:E40D41C2D6C1CBA394DE7E813752F157D47E63C7F1A0727EC3D4B72A1CDBCA03A15D7A932971E879B43296D5251A4F6D441CF7E2280275EF097BA7BAC742DF9F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$kf...........!..0..v............... ........... ....................................`.................................L...O.......p...............h(........................................................... ............... ..H............text....u... ...v.................. ..`.rsrc...p............x..............@..@.reloc...............~..............@..B........................H........>..............$...p.............................................(....*:.(......}....*..(....*..0..-.......~....- r...p.....(....o....s...........~....*.~....*.......*V(....r}..p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r...p~....o....*V(....r/..p~....o....*V(....rA..p~....o....*V(....rS..p~....o.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):828008
                                                              Entropy (8bit):5.889714361137683
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A76F700A9FA7E5213CD9BD32D171173C
                                                              SHA1:A5A4A449DF9C526A3AB67DBEC8171F39FEB73C4A
                                                              SHA-256:FA34F89FB51BA30767F238CF1B93C109D87AAD9136EB3D17F2D242C15A579C65
                                                              SHA-512:AEAF77823AFA504D8308FD72DAF18417D798A55BFABC30B981BF1A44430E2DCAF6E4A6C7BA00867B8A012068BE2B31B2024C2816214979DB04B7DCB2E4199EBA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..................!..0..p............... ........... ..............................1.....`.................................X...O.......8............z..h(..........\...T............................................ ............... ..H............text....n... ...p.................. ..`.rsrc...8............r..............@..@.reloc...............x..............@..B........................H........... ................r...........................................(+...*:.(+.....}....*..{....*:.(+.....}....*..(+...*...0..9........-...../....+..o(...%-.&..../....+.o5...s,......(-......*.. ....... ....... ....... ......*.*^(.....o/....(0...(....*N..(1....(0...(....*Fr...p.(....(2...*..0..Y.........3..*..Y(3....."......."......."....4..l.#........Z..*.(3.....(3.......X"....(4...[l...*....0..:.........>j..(5......j1..(.....(.......(6...(2...*.(.......(6...*...0..)...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):52840
                                                              Entropy (8bit):6.0948001782659444
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E6A5D270DC5B9C005ACC191BEB71D265
                                                              SHA1:60F02D57A95006ADE875A74242BBC7B7C2712114
                                                              SHA-256:D4D5BABFA749550D53CFBBAB4053238E783BD4DF6CF50CD73944CA6A22A99C76
                                                              SHA-512:BFA86C70FB23C998007AD034A42F0FB1268EC30C53D8155A4808691F6908C70421B9BEDEFD623C0AAB55A24BA26929844CEA907B07B004E87B6F7B8982CAF0D2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...z.$..........." ..0................. ........... ...............................Y....`.....................................O.......`...............h(..........d...T............................................ ............... ..H............text........ ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B........................H........=...[..........l...x ..........................................0...........s....s{...s.....+..*....0..$........~+....(...+..,...(.....+.s.....+..*.0..?........~.....(...+..,%.s....s{...s....sr...(.......ss....+.s.....+..*..0...........s.....s{......s.......s......s....(.......s....(.........~,.........%.......(...+sk........~+.........%.......(...+sk.........s......+...*..0.............s....s.....+..**..(!.....*&.(".....*..0..9........~.........,".r...p.....(#...o$.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):2383976
                                                              Entropy (8bit):6.507344437159318
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FE329FF0A398B8AA5113613A1338F40D
                                                              SHA1:DE0DB40DA5FB35FAC23E1B961998BF51DE48AE12
                                                              SHA-256:36BE47330CDCE98D7AEEF2F5C35D4A42854E47BECF160E3045403D2523F204A2
                                                              SHA-512:20DD67672E4410EF0A31CF59B17566C678168C5DCAD77E21EEDB343FA7230CB681F0CA66D99F0216DCE8C083BA408E199887E9966BA7B5D12E0522FF4D4618EC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......>5.4zT`gzT`gzT`g1,cfpT`g1,ef.T`g1,dfnT`g1,afyT`gzTag(T`g.(efdT`g.(dfuT`g.(cfnT`g ..g.T`gzT`g.Q`g.)ef{T`g.)`f{T`g.).g{T`g.)bf{T`gRichzT`g........................PE..L....gnd...........!...#.>"..................`"...............................$.......$...@...........................#.......#.(.....$..............8$.h(... $. U....#...............................#.@............`"..............................text...Sr.......t.................. ..`IPPCODE..............x.............. ..`.rdata.......`"......B".............@..@.data...4.....#.......#.............@....rsrc.........$.......#.............@..@.reloc.. U... $..V....#.............@..B................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):227432
                                                              Entropy (8bit):6.495726601049763
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:EC7F6CB78F4E593013E7AB9FB9F5449B
                                                              SHA1:1A869790BC96718C7F57E95AC2C13CD644D7C61E
                                                              SHA-256:BC6375C794679C52852B4B866B4F60DD00C46FF10AE0F843F789310DDEC65D96
                                                              SHA-512:C995101B1473553BCA293BAF063F2778D5C79E0426946D9082A15E05C4456D8D1AFD5596D0C138F46C3BA5F3DB248CB87A54F07CF1B9AF349A8E47BF080AEBAA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........v&..H...H...H..o...H..E...H..bM...H..bL...H..bK...H..bI...H..qI...H...I...H.{bA...H.{bM...H.{b....H......H.{bJ...H.Rich..H.........................PE..L....$kf...........!......................................................................@..........................................P..H............P..h(...`......8...T...............................@...........................8...H............text...1........................... ..`.rdata...E.......F..................@..@.data........0......................@....rsrc...H....P......................@..@.reloc.......`.......4..............@..B................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):197736
                                                              Entropy (8bit):6.2157133059117085
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FCF2116D93EFC021F4DB56AFFF8B5249
                                                              SHA1:EC02333C0781ECFD0DA81B323D8C939442F7A069
                                                              SHA-256:22FFADF189388144A56A8275F108EC61E647F63B11587036A530C1249BBE1665
                                                              SHA-512:141A194EA1B50A94236DB4F3D9F51D989EF7172D8BF257A6A68F493891A0C5E3EB02ABB6C4D43C7A9663F0C4668FF0245E10D4B9A11854D7831CF41C89947DC9
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....B.............!..0.................. ........... .......................@...........`.....................................O.......|...............h(... ..........T............................................ ............... ..H............text........ ...................... ..`.rsrc...|...........................@..@.reloc....... ......................@..B........................H....... .................................................................{....*..{....*..{....*..{....*..( .....}......}......}.......}....*....0..q........u........d.,_(!....{.....{....o"...,G(#....{.....{....o$...,/(%....{.....{....o&...,.('....{.....{....o(...*.*.*....0..b....... ._). )UU.Z(!....{....o)...X )UU.Z(#....{....o*...X )UU.Z(%....{....o+...X )UU.Z('....{....o,...X*...0...........r...p......%..{.......%q.........-.&.+.......o-....%..{.......%q.........-.&.+.....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):581224
                                                              Entropy (8bit):5.795571130959023
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1E0CD9C6BEEB669C1878984798CEFECD
                                                              SHA1:0DAE151783367F36F85D46E884D61A055A4E1D0F
                                                              SHA-256:CB5AC0608B7874F6C8516E05E8B10436A55627FA3224A92BE5619F8119DFC778
                                                              SHA-512:C94CE4E5E6AF6F6F9C8B8521C182FA1762B5D107B9844BC0A736C0AD139FB1C428FDDDF0819D49F818FA4C4B982EEEA62A2F4DE693833E0F592C2957DD081E39
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!..0.................. ........... ....................... ......~.....`.................................p...O.......................h(..........8................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........h...Z............................................................{P...*..{Q...*V.(R.....}P.....}Q...*...0..A........uS.......4.,/(S....{P....{P...oT...,.(U....{Q....{Q...oV...*.*.*. ...( )UU.Z(S....{P...oW...X )UU.Z(U....{Q...oX...X*...0..b........r...p......%..{P......%q.........-.&.+.......oY....%..{Q......%qV....V...-.&.+...V...oY....(Z...*..{[...*..{\...*V.(R.....}[.....}\...*.0..A........uW.......4.,/(S....{[....{[...oT...,.(U....{\....{\...oV...*.*.*. .#c/ )UU.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):140904
                                                              Entropy (8bit):6.349151193691228
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:137D9DF58782E276100FF6C99B455386
                                                              SHA1:847A83D3E68AF91FBC374E8D529973182485808D
                                                              SHA-256:0CBA793B2F7EC01162C24D57382353039E1B45D74ACEC00CEE868CD5EBA2511F
                                                              SHA-512:B2D0BDF6DE66A53036D8125D38B93F8D0FF33FDC2D83706898D8ACF117275B72CF69D088A42D98098963D8A5E10907DD853C170149CB48FF938AD349D3F4E7B8
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!..0.................. ... ....... .......................`............`.................................H...O.... ..................h(...@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................|.......H.......p... Y............................................................(&...*^.(&..........%...}....*:.(&.....}....*:.(&.....}....*:.(&.....}....*....0..............('...((...()...(*...~....%-.&...+...s,...%.....~....%-.&...-...s....%.....~....%-.&.../...s0...%.....~....%-.&...1...s2...%.....(3...(4...(5...~....%-.&...6...s7...%.....(8...(9...(:...(;...(<...(=...(>...(?...(@...(A...(....*...0...........(B......sC.....(D...}.....-.~E...r...p(...+(G...sH...z.~E...r...p(...+(
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1489000
                                                              Entropy (8bit):5.890458676300453
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:53EBA9545FA12BED8527A2C23711FF46
                                                              SHA1:BA8CB38FF4C315911D50826D7DD8FBBC15B7EE28
                                                              SHA-256:3E979E409BF99295D0BAE270126C0BC0156875953E9F81E0BBF76F2E5234E672
                                                              SHA-512:FBDC9831C64286639F47A3A37133A48F27374E9BF6DB3AEF3174AC2ADB0A2E7764914B837CA67C0F737D147E6B7725553D2240D25C1893BFC991CC5F564A3A89
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Z.............!..0..`... ......zq... ........... ..............................'I....`.................................(q..O.......................h(..........@p..T............................................ ............... ..H............text....S... ...`.................. ..`.rsrc................p..............@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):163864
                                                              Entropy (8bit):6.2886591641914595
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:22A92B5859F7AFC9BEF8B2FC39FA738E
                                                              SHA1:F3E5795DDFF23557F0E586321F509D97D34FB670
                                                              SHA-256:909F5C7909FC25812A16AB711990360749BCC71FDACBC482674E1012B7E5A3EF
                                                              SHA-512:D6A09D6DC4291573DE03D6E3AE442D16A67DD52B0ADEAAFF11A47FBF43A3BE31267B74F6D11776E04DCD114BA45AEED1EF787D73B6FAB035357677B428A631D3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....'............" ..0..............L... ...`....... ....................................`.................................kL..O....`...............8...H...........K..T............................................ ............... ..H............text....,... ...................... ..`.rsrc........`.......0..............@..@.reloc...............6..............@..B.................L......H................................K......................................N.r...p..(....(....*.0..;........(....,.r...ps....z.-.r...p..(....r!..p..(......o....(....*N.r...p..(....(....*..0..E........(....,.r...ps....z.-.r...p..(.....(....r1..p.(....( .....o....(....*..(!...,.~"...*.(#...r5..pr=..po$...*N.o%.....s....o&...*N.o%.....s....o&...*N.o%.....s....o&...*6.rA..p.(....*N.o'.....s....o&...*N.o'.....s....o&...*N.o'.....s....o&...*6.rA..p.(....*..(......^...%..=.o(......+.-o
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):22120
                                                              Entropy (8bit):6.620532554323023
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:0B44557CF13D0CF87B14F05E5B1A6507
                                                              SHA1:EABA25D182D732EC6F1E79B0A78A4C58FA0CB47A
                                                              SHA-256:DD4BAF0AAE6D2535FF8AA8F60F9FFC7A94AE10FD2ADB2C8234A4B0ACD1C57F4A
                                                              SHA-512:42105B12E5751FA4891FB774113AC9737A5E1CFD0587445AB3B6E7105BA56491A1455DF7F5E63F67D44CFE758A633747630AE62F53E9DC84E1A4AA71F606704C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..$...........C... ...`....... ..............................!Y....`..................................B..O....`..................h(...........A..T............................................ ............... ..H............text....#... ...$.................. ..`.rsrc........`.......&..............@..@.reloc...............,..............@..B.................B......H........"..l...................TA........................................(....*^.(...........%...}....*:.(......}....*:.(......}....*V!.I.......s.........*..{....*"..}....*:.(......(....*..{....*"..}....*..{....*"..}....*N.(......s....(....*v.(......%-.&r...ps....z(....*..(....*..{....*"..}....*..{....*"..}....*..(......(......%-.&r...ps....z(....*n.(......(.......(....(....*..(....*..{....*"..}....*..{....*"..}....*v.(......%-.&r...ps....z(....*..(......%-.&r...ps....z(....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):343144
                                                              Entropy (8bit):6.2325313418324155
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C05B2BEAF349B7754EDF1FF023873C6E
                                                              SHA1:63D966470886FFE20F994D054ECE5BC8EF69165E
                                                              SHA-256:63B7C8C5B833574110CE84EAC8C12F29B49B7615D724B704EB310ACFD4173305
                                                              SHA-512:D9AFD39F2CC6498EC71A0EA1C2E0680C7B6BE25D506F777FA297F181945FEC8088A6BC1F14FB6033BB59C280D09F4FA3B5CE97D887652C42D73A4264FD871868
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....,..........." ..0..............%... ...@....... ...............................O....`.................................3%..O....@..................h(...`......\$..T............................................ ............... ..H............text...P.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................g%......H........7.......................#........................................{A...*..{B...*V.(C.....}A.....}B...*...0..A........u........4.,/(D....{A....{A...oE...,.(F....{B....{B...oG...*.*.*. .._. )UU.Z(D....{A...oH...X )UU.Z(F....{B...oI...X*...0..b........r...p......%..{A......%q.........-.&.+.......oJ....%..{B......%q.........-.&.+.......oJ....(K...*..(L...*..(L...*..(L...*..(L...*^.(L..........%...}....*:.(L.....}....*:.(L.....}....*V!.I.......sM........*2.(N...(O...*..sP.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):37128
                                                              Entropy (8bit):6.930538442862362
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:CAC7AC954F2FC94B675279703196DF4D
                                                              SHA1:E6271AF322655AD85AED803ED9509194B41527DE
                                                              SHA-256:4FA2D53629881A90B94FB6DFAFA3AD97933DEC08600D8E94D8331478E68EA54E
                                                              SHA-512:C078FDAEF548F78B3420BF34DD45D2C2419BBB24D2F637AF8C07EB984B65AA421D6C0CE43B9EE16C72C4219DB1766E4B785368B027B181736AAC43A5390A1032
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...$:............" ..0..4...........S... ...`....... ....................................`..................................S..O....`...............@...Q...........R..T............................................ ............... ..H............text....3... ...4.................. ..`.rsrc........`.......6..............@..@.reloc...............>..............@..B.................S......H........'..P*..................,R........................................(....*..(....*^.(.......1...%...}....*:.(......}....*:.(......}....*:.(......}....*:.(......}....*..(....*..(....*..(....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*..(....*:.(......}....*..{....*^.(.......2...%...}....*:.(......}....*..{....*z.(......}.......2...%...}....*V.(......}......}....*..{....*..{....*:.(......}....*..{....*..{....*"..}....*..{....*"..}....*..{
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):58632
                                                              Entropy (8bit):6.582013813731532
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A95EA2C3B0226B9251A496D84739FA67
                                                              SHA1:1063E4315C2B8338F77C737060C381C9F35E26CA
                                                              SHA-256:48A107A1853733A938D5ADD5FBEE44229CDDD38D57137361EB2DA76C4725F359
                                                              SHA-512:9E65A966E73A8BAAB5035737DB8EE1F2141BB037801FB7C65F1E72AF080A393095EA655FC67A2E0370AE57108F2068E5676A723762B84F0510C937F973DE4059
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....v..........." ..0.................. ........... ...............................C....`.....................................O........................Q..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B.......................H........=..da..........0.................................................(....*..(....*^.(.......>...%...}....*:.(......}....*:.(......}....*:.(......}....*:.(......}....**.-..(....*..s....z.~....*...0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..( ...*.(....,.r...p......%...%...%...(....*...(!...*.(....,!r...p......%...%...%...%...(....*....("...*..,&(....,..r...pr...p.(....(#...*..($...*.*.(.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):76544
                                                              Entropy (8bit):6.513714117866018
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C6946A811684C490C28F20E53E2A9467
                                                              SHA1:E961F5C72B294430F68C9AA754CE9154C79055B5
                                                              SHA-256:D887913710ABF0D4A4E5822052E2ADFF8CF4C834B49AF2AC16E0FD572486F8EC
                                                              SHA-512:E5D78E335C3433430D29EF11D40A9CD513133E578B5EA60385C515F6CB2C6A4E9742E543260291A5EACCFEEFCF02E9C6C3B7C9567BE5A82052689C368DFDDCA1
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..."Y#..........." ..0.............B.... ........... .......................@.......F....`.....................................O........................Q... ..........T............................................ ............... ..H............text...H.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................#.......H.......|P..(...................d.........................................("...*..("...*..("...*^.("......G...%...}....*:.(".....}....*:.(".....}....*:.(".....}....*:.(".....}....**.-..(....*..s#...z.~....*...0..........(....,..*..(.....o$......&...*...................0...........(.......(%...-..,..*.*.(....,.r...p......%...%...(&...*..('...*.(....,.r...p......%...%...%...(&...*...((...*.(....,!r...p......%...%...%...%...(&...*....()...*..,&(....,..r...pr...p.(&...(*...*..(+.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):74504
                                                              Entropy (8bit):6.560967243169765
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3C7E8B11F491D05D4CAB89F35888ED02
                                                              SHA1:743128E29A1DD64E69627A3220D62F6CB0D957F1
                                                              SHA-256:64134C03303BE82285BC6C3C146C9791182DF3DECCAA946BBDB4F07633A9CC9A
                                                              SHA-512:C683C534FFEB9B5571F55F98838C9495CA5238E6EA0511BB1F701381805F96455E02FF06CD19FC17CE4DA535C91FAAE692765B1D06C691CDEE6FF26579CBA2E0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?9V..........." ..0.................. ........... .......................@......9.....`.................................-...O.......H................Q... ......<...T............................................ ............... ..H............text........ ...................... ..`.rsrc...H...........................@..@.reloc....... ......................@..B................a.......H........G..............$.................................................( ...*^.( ......>...%...}....*:.( .....}....*:.( .....}....*:.( .....}....*:.( .....}....**.-..(....*..s!...z.~....*...0..........(....,..*..(.....o"......&...*...................0...........(.......(#...-..,..*.*.(....,.r...p......%...%...($...*..(%...*.(....,.r...p......%...%...%...($...*...(&...*.(....,!r...p......%...%...%...%...($...*....('...*..,&(....,..r...pr...p.($...((...*..()...*.*.(....,.r..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):41184
                                                              Entropy (8bit):6.942134034914649
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:943A84A4365441036FBB195C86CAD200
                                                              SHA1:A43354CC858A7AA21B8F84688DCC54EB4782FCC7
                                                              SHA-256:FB03764286B81FDA24636AB8035A4CCF36D37EE038C2E5A52FBEADEE2F35CF94
                                                              SHA-512:4637A7E6F82024ABF7AAA77F74F34796A14BC652AE56246B5995E22BA616FBF88F32487963C71799A622A6CFD837FEECB071E32B39446E602BE91E55CD0AE0E4
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....g..........." ..0..0...........N... ...`....... ...............................1....`..................................N..O....`..0............:...f...........M..8............................................ ............... ..H............text........ ...0.................. ..`.rsrc...0....`.......2..............@..@.reloc...............8..............@..B.................N......H.......,)...$..................DM......................................n......r...p.....s.........*:.(......(....*.~....*.~....*.......*.~....*..(....,..........(.........(....*..(....,..,....(/...(....*..(....*..(....,!.(.....2..........(.........(....*..(....,!.(.....2..,....(/...(....*..(....*..(....,!.(.....2..........(.........(....*..(....,!.(.....2..,....(/...(....*..(....*..(....,!.(.....2..........(.........(....*f.,....(/...(....*..(....*..(....,!.(.....2..........
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):149728
                                                              Entropy (8bit):6.007863508646638
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5606A0CF5178E1B2C4FBC3F3407D8A03
                                                              SHA1:AAB75888C897DDDC2EB67CEFACA6F44018F00DCC
                                                              SHA-256:F712DCB1DBBA80B72DD5A4C57BD8F9AFDDDC7985FA514DC74C20C423234D7B9E
                                                              SHA-512:45D88B5942B425D03EC3E3C7ACE76867EA24B418F2EB95390EC73DA008BF89DF54C8BC80C142A7723495BF0FC6315703EB9CC92E45A56B3C59DFBF5C6CEFCCC0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....,0..........." ..0.................. ........... .......................@.......d....`.....................................O........................f... ..........8............................................ ............... ..H............text...P.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H.......d....v..................p.........................................(&...**....(....*..0.............(P....-.r...p(....z.~....s....}.....~....s....}.....,)..(.....3.r...p......%...(....s....( ...z.o$.....o ...-,r...p......%..%-.&r...p.%...(....s!...( ...z....o........(....*..{....*..{....*.0..)........u......,..o....*.u%.....,..o....-..*.*.*....0...........("...,.r...p(....z.(...... [.0y5N. .355#. w..';..... .I<-;&.... .35.s8I.... .K.S;..... ..pu;..... [.0y.e8&.... ..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):45112
                                                              Entropy (8bit):6.6982838981969595
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:ED48B064F5EFCFCEFB574D23E0254FBC
                                                              SHA1:98158725267E50A444157FE73F4D98E981A91F37
                                                              SHA-256:CB9266EEF04D01F7EAB39EC5DDFF8B7452C31494FD66CA15B0A97564BCC1DED7
                                                              SHA-512:0633215BA13989F6694256224F4931FBEE5458667DD50A066946FB7FDEE58937AC958A3EB2542251F5E211A044FECFD531BA059081B14E13CA5AED1A69B83793
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0..X..........rv... ........... ....................................`..................................v..O....................b..8N...........u..T............................................ ............... ..H............text...xV... ...X.................. ..`.rsrc................Z..............@..@.reloc...............`..............@..B................Qv......H...........@A...........p.......t........................................(....*^.(.......?...%...}....*:.(......}....*:.(......}....*:.(......}....*V!.S.ux&...s ........*R.........r...p(....*J..(!...r!..p(....*..(...+.o"......r?..p(......o#......ra..p(....*j.(...+.o$......r...p(....*....0..[........(...+.u......,..o$.......+3.u......,..o%.......+..o&.....o'..........,..o(.....r...p(....*.......9..E......R.........r...p(....*J..(!...r!..p(....*R.u.......r...p(....*..,..(....&
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):36872
                                                              Entropy (8bit):6.704491010445066
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:0B1D24B3AC4B00EF72D6F4C4403F3A6F
                                                              SHA1:B00E96E82F5E8D1FF1FF69D0550A6600F5E38896
                                                              SHA-256:82726367149EDFA3746D12BE7B010C412C95727485DD9E1A202E4CEB5046DC8D
                                                              SHA-512:F6C650CD75A7B3EE40D2EFC3C724F1A07A7257311669AEAB9B733726429A41D544F7E8C7F397BE997E99623C35A30477CE39623601CD09D58C14DE20EA49320D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....j............" ..0..:..........jX... ...`....... ....................................`..................................X..O....`...............D...L..........$W..T............................................ ............... ..H............text...p8... ...:.................. ..`.rsrc........`.......<..............@..@.reloc...............B..............@..B................LX......H........$..8"...........G.......V.......................................~....*..0..1.......(....,..%-.&.*..(.....o.......&...,...o....,..*.*....................(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%...%...%...(....*....(....*.(....,"r...p......%...%...%...%....(....*......(
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):155136
                                                              Entropy (8bit):6.237526572569218
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D8FBA7FC4760C35D1BCEF80720A7FD47
                                                              SHA1:80C48C769CA00D4D631D99A4E463BE5D984E1CC2
                                                              SHA-256:BD98C0B28D83B64762EB2DEDAB81125D07D764477A2A85EC0C76F5F27957197A
                                                              SHA-512:6E54005DCB9D844D80B1463EAFF3047A1264BBA70F6B4EA167AC96F226E6C27CF1E01E1B537D7F8303D23A78560131EC8A82AB2BC6BDCC26B0301337ACCA0FAF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...g............" ..0..............'... ...@....... ....................................`..................................'..O....@...................L...`.......&..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H.......X....@..............8...4&........................................(-...*6.(.....{/...*..(0.......1...s2...o3....s4...}5...*..0..F........(6....{5...o7.....,0..+#..(8.........{5....o9........3...X...(6...2.*...0..J........{5....o:...,;(;...(v.........%......(<...o=....%..(>...o=....(?...s@...z*...0...........oA.....E............].......Y...*.oB...o#....+0.o!...........(C.....oD......{5.....(E....oF.....o....-......u#.....,..o......oG...o#....+#.o!.............oH....{5
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):712368
                                                              Entropy (8bit):5.978392845826107
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3B27EF279B89EE38EDCD828EFC594405
                                                              SHA1:3879C1FE3125E46AA29073DBC2A3EF1FBEDD7B1E
                                                              SHA-256:35EB8F04B397C3A1AE87684FEB066B0E0DB1CAD540DDF44CF0E474A206D97093
                                                              SHA-512:442B1D8FF4960336D1E8B879C7B9C2F866C98743C30BEAF960FEDDBF94A301E1B412A0375548D9179F3FBBD60BE27A016ACD39DD8C0DA8E0AF82B8F971ABA126
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.................. ........... ..............................<.....`.....................................O........................F.............T............................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B.......................H........{...,..................d.........................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X.+....b...aX...X...2.....cY.....cY....cY...{...._..{........+,..{^....3...{]......(....,...{]...*..{_.......-..*...0...........-.r...ps....z.o......-.~....*.~....X...+....b..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):19048
                                                              Entropy (8bit):6.729961007725467
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:45F025B6C903A4749FD42E9BA51EB575
                                                              SHA1:68BB8ED95B4FA14E05CEC56E7FDD980ECFF330D9
                                                              SHA-256:39B46EFA8958835E838D3DA35A872AE8271575EC45CFF50DC41BD81CAD735473
                                                              SHA-512:287C8F9BFECFD43300210E17041090D00D0D5173DBFA89758D0054457479E84E9927D1266B2529E17D3FB844BF21C70149CFFE6F915EE231FA7CB19AF704BEDA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...vY............!..0.............>9... ........@.. ...............................+....`..................................8..W....@..D............"..h(...`.......8............................................... ............... ..H............text...D.... ...................... ..`.rsrc...D....@......................@..@.reloc.......`....... ..............@..B................ 9......H.......X#..p....................".......................................*...0..o.......s....%.o......o..............i.........i.o.....o.....o....(......{....-...{ ....{!...s.........+.........{....*..0...............(......E....l.......?...E...K...............V...)...4...+_s....zr...ps....zr5..ps....zr_..ps....zr...ps....zr...ps....zs....zs....zr...ps....zr...ps....zr-..ps....z.*..{....*"..}....*z.rI..p......(....(......(....*2.{#...o....*..{$...*"..}$...*..{%...*"..}%...*..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):693248
                                                              Entropy (8bit):5.6609319136169685
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F59149C0D889E0FFCA3EAEF76AC6505E
                                                              SHA1:DE95C4D1D07B1F2656E7958C660C1BC2F0023188
                                                              SHA-256:CEF32579D19FBF9F036708C3928EE63623888F571B4B271A7CCB2ADDB1BB31FC
                                                              SHA-512:3DECF7E575031E44AA326667D293D42422E231D5CC323D26F1BDA17108C612D04E80D831E93E03EAA7232D15D08323E7D18603A2D3898A9171C17A8F29AB91DA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0......6.......+... ...@....... ....................................`..................................+..O....@...2...........F...N...........*..T............................................ ............... ..H............text...p.... ...................... ..`.rsrc....2...@...4..................@..@.reloc...............D..............@..B.................+......H............&..............h*..0*........................................{J...*..{K...*V.(L.....}J.....}K...*...0..A........u1.......4.,/(M....{J....{J...oN...,.(O....{K....{K...oP...*.*.*. .... )UU.Z(M....{J...oQ...X )UU.Z(O....{K...oR...X*...0..b........r...p......%..{J......%q4....4...-.&.+...4...oS....%..{K......%q5....5...-.&.+...5...oS....(T...*..{U...*..{V...*V.(L.....}U.....}V...*.0..A........u6.......4.,/(M....{U....{U...oN...,.(O....{V....{V...oP...*.*.*. ..#. )UU.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):564328
                                                              Entropy (8bit):6.295919812509042
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:687BDABE37CFBC1C8E3072ED689ED218
                                                              SHA1:11E311525B7DAE99CD9858C41ECF0341F0F1FE84
                                                              SHA-256:EB9EC59ADDE6B58121F306B5992734741A8ECA05F7205682D0142E117137FB67
                                                              SHA-512:521261135BBB22A36BF75F1EA2BE41EA4322D4E21F0EAD08F04A85A56C368FFC3B3FD54D4FD7020C449181F9F13022882043C5A864EA4BD011893497428352B8
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Y.d..........." ..0..f.............. ........... ....................................`.....................................O.......D............t..h(.............T............................................ ............... ..H............text...,e... ...f.................. ..`.rsrc...D............h..............@..@.reloc...............r..............@..B........................H...........h...........tw......D.........................................{0...*..{1...*V.(2.....}0.....}1...*...0..;........uD.....,/(3....{0....{0...o4...,.(5....{1....{1...o6...*.*. A.g. )UU.Z(3....{0...o7...X )UU.Z(5....{1...o8...X*.0..b........r...p......%..{0......%qG....G...-.&.+...G...o9....%..{1......%qH....H...-.&.+...H...o9....(:...*J.o.....o....s....*..{....*...}.....o;...r?..p..H...o......o....*..{....*...}.....o;...rE..p..H...o......o....*..{....*...}.....o;...r
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):31232
                                                              Entropy (8bit):6.9426695104256275
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:40DE61299AE8C7FE23B9E300DCFC5F2E
                                                              SHA1:F1FC0ED434A77BE3730637137D7FF8E6825C9C1B
                                                              SHA-256:DD9806BFBC8E415472BF0A678F30AA1CA5E6F83006E9E1F02BFE586E6FC14B14
                                                              SHA-512:880161BB62C882C1551047157B8F2B183FD7A425F8EC29BB1D687EB442C3E42AB54459204178D9FA6E02CF23519522C7C90ADC1E7EE0837D4B5ADB36D9295CD1
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....jM^.........." ..0..$..........BC... ...`....... ..............................4.....@..................................B..O....`..@................L...........A............................................... ............... ..H............text...H#... ...$.................. ..`.rsrc...@....`.......&..............@..@.reloc...............,..............@..B................$C......H........'...............?..X...8A......................................j~....%-.&(....s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*.~....*2r...p.(....*B.....(.........*R.....(...+%-.&(!...*^.....("....(...+&~....*.s$...*"..s%...*..(&...*.*....0......................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):183608
                                                              Entropy (8bit):6.377529050561113
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7F68A648B7EBA6DA9AB7BD1DFA108F67
                                                              SHA1:CE94606194D86ABB36A3EF2145489F526B1609F7
                                                              SHA-256:6E48DAE4ADF8BD54FC6E311B2D3D83909CB2A7482E5E5E466939300131786DAF
                                                              SHA-512:1B51763781B578428249DD94696ADE257E56EB96C83D0EBE301F718A0846C35832FC6B5B1264E8913A5136A314DB67B8403164F6E15D44448AAED14B2B986F53
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....'..........." ..0..p.............. ........... ....................................`.................................s...O....................|..8Q..........t...T............................................ ............... ..H............text....o... ...p.................. ..`.rsrc................r..............@..@.reloc...............z..............@..B........................H...........(...........4................................................{....*:.(/.....}....*..0..)........u%.........,.(0....{.....{....o1...*.*.*v ..yN )UU.Z(0....{....o2...X*..0..:........r...p......%..{.......%q'....'...-.&.+...'...o3....(4...*..{5...*:.(/.....}5...*....0..)........u(.........,.(0....{5....{5...o1...*.*.*v ..:. )UU.Z(0....{5...o2...X*..0..:........r-..p......%..{5......%q'....'...-.&.+...'...o3....(4...*..{6...*..{7...*V.(/.....}6.....}7...*.0..A.......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):95496
                                                              Entropy (8bit):6.472698141897204
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:82DC92BB08C340B18E4488FC8D618F85
                                                              SHA1:A6D0CCF9A0E0224AEDB9A8266B41D5F6685897B1
                                                              SHA-256:5AA3E131C3769075C057440FE887B40D8D6DB28E62E86C54AABD88918D1E10F7
                                                              SHA-512:0BCD77AC9C09BB7E3F614D23E520EE0724F8E25199DB34A92D29BC2CED559A1391E576F70DFFBB125DA7BE7BE27130A7CE323F21F637BC4FD3DAD00EB7B8E520
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....l..........." ..0..............9... ...@....... ...............................8....`..................................9..O....@...............$...Q...`.......8..T............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B.................9......H.......................`-......(8........................................(....*..(....*^.(.......]...%...}....*:.(......}....*:.(......}....*:.(......}....*:.(......}....*.~....*..0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...( ...*..(!...*.(....,.r...p......%...%...%...( ...*...("...*.(....,!r...p......%...%...%...%...( ...*....(#...*..,&(....,..r...pr...p.( ...($...*..(%...*.*.(....,.r...p......%...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):100576
                                                              Entropy (8bit):6.039946193838771
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:37D6F591907C6BC8CF43CDB9ED1C7C55
                                                              SHA1:7E279DD1C9DB73732D0E813A58AF08F9B62D0462
                                                              SHA-256:6D2B91496A3D3DF6970710EA7E20C9D98F229A0BA3ADABEB0CA167DA72EF3DD8
                                                              SHA-512:91191972E70AE50A5E2F50177F48A69EA7B7007299AC1FA93B0E71EC48CBA9F2FD16D47B03C44685E28CA267D9CC091186C9E1C6ED8485CE1631C4FFE10D58B9
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[A............" ..0..............7... ...@....... ....................................`..................................7..O....@..............."...f...`.......6..8............................................ ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B.................7......H.......|`......................h6.......................................0..........s....%r...pr...po....%r...pr...po....%r ..pr,..po....%r...pr...po....%rG..prU..po....%r...pr...po....%re..prs..po....%r...prs..po....%r...pr...po....%r...pr...po....%r ..pr(..po....%r...pr...po....%r...pr...po....%r...pr...po....%r...pr...po....%rr..pr...po....%r...pr...po....%rN..prd..po....%r...pr...po....%r...pr...po....%r...pr...po....%r~..pr...po....%r...pr1..po....%r...pr...po....%rm..pr
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):152616
                                                              Entropy (8bit):6.2972595497393575
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D4F4C943551089F0CAED130E9582F492
                                                              SHA1:6212B9E59EEFAE4E0573BDCFF46C0D420B0FA3A8
                                                              SHA-256:AC3BBA569FAC7B710CC2F8197AD32578DB13F4652ADEC78E348E2DC28778F50D
                                                              SHA-512:C76644137B2AB3EEAA8E5FE720BD1B093B847C7527ADE97AE2C5A13E1B282D9D3B5DBAF004AC90E9901F64ADF3D5DFD646C025371DAA5C78990BDC3FD4F69D0B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....6wb.........." ..0.................. ... ....... .......................`......$.....@.................................`...O.... ..@...............(P...@......(................................................ ............... ..H............text........ ...................... ..`.rsrc...@.... ......................@..@.reloc.......@......................@..B........................H........,................................................................('...*>..}......}....*..{....*..{....*..{.....{....3..{.....{....((...*.*..0...........%.u....,..........(....*.*z.{....%-.&.+.o)....{....(a...*..(....zN........o*...s+...*.(....z.s,...*..(....zF(U....(O...s-...*.(....z.(V...s-...*.(....z.s....*.(....z.s/...*..(....zN........o*...s0...*.(....zrr...p(\....c.K...(O...s1...*.(....zBr...p(Y...s1...*.(....z.s2...*.(....z.(X...s3...*.(!...z.(_...s3...*.(#...z
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):190048
                                                              Entropy (8bit):6.2777313746279555
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:BA7C57B0D4F18B0667CF788C5F8C7218
                                                              SHA1:4114148EFBC7BC3B22C3D66B33233D0C3C6A0609
                                                              SHA-256:AFF800027589D4AFC220F8C94A3231F8AC773C79C2495A25119114A8C9D19790
                                                              SHA-512:57366183AA98484AFE601321D5E882F64784FE1E6B542D68B68BAB20CFFC7488B96C9B117B946867378A5D42FE17B35983F3503DD73A8EE3686871047779DAA4
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....].b.........." ..0.................. ........... ....................................`.................................h...O.......................`P..........0................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......`...H............v...3..........................................R....s*... ....(....*F....s*.....(....*>.... ....(....*..0..d........(+....-.r...p(c...z.o,...-(r...p(...... ...%......(-...o.....(^...z.-.r...p(c...z.-.r...p(c...z.../.r1..p.............(g...z.o/...rG..p.o0...-'r...p(...... ...%..o/....%.rG..p.(^...z..o1...o2....>....rS..ps3......}.....o1...o4....+E.o5......s........s6.......o7....o8.....o7....o....o9......o:.....&...o$...-....,..o#.....(...+:.....o<...s
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):126208
                                                              Entropy (8bit):5.887302895374528
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:12F4C083CEFF6A1B9C8C3A2B723EBB61
                                                              SHA1:3441F8BE962C039B9C0F649793ADA72C58BF536D
                                                              SHA-256:47F4E25104D73F50C1313FDDEEA83443DA9581F77DAC0643177F2453486E13A3
                                                              SHA-512:2512A8E3A7CCD1670E17B4BDDFF4F2B3D095838DC6C633D3A75ECC1581CF9AEBCC4A2FE03D4FA6DCD3ED000C044331C05316C89B35DE20943BEECD9149A7B31A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....?.Z.........." ..0..v............... ........... ....................................@.................................f...O........................g.......................................................... ............... ..H............text....u... ...v.................. ..`.rsrc................x..............@..@.reloc..............................@..B........................H........Q..|?..........$... ...D.........................................(....*&.l(....k*&.l(....k*..l.l(....k*..l.l(....k*&.l(....k*&.l(....k*&.l(....k*j~....%-.&(....s....%.....*..*.0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*.~....*2r...p.(....*2rG..p.(....*2r...p.(....*2r...p.(.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):462328
                                                              Entropy (8bit):6.148359175016031
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A581664CB59F9D2818087F7E83FDE791
                                                              SHA1:EC80F4091825DC7A5D9DE070C3F4F48343F0CFD6
                                                              SHA-256:DEDBCC4479D8AB0996B5F41A4ADB9FDD52FA691CB2FAA30268D12859A3C902BB
                                                              SHA-512:6BB4528699303029EEB456A7D9527B8522B0A4A209F451A111A08E16A63A060C7D8C23ECDDBAEAB20790B25A3C47AB8B0B33E357A198719CE869E2FAF5C768CD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...$.oY.........." ..0.................. ........... ..............................`.....@.................................X...O.......0................g.......... ................................................ ............... ..H............text........ ...................... ..`.rsrc...0...........................@..@.reloc..............................@..B........................H........f..."...............,..........................................j~....%-.&(x...sN...%.....*..*...0..$.........(.....oO......&...,....oP...,..*.*..................,!(....,..r...p.(Q...(R...*..(S...*.*.(....,.r...p......%...%...(Q...*..(T...*.(....,.r...p......%...%...%...(Q...*...(U...*.(....,!r...p......%...%...%...%...(Q...*....(V...*2r...p.(....*2r#..p.(....*2rM..p.(....*2ri..p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2r!..p.(....*2rK..p.(....*2ru..p.(....*2r...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):36352
                                                              Entropy (8bit):6.795634236587184
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:595BE672318AFC6C1510C7889F1EB868
                                                              SHA1:CA93B1CFD3CC55317B2723FFC50A7D2B5EF36293
                                                              SHA-256:BE3F28AFB9F60C302241DF7BD226C25B85279DEC2D8F9CE25B41C675BC6F0B10
                                                              SHA-512:73D3D727848F41A0B0E99B279062BDD3B917209B4835B1A2D0737C5515BA1B5F250CB5C8502AB8946B8D2225CFB0894A564A59DB22D92E90E0FD9FA82ADA7728
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....jM^.........." ..0..8...........V... ...`....... ..............................!.....@..................................V..O....`...............B...L..........PU............................................... ............... ..H............text....6... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B.................V......H........0...$...................T........................................(....*..(....z..(....z2.(....s....*2.(....s....*:........o....*.~....*~.-..(......}......}......}....*~.-..(......}......}......}....*Z..}......}......}....*J.{....%-.&.*o....*^.u....,........(....*.*~.{.....{....3..{.....{......*.*&...(....*2...(.......*....0..'........{......,..u....%-.&..(...+(....*(....*n.{....,..(....s....*.q....*..0..a.........{....o0.....,;..{....o2...(......;...3.~.......s......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):35584
                                                              Entropy (8bit):7.035214210797738
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:73EA288B8622A1886F025239AE36C942
                                                              SHA1:06D1109E2CD36752622410A98CC99FCE9B21E0F9
                                                              SHA-256:B9B11CF6F9655C6870E40B3573EB714CDEF0B14D6BBEBF57FA6B5616617D0200
                                                              SHA-512:F7B1D7F20B7F973B67D682A0F2C55475E2AFA2ED58B330CEF5502E33FE1EBBA60D73C38FFCB2598CCAFC96A0930CC53262297170354B6F1F2362839349CAF5E4
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....?.Z.........." ..0.............b2... ...@....... ...............................6....@..................................2..O....@...............$...g...`......x1............................................... ............... ..H............text...h.... ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B................B2......H........!..T....................0......................................j~....%-.&(....s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*.~....*2r...p.(....*2r[..p.(....*B.....(.........*.BSJB............v4.0.30319......l...4...#~..........#Strings....t.......#US.@.......
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):27752
                                                              Entropy (8bit):6.579791647175713
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3042E59539BD5EF864DDCEE470907242
                                                              SHA1:1B6CA4B169B6BF2673D254AE1862C8BD24439B03
                                                              SHA-256:65C7942A316975ABB8290ADFCC84EB798D9E1C979B98D3C5BD764520162838A9
                                                              SHA-512:88F9E9F96ED9BB149D4AEF510D4D3ABB16DABD9B37524D4C6E70AF9F0F91CFE727CDAF74AC1F55003D83C89D9DB512B38303441B7CC44B5D0B16AA4986D6C966
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...nN............" ..0..<...........Z... ...`....... ....................................`..................................Z..O....`..t............D..h(...........Y..T............................................ ............... ..H............text....:... ...<.................. ..`.rsrc...t....`.......>..............@..@.reloc...............B..............@..B.................Z......H.......x0...(..................,Y........................................(....*^.(.......8...%...}....*:.(......}....*:.(......}....*:.(......}....*.*..(....*r.(......}......}......}....*.0..?.........(....}.......}.......}.......}......|......(...+..|....(....*>..{....o....U.*Z.,..{....o......(....*..{....,".{....o ...,..{.....jo!...+.s"...z..}....*:..}.....(....*......(#...*..{....*.0..@.......s$.....r...po%...&.r...po%...&..o....,... o&...&..}o&...&.o'...*.0..........((..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):36968
                                                              Entropy (8bit):6.036933164230375
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9387FCC0B96D448D8D3C1B9237125532
                                                              SHA1:12C862F9CCEB4327567F27E9F8C44132C04123E3
                                                              SHA-256:D81ABE494F24D40AE9F74951F0C5EBE5EDE7009D30FA0C056EA5DA4D60A7FF83
                                                              SHA-512:688F8028C9BE10205B122B3CBDAF42393AAD130F13290F0EE66DBFF3E602C0335CABD51FF10CAB85FF4A59DDA669EB3DDABFD9761BA2ABC9CFB37A0BB8753C43
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$kf...........!.....^..........^|... ........... ....................................@..................................|..K.......x............h..h(........................................................... ............... ..H............text...d\... ...^.................. ..`.rsrc...x............`..............@..@.reloc...............f..............@..B................@|......H....... w............... ..NV..P ...........................................l.y.......%..$Q...n......N...[..._...,aM...Ww..\..^.;......6..+ ?I..{.Q0...U..6..4.4.....=......`..:Iv..,6..:.y......L.T.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPm......*6... ..Qq.7.....$.....pn.0.).......H.x.`..F...6.............yk.5.l.EK .|M.."b=....%.!.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):127592
                                                              Entropy (8bit):5.568610604231904
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:53C7E0BE9273D2319CFB7D675FACBCF2
                                                              SHA1:E598E065437FD7F86402CE99FF65B3ED3D12B1BC
                                                              SHA-256:133DEF11002B9862333D4C212D65C2CBEC03C9FFA4174926F165EEFD7D6EF73E
                                                              SHA-512:CCA97B2F1DCCF8C169B18C5E8D18B806A6E5CEC1D41248AA028AFDC0BF48BCD1CD8505B2FF823DC0A2102DF639FFE615CA5EAFE0E4323F1E18CB9471A8F339D3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...t%kf...........!................N.... ........... ....................... .......\....@.....................................W.......@...............h(........................................................... ............... ..H............text...T.... ...................... ..`.rsrc...@...........................@..@.reloc..............................@..B................0.......H...........l............ ......P ........................................V......[[....|~...h.......P......CF)..YY..._.`<..$.9.G.9eH.%..../.`........X.zp./.`.....rj..d...p.(......../..Jm..Z$...............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADP.S,.../..aZ........g=B........(3.....-N...|..........}......F.^.........%K.>.W..l...g..P..6...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):23144
                                                              Entropy (8bit):6.360258285049153
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1BBD42B70C94BB41A2FB933D57EA4CBC
                                                              SHA1:C5C842B07F6CFB3A0247C7FADDC11D8BB821E312
                                                              SHA-256:A04B6E65F621957A19042B748B0F2E4D36E001BD690F2A6005AAD29B56DECEF7
                                                              SHA-512:9793464E1141B67F74CC9C592F6F91ABFC9E42405435D1EF405904A7C7A7BE349E7F295422AA105363E53783D5C1A0FF2381D982DEB0BA8909AC945C06D1E0BC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.....(..........^F... ...`....... ....................................@..................................F..W....`...............2..h(........................................................... ............... ..H............text...d&... ...(.................. ..`.rsrc........`.......*..............@..@.reloc...............0..............@..B................@F......H........A..P............ ... ..P .......................................:A...pq~..7..6.].<.PT.^...1.....-U...4.[s<...G-...a7....Ek.w..U....o(M5..a.e.X..h.f$...f=.{;.........DVb.4..5...]N.^.).E. .............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....a.......PADPADP`pc.C{D..vU.c.$.XK.B9...T..P#..S..*.@.yl.K....N.J1..0.....r...l.........#.q......n"..z...i..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):36456
                                                              Entropy (8bit):6.029199581396618
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:2002878B1AB7B2E6A19C67F517E4B711
                                                              SHA1:5CF371EC916C712A0EBDC119D5498592905E7C28
                                                              SHA-256:8F1B1C0EBC25D776DC7CE9DD91C8F632BCA91DF72DB378643FC6066A8148C2DB
                                                              SHA-512:4857BC2F10967B11012266B0DB114CA7A895356C7C86BD51DC945AB05E638CA55828061062D2F51891DB4A4A6E4F4E8C8406B51DCFCBB324339B954F97458A49
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$kf...........!.....\...........z... ........... ..............................l.....@..................................z..S.......x............f..h(........................................................... ............... ..H............text....[... ...\.................. ..`.rsrc...x............^..............@..@.reloc...............d..............@..B.................z......H........u............... ...T..P .........................................9$V..u.<.G.@[...S.3...Py..PW*NLk(..TD......o.....+XM.%.6.S.Vc..r....V..|}...M...`.$...=.R.I.k..ZHZZ...7.?9.v.........ed.R.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPm......*6... ..Qq.7.....$.....pn.0.).......H.x.`..F...6.............yk.5.l.EK .|M.."b=....%.!.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):23144
                                                              Entropy (8bit):6.367817006440025
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:57213B44E7FE6176ABB92FF0A606B8BB
                                                              SHA1:AC8C99C1EF21667FAA188157BA2B1E71BACB1853
                                                              SHA-256:4966A811985FDBA60A34D3C25FF2DBDD3C70DA30F32C929BA1E378594AB39B5F
                                                              SHA-512:9E7452A2F05AC8E07A2D2431F0B7D8550B85D02C2C4EC37926012F3B6673A15D4574EE59352F432C2CD7C44309255F5482B0E805FC8BF41FF5F5B5384D45D0C1
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.....(...........F... ...`....... ..............................o.....@..................................F..O....`...............2..h(........................................................... ............... ..H............text....&... ...(.................. ..`.rsrc........`.......*..............@..@.reloc...............0..............@..B.................F......H.......TB..H............ ...!..P ......................................O.DU...t...P..j.....@...e!.J..c.+).....&3<.f.....#........G"....(.@m.#_..z.........\:.....KU..4.`..g.#..).\..0.^....C7.!.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....a.......PADPADP`pc.C{D..vU.c.$.XK.B9...T..P#..S..*.@.yl.K....N.J1..0.....r...l.........#.q......n"..z...i..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):36968
                                                              Entropy (8bit):6.078088916420306
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E25A70E8C85D6D6E31A862325AE0A248
                                                              SHA1:3A2A97EEFEA78D68FBCBF712DDE70693B80343EF
                                                              SHA-256:50BDDC1A1EA89B296199CDC5AF32329AB445F1897BF4B86B42B7DF8982244741
                                                              SHA-512:4B66B41EFDB3882379E1E263B0FF87BF7A0CBE3A525CDA829A3306B90D048815698EBBD2D8C08FF8B0026FE41BDCD186DE96D936421592CDBA83AC393BEDFFA2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$kf...........!.....^..........N}... ........... ...............................\....@..................................|..S.......x............h..h(........................................................... ............... ..H............text...T]... ...^.................. ..`.rsrc...x............`..............@..@.reloc...............f..............@..B................0}......H........x............... ..8W..P .......................................F..88.._...........4......._...|...Lq.).$...\...X.-.{....1..Tr....o.TB.\.W+.M.S..|.+..N.......(......u...!-.....n.H(...p.{I.U.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet............PADPADPm......*6... ..Qq...$.....pn.0.).......H.x.`..F...6.............yk.5.l.EK .|M.."b=....%.!....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):23144
                                                              Entropy (8bit):6.380799726069909
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E560F96593CE9A036CF4B2A7F46DE777
                                                              SHA1:9E3E2AE3535FCBDF1217852C130CB401A9571468
                                                              SHA-256:1BED1B4D6F8F417BB5D8AF56F4D7A1C8502F82D234E708E4C768CFF6AAAE91BF
                                                              SHA-512:39B548BE40F20DFFAB4FF8C300266273C1D7C6BBE56DB410EB834064FAB8812FD00C476B7588A96FACAF5A82EB543FBCF0DC86B5FB0CC31DA5FB29AEC3C70F64
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....%kf...........!.....(...........F... ...`....... ....................................@..................................F..O....`...............2..h(........................................................... ............... ..H............text....'... ...(.................. ..`.rsrc........`.......*..............@..@.reloc...............0..............@..B.................F......H.......\B..P............ ...!..P ......................................R.5.m.mx..mT........W....'..F......,...F..3.[..c.}..g..y..."..?...3........-....y.Rh... .%ym....9.H?.,.V..F.?<t..,o.Pp.....o.!.............lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....`.......PADPADP`pc.C{D..vU.c.$.XK.B9...T..P#..S..*.@.yl.N.J1..0.....r...l.........#.q......n"..z...i...i..
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):2090088
                                                              Entropy (8bit):6.557356565381784
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7E1A33A581731E36326B78EB8455C828
                                                              SHA1:848288EFE72FC2B7D7AB301D2EBCEFC451194C74
                                                              SHA-256:3E3596C04B1547E6CD28ACCECE60883B721D69789BEB675A98A360BA7DF65165
                                                              SHA-512:5B3C1900C00AE843A2034B00281BC905C2AD3972172CDF58C5AC32316D46579C6088AA3F3CE0A3789A94830571D487172CFC92E12359DCD3BF6D76654946098B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........Ju..Ju..Ju..C.l.Bu......Hu......Zu......@u......Ou.....Au..Ju...u..Ju..,t.....Ku.....Ku..RichJu..................PE..L...$.md.........."!......................... .......................................j ...@.............................................................h(...0..H....s..T...................@u......Pt..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...X.... ......................@....reloc..H....0......................@..B........................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:MS Windows shortcut, Item id list present, Has Relative path, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
                                                              Category:dropped
                                                              Size (bytes):2487
                                                              Entropy (8bit):2.585592016424218
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:0B86814355784BA22E1F787DAC483FB8
                                                              SHA1:BD908642C605A52D8F84AA654C169DFA557B2583
                                                              SHA-256:D4FD3E7AFC93C0491BE0262AC9770C3E60EC149231939D72C6C5FED4ECE08521
                                                              SHA-512:BE83A8020820C8FD3A5CDB88F16E33B9E69DC9D77E81DC6898920503F5C5282FAC2CFAEF9B3531F4FC6F0DCEEA9F9ED907B20150289E6B2FECD3F113F4BE937A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.P...........................................................P.O. .:i.....+00.../C:\...................V.1.....VY.F..Windows.@......OwHVY.G....3.....................}/8.W.i.n.d.o.w.s.....\.1.....VY.G..Installer.D......O.IVY.G...........................'..I.n.s.t.a.l.l.e.r.......1.....VY.G..{1D482~1..~......VY.GVY.G..............................{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.....r.2.h&..VY.G!.DESKTO~1.EXE..V......VY.GVY.G..............................D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.......Z.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.N.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.........(LyJ,d[Q}96FN{74yHvfDesktopApp>[}JsY8X@QBqp9g2'0e@3..................................
                                                              Process:C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Articulate 360, Author: Articulate Global, LLC, Keywords: Installer, Comments: This installer database contains the logic and data required to install Articulate 360., Template: Intel;1033, Revision Number: {C5D0A98E-A4FF-4ADA-8410-5E4BAF9F113F}, Create Time/Date: Thu Jun 13 18:18:00 2024, Last Saved Time/Date: Thu Jun 13 18:18:00 2024, Number of Pages: 405, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9AD0A2B63668CD1F296D024406A97BF6
                                                              SHA1:6CC4F86DD636F2D9E0677A9CCABFCE7773E85B1C
                                                              SHA-256:5C17C2604055456111C0A3BE3F17F092007AE4A9000D074CE0C59315F019CDEE
                                                              SHA-512:DA6A6C39BC8BEA088211360956865EB976D74AD0658C64D204ED72C89FB3955C485C2BAFBE54F187CEB83903450B23BF4190B7A858D3267C68AAD4271470926B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9882A328C8414274555845FA6B542D1E
                                                              SHA1:AB4A97610B127D68C45311DEABFBCD8AA7066F4B
                                                              SHA-256:510FC8C2112E2BC544FB29A72191EABCC68D3A5A7468D35D7694493BC8593A79
                                                              SHA-512:C08D1AA7E6E6215A0CEE2793592B65668066C8C984B26675D2B8C09BC7FEE21411CB3C0A905EAEE7A48E7A47535FA777DE21EEB07C78BCA7BF3D7BB17192ACF2
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c...'.u.'.u.'.u.......u.....[.u.....?.u...v.4.u...q.4.u...p...u.....".u....6.u.'.t.v.u...p.l.u....&.u.'..%.u...w.&.u.Rich'.u.........................PE..L......Z.....................v......m.............@..........................p......!.....@..............................................;...........;..8(...0...=.. t..T...................tt......@n..@...................$........................text.............................. ..`.rdata..............................@..@.data...@...........................@....wixburn8...........................@..@.tls................................@....gfids..............................@..@.rsrc....;.......<..................@..@.reloc...=...0...>..................@..B........................................................................................................................................................
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Microsoft Cabinet archive data, many, 824123 bytes, 11 files, at 0x44 +A "concrt140.dll_x86" +A "msvcp140.dll_x86", flags 0x4, number 1, extra bytes 20 in head, 62 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A57EFC0AFFFDF914CBC76BB882CAD37E
                                                              SHA1:732DBEF27C49C27D9F1C00EBA177EABC21650FB8
                                                              SHA-256:C384DA7CC6EAD2CE054A67FDED26D7E4CFF2F981A83C64DE62E53864665E5F45
                                                              SHA-512:AD2CFC0FD199FE2726FD18C0A5972185E8331FE49807CA6340212901DD61D30853E2C72015EE9BAC0425E287EF488190A245676173194FAFBF8F6FC7FBF9BABA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MSCF....;.......D...........................;....'..............>...P.........3X,. .concrt140.dll_x86.x...P.....3X-. .msvcp140.dll_x86.P........3X-. .msvcp140_1.dll_x86......B....3X-. .msvcp140_2.dll_x86.P.........3X-. .msvcp140_atomic_wait.dll_x86.Pv..h.....3X-. .msvcp140_codecvt_ids.dll_x86.p....B....3X-. .vcamp140.dll_x86.pZ..(.....3X-. .vccorlib140.dll_x86.px...-....3X-. .vcomp140.dll_x86..c........3X-. .vcruntime140.dll_x86.P.........3X-. .vcruntime140_threads.dll_x86.!.)..4..CK.}|.U...E..Ge....WV..P...$@)...R..M..i...."b.UX.j]Y.b..V@..h.q.j.......*j]..R]..&S23NX|.........r....3s..3..D..".....-".....I..g>5P.8..Z..W.*\....r...Z..x..k....X..k.9.Jo.k.....>......U.z..........8...YK.<...%.*..}YE.qe...X..H9...<^.........B.K}.y....M.._.u.4..q.F.&....".... .0.....H...3...V..q.MP...".c...o....^.!v01.!b....!.v.#..s.../....c.u....3.`Kz...WM........l..c..1...p".6Z...8......Hw.p...[.D.?....W.K9...>+uz..\.^.....1.G...&..........r..@xm..|n...`..."D.S".K..g4...Z.Q..+
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Microsoft Cabinet archive data, many, 5167260 bytes, 14 files, at 0x44 +A "mfc140.dll_x86" +A "mfc140chs.dll_x86", flags 0x4, number 1, extra bytes 20 in head, 323 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4A17E4DA145FA1EA92A52266221AD628
                                                              SHA1:F6304DE9D73609F6B9717D6A4D44EFD7AB7FFE9E
                                                              SHA-256:9544ABBD46B39BEC491CF63076FB109306E519F303DF9CD583A28956172BF038
                                                              SHA-512:DE9A6A1391070A9470F78208FF74120CFFD2A1E2580AF4ADD87914BA6DD27E07B092E66CAA847726E05EB5FAE0C1252681DE37F34B560D4D95F3B76F3599E16C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MSCF......N.....D.............................N..'..............C.....I.......3X-. .mfc140.dll_x86.P.....I...3X,. .mfc140chs.dll_x86.P....J...3X,. .mfc140cht.dll_x86..7..8rK...3X,. .mfc140deu.dll_x86.P.....L...3X,. .mfc140enu.dll_x86..3..h.M...3X,. .mfc140esn.dll_x86.h8..H.N...3X,. .mfc140fra.dll_x86.p0...(P...3X,. .mfc140ita.dll_x86..... YQ...3X,. .mfc140jpn.dll_x86......?R...3X,. .mfc140kor.dll_x86.P(...#S...3X,. .mfc140rus.dll_x86.xMJ.PKT...3X-. .mfc140u.dll_x86.pR.......3X,. .mfcm140.dll_x86.PR..8....3X,. .mfcm140u.dll_x86.z...4..CK..w..T.0.0" 8C(.R.X..6U..^..)...;..!.;.J'...w..C....."."..|...9.W.s......{V.Z.z.J.0.7...w.(.4\.|.E.D../.....O.E.~t...=1.-.....km...p....e...f.w.q..M.Hv.}.d...eW_3.a...0v.s.W................=.............NZ...L..T.......?3...>.L>...3..r...T....33.......{..M..a.~.u.Q.w.l..u.{O.rQ..$.E{...M.}..~<.T...Y..Q...{.s....p..Q..1Q4Y.2e...o....p.ye.p..R.I.S........oEQ.. .0.k........a..Rt...k.|....>X..Z...&]p....f...Q..~..j..}....k........ {
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Visual C++ 2022 X86 Additional Runtime, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135., Template: Intel;1033, Revision Number: {29E9ACD5-6C1B-48C9-A316-358656F83B42}, Create Time/Date: Fri Jan 19 22:58:04 2024, Last Saved Time/Date: Fri Jan 19 22:58:04 2024, Number of Pages: 301, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.10.4.4718), Security: 2
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A37983D3FCA236D6AE2D22AB0FA9F1D4
                                                              SHA1:82F77032813AEDDF321D681DA4E1AA50786258DD
                                                              SHA-256:A7F13351CE5B41FCF6C2ED95F223F5E2AAB5411BF8499A772F69AD8FFB87F96B
                                                              SHA-512:619467E6D4AA6BC8F1CC02DAF52330E28C313D774A1D0B0BB96D40A2ED2DC3697CEE738463FAED040E1BCA407C3471AE1BC8DD91472682B25C579CAACDBF7374
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Visual C++ 2022 X86 Minimum Runtime, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135., Template: Intel;1033, Revision Number: {83CEF352-ED74-4B1D-B0E7-96CDF4DA1C2D}, Create Time/Date: Fri Jan 19 22:52:32 2024, Last Saved Time/Date: Fri Jan 19 22:52:32 2024, Number of Pages: 301, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.10.4.4718), Security: 2
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3CA6B74AEFE34587F479055F5915E136
                                                              SHA1:61771E0A8CCABAC8783A22F67ADCBCE612F11704
                                                              SHA-256:A6F3A8E4E2162D8DF176418E9A238BECB645B2DB31D8073BFC4F4CDB7FB1AA22
                                                              SHA-512:3949CB3FDAD3E8D5E9C649141A72783E0B403D3E835433D4D456654BCDAD1290258F6D023CE127740F9C82459D337B9F8731C799EFCF99775955D38CF3FEF750
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9882A328C8414274555845FA6B542D1E
                                                              SHA1:AB4A97610B127D68C45311DEABFBCD8AA7066F4B
                                                              SHA-256:510FC8C2112E2BC544FB29A72191EABCC68D3A5A7468D35D7694493BC8593A79
                                                              SHA-512:C08D1AA7E6E6215A0CEE2793592B65668066C8C984B26675D2B8C09BC7FEE21411CB3C0A905EAEE7A48E7A47535FA777DE21EEB07C78BCA7BF3D7BB17192ACF2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c...'.u.'.u.'.u.......u.....[.u.....?.u...v.4.u...q.4.u...p...u.....".u....6.u.'.t.v.u...p.l.u....&.u.'..%.u...w.&.u.Rich'.u.........................PE..L......Z.....................v......m.............@..........................p......!.....@..............................................;...........;..8(...0...=.. t..T...................tt......@n..@...................$........................text.............................. ..`.rdata..............................@..@.data...@...........................@....wixburn8...........................@..@.tls................................@....gfids..............................@..@.rsrc....;.......<..................@..@.reloc...=...0...>..................@..B........................................................................................................................................................
                                                              Process:C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Articulate 360, Author: Articulate Global, LLC, Keywords: Installer, Comments: This installer database contains the logic and data required to install Articulate 360., Template: Intel;1033, Revision Number: {C5D0A98E-A4FF-4ADA-8410-5E4BAF9F113F}, Create Time/Date: Thu Jun 13 18:18:00 2024, Last Saved Time/Date: Thu Jun 13 18:18:00 2024, Number of Pages: 405, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9AD0A2B63668CD1F296D024406A97BF6
                                                              SHA1:6CC4F86DD636F2D9E0677A9CCABFCE7773E85B1C
                                                              SHA-256:5C17C2604055456111C0A3BE3F17F092007AE4A9000D074CE0C59315F019CDEE
                                                              SHA-512:DA6A6C39BC8BEA088211360956865EB976D74AD0658C64D204ED72C89FB3955C485C2BAFBE54F187CEB83903450B23BF4190B7A858D3267C68AAD4271470926B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Microsoft Cabinet archive data, many, 824123 bytes, 11 files, at 0x44 +A "concrt140.dll_x86" +A "msvcp140.dll_x86", flags 0x4, number 1, extra bytes 20 in head, 62 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A57EFC0AFFFDF914CBC76BB882CAD37E
                                                              SHA1:732DBEF27C49C27D9F1C00EBA177EABC21650FB8
                                                              SHA-256:C384DA7CC6EAD2CE054A67FDED26D7E4CFF2F981A83C64DE62E53864665E5F45
                                                              SHA-512:AD2CFC0FD199FE2726FD18C0A5972185E8331FE49807CA6340212901DD61D30853E2C72015EE9BAC0425E287EF488190A245676173194FAFBF8F6FC7FBF9BABA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MSCF....;.......D...........................;....'..............>...P.........3X,. .concrt140.dll_x86.x...P.....3X-. .msvcp140.dll_x86.P........3X-. .msvcp140_1.dll_x86......B....3X-. .msvcp140_2.dll_x86.P.........3X-. .msvcp140_atomic_wait.dll_x86.Pv..h.....3X-. .msvcp140_codecvt_ids.dll_x86.p....B....3X-. .vcamp140.dll_x86.pZ..(.....3X-. .vccorlib140.dll_x86.px...-....3X-. .vcomp140.dll_x86..c........3X-. .vcruntime140.dll_x86.P.........3X-. .vcruntime140_threads.dll_x86.!.)..4..CK.}|.U...E..Ge....WV..P...$@)...R..M..i...."b.UX.j]Y.b..V@..h.q.j.......*j]..R]..&S23NX|.........r....3s..3..D..".....-".....I..g>5P.8..Z..W.*\....r...Z..x..k....X..k.9.Jo.k.....>......U.z..........8...YK.<...%.*..}YE.qe...X..H9...<^.........B.K}.y....M.._.u.4..q.F.&....".... .0.....H...3...V..q.MP...".c...o....^.!v01.!b....!.v.#..s.../....c.u....3.`Kz...WM........l..c..1...p".6Z...8......Hw.p...[.D.?....W.K9...>+uz..\.^.....1.G...&..........r..@xm..|n...`..."D.S".K..g4...Z.Q..+
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Visual C++ 2022 X86 Minimum Runtime, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135., Template: Intel;1033, Revision Number: {83CEF352-ED74-4B1D-B0E7-96CDF4DA1C2D}, Create Time/Date: Fri Jan 19 22:52:32 2024, Last Saved Time/Date: Fri Jan 19 22:52:32 2024, Number of Pages: 301, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.10.4.4718), Security: 2
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3CA6B74AEFE34587F479055F5915E136
                                                              SHA1:61771E0A8CCABAC8783A22F67ADCBCE612F11704
                                                              SHA-256:A6F3A8E4E2162D8DF176418E9A238BECB645B2DB31D8073BFC4F4CDB7FB1AA22
                                                              SHA-512:3949CB3FDAD3E8D5E9C649141A72783E0B403D3E835433D4D456654BCDAD1290258F6D023CE127740F9C82459D337B9F8731C799EFCF99775955D38CF3FEF750
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7BD0B2D204D75012D3A9A9CE107C379E
                                                              SHA1:41EDD6321965D48E11ECDED3852EB32E3C13848D
                                                              SHA-256:D4C6F5C74BBB45C4F33D9CB7DDCE47226EA0A5AB90B8FF3F420B63A55C3F6DD2
                                                              SHA-512:D85AC030EBB3BA4412E69B5693406FE87E46696CA2A926EF75B6F6438E16B0C7ED1342363098530CDCEB4DB8E50614F33F972F7995E4222313FCEF036887D0F0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c...'.u.'.u.'.u.......u.....[.u.....?.u...v.4.u...q.4.u...p...u.....".u....6.u.'.t.v.u...p.l.u....&.u.'..%.u...w.&.u.Rich'.u.........................PE..L......Z.....................v......m.............@..........................p............@..............................................;...............(...0...=.. t..T...................tt......@n..@...................$........................text.............................. ..`.rdata..............................@..@.data...@...........................@....wixburn8...........................@..@.tls................................@....gfids..............................@..@.rsrc....;.......<..................@..@.reloc...=...0...>..................@..B........................................................................................................................................................
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):1052
                                                              Entropy (8bit):2.798084555002691
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:10EB3265524728F652E7385A7A7FF692
                                                              SHA1:45695048BE4B06E13445D4F2A913D59F435D6A56
                                                              SHA-256:6C0F8A122328B1FE71B071F6C22E128B71AA6B2C8ECB5E29503F6997F912F3E3
                                                              SHA-512:4875D3B3AF2639B17EE1C508B42BC2AAECC899C430760127EE881350381ECA984232DA5070B1F6B12B0CC200709B5C11C7CA9678D21D83010A365B981FEFCC78
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:J...............................................................................................................................................................................................................................................W.i.x.B.u.n.d.l.e.F.o.r.c.e.d.R.e.s.t.a.r.t.P.a.c.k.a.g.e.....................W.i.x.B.u.n.d.l.e.L.a.s.t.U.s.e.d.S.o.u.r.c.e.................................W.i.x.B.u.n.d.l.e.N.a.m.e.....B...M.i.c.r.o.s.o.f.t. .V.i.s.u.a.l. .C.+.+. .2.0.1.5.-.2.0.2.2. .R.e.d.i.s.t.r.i.b.u.t.a.b.l.e. .(.x.8.6.). .-. .1.4...3.8...3.3.1.3.5.............W.i.x.B.u.n.d.l.e.O.r.i.g.i.n.a.l.S.o.u.r.c.e.....W...C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.P.a.c.k.a.g.e. .C.a.c.h.e.\.A.B.4.A.9.7.6.1.0.B.1.2.7.D.6.8.C.4.5.3.1.1.D.E.A.B.F.B.C.D.8.A.A.7.0.6.6.F.4.B.\.v.c._.r.e.d.i.s.t...x.8.6...e.x.e.............W.i.x.B.u.n.d.l.e.O.r.i.g.i.n.a.l.S.o.u.r.c.e.F.o.l.d.e.r.....F...C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.P.a.c.k.a.g.e. .C.a.c.h.e.\.A.B.4.A.9.7.6.1.0.B.1.2.7.D.6.8.C.4.5.3.1.1.D.E.A.B.F.B.C.D.8.
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Microsoft Cabinet archive data, many, 5167260 bytes, 14 files, at 0x44 +A "mfc140.dll_x86" +A "mfc140chs.dll_x86", flags 0x4, number 1, extra bytes 20 in head, 323 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4A17E4DA145FA1EA92A52266221AD628
                                                              SHA1:F6304DE9D73609F6B9717D6A4D44EFD7AB7FFE9E
                                                              SHA-256:9544ABBD46B39BEC491CF63076FB109306E519F303DF9CD583A28956172BF038
                                                              SHA-512:DE9A6A1391070A9470F78208FF74120CFFD2A1E2580AF4ADD87914BA6DD27E07B092E66CAA847726E05EB5FAE0C1252681DE37F34B560D4D95F3B76F3599E16C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MSCF......N.....D.............................N..'..............C.....I.......3X-. .mfc140.dll_x86.P.....I...3X,. .mfc140chs.dll_x86.P....J...3X,. .mfc140cht.dll_x86..7..8rK...3X,. .mfc140deu.dll_x86.P.....L...3X,. .mfc140enu.dll_x86..3..h.M...3X,. .mfc140esn.dll_x86.h8..H.N...3X,. .mfc140fra.dll_x86.p0...(P...3X,. .mfc140ita.dll_x86..... YQ...3X,. .mfc140jpn.dll_x86......?R...3X,. .mfc140kor.dll_x86.P(...#S...3X,. .mfc140rus.dll_x86.xMJ.PKT...3X-. .mfc140u.dll_x86.pR.......3X,. .mfcm140.dll_x86.PR..8....3X,. .mfcm140u.dll_x86.z...4..CK..w..T.0.0" 8C(.R.X..6U..^..)...;..!.;.J'...w..C....."."..|...9.W.s......{V.Z.z.J.0.7...w.(.4\.|.E.D../.....O.E.~t...=1.-.....km...p....e...f.w.q..M.Hv.}.d...eW_3.a...0v.s.W................=.............NZ...L..T.......?3...>.L>...3..r...T....33.......{..M..a.~.u.Q.w.l..u.{O.rQ..$.E{...M.}..~<.T...Y..Q...{.s....p..Q..1Q4Y.2e...o....p.ye.p..R.I.S........oEQ.. .0.k........a..Rt...k.|....>X..Z...&]p....f...Q..~..j..}....k........ {
                                                              Process:C:\Windows\Temp\{24DB894E-9C95-4936-917E-41E84F602191}\.be\VC_redist.x86.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Visual C++ 2022 X86 Additional Runtime, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135., Template: Intel;1033, Revision Number: {29E9ACD5-6C1B-48C9-A316-358656F83B42}, Create Time/Date: Fri Jan 19 22:58:04 2024, Last Saved Time/Date: Fri Jan 19 22:58:04 2024, Number of Pages: 301, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.10.4.4718), Security: 2
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A37983D3FCA236D6AE2D22AB0FA9F1D4
                                                              SHA1:82F77032813AEDDF321D681DA4E1AA50786258DD
                                                              SHA-256:A7F13351CE5B41FCF6C2ED95F223F5E2AAB5411BF8499A772F69AD8FFB87F96B
                                                              SHA-512:619467E6D4AA6BC8F1CC02DAF52330E28C313D774A1D0B0BB96D40A2ED2DC3697CEE738463FAED040E1BCA407C3471AE1BC8DD91472682B25C579CAACDBF7374
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:27A052A559D18C7A5823AA55D41A1A14
                                                              SHA1:50F398EF91B20AA9E9179C805E62CD995941DE2B
                                                              SHA-256:A0F34A8BBAD9BA7BCBAD63E7F1E382C37BCC27114A2B7EEEC390B4E0F4071AAA
                                                              SHA-512:766244A215F4FD37F009B13E954E3DA6CAFF7E7C33BD51CE0654BBBBB225916B8384CD0F08918A8ED1C5AC33EC46EF8272F125C3D7F3C34CED7F79CD02250A9B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9.o.}k..}k..}k.....wk......k.....ek../...nk../...ik../...Vk..t...xk..t...lk..}k..(j......6k......|k..}k...k......|k..Rich}k..........PE..L...2p.].....................X......q.............@..........................0............@.........................................................({..h(.......=..0p..T....................p.......j..@...................4|.......................text............................... ..`.rdata..`...........................@..@.data...............................@....wixburn8...........................@..@.rsrc...............................@..@.reloc...=.......>..................@..B........................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{F8FE0D25-EDD3-4C18-909A-54D08E28577C}\.be\Articulate.360.Bundle.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):790
                                                              Entropy (8bit):2.202614912630957
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9C802FABD32CADFA1F321EBD7EBB987B
                                                              SHA1:0A2EF5DA32A6567B6A9F71AA6CF332BAA88A749E
                                                              SHA-256:968571ADDFD0022019923077769838281A7D658510420EF94518ED8E2FBC4190
                                                              SHA-512:D3779CDBBEE72A0F1C877D44CEFC7E01DC45EAD9B798A66A677FC8C35A17302F83BA2CB49ED34805E0450F145F101BD9FF7573D98DC4F2AC05AFF2E395C013B6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:P.......................................................................................................................................................................................................................................................................W.i.x.B.u.n.d.l.e.F.o.r.c.e.d.R.e.s.t.a.r.t.P.a.c.k.a.g.e.....................W.i.x.B.u.n.d.l.e.L.a.s.t.U.s.e.d.S.o.u.r.c.e.................................W.i.x.B.u.n.d.l.e.N.a.m.e.........A.r.t.i.c.u.l.a.t.e. .3.6.0.............W.i.x.B.u.n.d.l.e.O.r.i.g.i.n.a.l.S.o.u.r.c.e.....*...C.:.\.U.s.e.r.s.\.t.o.r.r.e.s.\.D.e.s.k.t.o.p.\.a.r.t.i.c.u.l.a.t.e.-.3.6.0...e.x.e.............W.i.x.B.u.n.d.l.e.O.r.i.g.i.n.a.l.S.o.u.r.c.e.F.o.l.d.e.r.........C.:.\.U.s.e.r.s.\.t.o.r.r.e.s.\.D.e.s.k.t.o.p.\.................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:MS Windows shortcut, Item id list present, Has Relative path, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
                                                              Category:dropped
                                                              Size (bytes):2475
                                                              Entropy (8bit):2.579001669679259
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E881A351C0969F849848D6BC4B35A20D
                                                              SHA1:23E2ABD0DEE5F6208C512BE3B3EF5A4E072C4347
                                                              SHA-256:DBFE4D5BA0A509A6CE1CF008038539ACA832B5C5111CC412F9AACE61034E24D3
                                                              SHA-512:DB0B0A1017FE78234A6D98CD9A0DAD87F2FBA756F975328341F9A165764E9D272F38A0298D1B4E6539C2AB0766460BE1CB15D755EF0609EEE9B7803365DF938F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.P...........................................................P.O. .:i.....+00.../C:\...................V.1.....VY.F..Windows.@......OwHVY.G....3.....................}/8.W.i.n.d.o.w.s.....\.1.....VY.G..Installer.D......O.IVY.G...........................'..I.n.s.t.a.l.l.e.r.......1.....VY.G..{1D482~1..~......VY.GVY.G..............................{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.....r.2.h&..VY.G!.DESKTO~1.EXE..V......VY.GVY.G..............................D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.......T.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.N.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.\.D.e.s.k.t.o.p.A.p.p.I.c.o.n...e.x.e.........(LyJ,d[Q}96FN{74yHvfDesktopApp>[}JsY8X@QBqp9g2'0e@3..............................................
                                                              Process:C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):995
                                                              Entropy (8bit):4.897523442531414
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:22FEFE7FD25CFD08B3C330FC14935E64
                                                              SHA1:2B3F829F10EF530BC8D2079EA83838A68270E2B4
                                                              SHA-256:13A6ACA804C8BBA18406705F6E3CC12D3FE308C220127FEA276B8574E8E84AB0
                                                              SHA-512:BA13D4428F8CE19370A714410AEDC53C6B227DDF6AC120BD3F7B7452486B75AE9DCE9CF8C1DE8560D47B1D7CA33BDBD3C23BB4137664DF31DBCFBB510A536A1D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" >.. <section name="Articulate.ThreeSixty.App.ViewModel.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false" />.. </sectionGroup>.. </configSections>.. <userSettings>.. <Articulate.ThreeSixty.App.ViewModel.Properties.Settings>.. <setting name="Top" serializeAs="String">.. <value>NaN</value>.. </setting>.. <setting name="Left" serializeAs="String">.. <value>402</value>.. </setting>.. </Articulate.ThreeSixty.App.ViewModel.Properties.Settings>.. </userSettings>..</configuration>
                                                              Process:C:\Program Files (x86)\Articulate\360\Desktop Application\Articulate 360 Desktop App.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):995
                                                              Entropy (8bit):4.89678000027516
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B4F77A7CF3F6BEDCF0C6E0D1A5B73127
                                                              SHA1:4943F193D33D311B000C9E57B8B33A13D2AE1CC7
                                                              SHA-256:0BDE99F8710D364D8C973DE1DA2E5FF7F488B5F68907BA358840A63069CC13CD
                                                              SHA-512:F027424558C2F26D17F9A31A914183FFB3C8B04BD9EF968C168012DEB2F4E574A225921473022F00FD9128AF5CE2B321EE0A6BE90C1CFA321F5ECA8E370DDFFF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <sectionGroup name="userSettings" type="System.Configuration.UserSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" >.. <section name="Articulate.ThreeSixty.App.ViewModel.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" allowExeDefinition="MachineToLocalUser" requirePermission="false" />.. </sectionGroup>.. </configSections>.. <userSettings>.. <Articulate.ThreeSixty.App.ViewModel.Properties.Settings>.. <setting name="Top" serializeAs="String">.. <value>152</value>.. </setting>.. <setting name="Left" serializeAs="String">.. <value>402</value>.. </setting>.. </Articulate.ThreeSixty.App.ViewModel.Properties.Settings>.. </userSettings>..</configuration>
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:Unicode text, UTF-8 text, with very long lines (619), with CRLF line terminators
                                                              Category:modified
                                                              Size (bytes):15618
                                                              Entropy (8bit):5.491633842092729
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:021BA6C0B01FE214D5323E98420465A0
                                                              SHA1:8E045492C98D1E1F33A7469BB8386FB9DFB8E1B3
                                                              SHA-256:C98E6A1ACA6B98BA750524A2A746B0A6C4B4F426A550EF2B7AF9122A22FA5942
                                                              SHA-512:4685BA54AF3FD9D34930729F2805EA2B0EB8D2E2D7CE75D1F0C32217F4B64C3A818CFA10682ABD7E2C660A362B028A8EB2563E1DDB5C0EC3F83176EE560D0083
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:[1B48:1B4C][2024-10-22T04:55:44]i001: Burn v3.11.2.4516, Windows v10.0 (Build 19045: Service Pack 0), path: C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe..[1B48:1B4C][2024-10-22T04:55:44]i000: Initializing string variable 'ApplicationName' to value 'Articulate.360'..[1B48:1B4C][2024-10-22T04:55:44]i000: Initializing string variable 'PackageFileName' to value 'Articulate.360.Package.msi'..[1B48:1B4C][2024-10-22T04:55:44]i000: Initializing string variable 'PackageUpgradeCode' to value '92617AD6-B1BB-49BD-A986-9939F3D5F002'..[1B48:1B4C][2024-10-22T04:55:44]i000: Initializing string variable 'LaunchProcessInstallLocationRegistryKeys' to value 'HKEY_LOCAL_MACHINE\Software\Articulate\360\Desktop Service;HKEY_LOCAL_MACHINE\Software\Articulate\360\Desktop Application'..[1B48:1B4C][2024-10-22T04:55:44]i000: Initializing string variable 'LaunchProcessNames' to value 'Articulate 360 Desktop Service.exe;Articulate 360 Desktop App.exe'..[1B48:1B4C][2024-10-22T04:55:
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Unicode text, UTF-16, little-endian text, with very long lines (542), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):632230
                                                              Entropy (8bit):3.8139858848975883
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C83654EDF78C1E69B42860879C48D0F5
                                                              SHA1:5D38D8BEC6D10190EFC6E27ADAD9B42FD710582D
                                                              SHA-256:23F740E17070469E3BB7EF93F3F8FA297C14200B0FDD8223560291946FAA1143
                                                              SHA-512:F9EAABFDB0CA71E8FD0374AB03D0CA70E4789F67F224FC574C124A1B0E4C324FA23BC7EB45CCE76BAF2F11DA6043C3E4B339E52344D8E50EBCD7F6E8110D89DF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:..=.=.=. .V.e.r.b.o.s.e. .l.o.g.g.i.n.g. .s.t.a.r.t.e.d.:. .2.2./.1.0./.2.0.2.4. . .0.4.:.5.6.:.2.8. . .B.u.i.l.d. .t.y.p.e.:. .S.H.I.P. .U.N.I.C.O.D.E. .5...0.0...1.0.0.1.1...0.0. . .C.a.l.l.i.n.g. .p.r.o.c.e.s.s.:. .C.:.\.W.i.n.d.o.w.s.\.T.e.m.p.\.{.F.8.F.E.0.D.2.5.-.E.D.D.3.-.4.C.1.8.-.9.0.9.A.-.5.4.D.0.8.E.2.8.5.7.7.C.}.\...b.e.\.A.r.t.i.c.u.l.a.t.e...3.6.0...B.u.n.d.l.e...e.x.e. .=.=.=.....M.S.I. .(.c.). .(.8.8.:.3.C.). .[.0.4.:.5.6.:.2.8.:.2.4.2.].:. .R.e.s.e.t.t.i.n.g. .c.a.c.h.e.d. .p.o.l.i.c.y. .v.a.l.u.e.s.....M.S.I. .(.c.). .(.8.8.:.3.C.). .[.0.4.:.5.6.:.2.8.:.2.4.2.].:. .M.a.c.h.i.n.e. .p.o.l.i.c.y. .v.a.l.u.e. .'.D.e.b.u.g.'. .i.s. .0.....M.S.I. .(.c.). .(.8.8.:.3.C.). .[.0.4.:.5.6.:.2.8.:.2.4.2.].:. .*.*.*.*.*.*.*. .R.u.n.E.n.g.i.n.e.:..... . . . . . . . . . . .*.*.*.*.*.*.*. .P.r.o.d.u.c.t.:. .C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.P.a.c.k.a.g.e. .C.a.c.h.e.\.{.1.D.4.8.2.3.7.C.-.3.F.A.7.-.4.4.6.5.-.8.B.7.B.-.2.2.3.E.3.6.C.D.A.0.C.0.}.v.1...8.9...3.2.6.1.8...0.\.A.r.t.i.c.u.l.a.t.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D59C28A6163C13B4719B1CC993AFE1CC
                                                              SHA1:4333FE043063AA9F196394030C612BAC120266DD
                                                              SHA-256:C97AA9BBEC20C06CD691EFF0AC0F1C48A84FACB56B8326A028343CA9FCA1BDC7
                                                              SHA-512:42E6527346C712F0D476D020B923D25738D5D0DE473FFB62F6B666E939532FB70C134E930D0CAFA35BD35AF2EBAE1055C43E5AE40BC667272EC62BB882FFC736
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)kf...........!..0.................. ........... .......................@............`.................................D...O............................ ....................................................... ............... ..H............text...@.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................x.......H............M..........,.................................................( ...*:.( .....}....*..0..)........{.........(!...t......|......(...+...3.*....0..)........{.........(#...t......|......(...+...3.*"..(....*b.{....%-.&*..s$...o%...*N.{....%-.&*..o%...*..(&...*..0..l.......~....%-c&.....('...((...~....%-.&~...... ...s)...%.....(...+~....%-.&~......!...s+...%.....(...+(...+%.....*:.(&.....}....*6..u....(....*....0.......... .....{.......(....X*....0..8.........3..*.{....
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:522305321F0FBF3FAA7A8324F3AFB66B
                                                              SHA1:D88F6661EEA70FDE9C0F83B0076D6B33EA92A76A
                                                              SHA-256:6741BC128631EB442EC198AF0C3ADD97625629C4E90AEFBAE3DCC1F21FD11F34
                                                              SHA-512:8507A280ED4279F5A530412BF48D4C5AF50704E48394F913A45ABC72FD00780E49832DA611E8F75B564700C1E03B0B00F6F819E2A61C1672424785D74730F80D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..8...........W... ...`....... ....................................`.................................KW..O....`...............................V..8............................................ ............... ..H............text....7... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B.................W......H.......L*..4,............................................................(....*:.(......}....*..0...........r...po.....s5......rS..po6...s8.....r...po6.....(....-n~....~....%-.&~......=...s....%.....(...+(...+...o....-*.r...p.r...pr...p.(....(....o.... C......>.r...p.o9....r...po........"...rk..pr...p..(....o.... C.........*............".....0..`........r...po.....s5......rS..po6...s8....r!..po6...(......r5..p..(...(....o....r...p.o:.....(....._..r...p..(...(....o.....-.....
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:137BE966EA4B1E837A75F425A05B5295
                                                              SHA1:5F2BB9385BBEAD1518C37004521BF990A950C2FA
                                                              SHA-256:C049DE98298073404558A5570802896E14D4BA5EF19C90B64FDE11ACD324FD8F
                                                              SHA-512:493974BD331C696D2DE616E6615660FFE6A77A925092D908CCF68183975E6A659485DC805CF28D0D78446DF22C3FED8B73D4FB76F760534ACDB353D724313156
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...z.$..........." ..0................. ........... ....................................`.....................................O.......`...........................d...T............................................ ............... ..H............text........ ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B........................H........=...[..........l...x ..........................................0...........s....s{...s.....+..*....0..$........~+....(...+..,...(.....+.s.....+..*.0..?........~.....(...+..,%.s....s{...s....sr...(.......ss....+.s.....+..*..0...........s.....s{......s.......s......s....(.......s....(.........~,.........%.......(...+sk........~+.........%.......(...+sk.........s......+...*..0.............s....s.....+..**..(!.....*&.(".....*..0..9........~.........,".r...p.....(#...o$.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B0D10A2A622A322788780E7A3CBB85F3
                                                              SHA1:04D90B16FA7B47A545C1133D5C0CA9E490F54633
                                                              SHA-256:F2C2B3CE2DF70A3206F3111391FFC7B791B32505FA97AEF22C0C2DBF6F3B0426
                                                              SHA-512:62B0AA09234067E67969C5F785736D92CD7907F1F680A07F6B44A1CAF43BFEB2DF96F29034016F3345C4580C6C9BC1B04BEA932D06E53621DA4FCF7B8C0A489F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Mp.].........." ..0...... ........... ...@....... ..............................N.....@.................................`...O....@...............@.......`......(-............................................... ............... ..H............text........ ...................... ..`.rsrc........@....... ..............@..@.reloc.......`.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5C9985D31E098BF7DF031171E046D67E
                                                              SHA1:C6A7DBD7B28B2F3721685A8D8658DCC0B229B09F
                                                              SHA-256:675EBD10802E628AEA65659A18505651FF945E70C8730F74CE5FF1674B2D45A8
                                                              SHA-512:6452FACCEDBA3AFCAC776A1A72179EEEE00284D45CFAA9CAF41462404B43B8E69F54852AA9E41FC87B484A15767A852A3439B3AF6DCC6C4CF5F18304351AC3B3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....X..........^w... ........... ..............................J.....@..................................w..S....................`...............u............................................... ............... ..H............text...dW... ...X.................. ..`.rsrc................Z..............@..@.reloc...............^..............@..B................@w......H.......p9..`<..........04..?...P .........................................w[...A....Ai.!mU.......;.`.....5.....t......&.|I%"N......N..:>...(U7.!..;..........s........m...j...y\#..\h....6..:....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*..q...............(....,..*.........(.....*.0...........{......,....s....o....*.0...........(...+...(....*..(....*..s....}.....(............s....}....*:.(......}....*..0..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7C08EA125D8054BFA6057104590A7F83
                                                              SHA1:E8F02BBDC181AFE2C32482EB2B453B05EBACCAF5
                                                              SHA-256:25F8CCD05C97805438D5A7E321765E92EDBA7F135960F345920AF779AD6A78FC
                                                              SHA-512:12D3033F9CBA4D571ACE655B8D2B7ACF1D550592A833895F0311E8E928A55C2900B02A6B2E22C607DC9501B06DC5C04899EC37DF14391D65BD446CAE54EDC83B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....3pQ...........!.....6..........~T... ...`....... ....................................@.................................$T..W....`...............>...............R............................................... ............... ..H............text....4... ...6.................. ..`.rsrc........`.......8..............@..@.reloc...............<..............@..B................`T......H........-...%...........*..x...P ........................................"N.e)&gn......A.I.............}..3.p..S.....,#.:...:.=.[.t..w...z........t.9.>.....3....8..>.....=.w<....F....^.. .0...........(.....-.r...ps....z.o....u....-4(....(&.................(....o......(....r...ps....z.-.r!..ps....z.o....u....-4(....(&.................(....o......(....r!..ps....z..}......}....*F.{....o....t....*F.{....o....t....*..{....*"..}....*..(....*.0..@................,...i.1
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):0
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B81F7CD09B39B8A5681D3E373C29C792
                                                              SHA1:966256B3F0E8D7FD5026E81CB33EC67122CF9BD4
                                                              SHA-256:B81FD01FF84915425375F74BAF46D0300F21CE63725A4D5F817BF901C6C212F1
                                                              SHA-512:A4E80C424ADCA342F4392724767D20132DEC56D6829CDB1A5A1FC89BE1DFD418CC26681FAD7669209A4F684B0D73DBF48C8CC09BEA6CCEEA8B4677A8B18B6702
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.................)... ...@....... ...............................c....@..................................)..W....@.......................`......l(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P .......................................K..H.:B...X....1cHs.^.[xh.......)@1W.c(........V,_..(7..G..H.M/..$`........*hf.u.....-.=j....!q .B.a1..e..\...p....~}..%F}BSJB............v4.0.30319......l...(...#~......(...#Strings............#US.........#GUID...........#Blob...........G.........%3....................................................................................,.....C.....`.........................................3.....L.....|.
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:ASCII text, with very long lines (321), with CRLF line terminators
                                                              Category:modified
                                                              Size (bytes):16536
                                                              Entropy (8bit):5.491358346494337
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4B012761A74D5A37F9939D30A76D66F9
                                                              SHA1:193B096DCCBC500FC8E12FCF5F13127B9F26F026
                                                              SHA-256:A40C1F3A1769D6564DBC775A032B524BB97BFEFB617A7E237950AD442D9CEB90
                                                              SHA-512:E53F748289B898260914132173110BD5E63F8C99314E695525636609F00A8B7B8EDEB8B2F289F5CFEBE0B32932156420D13461276DFFB3508B20B4B641C1949C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:[1810:181C][2024-10-22T04:56:02]i001: Burn v3.10.4.4718, Windows v10.0 (Build 19045: Service Pack 0), path: C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe..[1810:181C][2024-10-22T04:56:02]i009: Command Line: '"-burn.clean.room=C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe" -burn.filehandle.attached=536 -burn.filehandle.self=532 /quiet /norestart'..[1810:181C][2024-10-22T04:56:02]i000: Setting string variable 'WixBundleOriginalSource' to value 'C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\vc_redist.x86.exe'..[1810:181C][2024-10-22T04:56:02]i000: Setting string variable 'WixBundleOriginalSourceFolder' to value 'C:\ProgramData\Package Cache\AB4A97610B127D68C45311DEABFBCD8AA7066F4B\'..[1810:181C][2024-10-22T04:56:02]i000: Setting string variable 'WixBundleLog' to value 'C:\Users\user\AppData\Local\Temp\dd_vcredist_x86_20241022045602.log'..[1810:181C][2024-10-22T04:56:02]i000: Setting string v
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Unicode text, UTF-16, little-endian text, with very long lines (319), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):147064
                                                              Entropy (8bit):3.83917041359198
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:664F38C4C49F6B4C7626A52459AB7690
                                                              SHA1:CCAB70EDDDBDB7DF8FEF085A989AB26DDEE5A95D
                                                              SHA-256:F26D16EB29AD5398A0C82F8D57FCF78F1BC830E99E5A006C55174B577A18CC0B
                                                              SHA-512:43E9687188DB5105269C608384EB94AD349DB5B05C9BFDB5E952175CDD6F4CF23ED980E82787670EBF843184E753DDDC1F6D096DA6ECB4C3E78AA2410D99924D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:..=.=.=. .V.e.r.b.o.s.e. .l.o.g.g.i.n.g. .s.t.a.r.t.e.d.:. .2.2./.1.0./.2.0.2.4. . .0.4.:.5.6.:.2.1. . .B.u.i.l.d. .t.y.p.e.:. .S.H.I.P. .U.N.I.C.O.D.E. .5...0.0...1.0.0.1.1...0.0. . .C.a.l.l.i.n.g. .p.r.o.c.e.s.s.:. .C.:.\.W.i.n.d.o.w.s.\.T.e.m.p.\.{.2.4.D.B.8.9.4.E.-.9.C.9.5.-.4.9.3.6.-.9.1.7.E.-.4.1.E.8.4.F.6.0.2.1.9.1.}.\...b.e.\.V.C._.r.e.d.i.s.t...x.8.6...e.x.e. .=.=.=.....M.S.I. .(.c.). .(.8.C.:.4.4.). .[.0.4.:.5.6.:.2.1.:.1.6.0.].:. .R.e.s.e.t.t.i.n.g. .c.a.c.h.e.d. .p.o.l.i.c.y. .v.a.l.u.e.s.....M.S.I. .(.c.). .(.8.C.:.4.4.). .[.0.4.:.5.6.:.2.1.:.1.6.0.].:. .M.a.c.h.i.n.e. .p.o.l.i.c.y. .v.a.l.u.e. .'.D.e.b.u.g.'. .i.s. .0.....M.S.I. .(.c.). .(.8.C.:.4.4.). .[.0.4.:.5.6.:.2.1.:.1.6.0.].:. .*.*.*.*.*.*.*. .R.u.n.E.n.g.i.n.e.:..... . . . . . . . . . . .*.*.*.*.*.*.*. .P.r.o.d.u.c.t.:. .C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.P.a.c.k.a.g.e. .C.a.c.h.e.\.{.2.8.6.D.C.3.9.B.-.5.F.B.7.-.4.A.F.F.-.9.D.D.4.-.2.2.D.B.4.7.6.6.4.C.D.7.}.v.1.4...3.8...3.3.1.3.5.\.p.a.c.k.a.g.e.s.\.v.c.R.u.n.t.i.m.e.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Unicode text, UTF-16, little-endian text, with very long lines (411), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):147286
                                                              Entropy (8bit):3.8258789782693534
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:54DD77B6D62C53DACA54821859C89E1A
                                                              SHA1:B1BB08BD90D85ED8532349C45E7C0E5A30E85173
                                                              SHA-256:04B49E4CC233B81F4F016E954B2BFED3791E2BEBA98F4AF25033BE62107B9E66
                                                              SHA-512:04F4292D8D0CB9B13DB15581F3512F7CB24D8E4EE9C1E59057244374A02B8D99ABEB7F363CD5BDF3BE760247CAA76B7FED3309C0F2F74B725129903BFCB66493
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:..=.=.=. .V.e.r.b.o.s.e. .l.o.g.g.i.n.g. .s.t.a.r.t.e.d.:. .2.2./.1.0./.2.0.2.4. . .0.4.:.5.6.:.2.2. . .B.u.i.l.d. .t.y.p.e.:. .S.H.I.P. .U.N.I.C.O.D.E. .5...0.0...1.0.0.1.1...0.0. . .C.a.l.l.i.n.g. .p.r.o.c.e.s.s.:. .C.:.\.W.i.n.d.o.w.s.\.T.e.m.p.\.{.2.4.D.B.8.9.4.E.-.9.C.9.5.-.4.9.3.6.-.9.1.7.E.-.4.1.E.8.4.F.6.0.2.1.9.1.}.\...b.e.\.V.C._.r.e.d.i.s.t...x.8.6...e.x.e. .=.=.=.....M.S.I. .(.c.). .(.8.C.:.6.0.). .[.0.4.:.5.6.:.2.2.:.7.0.8.].:. .R.e.s.e.t.t.i.n.g. .c.a.c.h.e.d. .p.o.l.i.c.y. .v.a.l.u.e.s.....M.S.I. .(.c.). .(.8.C.:.6.0.). .[.0.4.:.5.6.:.2.2.:.7.0.8.].:. .M.a.c.h.i.n.e. .p.o.l.i.c.y. .v.a.l.u.e. .'.D.e.b.u.g.'. .i.s. .0.....M.S.I. .(.c.). .(.8.C.:.6.0.). .[.0.4.:.5.6.:.2.2.:.7.0.8.].:. .*.*.*.*.*.*.*. .R.u.n.E.n.g.i.n.e.:..... . . . . . . . . . . .*.*.*.*.*.*.*. .P.r.o.d.u.c.t.:. .C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.P.a.c.k.a.g.e. .C.a.c.h.e.\.{.9.C.1.9.C.1.0.3.-.7.D.B.1.-.4.4.D.1.-.A.0.3.9.-.2.C.0.7.6.A.6.3.3.A.3.8.}.v.1.4...3.8...3.3.1.3.5.\.p.a.c.k.a.g.e.s.\.v.c.R.u.n.t.i.m.e.
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 07:57:12 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                              Category:dropped
                                                              Size (bytes):2677
                                                              Entropy (8bit):3.9859604706917096
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4CD8D27583E417F25058977102F031DA
                                                              SHA1:80B1D1F32B5FE8A92162077216E1281F7108E337
                                                              SHA-256:E98CAC514A2B9CF401B82D31228DCBF3EFCDF67C76806C997E8E3C126E9AD8E3
                                                              SHA-512:D0A81E4A63186E0CB8C598B550CE1F453E74268C37A779697210638E98B3AEBB6B4CB612D82F2E591D245EA3E9A512858E95A0E019F65C5417BF520855A4A8EE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.@.. ...$+.,.....x5b`$......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IVY.F....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VVY%G....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VVY%G....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VVY%G...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VVY&G...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........p@.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 07:57:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                              Category:dropped
                                                              Size (bytes):2679
                                                              Entropy (8bit):4.000381079847924
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B0EB4FCBEEE0C630D3B10EF76DBD69EF
                                                              SHA1:442347BEB2F4C1F2F61CD367E5C77C5B89D56942
                                                              SHA-256:177BB2D889E628BEA4410DC2C1E7833A8D585097A70C79BCC91F0384784B3FA9
                                                              SHA-512:8FBBDBA9086D4C7E70E415728D76E96DD536F0EB3DA22FB85F5B373DBDEF89975653ACF992E64B4663F939B7BB9C8CF669CDB460359618F516F771F4E3662FEC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.@.. ...$+.,....h.&b`$......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IVY.F....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VVY%G....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VVY%G....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VVY%G...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VVY&G...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........p@.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Fri Oct 6 08:54:41 2023, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                              Category:dropped
                                                              Size (bytes):2693
                                                              Entropy (8bit):4.012963592986388
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8F314AFD8CBA80849480D34877C5CB6F
                                                              SHA1:56F94F2B203B2E0AA98B92EC7DC2187F2CCCB4BD
                                                              SHA-256:7E990B4FA7442773EB98721DD9CC0218751DB07C7172B51DA87FAB01210E4347
                                                              SHA-512:88C2CB41644A61CE1B6962A919DDF96111BC7342F9BFD520407231543412D423445EB96B93411D920B1F3125DF750C53A6D6ABC27FED91CB4609E2876495D61F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.@.. ...$+.,.....v. ;.......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IVY.F....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VVY%G....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VVY%G....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VVY%G...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VFW.N...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........p@.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 07:57:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                              Category:dropped
                                                              Size (bytes):2681
                                                              Entropy (8bit):4.000467480828417
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F038E9E7537F418577CE5F6F0A92F852
                                                              SHA1:FB8865A41DB98C73901D5F3FC66EBC1EB7159EE1
                                                              SHA-256:78A1CE6C846112186FE3FC31F3043E1827AA6CB4F5160DE84D2CD4BA354E04D7
                                                              SHA-512:9F6EB523D5634D5B7D430F3ECB1C11D73258CC48D74E2D51F035B438FF9C9E52DE737714B2B939D5C7ACC9B9E7305743BA7F9975AD524DA75E9010746D325EF3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.@.. ...$+.,.......b`$......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IVY.F....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VVY%G....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VVY%G....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VVY%G...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VVY&G...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........p@.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 07:57:12 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                              Category:dropped
                                                              Size (bytes):2681
                                                              Entropy (8bit):3.9883143364359426
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:20E932CF7796F3325B665FB57D2F00D0
                                                              SHA1:79C57279ADA28FB318EDEFEA91C03AEC1C47B057
                                                              SHA-256:4C0A961C8389DA2E5FEECB4C8C29D2CB3995DFF6DFA0A6CB09E78E6B30EBB60D
                                                              SHA-512:64E3369FE49FF59C2E895ECCBBA6FE799518CE51DFFFA65BB3E6D189281D48D411AC1E93FD2374CD60E92B233804D2997BAC87C2153BDF42E365C4DAA80A6E3F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.@.. ...$+.,.......b`$......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IVY.F....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VVY%G....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VVY%G....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VVY%G...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VVY&G...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........p@.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Tue Oct 3 09:48:42 2023, mtime=Tue Oct 22 07:57:11 2024, atime=Mon Oct 2 20:46:57 2023, length=1210144, window=hide
                                                              Category:dropped
                                                              Size (bytes):2683
                                                              Entropy (8bit):4.000440448916973
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B898C7E4B4212024230D72D75C3BC290
                                                              SHA1:30E05A28AE85D0497B3717D9C935B3B6C92FFA5E
                                                              SHA-256:6B07DBFA873AEA38A862C575F10E97258ED02CACFD91A75F2F07F38531E6CF67
                                                              SHA-512:8DA60C484FC08CD8B6BE8E7783B6B16B36A3DD2C6A4B3C378B071F0F75336819E850199D05CECCF458A376C8ABC3D8582F9C682DFB6F4290995EB82FBF00A7B9
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:L..................F.@.. ...$+.,.......a`$......y... w......................1....P.O. .:i.....+00.../C:\.....................1.....FWoN..PROGRA~1..t......O.IVY.F....B...............J.........P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1.....CW.V..Google..>......CW.VVY%G....L.....................p+j.G.o.o.g.l.e.....T.1.....FW.N..Chrome..>......CW.VVY%G....M......................W..C.h.r.o.m.e.....`.1.....FW.N..APPLIC~1..H......CW.VVY%G...........................W..A.p.p.l.i.c.a.t.i.o.n.....n.2. w..BW. .CHROME~1.EXE..R......CW.VVY&G...........................3.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.......j...............-.......i...........p@.......C:\Program Files\Google\Chrome\Application\chrome_proxy.exe..S.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.\.c.h.r.o.m.e._.p.r.o.x.y...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.G.o.o.g.l.e.\.C.h.r.o.m.e.\.A.p.p.l.i.c.a.t.i.o.n.F
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):9501
                                                              Entropy (8bit):5.666095832344591
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7F221E8CF69797CC51A6D8307C650D5B
                                                              SHA1:E8CE4D3C2303E0060DCC487ECF95CE9E1CFC1D07
                                                              SHA-256:E383316518401E0CDDC0E01C4C0F645A1FF24239C79B4849F495C9BBF2C4294C
                                                              SHA-512:73431DD325C623C6210420C38F85F8686153DBB93F2A52F9D1C04E2F8DD9566AB919DFBF390014D26D329A3DA478629234C4F096FB0E38C9B0DAB5762BA68C67
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{286DC39B-5FB7-4AFF-9DD4-22DB47664CD7};.Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135..vc_runtimeMinimum_x86.msi.@.....@o.&..@.....@........&.{83CEF352-ED74-4B1D-B0E7-96CDF4DA1C2D}.....@.....@.....@.....@.......@.....@.....@.......@....;.Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{E3819B64-3C56-3DD7-921D-00B011AD31DE}@.02:\SOFTWARE\Microsoft\VisualStudio\14.0\VC\Runtimes\X86\Version.@.......@.....@.....@......&.{E8E39D3B-4F35-36D8-B892-4B28336FE041}$.C:\Windows\SysWOW64\vcruntime140.dll.@.......@.....@.....@......&.{F4F89385-AC80-4040-ADA6-06D37B69832E},.C:\Windows\SysWOW64\vcruntime140_threads.dll.@.......@.....@.....@......&.{A2AA960C-FD3C-3A6D-BD6F-14933011AFB3} .C:\Windows\SysWOW64\msvcp140.dll.@.......@.....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):9740
                                                              Entropy (8bit):5.6385048674426415
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:65A59D5B416FF0E132213B08C7E7B2B8
                                                              SHA1:3EB7BA55E6B22F99708D562CE4521E49C8BA6FE6
                                                              SHA-256:3FB7A65D09B92EFE62BD0D230AD91A8EBAD1A091D2DD4EAC669140ECA903CA1E
                                                              SHA-512:C167F4870ED7921BCAA2CBFCAC52A41FBD2AD18FCFCD6FE828C382C5CC1FBE0B1FC492E2E73E269C679486660D21FF28450BB5D9065C43F54BB0C41DE2B9B821
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{9C19C103-7DB1-44D1-A039-2C076A633A38}>.Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135..vc_runtimeAdditional_x86.msi.@.....@o.&..@.....@........&.{29E9ACD5-6C1B-48C9-A316-358656F83B42}.....@.....@.....@.....@.......@.....@.....@.......@....>.Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{E3819B64-3C56-3DD7-921D-00B011AD31DE}@.02:\SOFTWARE\Microsoft\VisualStudio\14.0\VC\Runtimes\X86\Version.@.......@.....@.....@......&.{4FD4AB8C-C57F-3782-9230-9CCA22153AD3}..C:\Windows\SysWOW64\mfc140.dll.@.......@.....@.....@......&.{46A1EA6B-3D81-3399-8991-127F7F7AE76A}..C:\Windows\SysWOW64\mfc140u.dll.@.......@.....@.....@......&.{C94DDE19-CC70-3B9A-A6AF-5CA7340B9B9A}..C:\Windows\SysWOW64\mfcm140.dll.@.......@.....@.....@....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):497154
                                                              Entropy (8bit):6.216101847333104
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3DEE14D72113CC5F28AFB2BF4B93502F
                                                              SHA1:77ABE74B275E9C7EA1B8650462F65EC75DA6C484
                                                              SHA-256:A216CAEAF9F5E998BDD94697B96316BFD546AC4A9275C0373EB31457C70FBCD2
                                                              SHA-512:CF952E08EEC30C62B8DBA91A9973C06342493450DB7DA3E495D19393B5A487A92CB9679269B2FD8FFFF123903A1C9EE92D2FEEA3B6F53B9FA056C89BC4B2518F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}..Articulate 360..Articulate.360.Package.msi.@.....@j.Y..@.....@........&.{C5D0A98E-A4FF-4ADA-8410-5E4BAF9F113F}.....@.....@.....@.....@.......@.....@.....@.......@......Articulate 360......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........WixCloseApplicationsDeferred....J...WixCloseApplicationsDeferred.@.......M..MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........................^.......\......].........................,.......<.........L...'.....'.....'.P.......8.....'.....Rich............................PE..L...Ap.]...........!.........P............................................................@.........................@................P..x....................`..........T...............................@...............<.....................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):748952
                                                              Entropy (8bit):6.965470075254912
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7E158C5747F971EDBE2A7F89639CC22B
                                                              SHA1:3EC8DDFB160296CC9FCDB6A9E88D0A6F6E3A8758
                                                              SHA-256:3E5403AC1CF7D8F1AABDFAF820DB6BFA363BD31C436F025CE9791972B2B36E58
                                                              SHA-512:43DE1EFB97177B14396483DB19FF6AB96593EAB2474368253A56B8520DCB74D483C4EAF14F8B586D5A64D0796EAAA43F45C7E86C254E9FCF48D05F41E0AB4105
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:...@IXOS.@.....@.'VY.@.....@.....@.....@.....@.....@......&.{1D48237C-3FA7-4465-8B7B-223E36CDA0C0}..Articulate 360..Articulate.360.Package.msi.@.....@j.Y..@.....@........&.{C5D0A98E-A4FF-4ADA-8410-5E4BAF9F113F}.....@.....@.....@.....@.......@.....@.....@.......@......Articulate 360......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........CreateRegistryValuesAction....J...CreateRegistryValuesAction.@......i...MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................'P\....'P^....'P_...........................>.......4..................R......:...........Rich...........................PE..L....o.]...........!.....D...~.......L.......`......................................S#....@.........................0}...*......x...............................4... s..T...........................xs..@............`..l............................text.
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive
                                                              Category:dropped
                                                              Size (bytes):373865
                                                              Entropy (8bit):6.9647887754680236
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:233089C534D6D5227CFA042CC968A44B
                                                              SHA1:1911DD4BED14CD67D9C33B9F6CD85FDB077FF170
                                                              SHA-256:CB8531F797B85D64A15959D476D62864B5906DE4D1029817ECC000482CDF830F
                                                              SHA-512:49FAD40B6C487AAB5C3DA22D2F68923FD2E31186A79E80088F6372D3C0FC567D7F974867A1E37C8BEB1763E8DECEAD8384AB03B70641C7970A65060E53057CE3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..................'P\....'P^....'P_...........................>.......4..................R......:...........Rich...........................PE..L....o.]...........!.....D...~.......L.......`......................................S#....@.........................0}...*......x...............................4... s..T...........................xs..@............`..l............................text....B.......D.................. ..`.rdata...Q...`...R...H..............@..@.data...p...........................@....rsrc...............................@..@.reloc..4...........................@..B................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\SysWOW64\rundll32.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):244
                                                              Entropy (8bit):4.84728008329042
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A489EFB3754FC7CF3C9C84D9C2C4BFB6
                                                              SHA1:C8502CF7D6966F0DFFB32FA9CACFA0B02AA33568
                                                              SHA-256:EB17C2CF1D92FD7DF43B22F32DACB34918F2EBE5963A3AA47BBC65CB93988B1E
                                                              SHA-512:35A7710BF8FF5474C0CD1BF7AE1CAB07622A557C68A2F5EB7573AA9B8DAC15BB9B3AF08C3D9F531BE3DBCBEEC2C017AE396DBA3ADB4A1FB307E96092BE640FD5
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <startup useLegacyV2RuntimeActivationPolicy="true">.. <supportedRuntime version="v4.0" />.. <supportedRuntime version="v2.0.50727"/>.. </startup>..</configuration>..
                                                              Process:C:\Windows\SysWOW64\rundll32.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):10240
                                                              Entropy (8bit):4.423102777087469
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B4D8DAD65CF300C65E955938555A35FE
                                                              SHA1:648F5EE7729664753EDD8E7C11F5EB7C92246C72
                                                              SHA-256:C71EE5893A85FDB047FF9890002A9FB4816C11BAE7BC08B66212E6B8B3AD25B0
                                                              SHA-512:F8E485C0083E4872CA843CD9E0DED69307590D44055F85356F8444650E5D9975CBD35CD096DFAD6FD5158061C9B48D8C3C3B5A07C9D057A6C137EDA8314F74E1
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...d;.]...........!................>:... ...@....... ....................................@..................................9..W....@.......................`....................................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`.......&..............@..B................ :......H........4..<............ ......P ......................................w..!.._1......B.Q..vR.N...._.5..Nw0.f......>s...3......r9.....s.A...<,.%.B..P.A7...=]....7?...8....U*Z.1,..u'.E.H.(.jy................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....G.......PADPADP..7...7....\.....`.Q......!...........:oH..S....c...........L.}..>.. 2...3...5......:...
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:modified
                                                              Size (bytes):216496
                                                              Entropy (8bit):6.646208142644182
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A3AE5D86ECF38DB9427359EA37A5F646
                                                              SHA1:EB4CB5FF520717038ADADCC5E1EF8F7C24B27A90
                                                              SHA-256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
                                                              SHA-512:96ECB3BC00848EEB2836E289EF7B7B2607D30790FFD1AE0E0ACFC2E14F26A991C6E728B8DC67280426E478C70231F9E13F514E52C8CE7D956C1FAD0E322D98E0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........................^.......\......].........................,.......<.........L...'.....'.....'.P.......8.....'.....Rich............................PE..L...Ap.]...........!.........P............................................................@.........................@................P..x....................`..........T...............................@...............<............................text...[........................... ..`.rdata..............................@..@.data...."... ......................@....rsrc...x....P......................@..@.reloc.......`......................@..B........................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):20480
                                                              Entropy (8bit):1.1704667084264941
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1C161862C5F2DCB00627851876B61473
                                                              SHA1:AD5F52C633611592266C813F085591B0AA04F47F
                                                              SHA-256:DBE51FA8738FEB02D5BD5AB092B1074081D92A659127C9672159D05E6694F6A3
                                                              SHA-512:F6C1B2FA8C3012BE101C10ACB006BE1EBD2EA9A28C1D8D21B0A7D099D04CCB2969B64AC27B77B5F0873E7F0F0BCED60114AF322BD18D46BF6CD3535CA7D01197
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):20480
                                                              Entropy (8bit):1.2077637020034548
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3DDBEEC5B8FB7E9120E88FC25EFA5DEC
                                                              SHA1:2E96940D639C745BCCEAAF08E3D8F4C3166C8FA9
                                                              SHA-256:4A69A66EA702BDA8128F6F68EAF7F1BF45BA60342A13E948246B8758A154A6F8
                                                              SHA-512:42323464AE7DBADE3CD2BB811C9ADBD5D64011A0C859E1D1D9E6F30165024A9B5F56C766F4F8FA94DA204331A590B2E47FB9AD311F15BBD1FDFD224507D6AE2F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):20480
                                                              Entropy (8bit):1.2085313489870706
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F91EB966C8254B597E777617B10C7AA3
                                                              SHA1:44112DE00AF51F9C50D56332E64C722FF898B3C3
                                                              SHA-256:F5065E4B73ED51F7901EA2CB3C4EDA058C811C0E1F81E1630E6AC71C4E786E41
                                                              SHA-512:600FD526897C908B2969314C5B9D5FA485087263C3FEEFEAFCA5380B0DAE0344D2C3C07C13D7787615C3B970B4F09A191EB8AD67332F64C9D3661915CB2FFAA6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):206440
                                                              Entropy (8bit):5.116568096217514
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4131280CF86DCB3076FFCCBCF87C814A
                                                              SHA1:B0751994FF6D364C99BEFF4AAA868BE0A332EFB7
                                                              SHA-256:9D7E5098CDA1E94E44F529233CC30F746E48BFC32B0033349629D8711043CE59
                                                              SHA-512:AB3DB75143617FFB9E6DD6FF4CE53EB3E09162201C174E0CEB286A1D12AB17F0430C093B5DADC0A7AEC0E0098B16ECF65E042F0D2F70C4A7808A8EC97D37F79F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....$kf..............0..............*... ...@....@.. .......................`......ga....`.................................|*..O....@..P...............h(...@......D)............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......@......................@..B.................*......H.......t ..P....................(........................................(....*:.(......}....*.*..(....*...BSJB............v4.0.30319......l...<...#~..........#Strings............#US.........#GUID...........#Blob...........W..........3........................................................-.\.....\...f.*...|.................M.....f.......................z.=...@.=.........%.\...............N...............................A...........\.A.............M.....&.....P ......$.....
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):403156
                                                              Entropy (8bit):5.359654799021088
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C78C96A2369841289DDFBBE922F02B69
                                                              SHA1:B182201B9E36FF62311DA976615A9C6C5EF5FE52
                                                              SHA-256:F3F11F8A305A975862ADACAA10FFE4BC08D755BA1A70118E8934B17EF324C7CE
                                                              SHA-512:B69EB6B2638BAE226A8815F09E1D9743CA62B16CE551EDD6CF16154C004CBF8E2ED31F0A7095C173911C3D2E6BA447B83472A921F2593E6D8BD2349F46F57DEE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):257616
                                                              Entropy (8bit):6.701518252422076
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3D0EA6BA3551AEC4717AB2827319A741
                                                              SHA1:E1273BA1B3D6CDBF93C99B115EF8ACCD84568718
                                                              SHA-256:1573721C06F70D779F5AEBA175C039202069DA15D8526C3CE0C19B8C7FA985B1
                                                              SHA-512:BADE3D768BF435C0ADD77BA377866A59146D22E102932FBEAB08FC10B27B9F5BCC5375ED26EE48847FB57649D706FF2AD6192895780C6924E34CAA7FCCA3514A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........z[.s)[.s)[.s)..r(Y.s)R..)Q.s)].r(^.s)[.r).s)].w(P.s)].p(\.s)].v(..s)].s(Z.s)]..)Z.s)].q(Z.s)Rich[.s)........PE..L...+............."!...&.&...x..............@......................................Jc....@A.............................K.. ...........................PP.......*...;..T...........................(;..@............................................text...\$.......&.................. ..`.data....4...@...2...*..............@....idata...............\..............@..@.rsrc................n..............@..@.reloc...*.......,...r..............@..B........................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):4841880
                                                              Entropy (8bit):7.037865881588186
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:968006878A0703C6D528C315AAA64E92
                                                              SHA1:EDCC9FBA54F81ABB6162C6FEC2A56AE0472EDF68
                                                              SHA-256:20F9A3BDBE5981EE42E2665623BFE342BFAC18BA7209E889ABDA2FE88AD7EC3D
                                                              SHA-512:961D49A5529F833A03FC3A117EE4379D9AD8F17C2780A42796D9C775577CA31A5CFD4E66C0FDDE6DA3E41AF0E0B2DB655ADAB32E5041107EE31F169FF1C45CFB
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......I.....y...y...y..|...y..~...y..}...y.......y..ix...y..i}...y..iz...y..x...y...x...y..i|...y..ip..y..iy...y..i....y..i{...y.Rich..y.........PE..L...v............"!...&.^/..n........*......p/...............................J.......J...@A.................................]0.......0.`.............I..O...`F.....?..T...........................@4..@............P0.....h|.......................text....\/......^/................. ..`.data...$....p/......b/.............@....idata...T...P0..V....0.............@..@.didat........0......Z0.............@....rsrc...`.....0......^0.............@..@.reloc......`F.......E.............@..B................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):51280
                                                              Entropy (8bit):6.318544681380016
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FB70AD75D602984A07427BB47DF41DFA
                                                              SHA1:38AFD8EA3364670FFA148E8FA0A886D882806B22
                                                              SHA-256:0138CC6A774EAB4AA3745F35F8C1551691892F5C39D9DCFF287B65B02715F74D
                                                              SHA-512:15DC82046276766B1E10B237254184583A37676C4A526123E1D7CB6390A95CD0EC3469FDB4093F16C8676B0EE4876FE41C61D6B67B67C70EF9C2D85B8468AF0A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L................"!...&.....v......................................................K.....@.......................................... ...s...........x..PP..............T............................................................................text...P...........................@..@.rsrc....s... ...t..................@..@...............T...l...l..................l..........................$...,...,...........................RSDSm.....XN.C..yR....D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140CHS.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1...a...rsrc$02.... ...m.....XN.C..yR.8....7...=5...........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):51280
                                                              Entropy (8bit):6.351909249754834
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:074D25DA33A285E836E57B3AD5E9BE03
                                                              SHA1:9AC12AD02F6EB317EB2C1C5538E6A738F573026E
                                                              SHA-256:85B4BEE99F4214F67230AF2A2E456F0F07C22791468F488D6FDCBE6FE168E1AB
                                                              SHA-512:1EE9467379AA7074F1F9B14B44A739E50C650DF79EF17B76F4467A56A3D6A2AD2BE224EDE16331895B047EDE102DEB4E4F3D4A4DCB10A215C47F8D5362B492B8
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L...jZ............"!...&.....v......................................................].....@.......................................... ..8s...........x..PP..............T............................................................................text...P...........................@..@.rsrc...8s... ...t..................@..@....jZ..........T...l...l.......jZ..........l...............jZ..........$...,...,...........................RSDS....=?..ZNf........D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140CHT.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1...a...rsrc$02.... .......=?..ZNf.....,E..(..+*.JjZ..........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):79840
                                                              Entropy (8bit):4.98555855763647
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:AF28BE398C058FF622DFBDFB0925DFB4
                                                              SHA1:E92A9588DF07463A4D1E9AB72AC5FE7D4A12B139
                                                              SHA-256:91E58759C63DFD325C38B25C44395333FFEE3010A19FD43CF0B3A37706180B1F
                                                              SHA-512:6745745B8905E76438012C5C28A149AA5A406B32C07E0E9961B8C54D32768C47FF3521AAED7F0A7D9CBA70835FFA579A98D91D4CE2BD5C6593E30A3733ADAE7C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L....U.........."!...&..................................................................@.......................................... ..0................O..............T............................................................................text...P...........................@..@.rsrc...0.... ......................@..@.....U........T...l...l........U........l................U........$...,...,...........................RSDS........e3.L.....D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140DEU.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1.......rsrc$02.... ...........e3.L...".u........U........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):70224
                                                              Entropy (8bit):5.147993943292643
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:DADB101E49A2CD1F0451AA7762D4B83C
                                                              SHA1:E2DDB718652E3276244F16BE562E07925ED2623A
                                                              SHA-256:5EE1FE1A80A2294DB5719502D1E089B0B18AB202B617157D114039789A9A396E
                                                              SHA-512:C16B9B52B0CB1A0CB127D040681A0381236121BA33EB2DA3AD728109EA79C0B335CAF8FB7912AF050409D0FB5690C959C9113EF26E98FBEA4E9C5BD1173AC8AA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L................."!...&.............................................................^....@.......................................... ..................PP..............T............................................................................text...P...........................@..@.rsrc........ ......................@..@................T...l...l...................l...........................$...,...,...........................RSDS\..V....4O(...n.....D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140ENU.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1..0....rsrc$02.... ...\..V....4O(...n.....d.,t.t..............................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):78816
                                                              Entropy (8bit):4.965207644229018
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:808433A96FD0473B48EE41807E83080B
                                                              SHA1:36B08BA26CCBFDE65C45BD7E145E29EA92B9FC5C
                                                              SHA-256:A9279F19BF76416A7A2BFD9C0642D8652BC55151E0D7467F173470BFD0275CC0
                                                              SHA-512:4508E24519258188F5A4370C980D6F79EE185A20C7CA2180E1DB48A86A1B93CB50B6652080B613EF81D443806756BFEA994746704B6B053A501F4BCD2BE10D8D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L......M.........."!...&............................................................-.....@.......................................... ...................O..............T............................................................................text...P...........................@..@.rsrc........ ......................@..@.......M........T...l...l..........M........l..................M........$...,...,...........................RSDS.....m|.. ..y......D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140ESN.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1..`....rsrc$02.... ........m|.. ..y..4./.t}/.gQM...M........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):79976
                                                              Entropy (8bit):4.976328786867478
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:436171AEF87B307673BCDCB7202DBE97
                                                              SHA1:5E9098546ADBE10C7CED411A64C18343F7280F0E
                                                              SHA-256:7013BF84EDD1B99B705A2FC9FBF78314C9A029EDB77C097F290116C6EC40AD6D
                                                              SHA-512:E0B9D8EAD571175627A02295C1E18B405F75D4F828F5CAC53F7FAE731C438034201B335FEB3B8346C20C55CBAA308E3A1118A0D5BA655F6B83B53E7A1316006C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L....b............"!...&.............................................................U....@.......................................... ..x...............hP..............T............................................................................text...P...........................@..@.rsrc...x.... ......................@..@.....b..........T...l...l........b..........l................b..........$...,...,...........................RSDS...~[......P......D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140FRA.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1.......rsrc$02.... ......~[......P.........`.e$.b..........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):77936
                                                              Entropy (8bit):4.97984716808543
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:EC1A565CC69D83ADD23FE170CF151438
                                                              SHA1:81C76303AEF42002359DBB6F85CDD9CD71E1AD87
                                                              SHA-256:46DD968B20EE4AF1DF54DF26EE71CA4E22FEC3A08A50891FFC9041440AB3B47B
                                                              SHA-512:E025AD07AB96263EE0F99EF6337625F6609AF41AF62BB99DA90528533894C74D6F3DB3ED3870A0E72CED50A156428F01ED2101A6A1E9039D924DDC437CA6ED17
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L....X.........."!...&..................................................................@.......................................... ..X...............pP..............T............................................................................text...P...........................@..@.rsrc...X.... ......................@..@.....X........T...l...l........X........l................X........$...,...,...........................RSDSy.0{.y.P............D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140ITA.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1.......rsrc$02.... ...y.0{.y.P...........\".O.....X........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):58848
                                                              Entropy (8bit):6.147967055664089
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:73E3D2A7CBA6E84F612D7F3983DA672A
                                                              SHA1:F53319BD699998E2267FD0782BD48F187151FFFA
                                                              SHA-256:14321F9C9BA3C2C86CE1AA59D9FD6C9768093384C14DA61F74CE1BA1B85CFBCB
                                                              SHA-512:AE15BFBAB4AFE8D944003DD394A3B12631EA637BCBAF31D50EAF49B246851EEA644ADA90C0F6DE4B62FA24AD0F82F856A0AF32FA5A0D22C95D1C5230EF7C775E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L...s.*..........."!...&.................................................................@.......................................... ...................O..............T............................................................................text...P...........................@..@.rsrc........ ......................@..@....s.*.........T...l...l.......s.*.........l...............s.*.........$...,...,...........................RSDSy.+...Y'.2/.........D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140JPN.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1..p....rsrc$02.... ...y.+...Y'.2/......S..C..@...-s.*.........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):58368
                                                              Entropy (8bit):6.266737380122467
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5BE605895182F3D21CAE9F57747AC7AB
                                                              SHA1:72BF3A00F28A6EB5755A09C80AE06BC69F61EBDC
                                                              SHA-256:7A9B45A779C411F4CD46C91EBE45271D814DDE2F7678B694A8364B11E571EE1D
                                                              SHA-512:F7FE5A3684C541E2AF9979716EC8C9068ED8B656B14BC9B689B2BB639E48355ED4002F1F2BD2A4EC160D9B36AA0E35785831AB624FE3C0FFA54E720F955F103D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L...2............."!...&..................................................................@.......................................... ...................P..............T............................................................................text...P...........................@..@.rsrc........ ......................@..@....2...........T...l...l.......2...........l...............2...........$...,...,...........................RSDS..HE5.&...9-.uH1....D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140KOR.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1...~...rsrc$02.... .....HE5.&...9-.uH1.1...y&....+2...........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):75856
                                                              Entropy (8bit):5.5033560387700735
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A0A589DDE7A2A4FA6097323175FA70F7
                                                              SHA1:E8F3FF09F4F08CEFF009658E7AF2D7ABFDF5DDC0
                                                              SHA-256:7EF466D7D1803DEB0F63E021F58A780385DFAC3F3C286EE2C1E6DBFC5D54A424
                                                              SHA-512:8C921A033C4D3B6874E0C270E2D46154BDF4083087FF179F9750A07E7E7839889A858BB453C39817F72F557F3A50A3AAB753DCA9F17E272A892F49782387A9B6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......}Y=.98S.98S.98S.?...88S.?.Q.88S.Rich98S.................PE..L...vq............"!...&............................................................. ....@.......................................... ..................PP..............T............................................................................text...P...........................@..@.rsrc........ ......................@..@....vq..........T...l...l.......vq..........l...............vq..........$...,...,...........................RSDSl...k;.6a.{2.!!....D:\a\_work\1\s\binaries\x86ret\bin\i386\\MFC140RUS.i386.pdb.........T....rdata..T........rdata$voltmd...l........rdata$zzzdbg.... ..p....rsrc$01....p1.. ....rsrc$02.... ...l...k;.6a.{2.!!.%.(..m....vq..........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):4869496
                                                              Entropy (8bit):7.023063738664024
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:EC9829B23C2E5A7029AC2F9F81924EFA
                                                              SHA1:9B7400EE4282E4655C0CD5F54C41D3AE14095434
                                                              SHA-256:28EB2E4DE14C90B303E13EAFF2E65A4D57E4F5E220BD34CEB858D745A02BDF94
                                                              SHA-512:7B2831CA2CDE03F3F12240AE5F18386BBC1D6DA2B66A550515800E8A1947BC64F077EAF498E63CC3E1CAF39986CFEEB886F43562C0D451D8C54C196F4AF58662
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........W.M.9.M.9.M.9..<.L.9..>.L.9..=.W.9.D...Y.9.Ki8.O.9.Ki=.A.9.Ki:.G.9..8.^.9.M.8..9.Ki<.Z.9.Ki0...9.Ki9.L.9.Ki..L.9.Ki;.L.9.RichM.9.........PE..L...z............."!...&../..p.......*+......./...............................J.....V.J...@A........................P...L.....0......@1.`.............I.xO....F.\.......T............................5..@.............0..............................text...../......./................. ..`.data........./......./.............@....idata..JS....0..T...p0.............@..@.didat.......01.......0.............@....rsrc...`....@1.......0.............@..@.reloc..\.....F......`F.............@..B................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):86640
                                                              Entropy (8bit):6.569726153977617
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:ABF14CC1A720FF3968911F6FD2E6DD7E
                                                              SHA1:175ADE2E220DE9BF6C1595F9FF4A1E910F9B8C99
                                                              SHA-256:B6C3F35ABC2ED9B44CAEFEF8846A26C05D10B3619E298625B4D7891B16D8A539
                                                              SHA-512:AF0C6BEB089365A19181B27AA6C45656F409AFC36E1C76DCDB74DFDE70DFA75C8AD66442C4F94482A0BEBE96CCA4297E58FAABE2E92B77CEF77BBB1A1C538AAE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........qT.}...}...}.......}.../...}.......}.......}.......}.......}.......}...}..~}.......}.......}.......}.......}..Rich.}..........................PE..L.....!..........."!...&.@...........N.......P...............................0............@.........................p.......0...........................pP... ..P...pU..T............................T..@............P..(............R..H............text...U?.......@.................. ..`.rdata..d....P.......D..............@..@.data...L...........................@....rsrc...............................@..@.reloc..P.... ......................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):86608
                                                              Entropy (8bit):6.568249206613143
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F0CE2D4BE2A728B2767E3F5100DDE8CA
                                                              SHA1:124CFABF98D386F47E3D73EBDD4960DFF8B20864
                                                              SHA-256:EEA420619FBDCA1468DFA825E832BA14A21DC0402EBE90E75DDF3903DF4B8C61
                                                              SHA-512:67543A966A31163D78C23BE4B83300F211A23F3B0DB61A6E3707F6106FEC0462C67D1898C8D086A1B7A59F89A0E089140AB163B666A21E9A7311DD0C5F856D7F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........qT.}...}...}.......}.../...}.......}.......}.......}.......}.......}...}..~}.......}.......}.......}.......}..Rich.}..........................PE..L....3.+.........."!...&.@...........N.......P...............................0......t*....@.........................p.......0...........................PP... ..P...pU..T............................T..@............P..(............R..H............text...U?.......@.................. ..`.rdata..d....P.......D..............@..@.data...L...........................@....rsrc...............................@..@.reloc..P.... ......................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):446840
                                                              Entropy (8bit):6.690279428020546
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C766CA0482DFE588576074B9ED467E38
                                                              SHA1:5AC975CCCE81399218AB0DD27A3EFFC5B702005E
                                                              SHA-256:85AA8C8AB4CBF1FF9AE5C7BDE1BF6DA2E18A570E36E2D870B88536B8658C5BA8
                                                              SHA-512:EE36BC949D627B06F11725117D568F9CF1A4D345A939D9B4C46040E96C84159FA741637EF3D73ED2D01DF988DE59A573C3574308731402EB52BAE2329D7BDDAC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........O.$...w...w...w.\.v...w.V@w...w..v...w...w...w..v...w..v...w..vD..w..v...w.,w...w..v...wRich...w........................PE..L....4.w.........."!...&.....z...............0.......................................=....@A.........................S......8c..........................xO.......4...U..T...........................8U..@............`..0............................text...b........................... ..`.data....&...0......................@....idata..0....`.......0..............@..@.rsrc................H..............@..@.reloc...4.......6...L..............@..B........................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):33360
                                                              Entropy (8bit):6.931135692044243
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B262A68778D6117D77DFD88A7F43CA44
                                                              SHA1:839DE1D7BCFB4D91736707194B5F94BFF9285AFC
                                                              SHA-256:A7ED4A417F0C50578F2CA2C5106004DD82F78DD3658A852B37147FC362716667
                                                              SHA-512:4F417D12A86D19773D47BDD50D97BF975EADDF1DBBDFF72EA6EA9BA164E47503CD4BB4FFD9C308567EC1CE0A23C024C24BD8647AAFB68CEC4F747CE668296E28
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........B.I.,.I.,.I.,.-.K.,.@...M.,.OP(.C.,.OP/.H.,.I.-.a.,.OP-.L.,.OP).].,.OP,.H.,.OP..H.,.OP..H.,.RichI.,.................PE..L......+.........."!...&............@........0...............................p.......b....@A.........................*..J....@..x....P...............2..PP...`..x.......T...........................X...@............@...............................text............................... ..`.data........0....... ..............@....idata.......@.......$..............@..@.rsrc........P.......*..............@..@.reloc..x....`......................@..B................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):250880
                                                              Entropy (8bit):6.801697899047771
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:60BF20C3CC7A98169465CD85EE833D67
                                                              SHA1:D562FD487CDBA1EEBAD05D39DF4E143ACD9A50F1
                                                              SHA-256:3EEE52D6389E9F12FA38F71247656C414BA675A96F7FA9987ED598F5963711DB
                                                              SHA-512:D7A7859A86EECAADFDF6F5001595A331F5FDEC16112C5B9B6A314EB55C9EF49966A74F45E4EAA9912B0F2FD76E867C2AAAD4698B396989EB6532AFE53E4E8F67
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........>H..P...P...P.u.Q...P.......P..sT...P..sS...P...Q...P..sQ...P..sU...P..sP...P..s....P..sR...P.Rich..P.................PE..L...~.b.........."!...&.....~............... ......................................q.....@A............................@....Q.......`...................P...p...A...N..T........................... N..@............P...............................text...P........................... ..`.data...H&... ...$..................@....idata..6....P......................@..@.rsrc........`.......>..............@..@.reloc...A...p...B...B..............@..B................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):46672
                                                              Entropy (8bit):6.857457630149837
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C1FF4738F68A0570720F695B5A4837B9
                                                              SHA1:C7BA41BA8049409D2EA5A3B4DABC2499837CD60F
                                                              SHA-256:1B940CE6E0791B41538F475FF97FCD04156C2CAB924557199B57736D7EA510D5
                                                              SHA-512:EDB1FD8EFB8B45474F43472A88A404329C0E756E1EFD9F3FB1EF2C800CDF64BA705CC7A339650CF0E2978E8D38FE42A16CCC86FAAF6630986E3E2E01BB03E632
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........u.:...i...i...iJf.h...i.l.i...i...h...i...h...i...i...i...h...i...h...i...h...i..ei...i...h...iRich...i................PE..L....9..........."!...&.J.......... E.......`............................... ............@A........................`S..D............................f..PP......\.......T...............................@............................................text....H.......J.................. ..`.data...<....`.......N..............@....idata...............P..............@..@.rsrc................Z..............@..@.reloc..\............`..............@..B................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):30288
                                                              Entropy (8bit):6.991930067735414
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D90414F90993F195846C25140D47566B
                                                              SHA1:3D3EF684D63BC62EEF8CBE09EAF0EE88159FC17C
                                                              SHA-256:AF5645D93635823702F00E12C0C8D68EEA5D2F20EDCEBFDCF5E076E50A9CB64A
                                                              SHA-512:BD4D3E4681D766449F743A924783154A5916A85FFB72F2F0EF43EBBF8380869D58CED6F56E31534F8B70FEBD4EF5DE47A9B1760478966C5D26ACCD7173FDE45F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......A..[.....................\......i...............i.......i.......i.......i.......i0......i......Rich............PE..L.....8.........."!...&............@........0...............................p.......=....@A........................."../...p@..P....P...............&..PP...`..L.......T...........................H...@............@..h............................text............................... ..`.data........0......................@....idata..x....@......................@..@.rsrc........P......................@..@.reloc..L....`.......$..............@..B........................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):364656
                                                              Entropy (8bit):6.4963913214508
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6FAC04851CDA0F5F63714F3BDB7B17B8
                                                              SHA1:FF48AA1E6F53C21966AA55219C9BB168139599BF
                                                              SHA-256:8C94D1F200CCFA079EDD1993BDD355BC994F19D7889E46EB2D87B547BBE17AC9
                                                              SHA-512:8B182D6CC1C8E1B165CA1A06019244F3FEBCA47E47FFDE59DAFC44FE48D01915E845BB9ED0F445A40BAB634400BAB78FEA9521FC42CA9F30FF996E6AF673A6DE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......k.../.w./.w./.w.&..#.w.)3v.).w.)3r.2.w.)3s.$.w.)3t.'.w...v.".w./.v...w.)3~.#.w.)3w...w.)3....w./....w.)3u...w.Rich/.w.........PE..L....i.M.........."!...&............`).......................................p............@A.........................m..47......@.......8$...........@..pP...0...>...h..T....................i.......g..@...............x............................text.............................. ..`.data...L+.......(..................@....idata..............................@..@.rsrc...8$.......&..................@..@.reloc...>...0...@..................@..B........................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):285296
                                                              Entropy (8bit):6.61257647545177
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:934C75ADFF9036378FD34F526C6641A1
                                                              SHA1:0B9572EBE4FC49EF2DEF824327EFCAF9C9B90DAF
                                                              SHA-256:B4652ED190EEBF59D4CA8BB340CADFBCFBB7A32ABB893D57AC49B1F22CFA0861
                                                              SHA-512:A00B1BF0F10437A680C332E2FCE287C194B3CF666E985ACF047CEBE755596B15F99BAD5252B6A2244AE8805E24218ACA2A898E63C28CCF515D75232410ADD6E2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........s...........j&........................N`......................J.........Rich....................PE..L...~..w.........."!...&.*.......... ........@...............................@......=.....@A........................p....=..............................pP......xY.. K..T...........................`J..@............................................text....).......*.................. ..`.data....p...@...n..................@....idata..............................@..@.rsrc...............................@..@.reloc..xY.......Z..................@..B........................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):161904
                                                              Entropy (8bit):6.7450593736078766
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1BB877A36D2FCF866A79433D318A38C7
                                                              SHA1:ADF05679B78D0B15342CDFB4B5FA03C6FD7A140B
                                                              SHA-256:2FA5C0FA42036A1891A4824C41842869820BA6251D9BA39631B2F41636CC474F
                                                              SHA-512:B89BBCEBF968FD8D8038C4D61664ABF0AEDA77D15C1E8DD7083347272A1BBB22178A5DC6EFC20D428A38A7625B702C9BEE922A10C3BDE3F20A2DD043506152EF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........3.5.R.f.R.f.R.fX .g.R.fX .g.R.fX .g.R.f..g.R.f..g.R.f..g.R.fX .g.R.f.R.f.R.f..g.R.f..g.R.f..hf.R.f..g.R.fRich.R.f........................PE..L.....'..........."!...&.....L...............................................p......Z.....@......................... .......`!..(....0...............(..pP...P..L....p..T...........................Po..@............ ..X............................text............................... ..`.data...T...........................@....idata..$.... ......................@..@.rsrc........0......................@..@.reloc..L....P......................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):91104
                                                              Entropy (8bit):6.919609919273454
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9C133B18FA9ED96E1AEB2DA66E4A4F2B
                                                              SHA1:238D34DBD80501B580587E330D4405505D5E80F2
                                                              SHA-256:C7D9DFDDBE68CF7C6F0B595690E31A26DF4780F465D2B90B5F400F2D8D788512
                                                              SHA-512:D2D588F9940E7E623022ADEBEBDC5AF68421A8C1024177189D11DF45481D7BFED16400958E67454C84BA97F0020DA559A8DAE2EC41950DC07E629B0FD4752E2F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......................2........I..............o.......o.......o.......o.......o%......o......Rich............PE..L....s............"!...&............P........................................P...........@A........................@........ .......0...................O...@.......$..T............................#..@............ ...............................text...T........................... ..`.data...d...........................@....idata....... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):35920
                                                              Entropy (8bit):6.96589440050578
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:888FB15A3D5B671D0557B2D25A7EA1E7
                                                              SHA1:8F7FC210E96CB8BF5F4902B87495D6D9903A3E45
                                                              SHA-256:0ADC89F01F9719C26A1A6176690C2CA8E5E1FF8339A4B140E4260BA3D6AE78A6
                                                              SHA-512:E17CB660575A1B76637B50B63279BE2DFCF8B96E425E5572B73EF191497B0308408FDD6BF3D7849C52978E22C1763F05569774C4A6C8147ADB520B45360DFF63
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......-.&ki.H8i.H8i.H8..I9k.H8o.I9k.H8`..8n.H8i.I8U.H8o.L9b.H8o.K9j.H8o.M9b.H8o.H9h.H8o..8h.H8o.J9h.H8Richi.H8........................PE..L...u!............"!...&.&...........'.......@............................................@A.........................1.......P..x....`...............<..PP...p..D.......T...............................@............P...............................text...D$.......&.................. ..`.data........@.......*..............@....idata.......P.......,..............@..@.rsrc........`.......4..............@..@.reloc..D....p.......8..............@..B........................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):18415
                                                              Entropy (8bit):4.043868285184243
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:2B063D92663595DFE4781AE687A03D86
                                                              SHA1:0FB582E756DBC751EA380593AC4DA27DDB4EBB06
                                                              SHA-256:44C76290F7A2E45940E8338912FEB49BCF4E071CFA85D2D34762857743ACBC8D
                                                              SHA-512:94C8FDA6173C7F5740F206190EDCD1F1F1C309596B710D400E23CD363A619D707A5D4576D4FE63AB7CB68947F009EFD29A1FBE04743A294698BF2AE17E92C214
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset134 SimSun;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 MICROSOFT \f1\'dc\'9b\'f3\'77\'ca\'da\'99\'e0\'97\'6c\'bf\'ee\f0\par..MICROSOFT VISUAL C++ 2015 - 2022 \f1\'88\'cc\'d0\'d0\'eb\'41\'b6\'ce\f0 \par..\b0\f1\'b1\'be\'ca\'da\'99\'e0\'97\'6c\'bf\'ee\'ca\'c7\'d9\'46\'d3\'c3\'91\'f4\'c5\'63\f0 Microsoft Corporation (\f1\'bb\'f2\'c6\'e4\'ea\'50\'82\'53\'c6\'f3\'98\'49\'a3\'ac\'d2\'95\'d9\'46\'d3\'c3\'91\'f4\'cb\'f9\'be\'d3\'d7\'a1\'b5\'c4\'b5\'d8\'fc\'63\'b6\'f8\'b6\'a8\f0 ) \f1\'d6\'ae\'e9\'67\'b3\'c9\'c1\'a2\'b5\'c4\'ba\'cf\'bc\'73\'a1\'a3\'cb\'fc\'82\'83\'df\'6d\'d3\'c3\'ec\'b6\'c9\'cf\'ca\'f6\'dc\'9b\'f3\'77\'a1\'a3\'b1\'be\'ca\'da\'99\'e0\'97\'6c\'bf\'ee\'d2\'e0\'df\'6d\'d3\'c3\'ec\'b6\'c8\'ce\'ba\'ce\f0 Microsoft \f1\'b7\'fe\'84\'d5\
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2980
                                                              Entropy (8bit):6.163758160900388
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:472ABBEDCBAD24DBA5B5F5E8D02C340F
                                                              SHA1:974F62B5C2E149C3879DD16E5A9DBB9406C3DB85
                                                              SHA-256:8E2E660DFB66CB453E17F1B6991799678B1C8B350A55F9EBE2BA0028018A15AD
                                                              SHA-512:676E29378AAED25DE6008D213EFA10D1F5AAD107833E218D71F697E728B7B5B57DE42E7A910F121948D7B1B47AB4F7AE63F71196C747E8AE2B4827F754FC2699
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">[WixBundleName] ....</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">....</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [directory] - ................. ......................../passive | /quiet - .... UI ........... UI.... ........... UI ........../norestart - ................UI ............./log log.txt - .........
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):13234
                                                              Entropy (8bit):5.125368352290407
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E7DC9CA9474A13FA4529D91BCD2AB8CC
                                                              SHA1:511F5DE8A99C09EC3766C5E2494A79EACCA261C8
                                                              SHA-256:503C433DCDE2F3A9E7D388A5FF2B0612E7D8F90F5188D5B2B60228DB33044FDE
                                                              SHA-512:77108E53CD58E42F847D8EF23A07723C4849DC41DBE1C3EF939B9170E75F525BEC9D210D6C1FBFEB330ECE2E77B8A8E2808730D9E6F72F5B3FE626D58B6068C6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset238 Tahoma;}{\f2\fnil\fcharset0 Garamond;}{\f3\fnil Tahoma;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 LICEN\f1\'c8N\f0\'cd PODM\'cdNKY PRO SOFTWARE SPOLE\f1\'c8NOSTI MICROSOFT\par..\f0 MICROSOFT VISUAL C++ 2015 - 2022 RUNTIME \par..\b0 Tyto licen\f1\'e8n\f0\'ed podm\'ednky p\f1\'f8edstavuj\f0\'ed smlouvu mezi spole\f1\'e8nost\f0\'ed Microsoft Corporation (nebo n\f1\'eckterou z jej\f0\'edch afilac\'ed, v\~z\'e1vislosti na tom, kde bydl\'edte) a v\'e1mi. Vztahuj\'ed se na v\'fd\f1\'9ae uveden\f0\'fd software. Podm\'ednky se rovn\f1\'ec\'9e vztahuj\f0\'ed na jak\'e9koli slu\f1\'9eby Microsoft nebo aktualizace pro software, pokud se na slu\'9eby nebo aktualizace nevztahuj\f0\'ed odli\f1\'9an\f0\'e9 podm\'ednky.\par..\b DODR\f1\'8e\f0\'cdTE-LI
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3333
                                                              Entropy (8bit):5.370651462060085
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:16343005D29EC431891B02F048C7F581
                                                              SHA1:85A14C40C482D9351271F6119D272D19407C3CE9
                                                              SHA-256:07FB3EC174F25DFBE532D9D739234D9DFDA8E9D34F01FE660C5B4D56989FA779
                                                              SHA-512:FF1AE9C21DCFB018DD4EC82A6D43362CB8C591E21F45DD1C25955D83D328B57C8D454BBE33FBC73A70DADF1DFB3AE27502C9B3A8A3FF2DA97085CA0D9A68AB03
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">Instala.n. program [WixBundleName]</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Opravdu chcete akci zru.it?</String>.. <String Id="HelpHeader">N.pov.da nastaven.</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [adres..] . Nainstaluje, oprav., odinstaluje nebo.. vytvo.. .plnou m.stn. kopii svazku v adres..i. V.choz. mo.nost. je instalace...../passive | /quiet . Zobraz. minim.ln. u.ivatelsk. rozhran. bez v.zev nebo nezobraz. ..dn. u.ivatelsk. rozhran. a.. ..dn. v.zvy. V.choz. mo.nost. je zobrazen. u.ivatelsk.ho rozhran. a v.ech v.zev...../noresta
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):12392
                                                              Entropy (8bit):5.192979871787938
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:2DDCA2866D76C850F68ACDFDB696D6DE
                                                              SHA1:C5076F10B0F0654CDE2C990DEEB2772F3CC4844B
                                                              SHA-256:28F63BAD9C2960395106011761993049546607F8A850D344D6A54042176BF03F
                                                              SHA-512:E3A3693B92873E0B42007616FF6916304EDC5C4F2EEE3E9276F87E86DD94C2BF6E1CF4E895CDF9A1AA0CAC0B381B8840EEE1F491123E901DEE75638B8BC5CE1B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Garamond;}{\f2\fnil Tahoma;}{\f3\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 MICROSOFT-SOFTWARE-LIZENZBEDINGUNGEN\par..MICROSOFT VISUAL C++ 2015 - 2022 RUNTIME \par..\b0 Diese Lizenzbestimmungen stellen eine Vereinbarung zwischen Ihnen und der Microsoft Corporation (bzw. abh\'e4ngig von Ihrem Wohnsitz einem ihrer Affiliate-Partner) dar. Sie gelten f\'fcr die oben angef\'fchrte Software. Die Bestimmungen gelten ebenso f\'fcr jegliche von Microsoft angebotenen Dienste oder Updates f\'fcr die Software, sofern diesen keine anderen Bestimmungen beiliegen.\par..\b WENN SIE DIESE LIZENZBESTIMMUNGEN EINHALTEN, VERF\'dcGEN SIE \'dcBER DIE NACHFOLGEND AUFGEF\'dcHRTEN RECHTE.\par....\pard{\pntext\f3\'B7\tab}{\*\pn\pnlvlblt\pnf3\pnindent360{\pntxtb\'B7}}\
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3379
                                                              Entropy (8bit):5.094097800535488
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:561F3F32DB2453647D1992D4D932E872
                                                              SHA1:109548642FB7C5CC0159BEDDBCF7752B12B264C0
                                                              SHA-256:8E0DCA6E085744BFCBFF46F7DCBCFA6FBD722DFA52013EE8CEEAF682D7509581
                                                              SHA-512:CEF8C80BEF8F88208E0751305DF519C3D2F1C84351A71098DC73392EC06CB61A4ACA35182A0822CF6934E8EE42196E2BCFE810CC859965A9F6F393858A1242DF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">[WixBundleName] - Setup</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">M.chten Sie den Vorgang wirklich abbrechen?</String>.. <String Id="HelpHeader">Setup-Hilfe</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [Verzeichnis] - installiert, repariert, deinstalliert oder.. erstellt eine vollst.ndige lokale Kopie des Bundles im Verzeichnis. Installieren ist die Standardeinstellung...../passive | /quiet - zeigt eine minimale Benutzeroberfl.che ohne Eingabeaufforderungen oder keine.. Benutzeroberfl.che und keine Eingabeaufforderungen an. Standardm..ig werden die Benutzeroberfl.che und alle Eingab
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):12349
                                                              Entropy (8bit):5.108676965693909
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A6E352E5804313CCDE3E4D5DDDDE122D
                                                              SHA1:834E3AAA07DC675589A9E5FCD23CE5586C2739E8
                                                              SHA-256:5C13A65870D770D1642A4259EECB436257CA39016A0500F747BE9C79BE0C7009
                                                              SHA-512:6578AC6467F61930BC1B20E404441725C63790C65AEC1ACE297429EAD15F50E68D5FE9CC1451AC86AE23DC1A7FE967650166293010D687785FB81FB4492B87C4
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\fbidis\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil Tahoma;}{\f2\fnil\fcharset0 Garamond;}{\f3\fnil\fcharset177 Tahoma;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\ltrpar\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 TERMES DU CONTRAT DE LICENCE LOGICIEL MICROSOFT\par..MICROSOFT VISUAL C++ 2015 - 2022 RUNTIME \par..\b0 Les pr\'e9sentes conditions de licence constituent un contrat entre Microsoft Corporation (ou en fonction de votre lieu de r\'e9sidence, l\f1\rquote\f0 un de ses affili\'e9s) et vous. Ils s\f1\rquote\f0 appliquent au logiciel vis\'e9 ci-dessus. Les termes s\f1\rquote\f0 appliquent \'e9galement \'e0 tout service et \'e0 toute mise \'e0 jour Microsoft pour ce logiciel, \'e0 moins que d\f1\rquote\f0 autres termes n\f1\rquote\f0 accompagnent ces \'e9l\'e9ments.\par..\b SI VOUS VOUS CONFORMEZ AUX PR\'c9SENTS TERMES DU CONTRAT D
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3366
                                                              Entropy (8bit):5.0912204406356905
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7B46AE8698459830A0F9116BC27DE7DF
                                                              SHA1:D9BB14D483B88996A591392AE03E245CAE19C6C3
                                                              SHA-256:704DDF2E60C1F292BE95C7C79EE48FE8BA8534CEB7CCF9A9EA68B1AD788AE9D4
                                                              SHA-512:FC536DFADBCD81B42F611AC996059A6264E36ECF72A4AEE7D1E37B87AEFED290CC5251C09B68ED0C8719F655B163AD0782ACD8CE6332ED4AB4046C12D8E6DBF6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">Installation de [WixBundleName]</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Voulez-vous vraiment annuler.?</String>.. <String Id="HelpHeader">Aide du programme d'installation</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [directory] - installe, r.pare, d.sinstalle ou.. cr.e une copie locale compl.te du groupe dans le r.pertoire. Install est l'option par d.faut...../passive | /quiet - affiche une interface minimale, sans invite, ou n'affiche ni interface.. ni invite. Par d.faut, l'interface et toutes les invites sont affich.es...../norestart - supprime toutes les tentatives de red.
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):11440
                                                              Entropy (8bit):5.037988271709582
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:BC58AD6ABB16B982AEBADC121B37E706
                                                              SHA1:25E3E4127A643DB5DB2A0B62B02DE871359FAE42
                                                              SHA-256:70ECF23C03B66A2B18E173332586AFA8F00F91E02A80628F4F9CB2521E27F6AC
                                                              SHA-512:8340452CB5E196CB1D5DA6DBB3FA8872E519D7903A05331055370B4850D912674F0B6AF3D6E4F94248FE8135EB378EB36969821D711FE1624A04AF13BBE55D70
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Garamond;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 CONDIZIONI DI LICENZA SOFTWARE MICROSOFT\par..RUNTIME MICROSOFT VISUAL C++ 2015 - 2022 \par..\b0 Le presenti condizioni di licenza costituiscono il contratto tra Microsoft Corporation (o, in base al luogo di residenza del licenziatario, una delle sue consociate) e il licenziatario. Tali condizioni si applicano al software Microsoft di cui sopra. Le condizioni si applicano inoltre a qualsiasi servizio o aggiornamento di Microsoft relativo al software, tranne se accompagnato da condizioni differenti.\par..\b QUALORA IL LICENZIATARIO SI ATTENGA ALLE PRESENTI CONDIZIONI DI LICENZA, DISPORR\'c0 DEI DIRITTI INDICATI DI SEGUITO.\par....\pard{\pntext\f2\'B7\tab}{\*\pn\pnlvlblt\pnf2\pnindent360
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3319
                                                              Entropy (8bit):5.019774955491369
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D90BC60FA15299925986A52861B8E5D5
                                                              SHA1:FADFCA9AB91B1AB4BD7F76132F712357BD6DB760
                                                              SHA-256:0C57F40CC2091554307AA8A7C35DD38E4596E9513E9EFAE00AC30498EF4E9BC2
                                                              SHA-512:11764D0E9F286B5AA7B1A9601170833E462A93A1E569A032FCBA9879174305582BD42794D4131B83FBCFBF1CF868A8D5382B11A4BD21F0F7D9B2E87E3C708C3F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">Installazione di [WixBundleName]</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Annullare?</String>.. <String Id="HelpHeader">Guida alla configurazione</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [directory] - installa, ripara, disinstalla o.. crea una copia locale completa del bundle nella directory. L'opzione predefinita . Install...../passive | /quiet - visualizza un'interfaccia utente minima senza prompt oppure non visualizza alcuna interfaccia utente.. n. prompt. Per impostazione predefinita viene visualizzata l'intera interfaccia utente e tutti i prompt...../norestart - annulla quals
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):30228
                                                              Entropy (8bit):3.785116198512527
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:47C315C54B6F2078875119FA7A718499
                                                              SHA1:F650DDB5DF2AF2EE7555C410D034B37B9DFD055B
                                                              SHA-256:C3061A334BFD5F02B7085F8F454D5D3D97D477AF14BAB497BF31A7887BC90C5B
                                                              SHA-512:A0E4B0FCCCFDD93BAF133C2080403E8719E4A6984237F751BD883C0D3C52D818EFD00F8BA7726A2F645F66286305599403470F14D39EEDC526DDE59228A5F261
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset128 MS PGothic;}{\f1\fnil\fcharset0 Tahoma;}{\f2\fnil\fcharset134 SimSun;}{\f3\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9\'83\'7d\'83\'43\'83\'4e\'83\'8d\'83\'5c\'83\'74\'83\'67\f1 \f0\'83\'5c\'83\'74\'83\'67\'83\'45\'83\'46\'83\'41\f1 \f0\'83\'89\'83\'43\'83\'5a\'83\'93\'83\'58\'8f\'f0\'8d\'80\f1\par..MICROSOFT VISUAL C++ 2015 - 2022 \f0\'83\'89\'83\'93\'83\'5e\'83\'43\'83\'80\f1\par..\b0\f0\'96\'7b\'83\'89\'83\'43\'83\'5a\'83\'93\'83\'58\'8f\'f0\'8d\'80\'82\'cd\f2\'a1\'a2\f1 Microsoft Corporation\f2\'a3\'a8\f0\'82\'dc\'82\'bd\'82\'cd\'82\'a8\'8b\'71\'97\'6c\'82\'cc\'8f\'8a\'8d\'dd\'92\'6e\'82\'c9\'89\'9e\'82\'b6\'82\'bd\'8a\'d6\'98\'41\'89\'ef\'8e\'d0\f2\'a3\'a9\f0\'82\'c6\'82\'a8\'8b\'71\'97\'6c\'82\'c6\'82\'cc\'8c\'5f\'96\'f1\'82\'f0\'8d\'5c\'90\'ac\'82\'b5\'82\'dc\'82\'b7\f2\'a1\'a3\'b
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3959
                                                              Entropy (8bit):5.955167044943003
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:DC81ED54FD28FC6DB6F139C8DA1BDED6
                                                              SHA1:9C719C32844F78AAE523ADB8EE42A54D019C2B05
                                                              SHA-256:6B9BBF90D75CFA7D943F036C01602945FE2FA786C6173E22ACB7AFE18375C7EA
                                                              SHA-512:FD759C42C7740EE9B42EA910D66B0FA3F813600FD29D074BB592E5E12F5EC09DB6B529680E54F7943821CEFE84CE155A151B89A355D99C25A920BF8F254AA008
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.. <Control Control="InstallButton" X="275" Y="237" Width="110" Height="23"/>.. <Control Control="UninstallButton" X="270" Y="237" Width="120" Height="23"/>.. <Control Control="RepairButton" X="187" Y="237" Width="80" Height="23"/>.. .. <String Id="Caption">[WixBundleName] .......</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">..........</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [directory] - ............ ......... .........................
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):28393
                                                              Entropy (8bit):3.874126830110936
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:641D926354F001034CF3F2F3B0FF33DC
                                                              SHA1:5505107FFF6CF279769A82510276F61EA18637AE
                                                              SHA-256:3D4E9C165CBEAB829D608106F0E96450F839FFA8ADBD755F0B51867E89DA2AE0
                                                              SHA-512:B0339664434B096ABC26D600F7657919EF3689B4E0FDFD4EDD8E479859A51EF51BE8F05FA43E25567FFD6C1C2BCC6EF0D7A857B6D666D264C7783BAD3A383D0E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset129 Malgun Gothic;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 MICROSOFT \f1\'bc\'d2\'c7\'c1\'c6\'ae\'bf\'fe\'be\'ee\f0 \f1\'b6\'f3\'c0\'cc\'bc\'b1\'bd\'ba\f0 \f1\'b0\'e8\'be\'e0\'bc\'ad\f0\par..MICROSOFT VISUAL C++ 2015 - 2022 \f1\'b7\'b1\'c5\'b8\'c0\'d3\f0 \par..\b0\f1\'ba\'bb\f0 \f1\'b6\'f3\'c0\'cc\'bc\'b1\'bd\'ba\f0 \f1\'b0\'e8\'be\'e0\'c0\'ba\f0 Microsoft Corporation(\f1\'b6\'c7\'b4\'c2\f0 \f1\'b0\'c5\'c1\'d6\f0 \f1\'c1\'f6\'bf\'aa\'bf\'a1\f0 \f1\'b5\'fb\'b6\'f3\f0 \f1\'b0\'e8\'bf\'ad\'bb\'e7\f0 \f1\'c1\'df\f0 \f1\'c7\'cf\'b3\'aa\f0 )\f1\'b0\'fa\f0 \f1\'b1\'cd\'c7\'cf\f0 \f1\'b0\'a3\'bf\'a1\f0 \f1\'c3\'bc\'b0\'e1\'b5\'c7\'b4\'c2\f0 \f1\'b0\'e8\'be\'e0\'c0\'d4\'b4\'cf\'b4\'d9\f0 . \f1\'ba\'bb\f0 \f1\'b6\'f3\'c0\'cc\'bc\'b1\'bd\'ba\f0 \f1\'
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3249
                                                              Entropy (8bit):5.985100495461761
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B3399648C2F30930487F20B50378CEC1
                                                              SHA1:CA7BDAB3BFEF89F6FA3C4AAF39A165D14069FC3D
                                                              SHA-256:AD7608B87A7135F408ABF54A897A0F0920080F76013314B00D301D6264AE90B2
                                                              SHA-512:C5B0ECF11F6DADF2E68BC3AA29CC8B24C0158DAE61FE488042D1105341773166C9EBABE43B2AF691AD4D4B458BF4A4BF9689C5722C536439CA3CDC84C0825965
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">[WixBundleName] .. ....</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">........?</String>.. <String Id="HelpHeader">.. ...</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [directory] - ..... ... .. .. .... .., .., .. .... ...... ... .........../passive | /quiet - .... .. .. UI. ..... UI ... ..... .... ..... ..... UI. .. ..... ........../norestart - .. .... .. .... ...
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):13352
                                                              Entropy (8bit):5.359561719031494
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F140FD8CA2C63A861D04310257C1B1DB
                                                              SHA1:7BF7EF763A1F80ECACA692908F8F0790A88C3CA1
                                                              SHA-256:6F94A99072061012C5626A6DD069809EC841D6E3102B48394D522A0C2E3AA2B5
                                                              SHA-512:A0BD65AF13CC11E41E5021DF0399E5D21B340EF6C9BBE9B1B56A1766F609CEB031F550A7A0439264B10D67A76A6403E41ABA49B3C9E347CAEDFE9AF0C5BE1EE6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset238 Tahoma;}{\f2\fnil\fcharset0 Garamond;}{\f3\fnil Tahoma;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 POSTANOWIENIA LICENCYJNE DOTYCZ\f1\'a5CE OPROGRAMOWANIA MICROSOFT\par..\f0 MICROSOFT VISUAL C++ \f1\'8cRODOWISKO URUCHOMIENIOWE 2015-2022 \par..\b0\f0 Niniejsze postanowienia licencyjne stanowi\f1\'b9 umow\'ea mi\'eadzy Microsoft Corporation (lub, w zale\'bfno\'9cci od miejsca zamieszkania Licencjobiorcy, jednym z podmiot\f0\'f3w stowarzyszonych Microsoft Corporation) a Licencjobiorc\f1\'b9. Postanowienia te dotycz\'b9 oprogramowania okre\'9clonego powy\'bfej. Niniejsze postanowienia maj\'b9 r\f0\'f3wnie\f1\'bf zastosowanie do wszelkich us\'b3ug i aktualizacji Microsoft dla niniejszego oprogramowania, z wyj\'b9tkiem tych, kt\f0\'f3rym tow
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3212
                                                              Entropy (8bit):5.268378763359481
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:15172EAF5C2C2E2B008DE04A250A62A1
                                                              SHA1:ED60F870C473EE87DF39D1584880D964796E6888
                                                              SHA-256:440B309FCDF61FFC03B269FE3815C60CB52C6AE3FC6ACAD14EAC04D057B6D6EA
                                                              SHA-512:48AA89CF4A0B64FF4DCB82E372A01DFF423C12111D35A4D27B6D8DD793FFDE130E0037AB5E4477818A0939F61F7DB25295E4271B8B03F209D8F498169B1F9BAE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">Instalator [WixBundleName]</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Czy na pewno chcesz anulowa.?</String>.. <String Id="HelpHeader">Instalator . Pomoc</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [katalog] - Instaluje, naprawia, odinstalowuje.. lub tworzy pe.n. lokaln. kopi. pakietu w katalogu. Domy.lnie jest u.ywany prze..cznik install...../passive | /quiet - Wy.wietla ograniczony interfejs u.ytkownika bez monit.w albo nie wy.wietla ani interfejsu u.ytkownika,.. ani monit.w. Domy.lnie jest wy.wietlany interfejs u.ytkownika oraz wszystkie monity...../norestart - Pom
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):10956
                                                              Entropy (8bit):5.086757849952268
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9A8D2ACF07F3C01E5CBC461AB932D85B
                                                              SHA1:8781A298DCC14C18C6F6DB58B64F50B2FC6E338E
                                                              SHA-256:27891EEC899BE859E3B4D3B29247FC6B535D7E836DEF0329111C48741EC6E701
                                                              SHA-512:A60262A0C18E3BEF7C6D52F242153EBE891F676ED639F2DACFEBBAC86E70EEBF58AA95A7FE1A16E15A553C1BD3ECACCD8677EB9D2761CB79CB9A342C9B4252E2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Garamond;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 TERMOS DE LICEN\'c7A PARA SOFTWARE MICROSOFT\par..TEMPO DE EXECU\'c7\'c3O DO MICROSOFT VISUAL C++ 2015 - 2022 \par..\b0 Os presentes termos de licen\'e7a constituem um contrato firmado entre a Microsoft Corporation (ou, dependendo do local no qual voc\'ea esteja domiciliado, uma de suas afiliadas) e voc\'ea. Eles se aplicam ao software indicado acima. Os termos tamb\'e9m se aplicam a quaisquer servi\'e7os ou atualiza\'e7\'f5es da Microsoft para o software, exceto at\'e9 a extens\'e3o de que eles tenham termos diferentes.\par..\b SE VOC\'ca CONCORDAR COM ESTES TERMOS DE LICEN\'c7A, TER\'c1 OS DIREITOS INDICADOS ABAIXO.\par....\pard{\pntext\f2\'B7\tab}{\*\pn\pnlvlblt\pnf2\pnindent360{\pn
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3095
                                                              Entropy (8bit):5.150868216959352
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:BE27B98E086D2B8068B16DBF43E18D50
                                                              SHA1:6FAF34A36C8D9DE55650D0466563852552927603
                                                              SHA-256:F52B54A0E0D0E8F12CBA9823D88E9FD6822B669074DD1DC69DAD6553F7CB8913
                                                              SHA-512:3B7C773EF72D40A8B123FDB8FC11C4F354A3B152CF6D247F02E494B0770C28483392C76F3C222E3719CF500FE98F535014192ACDDD2ED9EF971718EA3EC0A73E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">[WixBundleName] Instala..o</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Tem certeza de que deseja cancelar?</String>.. <String Id="HelpHeader">Ajuda da Instala..o</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [diret.rio - instala, repara, desinstala ou.. cria uma c.pia local completa do pacote no diret.rio. Install . o padr.o..../passive | /quiet - exibe a IU m.nima sem nenhum prompt ou n.o exibe nenhuma IU e.. nenhum prompt. Por padr.o, a IU e todos os prompts s.o exibidos...../norestart - suprime qualquer tentativa de reiniciar. Por padr.o, a IU perguntar. antes de reiniciar
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):31981
                                                              Entropy (8bit):3.6408688850128446
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:62229BE4447C349DF353C5D56372D64B
                                                              SHA1:989799ED24913A0E6AE2546EE2A9A8D556E1CB3B
                                                              SHA-256:1BB3FB55B8A13FA3BAFFFE72F5B1ED8B57A63BD4D8654BB6DC5B9011CE803B44
                                                              SHA-512:FA366328C3FD4F683FDB1C5A64F5D554DE79620331086E8B4CCC2BFC2595B1FDED02CEC8AA982FCD8B13CC175D222AF2D7E2CD1A33B52F36AFD692B533FDBF13
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset204 Tahoma;}{\f1\fnil Tahoma;}{\f2\fnil\fcharset0 Tahoma;}{\f3\fnil\fcharset204 Garamond;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang1049\'d3\'d1\'cb\'ce\'c2\'c8\'df \'cb\'c8\'d6\'c5\'cd\'c7\'c8\'c8 \'cd\'c0 \'cf\'d0\'ce\'c3\'d0\'c0\'cc\'cc\'cd\'ce\'c5 \'ce\'c1\'c5\'d1\'cf\'c5\'d7\'c5\'cd\'c8\'c5 MICROSOFT\par..\'d1\'d0\'c5\'c4\'c0 \'c2\'db\'cf\'ce\'cb\'cd\'c5\'cd\'c8\'df MICROSOFT VISUAL C++ 2015\f1\endash\f2 2022 \par..\b0\f0\'cd\'e0\'f1\'f2\'ee\'ff\'f9\'e8\'e5 \'f3\'f1\'eb\'ee\'e2\'e8\'ff \'eb\'e8\'f6\'e5\'ed\'e7\'e8\'e8 \'ff\'e2\'eb\'ff\'fe\'f2\'f1\'ff \'f1\'ee\'e3\'eb\'e0\'f8\'e5\'ed\'e8\'e5\'ec \'ec\'e5\'e6\'e4\'f3 \'ea\'ee\'f0\'ef\'ee\'f0\'e0\'f6\'e8\'e5\'e9 Microsoft (\'e8\'eb\'e8, \'e2 \'e7\'e0\'e2\'e8\'f1\'e8\'ec\'ee\'f1\'f2\'e8 \'ee\'f2 \'ec\'e5\'f1\'f2\'e0
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):4150
                                                              Entropy (8bit):5.444436038992627
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:17C652452E5EE930A7F1E5E312C17324
                                                              SHA1:59F3308B87143D8EA0EA319A1F1A1F5DA5759DD3
                                                              SHA-256:7333BC8E52548821D82B53DBD7D7C4AA1703C85155480CB83CEFD78380C95661
                                                              SHA-512:53FD207B96D6BCF0A442E2D90B92E26CBB3ECC6ED71B753A416730E8067E831E9EB32981A9E9368C4CCA16AFBCB2051483FDCFC474EA8F0D652FCA934634FBE8
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.. <Control Control="InstallButton" X="275" Y="237" Width="110" Height="23"/>.... <String Id="Caption">......... ......... [WixBundleName]</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">........?</String>.. <String Id="HelpHeader">....... .. .........</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [.......] - ........., .............., ........ ..... ........ ...... ......... ..... ...... . ......... .. ......... - ............../passive | /quiet - ........... ....
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):13807
                                                              Entropy (8bit):5.2077828423114045
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9625F3A496DBF5E3E0D2F33D417EDBBF
                                                              SHA1:119376730428812A31B70D58C873866D5307A775
                                                              SHA-256:F80926604E503697247353F56856B31DE0B3FC1319F1C94068363952549CC9B1
                                                              SHA-512:DB91A14FC27E3A62324E024DD44E3B5548AF7E1C021201C3D851BD2F32537885AACFC64ADAE619BAC31B60229D1D5FC653F5301CD7187C69BD0ACECCE817D6A3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset238 Tahoma;}{\f2\fnil\fcharset238 Garamond;}{\f3\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 MICROSOFT YAZILIMI L\f1\u304?SANS KO\'aaULLARI\par..\f0 MICROSOFT VISUAL C++ 2015 - 2022 \'c7ALI\f1\'aaMA S\f0\'dcRESI \par..\b0 Bu lisans ko\f1\'baullar\u305?, Microsoft Corporation (veya ya\'baad\u305?\u287?\u305?n\u305?z yere g\f0\'f6re bir ba\f1\u287?l\u305? \'bairketi) ile sizin aran\u305?zda yap\u305?lan s\f0\'f6zle\f1\'bameyi olu\'baturur. Bu ko\'baullar, yukar\u305?da ad\u305? ge\f0\'e7en yaz\f1\u305?l\u305?m i\f0\'e7in ge\'e7erlidir. \f1\'aaartlar, yaz\u305?l\u305?m i\f0\'e7in t\'fcm Microsoft hizmetleri veya g\'fcncelle\f1\'batirmeleri i\f0\'e7in, beraberlerinde farkl\f1\u305? \'baartlar bulunmad\u305?\u287?\u305? s\f0\'fcrece ge\'e7erlidir.\pa
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3221
                                                              Entropy (8bit):5.280530692056262
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:DEFBEA001DC4EB66553630AC7CE47CCA
                                                              SHA1:90CED64EC7C861F03484B5D5616FDBCDA8F64788
                                                              SHA-256:E5ABE3CB3BF84207DAC4E6F5BBA1E693341D01AEA076DD2D91EAA21C6A6CB925
                                                              SHA-512:B3B7A22D0CDADA21A977F1DCEAF2D73212A4CDDBD298532B1AC97575F36113D45E8D71C60A6D8F8CC2E9DBF18EE1000167CFBF0B2E7ED6F05462D77E0BCA0E90
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">[WixBundleName] Kurulumu</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">.ptal etmek istedi.inizden emin misiniz?</String>.. <String Id="HelpHeader">Kurulum Yard.m.</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [dizin] - y.kler, onar.r, kald.r.r ya da.. dizindeki paketin tam bir yerel kopyas.n. olu.turur. Varsay.lan install de.eridir...../passive | /quiet - en az d.zeyde istemsiz UI g.sterir ya da hi. UI g.stermez ve.. istem yoktur. Varsay.lan olarak UI ve t.m istemler g.r.nt.lenir...../norestart - yeniden ba.lama denemelerini engeller. Varsay.lan olarak UI yeniden ba.l
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):18214
                                                              Entropy (8bit):3.9837154113926356
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D083C7E300928A0C5AEA5ECBD1653836
                                                              SHA1:08F4F1F9F7DFA593BE3977515635967CE7A99E7A
                                                              SHA-256:A808B4933CE3B3E0893504DBEF43EBF90B8B567F94BD6481B6315ED9141E1B11
                                                              SHA-512:8CB3FFAD879BABA36137B7A21B62D9D6C530693F5E16FBB975F3E7C20F1DB5A686F3A6EE406D69B018AA494E4CD185F71B369A378AE3289B8080105157E63FD0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset134 SimSun;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 Microsoft \f1\'c8\'ed\'bc\'fe\'d0\'ed\'bf\'c9\'cc\'f5\'bf\'ee\f0\par..MICROSOFT VISUAL C++ 2015 - 2022 RUNTIME \par..\b0\f1\'d5\'e2\'d0\'a9\'d0\'ed\'bf\'c9\'cc\'f5\'bf\'ee\'ca\'c7\f0 Microsoft Corporation\f1\'a3\'a8\'bb\'f2\'c4\'fa\'cb\'f9\'d4\'da\'b5\'d8\'b5\'c4\f0 Microsoft \f1\'b9\'d8\'c1\'aa\'b9\'ab\'cb\'be\'a3\'a9\'d3\'eb\'c4\'fa\'d6\'ae\'bc\'e4\'b4\'ef\'b3\'c9\'b5\'c4\'d0\'ad\'d2\'e9\'a1\'a3\'d5\'e2\'d0\'a9\'cc\'f5\'bf\'ee\'ca\'ca\'d3\'c3\'d3\'da\'c9\'cf\'ca\'f6\'c8\'ed\'bc\'fe\'a1\'a3\'d5\'e2\'d0\'a9\'cc\'f5\'bf\'ee\'d2\'b2\'ca\'ca\'d3\'c3\'d3\'da\'d5\'eb\'b6\'d4\'b8\'c3\'c8\'ed\'bc\'fe\'b5\'c4\'c8\'ce\'ba\'ce\f0 Microsoft \f1\'b7\'fe\'ce\'f1\'bb\'f2\'b8\'fc\'d0\'c2\'a3\'ac\'
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2978
                                                              Entropy (8bit):6.135205733555905
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3D1E15DEEACE801322E222969A574F17
                                                              SHA1:58074C83775E1A884FED6679ACF9AC78ABB8A169
                                                              SHA-256:2AC8B7C19A5189662DE36A0581C90DBAD96DF259EC00A28F609B644C3F39F9CA
                                                              SHA-512:10797919845C57C5831234E866D730EBD13255E5BF8BA8087D53F1D0FC5D72DC6D5F6945DBEBEE69ACC6A2E20378750C4B78083AE0390632743C184532358E10
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">[WixBundleName] ....</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">......</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [..] - .......... ..................Install ........../passive | /quiet - ..... UI ......... UI ... ........ UI ........../norestart - ..................... UI.../log log.txt - ............. %TEMP% ...
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):10825
                                                              Entropy (8bit):5.1113252296046126
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:873A413D23F830D3E87DAB3B94153E08
                                                              SHA1:24CFC24F22CEF89818718A86F55F27606EB42668
                                                              SHA-256:ABC11BB2B04DFF6AFE2D4D4F40D95A7D62E5AF352928AF90DAA3DADE58DD59BD
                                                              SHA-512:DC1ECCB5CC4D3047401E2BC31F5EB3E21C7881C02744A2E63C10D3C911D1158DCFAC023988E873C33DC381C989304FE1D3CB27ED99D7801285C4C378553CD821
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Garamond;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 T\'c9RMINOS DE LICENCIA DEL SOFTWARE DE MICROSOFT\par..MICROSOFT VISUAL C++ 2015 - 2022 RUNTIME \par..\b0 Los t\'e9rminos de esta licencia son un contrato entre Microsoft Corporation (o, en funci\'f3n de donde viva, una de las sociedades del grupo) y usted. Se aplican al software mencionado anteriormente. Los t\'e9rminos tambi\'e9n se aplican a los servicios o actualizaciones de software de Microsoft, excepto en la medida en que sus t\'e9rminos sean diferentes.\par..\b SI USTED CUMPLE LOS PRESENTES T\'c9RMINOS DE ESTA LICENCIA, DISPONDR\'c1 DE LOS DERECHOS QUE A CONTINUACI\'d3N SE DESCRIBEN.\par....\pard{\pntext\f2\'B7\tab}{\*\pn\pnlvlblt\pnf2\pnindent360{\pntxtb\'B7}}\fi-357\li357\sb1
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3265
                                                              Entropy (8bit):5.0491645049584655
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:47F9F8D342C9C22D0C9636BC7362FA8F
                                                              SHA1:3922D1589E284CE76AB39800E2B064F71123C1C5
                                                              SHA-256:9CBB2B312C100B309A1B1495E84E2228B937612885F7A642FBBD67969B632C3A
                                                              SHA-512:E458DF875E9B0622AEBE3C1449868AA6A2826A1F851DB71165A872B2897CF870CCF85046944FF51FFC13BB15E54E9D9424EC36CAF5A2F38CE8B7D6DC0E9B2363
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29"/>.... <String Id="Caption">Instalaci.n de [WixBundleName]</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">.Est. seguro de que desea cancelar la operaci.n?</String>.. <String Id="HelpHeader">Ayuda de configuraci.n</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [directory] - instala, repara, desinstala o.. crea una copia local completa del paquete en el directorio. La opci.n predeterminada es la instalaci.n...../passive | /quiet - muestra una IU m.nima sin solicitudes o no muestra ninguna IU ni.. solicitud. De forma predeterminada, se muestran la IU y todas las solicitudes...../norestart - elimina cualquier intento
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (558), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):12906
                                                              Entropy (8bit):3.7237107259370177
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:055DD6CC2667D43E89368B6672E378C9
                                                              SHA1:E4278D0440C2069F11735EE0AEECD9B576CB010C
                                                              SHA-256:88EFFBF5C9EEB280C03FC8E39FDD685F91F0B95842F36FDE55DB5B759C35D68D
                                                              SHA-512:1084EAC05F0931A7C6CA95A9AF44DE7E591DF17367AB58871B80D9C52E7208596B27F203C30EAF42DDD1913B4DC927B969CBE798CA4BA46D383A3DC427C7EB01
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.w.i.x./.2.0.1.0./.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a.".>..... . .<.W.i.x.B.a.l.C.o.n.d.i.t.i.o.n. .C.o.n.d.i.t.i.o.n.=.".V.e.r.s.i.o.n.N.T. .&.g.t.;.=. .v.6...1.". .M.e.s.s.a.g.e.=.".[.W.i.x.B.u.n.d.l.e.N.a.m.e.]. .c.a.n. .o.n.l.y. .b.e. .i.n.s.t.a.l.l.e.d. .o.n. .W.i.n.d.o.w.s. .7. .a.n.d. .n.e.w.e.r. .p.l.a.t.f.o.r.m.s...". ./.>..... . .<.W.i.x.B.u.n.d.l.e.P.r.o.p.e.r.t.i.e.s. .D.i.s.p.l.a.y.N.a.m.e.=.".M.i.c.r.o.s.o.f.t. .V.i.s.u.a.l. .C.+.+. .2.0.1.5.-.2.0.2.2. .R.e.d.i.s.t.r.i.b.u.t.a.b.l.e. .(.x.8.6.). .-. .1.4...3.8...3.3.1.3.5.". .L.o.g.P.a.t.h.V.a.r.i.a.b.l.e.=.".W.i.x.B.u.n.d.l.e.L.o.g.". .C.o.m.p.r.e.s.s.e.d.=.".y.e.s.". .I.d.=.".{.4.6.c.3.b.1.7.1.-.c.1.5.c.-.4.1.3.7.-.8.e.1.d.-.6.7.e.e.b.2.9.8.5.b.4.4.}.". .U.p.g.r.a.d.e.C.o.d.e.=.".{.F.8.9.9.B.
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
                                                              Category:dropped
                                                              Size (bytes):9235
                                                              Entropy (8bit):5.167332119309966
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:04B33F0A9081C10E85D0E495A1294F83
                                                              SHA1:1EFE2FB2D014A731B752672745F9FFECDD716412
                                                              SHA-256:8099DC3CF9502C335DA829E5C755948A12E3E6DE490EB492A99DEB673D883D8B
                                                              SHA-512:D1DBED00DF921169DD61501E2A3E95E6D7807348B188BE9DD8FC63423501E4D848ECE19AC466C3CACFCCC6084E0EB2F457DC957990F6F511DF10FD426E432685
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Garamond;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green32\blue96;\red0\green0\blue255;}..{\*\generator Riched20 10.0.19041}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang9 MICROSOFT SOFTWARE LICENSE TERMS\par..MICROSOFT VISUAL C++ 2015 - 2022 RUNTIME \par..\b0 These license terms are an agreement between Microsoft Corporation (or based on where you live, one of its affiliates) and you. They apply to the software named above. The terms also apply to any Microsoft services or updates for the software, except to the extent those have different terms.\par..\b IF YOU COMPLY WITH THESE LICENSE TERMS, YOU HAVE THE RIGHTS BELOW.\par....\pard{\pntext\f2\'B7\tab}{\*\pn\pnlvlblt\pnf2\pnindent360{\pntxtb\'B7}}\fi-357\li357\sb120\sa120\sl240\slmult1\tx360 INSTALLATION AND USE RIGHTS. \b0\par....\pard{\pntext\f2\'B7\tab}{\*\pn\pnlvlblt\pnf2\pnindent360{\pntxtb\'B7}}\f
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:PNG image data, 64 x 64, 8-bit colormap, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):1861
                                                              Entropy (8bit):6.868587546770907
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D6BD210F227442B3362493D046CEA233
                                                              SHA1:FF286AC8370FC655AEA0EF35E9CF0BFCB6D698DE
                                                              SHA-256:335A256D4779EC5DCF283D007FB56FD8211BBCAF47DCD70FE60DED6A112744EF
                                                              SHA-512:464AAAB9E08DE610AD34B97D4076E92DC04C2CDC6669F60BFC50F0F9CE5D71C31B8943BD84CEE1A04FB9AB5BBED3442BD41D9CB21A0DD170EA97C463E1CE2B5B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...@...@.............sRGB.........gAMA......a.....PLTE].q^.r_.r_.s`.s`.s`.ta.ta.ub.ub.vc.vd.vd.vd.we.we.xe.xg.yg yg zh zh"zi"{j#|i${j$|n*~n*.n,.o,.p..q0.r2.s3.t5.x;.x<.y>.z?.|B.~C.}E..F..F..H..I..J..L..O..P..W..Y..^..a..c..g..i..q..r..}.................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................S......pHYs..%...%....^.....tEXtSoftware.Paint.NET v3.5.100.r.....IDATXG..iW.@...EJ.$M...`AEpG..7TpWT@\.."....(..(.._;...di:9.c>q..g....T...._...-....F..+..w.
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2952
                                                              Entropy (8bit):5.052095286906672
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FBFCBC4DACC566A3C426F43CE10907B6
                                                              SHA1:63C45F9A771161740E100FAF710F30EED017D723
                                                              SHA-256:70400F181D00E1769774FF36BCD8B1AB5FBC431418067D31B876D18CC04EF4CE
                                                              SHA-512:063FB6685EE8D2FA57863A74D66A83C819FE848BA3072B6E7D1B4FE397A9B24A1037183BB2FDA776033C0936BE83888A6456AAE947E240521E2AB75D984EE35E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. .. Copyright (c) Microsoft Corporation. All rights reserved...-->..<WixLocalization Culture="en-us" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <Control Control="EulaAcceptCheckbox" X="11" Y="-41" Width="-11" Height="29" />.... <String Id="Caption">[WixBundleName] Setup</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Are you sure you want to cancel?</String>.. <String Id="HelpHeader">Setup Help</String>.. <String Id="HelpText">/install | /repair | /uninstall | /layout [directory] - installs, repairs, uninstalls or.. creates a complete local copy of the bundle in directory. Install is the default...../passive | /quiet - displays minimal UI with no prompts or displays no UI and.. no prompts. By default UI and all prompts are displayed...../norestart - suppress any attempts to restart. By default UI will prompt before restart.../log log.txt - logs to a specific file. B
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):8332
                                                              Entropy (8bit):5.184632608060528
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F62729C6D2540015E072514226C121C7
                                                              SHA1:C1E189D693F41AC2EAFCC363F7890FC0FEA6979C
                                                              SHA-256:F13BAE0EC08C91B4A315BB2D86EE48FADE597E7A5440DCE6F751F98A3A4D6916
                                                              SHA-512:CBBFBFA7E013A2B85B78D71D32FDF65323534816978E7544CA6CEA5286A0F6E8E7E5FFC4C538200211F11B94373D5658732D5D8AA1D01F9CCFDBF20F154F1471
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<Theme xmlns="http://wixtoolset.org/schemas/thmutil/2010">.. <Window Width="485" Height="300" HexStyle="100a0000" FontId="0">#(loc.Caption)</Window>.. <Font Id="0" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="1" Height="-24" Weight="500" Foreground="000000">Segoe UI</Font>.. <Font Id="2" Height="-22" Weight="500" Foreground="666666">Segoe UI</Font>.. <Font Id="3" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="4" Height="-12" Weight="500" Foreground="ff0000" Background="FFFFFF" Underline="yes">Segoe UI</Font>.... <Image X="11" Y="11" Width="64" Height="64" ImageFile="logo.png" Visible="yes"/>.. <Text X="80" Y="11" Width="-11" Heig
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):195600
                                                              Entropy (8bit):6.682530937585544
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:EAB9CAF4277829ABDF6223EC1EFA0EDD
                                                              SHA1:74862ECF349A9BEDD32699F2A7A4E00B4727543D
                                                              SHA-256:A4EFBDB2CE55788FFE92A244CB775EFD475526EF5B61AD78DE2BCDFADDAC7041
                                                              SHA-512:45B15ADE68E0A90EA7300AEB6DCA9BC9E347A63DBA5CE72A635957564D1BDF0B1584A5E34191916498850FC7B3B7ECFBCBFCB246B39DBF59D47F66BC825C6FD2
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........3..R...R...R..h.N..R..h.L.R..h.M..R.......R.......R.......R...*<..R...*,..R...R...S..K....R..K....R..N.@..R...R(..R..K....R..Rich.R..................PE..L......Z...........!................d.....................................................@..............................................................D......,.......T...............................@...............X............................text............................... ..`.rdata.............................@..@.data...............................@....gfids..............................@..@.rsrc...............................@..@.reloc..,...........................@..B........................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):650080
                                                              Entropy (8bit):7.2212720110363735
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7BD0B2D204D75012D3A9A9CE107C379E
                                                              SHA1:41EDD6321965D48E11ECDED3852EB32E3C13848D
                                                              SHA-256:D4C6F5C74BBB45C4F33D9CB7DDCE47226EA0A5AB90B8FF3F420B63A55C3F6DD2
                                                              SHA-512:D85AC030EBB3BA4412E69B5693406FE87E46696CA2A926EF75B6F6438E16B0C7ED1342363098530CDCEB4DB8E50614F33F972F7995E4222313FCEF036887D0F0
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c...'.u.'.u.'.u.......u.....[.u.....?.u...v.4.u...q.4.u...p...u.....".u....6.u.'.t.v.u...p.l.u....&.u.'..%.u...w.&.u.Rich'.u.........................PE..L......Z.....................v......m.............@..........................p............@..............................................;...............(...0...=.. t..T...................tt......@n..@...................$........................text.............................. ..`.rdata..............................@..@.data...@...........................@....wixburn8...........................@..@.tls................................@....gfids..............................@..@.rsrc....;.......<..................@..@.reloc...=...0...>..................@..B........................................................................................................................................................
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Microsoft Cabinet archive data, many, 824123 bytes, 11 files, at 0x44 +A "concrt140.dll_x86" +A "msvcp140.dll_x86", flags 0x4, number 1, extra bytes 20 in head, 62 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):834339
                                                              Entropy (8bit):7.997653805266825
                                                              Encrypted:true
                                                              SSDEEP:
                                                              MD5:A57EFC0AFFFDF914CBC76BB882CAD37E
                                                              SHA1:732DBEF27C49C27D9F1C00EBA177EABC21650FB8
                                                              SHA-256:C384DA7CC6EAD2CE054A67FDED26D7E4CFF2F981A83C64DE62E53864665E5F45
                                                              SHA-512:AD2CFC0FD199FE2726FD18C0A5972185E8331FE49807CA6340212901DD61D30853E2C72015EE9BAC0425E287EF488190A245676173194FAFBF8F6FC7FBF9BABA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MSCF....;.......D...........................;....'..............>...P.........3X,. .concrt140.dll_x86.x...P.....3X-. .msvcp140.dll_x86.P........3X-. .msvcp140_1.dll_x86......B....3X-. .msvcp140_2.dll_x86.P.........3X-. .msvcp140_atomic_wait.dll_x86.Pv..h.....3X-. .msvcp140_codecvt_ids.dll_x86.p....B....3X-. .vcamp140.dll_x86.pZ..(.....3X-. .vccorlib140.dll_x86.px...-....3X-. .vcomp140.dll_x86..c........3X-. .vcruntime140.dll_x86.P.........3X-. .vcruntime140_threads.dll_x86.!.)..4..CK.}|.U...E..Ge....WV..P...$@)...R..M..i...."b.UX.j]Y.b..V@..h.q.j.......*j]..R]..&S23NX|.........r....3s..3..D..".....-".....I..g>5P.8..Z..W.*\....r...Z..x..k....X..k.9.Jo.k.....>......U.z..........8...YK.<...%.*..}YE.qe...X..H9...<^.........B.K}.y....M.._.u.4..q.F.&....".... .0.....H...3...V..q.MP...".c...o....^.!v01.!b....!.v.#..s.../....c.u....3.`Kz...WM........l..c..1...p".6Z...8......Hw.p...[.D.?....W.K9...>+uz..\.^.....1.G...&..........r..@xm..|n...`..."D.S".K..g4...Z.Q..+
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Microsoft Cabinet archive data, many, 5167260 bytes, 14 files, at 0x44 +A "mfc140.dll_x86" +A "mfc140chs.dll_x86", flags 0x4, number 1, extra bytes 20 in head, 323 datablocks, 0x1 compression
                                                              Category:dropped
                                                              Size (bytes):5177492
                                                              Entropy (8bit):7.997816222199811
                                                              Encrypted:true
                                                              SSDEEP:
                                                              MD5:4A17E4DA145FA1EA92A52266221AD628
                                                              SHA1:F6304DE9D73609F6B9717D6A4D44EFD7AB7FFE9E
                                                              SHA-256:9544ABBD46B39BEC491CF63076FB109306E519F303DF9CD583A28956172BF038
                                                              SHA-512:DE9A6A1391070A9470F78208FF74120CFFD2A1E2580AF4ADD87914BA6DD27E07B092E66CAA847726E05EB5FAE0C1252681DE37F34B560D4D95F3B76F3599E16C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MSCF......N.....D.............................N..'..............C.....I.......3X-. .mfc140.dll_x86.P.....I...3X,. .mfc140chs.dll_x86.P....J...3X,. .mfc140cht.dll_x86..7..8rK...3X,. .mfc140deu.dll_x86.P.....L...3X,. .mfc140enu.dll_x86..3..h.M...3X,. .mfc140esn.dll_x86.h8..H.N...3X,. .mfc140fra.dll_x86.p0...(P...3X,. .mfc140ita.dll_x86..... YQ...3X,. .mfc140jpn.dll_x86......?R...3X,. .mfc140kor.dll_x86.P(...#S...3X,. .mfc140rus.dll_x86.xMJ.PKT...3X-. .mfc140u.dll_x86.pR.......3X,. .mfcm140.dll_x86.PR..8....3X,. .mfcm140u.dll_x86.z...4..CK..w..T.0.0" 8C(.R.X..6U..^..)...;..!.;.J'...w..C....."."..|...9.W.s......{V.Z.z.J.0.7...w.(.4\.|.E.D../.....O.E.~t...=1.-.....km...p....e...f.w.q..M.Hv.}.d...eW_3.a...0v.s.W................=.............NZ...L..T.......?3...>.L>...3..r...T....33.......{..M..a.~.u.Q.w.l..u.{O.rQ..$.E{...M.}..~<.T...Y..Q...{.s....p..Q..1Q4Y.2e...o....p.ye.p..R.I.S........oEQ.. .0.k........a..Rt...k.|....>X..Z...&]p....f...Q..~..j..}....k........ {
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Visual C++ 2022 X86 Additional Runtime, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Visual C++ 2022 X86 Additional Runtime - 14.38.33135., Template: Intel;1033, Revision Number: {29E9ACD5-6C1B-48C9-A316-358656F83B42}, Create Time/Date: Fri Jan 19 22:58:04 2024, Last Saved Time/Date: Fri Jan 19 22:58:04 2024, Number of Pages: 301, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.10.4.4718), Security: 2
                                                              Category:dropped
                                                              Size (bytes):184320
                                                              Entropy (8bit):6.383378429526644
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A37983D3FCA236D6AE2D22AB0FA9F1D4
                                                              SHA1:82F77032813AEDDF321D681DA4E1AA50786258DD
                                                              SHA-256:A7F13351CE5B41FCF6C2ED95F223F5E2AAB5411BF8499A772F69AD8FFB87F96B
                                                              SHA-512:619467E6D4AA6BC8F1CC02DAF52330E28C313D774A1D0B0BB96D40A2ED2DC3697CEE738463FAED040E1BCA407C3471AE1BC8DD91472682B25C579CAACDBF7374
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{902F5521-81A4-4EA4-B59E-2DD7517C3955}\.cr\vc_redist.x86.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Visual C++ 2022 X86 Minimum Runtime, Author: Microsoft Corporation, Keywords: Installer, Comments: This installer database contains the logic and data required to install Microsoft Visual C++ 2022 X86 Minimum Runtime - 14.38.33135., Template: Intel;1033, Revision Number: {83CEF352-ED74-4B1D-B0E7-96CDF4DA1C2D}, Create Time/Date: Fri Jan 19 22:52:32 2024, Last Saved Time/Date: Fri Jan 19 22:52:32 2024, Number of Pages: 301, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.10.4.4718), Security: 2
                                                              Category:dropped
                                                              Size (bytes):184320
                                                              Entropy (8bit):6.37750026266588
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3CA6B74AEFE34587F479055F5915E136
                                                              SHA1:61771E0A8CCABAC8783A22F67ADCBCE612F11704
                                                              SHA-256:A6F3A8E4E2162D8DF176418E9A238BECB645B2DB31D8073BFC4F4CDB7FB1AA22
                                                              SHA-512:3949CB3FDAD3E8D5E9C649141A72783E0B403D3E835433D4D456654BCDAD1290258F6D023CE127740F9C82459D337B9F8731C799EFCF99775955D38CF3FEF750
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2025
                                                              Entropy (8bit):6.231406644010833
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1D4B831F77EFEC96FFBC70BC4B59B8B5
                                                              SHA1:1B3ED82655AEC8A52DAEC60F8674BC7E07F8CFEB
                                                              SHA-256:1B93556F07C35AC0564D57E0743CCBA231950962C6506C8D4A74A31CD66FD04C
                                                              SHA-512:C6CCB188281F161DEBF02DCDDE24B77D8D14943DEED8852E77E5AFB18F3F62683AB1AE06DCEB1E09D53804A76DF6400A360712D8E7E228B7F971054BB4FB2496
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="zh-tw" Language="1028" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ....</String>.. <String Id="Title">[WixBundleName] ...... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">......</String>.. <String Id="HelpText">/passive | /quiet - ...... UI ............ UI ... ........... UI ........../norestart - ................UI ............./log log.txt - ............ %TEMP% ......</String>.. <Stri
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2458
                                                              Entropy (8bit):5.36165936198009
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:CC8C6D04DC707B38E0F0C08BA16FE49B
                                                              SHA1:95EA7F570677AEA52393D02FDB21CEBB218A7343
                                                              SHA-256:DC445E2457ED31ABF536871F90FF7CC96800A40B6BC033F37D45E3156A3B4FA9
                                                              SHA-512:A4B19EBC8BB0D88ABA7D3D5783E28F8B6E0960582A540059BC71076B1203BF43BCA15EA726272D15395C7B4E431046ADA1CBB9D55072BBC5DBE7729C4599F0E0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="cs-cz" Language="1029" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Instalace produktu [WixBundleName]</String>.. <String Id="Title">Pro instalaci produktu [WixBundleName] je vy.adov.no rozhran. Microsoft .NET Framework.</String>.. <String Id="ConfirmCancelMessage">Opravdu chcete akci zru.it?</String>.. <String Id="HelpHeader">N.pov.da k instalaci</String>.. <String Id="HelpText">/passive | /quiet - Zobraz. minim.ln. u.ivatelsk. rozhran. bez jak.chkoli.. v.zev, nebo nezobraz. ..dn. u.ivatelsk. rozhran. ani ..dn. v.zvy. Ve v.choz.m.. nastaven. se jak u.ivatelsk. rozhran., tak i v.echny v.zvy zobrazuj....../norestart - Potla.. jak.koli p
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2286
                                                              Entropy (8bit):5.061915970731254
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7C6E4CE87870B3B5E71D3EF4555500F8
                                                              SHA1:E831E8978A48BEAFA04AAD52A564B7EADED4311D
                                                              SHA-256:CAC263E0E90A4087446A290055257B1C39F17E11F065598CB2286DF4332C7696
                                                              SHA-512:2A02415A3E5F073F4530FD87C97B685D95B8C0E1B15EFD185CC5CB046FCF1D0DCE28DB9889AD52588B96FE01841A7A61F6B7D6D2F669EAB10A8926C46B8E93D1
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="da-dk" Language="1030" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Installation af [WixBundleName]</String>.. <String Id="Title">Microsoft .NET Framework skal v.re installeret i forbindelse med Installationen af [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Er du sikker p., at du vil annullere?</String>.. <String Id="HelpHeader">Hj.lp til installation</String>.. <String Id="HelpText">/passive | /quiet - viser en minimal brugergr.nseflade uden prompter eller.. viser ingen brugergr.nseflade og ingen prompter... Brugergr.nsefladen og alle prompter vises som standard...../norestart - skjuler fors.g p. genstart. Der vises som standard en.. foresp.rgse
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2442
                                                              Entropy (8bit):5.094465051245675
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C8E7E0B4E63B3076047B7F49C76D56E1
                                                              SHA1:4E44E656A0D552B2FFD65911CB45245364E5DBF3
                                                              SHA-256:631D46CB048FB6CF0B9A1362F8E5A1854C46E9525A0260C7841A04B2316C8295
                                                              SHA-512:FD7E8896F9414F0DB7A88F926F55EE24E0591DA676F330200BC6BB829EB32648D90D3094E0011BFE36C7BA8BE41DFD74B12D444AFEA0D2866801258DA4FA16E8
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="de-de" Language="1031" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <UI Control="InstallButton" Width="180" />.. .. <String Id="Caption">[WixBundleName]-Setup</String>.. <String Id="Title">F.r das [WixBundleName]-Setup ist Microsoft .NET Framework erforderlich.</String>.. <String Id="ConfirmCancelMessage">Sind Sie sicher, dass Sie den Vorgang abbrechen m.chten?</String>.. <String Id="HelpHeader">Setup-Hilfe</String>.. <String Id="HelpText">/passive | /quiet - zeigt eine minimale Benutzeroberfl.che ohne.. Eingabeaufforderungen oder keine Benutzeroberfl.che und keine.. Eingabeaufforderungen an. Standardm..ig werden die Benutzeroberfl.che und.. alle Eingabeaufforderungen angezeigt...../no
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):3400
                                                              Entropy (8bit):5.279888750092028
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:074D5921AF07E6126049CB45814246ED
                                                              SHA1:91D4BDDA8D2B703879CFE2C28550E0A46074FA57
                                                              SHA-256:B8E90E20EDF110AAAAEA54FBC8533872831777BE5589E380CFDD17E1F93147B5
                                                              SHA-512:28DAC36516BCC76BCC598C6E7ABDE359695F85AB7A830D6ADBC844EB240D9FA372CB5A5CE4DBE21E250408C6B246D371D3CDD656D2178FB0EC22DAC7D39CBD9F
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="el-gr" Language="1032" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">........... ... [WixBundleName]</String>.. <String Id="Title">... ... ........... ... [WixBundleName] .......... .. Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">..... ....... ... ...... .. ..... .......;</String>.. <String Id="HelpHeader">....... ... ... ...........</String>.. <String Id="HelpText">/passive | /quiet - ......... ........ ........... ... ............. .......... ...... ..... ........ . ... ..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2235
                                                              Entropy (8bit):5.142592159444541
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E338408F1101499EB22507A3451F7B06
                                                              SHA1:83B42F9D7307265A108FC339D0460D36B66A8B94
                                                              SHA-256:B7D9528F29761C82C3D926EFE5E0D5036A0E0D83EB4CCA7282846C86A9D6F9F3
                                                              SHA-512:F7BE923DC2856E0941D0669E2DE5A5C307C98DC7EBA0A1B68728EB29C95B4625145C2AD3AC6F6B6D82F062887EA349E2187F1F91785DDE5A5083BC1150E56326
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="fi-fi" Language="1035" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] -asennus</String>.. <String Id="Title">Microsoft .NET Framework tarvitaan [WixBundleName] -asennusta varten</String>.. <String Id="ConfirmCancelMessage">Haluatko varmasti peruuttaa?</String>.. <String Id="HelpHeader">Asennusohjelman ohje</String>.. <String Id="HelpText">/passive | /quiet - n.ytt.. mahdollisimman v.h.n k.ytt.liittym.st.; ei.. kehotteita tai ei k.ytt.liittym.. ja kehotteita. Oletusarvoisesti.. k.ytt.liittym. ja kaikki kehotteet n.ytet..n...../norestart - est.. uudelleenk.ynnistysyritykset. Oletusarvoisesti.. k.ytt.liittym. kysyy ennen uudelleenk.yn
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2306
                                                              Entropy (8bit):5.076293283609686
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:AA32A059AADD42431F7837CB1BE7257F
                                                              SHA1:4CD21661E341080FB8C2DEFD9F32F134561FC3BA
                                                              SHA-256:88E7DDACD6B714D94D5322876BD50051479B7A0C686DC2E9EB06B3B7A0BC06C9
                                                              SHA-512:78E201F369E65535E25722DFC0EFE99EDF641F7C14EFF1526DC1CC047FF11640079F1E3D25C9072CF25F4804195891BE006FC5ED313063AFCB91FB5700120B88
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="fr-fr" Language="1036" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Installation de [WixBundleName]</String>.. <String Id="Title">Microsoft .NET Framework requis pour l'installation de [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">.tes-vous s.r de vouloir annuler.?</String>.. <String Id="HelpHeader">Aide de l'installation</String>.. <String Id="HelpText">/passive | /quiet - affiche une interface minimale sans invites ou n'affiche.. aucune interface ni aucune invite. Par d.faut, l'interface et toutes les.. invites sont affich.es...../norestart - annule toute tentative de red.marrage. Par d.faut, l'interface.. affiche une invite avant de red.marrer..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2392
                                                              Entropy (8bit):5.293225307744296
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:17FB605A2F02DA203DF06F714D1CC6DE
                                                              SHA1:3A71D13D4CCA06116B111625C90DD1C451EA9228
                                                              SHA-256:55CF62D54EFB79801A9D94B24B3C9BA221C2465417A068950D40A67C52BA66EF
                                                              SHA-512:D05008D37143A1CC031F4B6268490A5A10FBB686C86984D20DB94843BDC4624EF9651D158DCB5B660FC239C3C3E8D087EB5D23FFFB8C4681910CBC376148F0F0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="hu-hu" Language="1038" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] telep.t.</String>.. <String Id="Title">A(z) [WixBundleName] telep.t.s.hez Microsoft .NET-keretrendszer sz.ks.ges</String>.. <String Id="ConfirmCancelMessage">Biztosan megszak.tja?</String>.. <String Id="HelpHeader">A telep.t. s.g.ja</String>.. <String Id="HelpText">/passive | /quiet - Minim.lis felhaszn.l.i fel.let megjelen.t.se k.rd.sek.. n.lk.l, illetve felhaszn.l.i fel.let .s k.rd.sek megjelen.t.se n.lk.li.. telep.t.s. Alapesetben a felhaszn.l.i fel.let .s minden k.rd.s megjelenik...../norestart - Az .jraind.t.si k.r.sek elrejt.se. Alapeset
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2304
                                                              Entropy (8bit):4.985260685429469
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:50261379B89457B1980FF19CFABE6A08
                                                              SHA1:F80B1F416539D33206CE3C24BA3B14B799A84813
                                                              SHA-256:A40C94EB33F8841C79E9F6958433AFFD517F97B4570F731666AF572E63178BB7
                                                              SHA-512:BBD9794181EEC95D6BE7A1B7BA83FD61AF2B2DF61D9DA8DDA2788B61BEC53C30FCEFE5222EDF134166532B36D3AB6CE8996F2D670DC6907C1864AF881A21EA40
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="it-it" Language="1040" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Installazione di [WixBundleName]</String>.. <String Id="Title">Microsoft .NET Framework necessario per l'installazione di [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Annullare?</String>.. <String Id="HelpHeader">Guida dell'installazione</String>.. <String Id="HelpText">/passive | /quiet - visualizza l'interfaccia utente minima senza istruzioni.. oppure non visualizza n. l'interfaccia utente n. le istruzioni. Per.. impostazione predefinita vengono visualizzate interfaccia utente e.. istruzioni...../norestart - elimina eventuali tentativi di riavvio. Per impostazione.. predefinita l'int
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2545
                                                              Entropy (8bit):5.923292576429967
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:DB0F5BAB42403FD67C0A18E35E6880EC
                                                              SHA1:C0A18C8C5BCD7B88C384B5304B56EEB85A0DA3DC
                                                              SHA-256:CCDCDB111EFA152C5F9FF4930033698B843390A549699AE802098D87431F16FE
                                                              SHA-512:589522BD4A26BF54CCF3564E392E41BBBA4E7B3FD1ED74E7F4F6AD6F2E65CDE11FFF32D0C5F3BCD09052FE5110FDC361D1926E220FD0BAD2D38CAC21BBE93211
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="ja-jp" Language="1041" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ......</String>.. <String Id="Title">[WixBundleName] ........ Microsoft .NET Framework .....</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">..........</String>.. <String Id="HelpText">/passive | /quiet - ... UI ....................UI.. .............. .....UI ....................../norestart - ........................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2236
                                                              Entropy (8bit):5.97627825234954
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:442F8463EF5CA42B99B2EFACA696BD01
                                                              SHA1:67496DB91CBAA85AC0727B12FC2D35E990537DAC
                                                              SHA-256:D22F6ADA97DBFFC1E7548E52163807F982B30B11A2A5109E71F42985102CCCBD
                                                              SHA-512:A350EAF9E7AEAFAB1163D7C0B8D014AFE07EE98BAE3915CBDD3C26282E345A0838E853C89BAE8943474758DCBCFD0BB0724A0C75CBF969F321FAB4944E8704FD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="ko-kr" Language="1042" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ..</String>.. <String Id="Title">[WixBundleName] ... ... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">........?</String>.. <String Id="HelpHeader">.. ...</String>.. <String Id="HelpText">/passive | /quiet - ... .. .. UI. ..... UI. .... .... .... ..... ..... UI . .. .... ........../norestart - .. ..... ... ...... ..... UI. .. .... .. .... ......../log log.txt - .
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2312
                                                              Entropy (8bit):4.965432037520827
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:67F28BCDB3BA6774CD66AA198B06FF38
                                                              SHA1:85D843B7248A5E1173FF9BD59CB73BB505F69B66
                                                              SHA-256:226B778604236931B4AE45F6F272586C884A11517444A34BF45CD5CAE49BE62E
                                                              SHA-512:7BC7D3E6E19ECF865B2CABFC46C75D516561D5A8A81A8ED55B4EDBA41A13A7110F474473740200AFB035B9597A2511D08C2A2E7A9ADE2C2AB4D3F168944B8328
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="nl-nl" Language="1043" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Installatie</String>.. <String Id="Title">Microsoft .NET Framework is vereist voor installatie [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Weet u zeker dat u de installatie wilt annuleren?</String>.. <String Id="HelpHeader">Help bij Setup</String>.. <String Id="HelpText">/passive | /quiet - geeft een minimale gebruikersinterface weer zonder prompts.. of geeft geen gebruikersinterface en geen prompts weer. Gebruikersinterface.. en alle prompts worden standaard weergegeven...../norestart - pogingen tot opnieuw opstarten onderdrukken... Gebruikersinterface vraagt standaard al
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2171
                                                              Entropy (8bit):5.089922193759582
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5454F724C9CDAB8172678A1CC7057220
                                                              SHA1:241A57018ACE1210881583A9CF646E7D2E51412F
                                                              SHA-256:41545AC1247B61C3C3E2A7E4659D9FAD2BCCA8347C69F2EB7B9D0CF5FC31E113
                                                              SHA-512:40E311EADA299996E32A7D35223CA678A03C869D63C023D59BC97A7B2049B0252AA9D0A7EC8558D5ACB73BD14C7BFA913097E65ABEE7455658DB7E35BBDA8AE1
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="nb-no" Language="1044" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Installasjonsprogram</String>.. <String Id="Title">Microsoft .NET Framework kreves for [WixBundleName]-installasjon</String>.. <String Id="ConfirmCancelMessage">Er du sikker p. at du vil avbryte?</String>.. <String Id="HelpHeader">Installasjonshjelp</String>.. <String Id="HelpText">/passive | /quiet - viser minimalt brukergrensesnitt uten ledetekster, eller.. ikke noe brukergrensesnitt og ingen ledetekster. Som standard vises.. brukergrensesnitt og alle ledetekster...../norestart - undertrykker alle fors.k p. omstart. Som standard sp.r.. brukergrensesnittet f.r omstart.../log log.txt
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2368
                                                              Entropy (8bit):5.270514043715206
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:96ACAAA5AEF7798E9048BAFF4C3FA8D3
                                                              SHA1:E76629973F6C1CFC06F60BA64FE9F237B2DB9698
                                                              SHA-256:F4AA983E39FB29C95E3306082F034B3A43E1D26489C997B8E6697B6A3B2F9F3C
                                                              SHA-512:964F73E572BDCB1AD946C770E6A2FB4A1CE54AF4B5BB072F64256083BA27A223F4DAD4A95B9D2A646180806D1F977726147970B06AAC35EED75AEC6CA89ED337
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="pl-pl" Language="1045" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Instalator programu [WixBundleName]</String>.. <String Id="Title">Do zainstalowania programu [WixBundleName] jest wymagany program Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">Czy na pewno chcesz anulowa.?</String>.. <String Id="HelpHeader">Pomoc instalatora</String>.. <String Id="HelpText">/passive | /quiet - wy.wietla minimalny interfejs u.ytkownika bez monit.w.. lub nie wy.wietla interfejsu u.ytkownika ani monit.w. Domy.lnie jest.. wy.wietlany interfejs u.ytkownika i wszystkie monity...../norestart - pomija wszelkie pr.by ponownego uruchomienia. Domy.lnie.. interf
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2147
                                                              Entropy (8bit):5.130635342194656
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:BD39ADB6B872163FD2D570028E9F3213
                                                              SHA1:688B8A109688D3EA483548F29DE2E57A8A56C868
                                                              SHA-256:ECB5C22E6C2423CAF07AEBE69F4FAF22450164EEE9587B64EF45A2D7F658CA15
                                                              SHA-512:F2826BE203E767D09FF0D7677E1CF5B13113B773D529166DAE02A1F5DB2DC58E0856A34901DF70011EBABB6E964FAB7ACF38590E650BD629D4E4DC4CB36C8D45
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="pt-br" Language="1046" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Instala..o</String>.. <String Id="Title">Microsoft .NET Framework . necess.rio para instala..o do [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Tem certeza de que deseja cancelar?</String>.. <String Id="HelpHeader">Ajuda da Instala..o</String>.. <String Id="HelpText">/passive | /quiet - exibe UI m.nima sem avisos ou exibe sem UI e.. sem avisos. Por padr.o a UI e todos avisos s.o exibidos...../norestart - suprime qualquer tentativa de reinicializa..o. Por padr.o a UI.. ir. solicitar antes de reiniciar.../log log.txt - logs para um arquivo espec.fico. Por padr.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2880
                                                              Entropy (8bit):5.408094213063887
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:DAF167AF4031EF47E562056A7D51AA73
                                                              SHA1:0156B230CADD6169AC2820865E3C031ED79785EF
                                                              SHA-256:C91C9E87AB4A6DB078F1991F4A2CDC726B58A40E47BCE49D39168A8F8F151C3B
                                                              SHA-512:5E87EE3838E3595ADBD7EABA6E3E33CDFEA5E15ED716FBCCDBD55235B3E53E1E41EA5A907F425E96C35167543C7F75AC5214B5AEE177D299FC2464A68B22851E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="ru-ru" Language="1049" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">......... [WixBundleName]</String>.. <String Id="Title">... ......... [WixBundleName] ......... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.. ............. ...... ........ ........?</String>.. <String Id="HelpHeader">....... .. .........</String>.. <String Id="HelpText">/passive | /quiet - ........... ............ .. ... ........ ... ...... ... .. .. . ............ .. ......... ............ .. . ... ......
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2334
                                                              Entropy (8bit):5.397882326481071
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:016C278E515F87F589AD22C856B201F7
                                                              SHA1:F20C7DB38B3161B143DEC4E578CE71D7F585F436
                                                              SHA-256:4A7FDF4A9033FE05C31F565ED3AE5B8C67D324B7AEADB737CE95DBB416D46868
                                                              SHA-512:310C85B27E1ECF4C6729E88051037150CFBA0234A0138666C26662B3D665FF38B74E95ABCADDEEF6CBEBB23E3357FAC487E6EE5EB8FE158C269D77672191B042
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="sk-sk" Language="1051" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] . in.tal.cia</String>.. <String Id="Title">Na in.tal.ciu aplik.cie [WixBundleName] sa vy.aduje s..as. Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">Naozaj chcete zru.i. oper.ciu?</String>.. <String Id="HelpHeader">Pomocn.k pre in.tal.ciu</String>.. <String Id="HelpText">/passive | /quiet . zobraz. minim.lne pou..vate.sk. rozhranie bez v.ziev alebo.. nezobraz. .iadne pou..vate.sk. rozhranie ani v.zvy. Predvolene sa.. zobrazuje pou..vate.sk. rozhranie aj v.etky v.zvy...../norestart . zru.. v.etky pokusy o re.tart. Pou..vate
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2132
                                                              Entropy (8bit):5.1255014007111495
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D95E81164C57B6FD75E7C3022454192E
                                                              SHA1:5D5ACBC56E7078AF4D04C45B78C0FF090C02EE6A
                                                              SHA-256:6DD61CC6B87B53EAF28430068A2A459730FD4B2BCF876CCDF040212D04C4FE7D
                                                              SHA-512:9E4BA81A145574818DD6A1F1D0EC38EA1629C7771919C35923F440E31EA9912E1630D94FCDB82B71104EBD61D0321DCDF935BA20D69988EE6E9B22259186AF0C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="sv-se" Language="1053" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName]-installation</String>.. <String Id="Title">Microsoft .NET Framework kr.vs f.r installation av [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Vill du avbryta?</String>.. <String Id="HelpHeader">Installationshj.lp</String>.. <String Id="HelpText">/passive | /quiet - visar ett minimalt anv.ndargr.nssnitt utan prompter,.. alternativt inget anv.ndargr.nssnitt och inga prompter. Som standard visas.. anv.ndargr.nssnitt och samtliga prompter...../norestart - hejdar omstart. Som standard visar anv.ndargr.nssnittet en.. prompt f.re omstart.../log log.txt - skapar logg till
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2303
                                                              Entropy (8bit):5.2754753523795275
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:01B200E06BA600A4EF00C00F7AAC5CE4
                                                              SHA1:22234426C42637E069A46217019551E4434A4AB6
                                                              SHA-256:06BFB6DFBC38105C699DEA226A029DF3EF673C33E4B8928DC4EC7FB8F761487D
                                                              SHA-512:8BDCF7533A6BCFA231B42A7EF845A70C7535FBF607D62FF6404928D5941BA6AFBF139450A1A1B58C65FACF88DC0785AEC4ABEFBCC803466A58B1930F7C468CDD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="tr-tr" Language="1055" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Kurulumu</String>.. <String Id="Title">[WixBundleName] kurulumu i.in Microsoft .NET Framework gerekir</String>.. <String Id="ConfirmCancelMessage">.ptal etmek istedi.inizden emin misiniz?</String>.. <String Id="HelpHeader">Kurulum Yard.m.</String>.. <String Id="HelpText">/passive | /quiet - komut istemi olmayan olabildi.ince k...k bir UI.. g.r.nt.ler veya komut istemi ve UI g.r.nt.lemez. Varsay.lan olarak UI.. ve t.m komut istemleri g.r.nt.lenir...../norestart - yeniden ba.latma denemelerini engeller. Varsay.lan.. olarak UI yeniden ba.latmadan .nce komut isteyecekt
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2200
                                                              Entropy (8bit):5.1485120966265
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5836F0C655BDD97093F68AAF69AB2BAB
                                                              SHA1:B6842E816F9E0DCC559A5692E4D26101D10B4B16
                                                              SHA-256:C015247D022BDC108B4FFCAE89CB55D1E313034D7E6EED18744C1BB55F108F8C
                                                              SHA-512:640A79D6A756E591AD02DDCCC53BC43F855C5148B8CBB5CE6C1CAF5419CA02F7B2AFF89CCA4C056356814D3899EF79BF038B4E8B4B79EB85138A3CEDCCE93E5B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="sl-si" Language="1060" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Namestitev</String>.. <String Id="Title">Microsoft .NET Framework, potreben za namestitev paketa [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Ali ste prepri.ani, da .elite preklicati?</String>.. <String Id="HelpHeader">Pomo. za namestitev</String>.. <String Id="HelpText">/passive | /quiet - prika.e minimalni uporabni.ki vmesnik brez pozivov ali ne prika.e.. uporabni.kega vmesnika in pozivov. Privzeto so prikazani uporabni.ki vmesnik in.. vsi pozivi...../norestart - skrije vse mo.nosti za vnovicni zagon. Privzeto uporabni.ki vmesnik.. prika.e poziv pred ponovnim zag
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1980
                                                              Entropy (8bit):6.189594519053644
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A34DCF7771198C779648B89156483E83
                                                              SHA1:A6E0FA91CD50048511C7BEF1BE3A8D32B42B6D1F
                                                              SHA-256:89C559C6765F8D643469E3C8F4AA93023F09369B0395EA647FAD5AF3C2893EB6
                                                              SHA-512:0F1D7BC4FD64E18EEEC488CDCE01FB6BFA5CD3BFF614A8D03E388D39F569B8341E74302946877EB25BA1EB17AEC137499189605E251FAFB6B20051744CB463B1
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="zh-ch" Language="2052" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] ..</String>.. <String Id="Title">[WixBundleName] .... Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.......?</String>.. <String Id="HelpHeader">......</String>.. <String Id="HelpText">/passive | /quiet - ..... UI .......... UI ... ........... UI ........../norestart - .............. UI ........../log log.txt - .............. %TEMP% ........</String>.. <String Id="HelpCloseButton"
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2211
                                                              Entropy (8bit):5.1155097909395035
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8A278E519EF81B2847490EFB070219BC
                                                              SHA1:7365EDF6E4F9E66B6CEE47933B6C70FF0B9ECFF8
                                                              SHA-256:E2BFDB2CF3BEAE2E988827C52C58006D7EEAD4ABA5312B5EAE1F6CCF3863C385
                                                              SHA-512:88275C1136FFB15AB04D315E8601BE2DE77387F3E00F17E9807E415A9DFC4A73E2CD3B5710E4CA58006F91E18180D7CFAEEF4E8319C624E1B81397F9CB9ECA92
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="pt-pt" Language="2070" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Configura..o do [WixBundleName]</String>.. <String Id="Title">O Microsoft .NET Framework . necess.rio para a configura..o do [WixBundleName]</String>.. <String Id="ConfirmCancelMessage">Tem a certeza de que pretende cancelar?</String>.. <String Id="HelpHeader">Ajuda da Configura..o</String>.. <String Id="HelpText">/passive | /quiet - apresenta IU m.nima sem mensagens ou n.o apresenta IU nem.. mensagens. Por predefini..o, s.o apresentadas a IU e todas as mensagens...../norestart - suprimir qualquer tentativa de rein.cio. Por predefini..o, a IU.. avisar. antes de reiniciar.../log log.txt - r
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2400
                                                              Entropy (8bit):4.992567587099768
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1024AA88AE01BC7BA797193CC6023375
                                                              SHA1:9252A309C1CB32573F4D58A595A78660FDF54B2F
                                                              SHA-256:B884C4ABB8867553C1FFADD6721C2135EC5F9F1455C3F668D711CCEA65363D1A
                                                              SHA-512:77E6DD332104C0461B7C5A08469161AF3F1DC51D3B55585D39DD9FC9E2088DA036BDF2278CFB96CA702FD26CE073C6C6F66611313270700B9E7A76600C1C8E38
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="es-es" Language="3082" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Instalaci.n de [WixBundleName]</String>.. <String Id="Title">La instalaci.n de [WixBundleName] requiere Microsoft .NET Framework</String>.. <String Id="ConfirmCancelMessage">.Est. seguro de que desea cancelar?</String>.. <String Id="HelpHeader">Ayuda del programa de instalaci.n</String>.. <String Id="HelpText">/passive | /quiet - muestra una interfaz de usuario m.nima y no realiza.. preguntas, o bien no muestra interfaz de usuario y no realiza preguntas... De manera predeterminada se muestra la interfaz de usuario completa y se.. realizan todas las preguntas necesarias...../norestart - suprime cu
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):905728
                                                              Entropy (8bit):6.729583436587489
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D59C28A6163C13B4719B1CC993AFE1CC
                                                              SHA1:4333FE043063AA9F196394030C612BAC120266DD
                                                              SHA-256:C97AA9BBEC20C06CD691EFF0AC0F1C48A84FACB56B8326A028343CA9FCA1BDC7
                                                              SHA-512:42E6527346C712F0D476D020B923D25738D5D0DE473FFB62F6B666E939532FB70C134E930D0CAFA35BD35AF2EBAE1055C43E5AE40BC667272EC62BB882FFC736
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)kf...........!..0.................. ........... .......................@............`.................................D...O............................ ....................................................... ............... ..H............text...@.... ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................x.......H............M..........,.................................................( ...*:.( .....}....*..0..)........{.........(!...t......|......(...+...3.*....0..)........{.........(#...t......|......(...+...3.*"..(....*b.{....%-.&*..s$...o%...*N.{....%-.&*..o%...*..(&...*..0..l.......~....%-c&.....('...((...~....%-.&~...... ...s)...%.....(...+~....%-.&~......!...s+...%.....(...+(...+%.....*:.(&.....}....*6..u....(....*....0.......... .....{.......(....X*....0..8.........3..*.{....
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):16896
                                                              Entropy (8bit):5.128503714775883
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:522305321F0FBF3FAA7A8324F3AFB66B
                                                              SHA1:D88F6661EEA70FDE9C0F83B0076D6B33EA92A76A
                                                              SHA-256:6741BC128631EB442EC198AF0C3ADD97625629C4E90AEFBAE3DCC1F21FD11F34
                                                              SHA-512:8507A280ED4279F5A530412BF48D4C5AF50704E48394F913A45ABC72FD00780E49832DA611E8F75B564700C1E03B0B00F6F819E2A61C1672424785D74730F80D
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..8...........W... ...`....... ....................................`.................................KW..O....`...............................V..8............................................ ............... ..H............text....7... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B.................W......H.......L*..4,............................................................(....*:.(......}....*..0...........r...po.....s5......rS..po6...s8.....r...po6.....(....-n~....~....%-.&~......=...s....%.....(...+(...+...o....-*.r...p.r...pr...p.(....(....o.... C......>.r...p.o9....r...po........"...rk..pr...p..(....o.... C.........*............".....0..`........r...po.....s5......rS..po6...s8....r!..po6...(......r5..p..(...(....o....r...p.o:.....(....._..r...p..(...(....o.....-.....
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):42496
                                                              Entropy (8bit):5.488906852124516
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:137BE966EA4B1E837A75F425A05B5295
                                                              SHA1:5F2BB9385BBEAD1518C37004521BF990A950C2FA
                                                              SHA-256:C049DE98298073404558A5570802896E14D4BA5EF19C90B64FDE11ACD324FD8F
                                                              SHA-512:493974BD331C696D2DE616E6615660FFE6A77A925092D908CCF68183975E6A659485DC805CF28D0D78446DF22C3FED8B73D4FB76F760534ACDB353D724313156
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...z.$..........." ..0................. ........... ....................................`.....................................O.......`...........................d...T............................................ ............... ..H............text........ ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B........................H........=...[..........l...x ..........................................0...........s....s{...s.....+..*....0..$........~+....(...+..,...(.....+.s.....+..*.0..?........~.....(...+..,%.s....s{...s....sr...(.......ss....+.s.....+..*..0...........s.....s{......s.......s......s....(.......s....(.........~,.........%.......(...+sk........~+.........%.......(...+sk.........s......+...*..0.............s....s.....+..**..(!.....*&.(".....*..0..9........~.........,".r...p.....(#...o$.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (572), with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):5252
                                                              Entropy (8bit):3.723439736905228
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:2686499F3F79904E50B200C1C87B1A25
                                                              SHA1:AB6C54D454C010720AFF5FE32591DD37E83C70B3
                                                              SHA-256:F163AB71FD234047B41820D7348BD8CE882D453BC6D967EE143D5573B82AECE7
                                                              SHA-512:7D7EE35AC880E1053F966D03F626D45A93A2C919AA8E42DDD5F3A23BB11FBF2E0B36DBEB018D0961CF68EA1C5D15135963EE5E1FE8A31BCBCBC2F140B3CF54FA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.w.i.x./.2.0.1.0./.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a.".>..... . .<.W.i.x.B.u.n.d.l.e.P.r.o.p.e.r.t.i.e.s. .D.i.s.p.l.a.y.N.a.m.e.=.".A.r.t.i.c.u.l.a.t.e. .3.6.0.". .L.o.g.P.a.t.h.V.a.r.i.a.b.l.e.=.".W.i.x.B.u.n.d.l.e.L.o.g.". .C.o.m.p.r.e.s.s.e.d.=.".n.o.". .I.d.=.".{.b.7.1.9.7.9.4.4.-.f.c.9.1.-.4.3.a.d.-.b.c.c.0.-.2.3.3.e.3.9.7.3.3.2.0.6.}.". .U.p.g.r.a.d.e.C.o.d.e.=.".{.0.A.2.4.B.5.4.3.-.1.0.6.7.-.4.5.A.9.-.B.E.8.9.-.D.7.5.F.B.9.3.B.F.6.3.9.}.". .P.e.r.M.a.c.h.i.n.e.=.".y.e.s.". ./.>..... . .<.W.i.x.M.b.a.P.r.e.r.e.q.I.n.f.o.r.m.a.t.i.o.n. .P.a.c.k.a.g.e.I.d.=.".N.e.t.F.x.4.8.W.e.b.". .L.i.c.e.n.s.e.U.r.l.=.".h.t.t.p.s.:././.r.e.f.e.r.e.n.c.e.s.o.u.r.c.e...m.i.c.r.o.s.o.f.t...c.o.m./.l.i.c.e.n.s.e...h.t.m.l.". ./.>..... . .<.W.i.x.P.a.c.k.a.g.e.P.r.o.p.e.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1119
                                                              Entropy (8bit):5.025269824504246
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:CD37E837EE00DF558A3A9CC42BD070BB
                                                              SHA1:EA08A3355720F40FAF624F13C556FE586381B55A
                                                              SHA-256:1939B78A3BF1A86C6FF16076DB07204BC40A15916B173F29D6C9E1C6F11FBF72
                                                              SHA-512:E46191574B87BD293FD1B64058A777C85795A01384C0A0CCDF71244672F51A0CBB996A1614CB6BF6C689E6F5F97061D8D2C62BDF2F1A14891D06805EAE1CC205
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.<?xml version="1.0" encoding="utf-8" ?>.. .. <copyright file="BootstrapperCore.config" company="Outercurve Foundation">.. Copyright (c) 2004, Outercurve Foundation... This software is released under Microsoft Reciprocal License (MS-RL)... The license and further copyright text can be found in the file.. LICENSE.TXT at the root directory of the distribution... </copyright>..-->..<configuration>.. <configSections>.. <sectionGroup name="wix.bootstrapper" type="Microsoft.Tools.WindowsInstallerXml.Bootstrapper.BootstrapperSectionGroup, BootstrapperCore">.. <section name="host" type="Microsoft.Tools.WindowsInstallerXml.Bootstrapper.HostSection, BootstrapperCore" />.. </sectionGroup>.. </configSections>.. <startup useLegacyV2RuntimeActivationPolicy="true">.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5"/>.. </startup>.. <wix.bootstrapper>.. <host assemblyName="Articulate.Bootstrapper.Application">.. <supportedFramework version
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):90032
                                                              Entropy (8bit):5.688550211341784
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B0D10A2A622A322788780E7A3CBB85F3
                                                              SHA1:04D90B16FA7B47A545C1133D5C0CA9E490F54633
                                                              SHA-256:F2C2B3CE2DF70A3206F3111391FFC7B791B32505FA97AEF22C0C2DBF6F3B0426
                                                              SHA-512:62B0AA09234067E67969C5F785736D92CD7907F1F680A07F6B44A1CAF43BFEB2DF96F29034016F3345C4580C6C9BC1B04BEA932D06E53621DA4FCF7B8C0A489F
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Mp.].........." ..0...... ........... ...@....... ..............................N.....@.................................`...O....@...............@.......`......(-............................................... ............... ..H............text........ ...................... ..`.rsrc........@....... ..............@..@.reloc.......`.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):184240
                                                              Entropy (8bit):5.876033362692288
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA
                                                              SHA1:F070AC0D91BD337D7952ABD1DDF19A737B94510C
                                                              SHA-256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA
                                                              SHA-512:A22DD3B7CF1C2EDCF5B540F3DAA482268D8038D468B8F00CA623D1C254AFFBBC1446E5BD42ADC3D8E274BE3BA776B0034E179FACCD9AC8612CCD75186D1E3BF1
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....o.].........." ..0...... ......z.... ........... ....................................@.................................(...O................................................................................... ............... ..H............text....w... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):140432
                                                              Entropy (8bit):6.059133240260085
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4CBC7B9D057E89C6A5BA313F6C2F036C
                                                              SHA1:BE57AE313DE841F987D0AE4CF9632E5F155955BE
                                                              SHA-256:EB8F7CECA9DFCA2080A8A9C30EBF49298778743F288A289970846D02074C5322
                                                              SHA-512:63077C81B1C0379FD86BC88571F8AEF227B449693C0B015BEEEABD99C3033C644F17AB089BBC55594C0FF98BD302C503C435B992DD7E83876CCB2111483CF902
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!..................... ... ....... .......................`...........`.....................................S.... ..`....................@....................................................... ............... ..H............text...4.... ...................... ..`.rsrc...`.... ......................@..@.reloc.......@......................@..B........................H............I..............%..P .......................................f.>dT.j.P..s..K..K...|"Y...r...^. ....}1k..mu...Q'Y......4..;b0.....\Y;....W...1..I...{...8...9M..-....,.......x...vG.IQ2..{....*"..}....*..{....*"..}....*..{....*"..}....*.sI...*"..o....*.s....*.*B.e...((...(u...*....0..........()...o...+..o....*...0..^.......()...o...+..,N......((...()...o...+o..........((...()...o...+o..........((...()...o...+o.....*...0..........()...o...+..9.....r...p.<...((..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):27792
                                                              Entropy (8bit):6.1321477705881335
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8AD746D4BB9B64AC5F0CE29896162259
                                                              SHA1:79041040D9CC0070B9DCE4026466B195BFF78EB4
                                                              SHA-256:F4043D2182666F67ACF71449EA60477DBDC577B1A09574ED6562A5C3FA6C42A9
                                                              SHA-512:D38CA6AE2133F231E89E15A7470E24D477F9D1DF7838E793FA427E048EBBADE1618EB08CDA30FFEC72080ED4EBF2EE2A897AB9D575C205EFBC4FCA92C88E0456
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....H...........f... ........... ...............................<....`.................................`f..K.......h............R..............(e............................................... ............... ..H............text....F... ...H.................. ..`.rsrc...h............J..............@..@.reloc...............P..............@..B.................f......H........7..............P-......P .......................................(>..P.^+..Vf.......y..Cd.^....kL*.C..d.....J.4.3..P3.}..1z...9...a>..uF..XR.o.(k.:.C3.R....:...../K%n..........e.S..(...........s....}............s....}....*..{....*..0..@........{....,..{.....{....o......}.....{....,..{.....{....o.....o....*..{....*^.{.........}.....o....*Z.{....o....u.........*..0..J........(.........-...( .....(!...*.("...,%.(........("....(#...o$.........o%...*..o....*..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):14496
                                                              Entropy (8bit):6.327509765949796
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:964AB2C3520B8A735329F0BE577C5850
                                                              SHA1:968EAB9103EC64A0DD4657582F28BB6FE9644209
                                                              SHA-256:DA3ABFEE09DDE110E4E9A0321F7223F7380A1052CB506313F44947E32F09BB5F
                                                              SHA-512:0BF393D15E64FB1A2BC0BEF663DD760E3ACDFDA503AEA185A83B904B01D612FA3AFFE7FFEC8780C23274D9B8E182B29CDD906CF8A0825569AB02ABBF4DE0AA61
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....="S...........!................>4... ...@....... ...................................`..................................3..O....@.......................`.......2............................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ 4......H.......(#...............!..X...P ......................................;.)%.6.h..q..O(-.`......&7.q.G..G1..J...S1.&..f....H.....bl....W(.E).K.RI..............8&Q.b......H+!df-.f..3h.H..h7|.]...(....*.0..3.......~.....(...., r...p.....(....o....s...........~....*.~....*.......*V(....ry..p~....o....*.0...........u!.....-.r...ps....z.(....*Z.,..~....o.....$...*.*V.,..~......$...o....*.r...p.$...(.........(......$..........s ...s!...("........*...T..............lSystem.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):31376
                                                              Entropy (8bit):6.161352322277959
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5C9985D31E098BF7DF031171E046D67E
                                                              SHA1:C6A7DBD7B28B2F3721685A8D8658DCC0B229B09F
                                                              SHA-256:675EBD10802E628AEA65659A18505651FF945E70C8730F74CE5FF1674B2D45A8
                                                              SHA-512:6452FACCEDBA3AFCAC776A1A72179EEEE00284D45CFAA9CAF41462404B43B8E69F54852AA9E41FC87B484A15767A852A3439B3AF6DCC6C4CF5F18304351AC3B3
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.....X..........^w... ........... ..............................J.....@..................................w..S....................`...............u............................................... ............... ..H............text...dW... ...X.................. ..`.rsrc................Z..............@..@.reloc...............^..............@..B................@w......H.......p9..`<..........04..?...P .........................................w[...A....Ai.!mU.......;.`.....5.....t......&.|I%"N......N..:>...(U7.!..;..........s........m...j...y\#..\h....6..:....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*..q...............(....,..*.........(.....*.0...........{......,....s....o....*.0...........(...+...(....*..(....*..s....}.....(............s....}....*:.(......}....*..0..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):22768
                                                              Entropy (8bit):6.201382004474863
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7C08EA125D8054BFA6057104590A7F83
                                                              SHA1:E8F02BBDC181AFE2C32482EB2B453B05EBACCAF5
                                                              SHA-256:25F8CCD05C97805438D5A7E321765E92EDBA7F135960F345920AF779AD6A78FC
                                                              SHA-512:12D3033F9CBA4D571ACE655B8D2B7ACF1D550592A833895F0311E8E928A55C2900B02A6B2E22C607DC9501B06DC5C04899EC37DF14391D65BD446CAE54EDC83B
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....3pQ...........!.....6..........~T... ...`....... ....................................@.................................$T..W....`...............>...............R............................................... ............... ..H............text....4... ...6.................. ..`.rsrc........`.......8..............@..@.reloc...............<..............@..B................`T......H........-...%...........*..x...P ........................................"N.e)&gn......A.I.............}..3.p..S.....,#.:...:.=.[.t..w...z........t.9.>.....3....8..>.....=.w<....F....^.. .0...........(.....-.r...ps....z.o....u....-4(....(&.................(....o......(....r...ps....z.-.r!..ps....z.o....u....-4(....(&.................(....o......(....r!..ps....z..}......}....*F.{....o....t....*F.{....o....t....*..{....*"..}....*..(....*.0..@................,...i.1
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):12432
                                                              Entropy (8bit):6.213812838430843
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B81F7CD09B39B8A5681D3E373C29C792
                                                              SHA1:966256B3F0E8D7FD5026E81CB33EC67122CF9BD4
                                                              SHA-256:B81FD01FF84915425375F74BAF46D0300F21CE63725A4D5F817BF901C6C212F1
                                                              SHA-512:A4E80C424ADCA342F4392724767D20132DEC56D6829CDB1A5A1FC89BE1DFD418CC26681FAD7669209A4F684B0D73DBF48C8CC09BEA6CCEEA8B4677A8B18B6702
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=S...........!.................)... ...@....... ...............................c....@..................................)..W....@.......................`......l(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H........ ......................P .......................................K..H.:B...X....1cHs.^.[xh.......)@1W.c(........V,_..(7..G..H.M/..$`........*hf.u.....-.=j....!q .B.a1..e..\...p....~}..%F}BSJB............v4.0.30319......l...(...#~......(...#Strings............#US.........#GUID...........#Blob...........G.........%3....................................................................................,.....C.....`.........................................3.....L.....|.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):18112
                                                              Entropy (8bit):6.224403881687228
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:92A533BE83B7FA43A1B18F009A7D450B
                                                              SHA1:E9AC62EBB0643BFFB243D889C535A8ABCD1BA52A
                                                              SHA-256:34005D6A80434542780C6D192E6ABD07BEA49B2EEB7E43FBFDFE90C2889986E5
                                                              SHA-512:B7AE35D9AB96C51B50998B46B8E73BA61BFC01812853C870872A18A3AA986DB8A66D3B8E173E1D7DD58097C07B07AFB64E5297B4B894B8FA1BF565773856A491
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...l.gS...........!....."...........A... ...`....... ....................................@..................................A..O....`...............,..............T@............................................... ............... ..H............text....!... ...".................. ..`.rsrc........`.......$..............@..@.reloc...............*..............@..B.................A......H........&..d............$..O...P .......................................J.#.....6z&2.c.d..4...L......|.<..bK... ....|e.u(.Q...v..D..#P.fu...........a[\%~..^..<..Y....,.{K....vE}+P.<..a.S+C...y.\..(....*"..(....*&...(....*v(....-.(#...s....z~....o....*.......*2~..........*&...o....*&...o....*...0.............o............o.....s....z.*...................0............o...........o.....s....z.*................^......(.....o.........*^......(.....o.........*.0..<.......(...
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):314880
                                                              Entropy (8bit):6.100714188266901
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:782C3D132E535F51E94433F5747099B5
                                                              SHA1:F1C5C6E9F9D9DD0DF6966DCE97DD2764CCC96AFA
                                                              SHA-256:C25B77353F7178386FFB28CCA0EBB8DB7F18F0D78514BAB8F175F1C637D651D9
                                                              SHA-512:9DF2A5CEF92133E791BE251E1677C71B29824D357BC7B59AB5671BCA1E0A7F958849D128D19BE89D39231A96E44D0B07D9A509309DE757A848B567E35E5C5794
                                                              Malicious:true
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...U..........." ..0.............~.... ........... .......................@............@.................................+...O............................ ......$...T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B................_.......H.......(...4...........\...H.............................................{....*..{....*V.(......}......}....*...0..;........u3.....,/(.....{.....{....o....,.(.....{.....{....o....*.*. ..<. )UU.Z(.....{....o....X )UU.Z(.....{....o....X*.0...........r...p......%..{...........6.....6...-.q6........6...-.&.+...6...o.....%..{...........7.....7...-.q7........7...-.&.+...7...o.....(....*..{....*..{....*..{....*r.(......}......}......}....*....0..S........u8.....,G(.....{.....{....o
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2118
                                                              Entropy (8bit):5.095838121091262
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:AF412C7C699D11570A55F4B96819E0D0
                                                              SHA1:B6B288116E267055F337ACE9FDCCEE8D409B92F7
                                                              SHA-256:A53A06ACF340E54F646334E4148C87628B699446D99A29B4A8D378F556832032
                                                              SHA-512:FFE2DA56F22BEF8D81AD77BA221715494B217627B3A0BA2E624506D5FBFE96E2B06BDD37103BC54E6AA9AED6A50610BF892B6C34958AB4631174F8C8854DCF9E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<WixLocalization Codepage="1252" Culture="de-DE" Language="1031" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Articulate-Einrichtung</String>.. <String Id="Title">Microsoft .NET Framework ist f.r [WixBundleName] erforderlich.</String>.. <String Id="ConfirmCancelMessage">M.chten Sie wirklich abbrechen?</String>.. <String Id="HelpHeader">Hilfe bei der Einrichtung</String>.. <String Id="HelpText">/passive | /quiet . zeigt eine minimale UI ohne Aufforderungen an oder zeigt keine UI und.. keine Aufforderungen an. Standardm..ig werden UI und alle Aufforderungen angezeigt..... /norestart . Neustartversuche werden unterdr.ckt. Standardm..ig zeigt die UI eine Aufforderung vor dem Neustart an... /log log.txt . protokolliert eine bestimmte Datei. Standardm..ig wird eine Protokolldatei in %TEMP% erstellt.</String>.. <String Id="HelpCloseButton">&amp;Schlie.en</String>..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2083
                                                              Entropy (8bit):4.973602923603804
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4FE12B13482C5EED59EE3F1E4B48D3AC
                                                              SHA1:AAD70F47DAF28BD205E53F4606E0E0E164FEBB08
                                                              SHA-256:15B688D125996692236B74F398596AA32646D8ACF14AA7310BCBC66E0BEFF6A1
                                                              SHA-512:9F3378EA5F59E901AA4CCE0E3F66814EB47F5FEFFFB037C11AF21DD74DDF99C35007DA3E4E19522E24417A52CC01211C497EF1A5694F1869D9BED3815DC50E83
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<WixLocalization Codepage="1252" Culture="es" Language="1252" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Instalaci.n de Articulate</String>.. <String Id="Title">Se requiere Microsoft .NET Framework para [WixBundleName].</String>.. <String Id="ConfirmCancelMessage">.Est.s seguro de que deseas cancelar?</String>.. <String Id="HelpHeader">Ayuda para instalaci.n</String>.. <String Id="HelpText">/passive | /quiet - muestra una interfaz de usuario m.nima sin indicaciones o no muestra ninguna interfaz de usuario y.. ninguna indicaci.n. Se muestran interfaz de usuario predeterminada y todas las indicaciones..... /norestart - suprime cualquier intento de reinicio. Se indicar. utilizar la interfaz de usuario predeterminada antes del reinicio... /log log.txt - se registra en un archivo espec.fico. De forma predeterminada, se crea un archivo de registro en %TEMP%.</String>..
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2150
                                                              Entropy (8bit):5.048706030328944
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5C3ECE79DE5581EAE4CAAD3F1EC54179
                                                              SHA1:8BD2B38228CE9E59F2C7669FA839A4E602868735
                                                              SHA-256:234F30802204F793E08FE0E8A6CD3C4996E03B52711252E7977EB060DED51BFD
                                                              SHA-512:8FFB3D261586D59D4D07DBCA25E9E27C0ED7AEE0C4794152AA7256A5548301805D60DD2212A611131F9C188BCC769CA5F6ABF2AEBD154FC50403377B99FD5E3B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<WixLocalization Codepage="1252" Culture="fr-FR" Language="1036" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Configuration d'Articulate</String>.. <String Id="Title">Microsoft .NET Framework est requis pour [WixBundleName].</String>.. <String Id="ConfirmCancelMessage">Voulez-vous vraiment annuler.?</String>.. <String Id="HelpHeader">Configuration de l'aide</String>.. <String Id="HelpText">/passive | /quiet - affiche l'interface utilisateur minimale sans instructions ou affichages, sans interface utilisateur et.. sans instructions. Par d.faut l'interface utilisateur et toutes les instructions sont affich.es..... /norestart - supprime toute tentative de red.marrage. Par d.faut l'interface utilisateur demandera confirmation avant de red.marrer... /log log.txt - enregistre le journal dans un fichier sp.cifique. Par d.faut un fichier journal est cr.. dans %TEMP%.</String
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):18671
                                                              Entropy (8bit):3.488026401558506
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C1B6CEFF1EDC6750FB9E0466CB20EA05
                                                              SHA1:4F36503B2836C8B15ADF8F86B7CD40240CD9AB36
                                                              SHA-256:0F166C6F763596BC8C3D04716C1641B95E167167F351FB1E82130774DAA939D3
                                                              SHA-512:FA7ACD7BF1D6DB883DEA2333328E2CDDB99B0DABDDFDA8538C59881ED7CD6A1DBA58A67136C8D4286200961E32D88F8A3B309ED56349A09ED2E1A32B669F251B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...@...@......iq.....pHYs...............8(iTXtXML:com.adobe.xmp.....<?xpacket begin="." id="W5M0MpCehiHzreSzNTczkc9d"?>.<x:xmpmeta xmlns:x="adobe:ns:meta/" x:xmptk="Adobe XMP Core 5.6-c111 79.158325, 2015/09/10-01:10:20 ">. <rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#">. <rdf:Description rdf:about="". xmlns:xmp="http://ns.adobe.com/xap/1.0/". xmlns:dc="http://purl.org/dc/elements/1.1/". xmlns:photoshop="http://ns.adobe.com/photoshop/1.0/". xmlns:xmpMM="http://ns.adobe.com/xap/1.0/mm/". xmlns:stEvt="http://ns.adobe.com/xap/1.0/sType/ResourceEvent#". xmlns:tiff="http://ns.adobe.com/tiff/1.0/". xmlns:exif="http://ns.adobe.com/exif/1.0/">. <xmp:CreatorTool>Adobe Photoshop CC 2015 (Macintosh)</xmp:CreatorTool>. <xmp:CreateDate>2016-09-09T10:44:29-07:00</xmp:CreateDate>. <xmp:ModifyDate>2016-09-09T10:44:41-07:00</xmp:ModifyDate>. <xmp
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):2588
                                                              Entropy (8bit):5.169290497785728
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7BB5D7BEF159150A61B1635801C60BDA
                                                              SHA1:C1EF8C7F5660FD90FAB8035C5FF4FC9233FDA235
                                                              SHA-256:EEFA3202636A40FCE0CC335D6D5429992B08FA380018E666EF96C1EE0B124616
                                                              SHA-512:79C2B245AE0CAA401D6BF52723B8E022715EC2B949C119CD943FA90D098AC2F82C51B1C6EF93BE455D72382A7DF359EC2A6F565509D445CC7D67101E003E2146
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<Theme xmlns="http://wixtoolset.org/schemas/thmutil/2010">.. <Window Width="500" Height="200" HexStyle="100a0000" FontId="0">#(loc.Caption)</Window>.. <Font Id="0" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="1" Height="-18" Weight="500" Foreground="000000">Segoe UI</Font>.. <Font Id="2" Height="-22" Weight="500" Foreground="666666">Segoe UI</Font>.. <Font Id="3" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="4" Height="-12" Weight="500" Foreground="ff0000" Background="FFFFFF" Underline="yes">Segoe UI</Font>.. <Image X="11" Y="11" Width="64" Height="64" ImageFile="PrerequisiteBootstrapperApplication.png" Visible="yes"/>.. <Text X="80" Y="11" Width="-11" Height="96" FontId="1" Visible="yes" DisablePrefix="yes">#(loc.Title)</Text>.. <Page Name="Help">.. <Text X="11" Y="112" Width="-11" Height="30" FontId="2" DisablePrefi
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                              Category:dropped
                                                              Size (bytes):1797
                                                              Entropy (8bit):5.021385067705324
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:411A6CDA5D091C1B0D9A9F59DBDF55A7
                                                              SHA1:1B5F5F8E73E086D83C4906E1A9BB1EDC22A07B4F
                                                              SHA-256:2EFA15A050EF58C5E363A8A690297891FE6C3D0A4CB1BD430516B2EA1CD7E96E
                                                              SHA-512:0492F95138F2484D7F18F8884BEC386E47E3B2C99B8C3DC4511E95E5477F8B0BD3F54B39B2275F31CB0EF84987E15C35523CBB5A99E6E257BF85B40425E066E6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:<?xml version="1.0" encoding="utf-8"?>..<WixLocalization Codepage="1252" Culture="en-us" Language="1033" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">Articulate Setup</String>.. <String Id="Title">The Microsoft .NET Framework is required for [WixBundleName].</String>.. <String Id="ConfirmCancelMessage">Are you sure you want to cancel?</String>.. <String Id="HelpHeader">Setup Help</String>.. <String Id="HelpText">/passive | /quiet - displays minimal UI with no prompts or displays no UI and.. no prompts. By default UI and all prompts are displayed...../norestart - suppress any attempts to restart. By default UI will prompt before restart.../log log.txt - logs to a specific file. By default a log file is created in %TEMP%.</String>.. <String Id="HelpCloseButton">&amp;Close</String>.. <String Id="InstallLicenseTerms">Click the "Accept" button to accept the Microsoft .NET Framework &lt;a href="#"&gt;license terms&lt;/a&gt;.</St
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):55904
                                                              Entropy (8bit):6.299047178318044
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:580244BC805220253A87196913EB3E5E
                                                              SHA1:CE6C4C18CF638F980905B9CB6710EE1FA73BB397
                                                              SHA-256:93FBC59E4880AFC9F136C3AC0976ADA7F3FAA7CACEDCE5C824B337CBCA9D2EBF
                                                              SHA-512:2666B594F13CE9DF2352D10A3D8836BF447EAF6A08DA528B027436BB4AFFAAD9CD5466B4337A3EAF7B41D3021016B53C5448C7A52C037708CAE9501DB89A73F0
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...W."Q...........!.................... ........ ;. ...................................`.....................................K.......................`>..........H................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......,O...`..........pD......P ......................................g.=d.N:..K..=mU.....M......^.....@........h.pX..9.web.~M}.R9 l9..2.....1S...{^..Pn....8.6k...S.-.K..$uXpy....t.'.%u/...+VC6.(.....{....*...0..&........(..............s....o.....s....}....*...0..K........(.....{....o........,3..+&..( .........{.....o!............*..X...(....2.*..0..L........{.....o"...,=(#...(..................($...o%.......(&...o%.....('...s(...z*.0...........o).......E............d
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):10752
                                                              Entropy (8bit):4.584539719672249
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D09236F3CC1A6503C8F5F13A683F4FCB
                                                              SHA1:4A884829374765592E2A332BC5A400FDE6BB4B52
                                                              SHA-256:9D2B4C507D2C5E14CC64941E8A8ED513AF9BAC145618EA205B13D1829E94C8A2
                                                              SHA-512:207D59A342C73229B7078812A8DFBCBA8F69777569EF6770D830BBE247CE641A15C768D06385E5D0EC26B27DCC59ACFB67B575CBACC0A286779C63603B05E98C
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)kf...........!..... ...........>... ...@....... ....................................@..................................>..K....@.......................`....................................................... ............... ..H............text........ ... .................. ..`.rsrc........@......."..............@..@.reloc.......`.......(..............@..B.................>......H.......P:..0...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....0.......PADPADP.Z&...........[.<.{.c...p....d...<..&..|,..h..G.B..f.._..._..._...`...`...d...t..x...x...x...x.....#.7.W... ...0....hO.....5.....Y......@..*.R....,n.)-...3.}.I.5LT..=U.MeY.PXe..e._.e....o...............D...9...........
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):10240
                                                              Entropy (8bit):4.48532556994611
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FE7AAB9888265BBE0DFAB0DC091163C7
                                                              SHA1:532CC4488F865BC93AA19FE2B0C2888B4A49DA4A
                                                              SHA-256:BBAF68A6A3E847D26DB7233CB536B6F85B37AD8E7931FC08BE05DA8C013D75E6
                                                              SHA-512:23362C1B192E553542D95B78793FC2D064AAD38384A4A3D9E134200264002BA424E046B85821353C0E5D1D34B21A8C589453BB29829FFE3C7D64CF176E63A5C1
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)kf...........!.................<... ...@....... ....................................@.................................4<..W....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@....... ..............@..@.reloc.......`.......&..............@..B................p<......H........8..(...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....0.......PADPADP.Z&...........[.<.{.c...p....d...<..&..|,..h..G.B..f.._..._..._...`...`...d...t..x...x...x...x.....#.7.W... ...0....hO.....5.....Y......@..*.R....,n.)-...3.}.I.5LT..=U.MeY.PXe..e._.e....o...............D...9...........
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):10240
                                                              Entropy (8bit):4.632374896858518
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7FA1FC19E4E2593A72DA99E779D202FE
                                                              SHA1:BEC4DC73EC76A444B9ADB62A2F1A4F467B3BB466
                                                              SHA-256:1610FF59CFDD70209B8F086336F843DE15D876C3D24E84EFB316B816363BE87D
                                                              SHA-512:A1859C3741E327658188CC3A23D4EB748BCF7C26E4592CF3E1AB64F3E395A99683A548F696F1C9789A8111BDE2BF8F709856CCAFA96CCA74B864CD580AD2A41B
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....)kf...........!.................=... ...@....... ....................................@.................................8=..S....@.......................`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@....... ..............@..@.reloc.......`.......&..............@..B................p=......H........9..0...........P .............................................................lSystem.Resources.ResourceReader, mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089#System.Resources.RuntimeResourceSet....0.......PADPADP.Z&...........[.<.{.c...p....d...<..&..|,..h..G.B..f.._..._..._...`...`...d...t..x...x...x...x.....#.7.W... ...0....hO.....5.....Y......@..*.R....,n.)-...3.}.I.5LT..=U.MeY.PXe..e._.e....o...............D...9...........
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):122288
                                                              Entropy (8bit):6.643662045821993
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C59832217903CE88793A6C40888E3CAE
                                                              SHA1:6D9FACABF41DCF53281897764D467696780623B8
                                                              SHA-256:9DFA1BC5D2AB4C652304976978749141B8C312784B05CB577F338A0AA91330DB
                                                              SHA-512:1B1F4CB2E3FA57CB481E28A967B19A6FEFA74F3C77A3F3214A6B09E11CEB20AE428D036929F000710B4EB24A2C57D5D7DFE39661D5A1F48EE69A02D83381D1A9
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........v........................}.......|..............................o..............2~......2~......2~q.............2~......Rich....................PE..L...Tp.]...........!.....&..........(>.......@.......................................;....@.....................................x......................................T...........................H...@............@...............................text....%.......&.................. ..`.rdata...s...@...t...*..............@..@.data...............................@....rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):188848
                                                              Entropy (8bit):6.598346436496911
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FE7E0BD53F52E6630473C31299A49FDD
                                                              SHA1:F706F45768BFB95F4C96DFA0BE36DF57AA863898
                                                              SHA-256:2BEA14D70943A42D344E09B7C9DE5562FA7E109946E1C615DD584DA30D06CC80
                                                              SHA-512:FEED48286B1E182996A3664F0FACDF42AAE3692D3D938EA004350C85764DB7A0BEA996DFDDF7A77149C0D4B8B776FB544E8B1CE5E9944086A5B1ED6A8A239A3C
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:v.O~.c.~.c.~.c....t.c......c....f.c.,.g.n.c.,.`.l.c.,.f.a.c.wo..z.c.wo..c.c.~.b.|.c..~f.g.c..~c...c..~....c.~.....c..~a...c.Rich~.c.........PE..L...Yp.]...........!................................................................1.....@.........................`.......L...................................`.......T...........................H...@...............\............................text............................... ..`.rdata..2...........................@..@.data...............................@....rsrc...............................@..@.reloc..`...........................@..B........................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PNG image data, 63 x 63, 8-bit/color RGBA, non-interlaced
                                                              Category:dropped
                                                              Size (bytes):797
                                                              Entropy (8bit):7.648767094164769
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A356956FD269567B8F4612A33802637B
                                                              SHA1:75AE41181581FD6376CA9CA88147011E48BF9A30
                                                              SHA-256:A401A225ADDAF89110B4B0F6E8CF94779E7C0640BCDD2D670FFCF05AAB0DAD03
                                                              SHA-512:A0F7836AEFA1747F481C116F6B085F503B5C09B3A1DD97CD2189F7CE4E6E7EA98F1F66503CBA2E6A83E873248CC7507328710DFA670AA5763DF8AEDCC560285E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.PNG........IHDR...?...?.....W_......sRGB.........gAMA......a.....pHYs..........+......IDAThC./W.0....P(...Db+q8$.........J...-..8.e]._..;........Y... .Y....z\........{W|..../q..<%.....C5...0....OrU....,..^........).....2.......i.Ge..T9T..}.7..J.......}..b...S.>.%y..Fc..j.X.....y."...e.U..M(ez....4\..C....u.......w..0..J.Wo."...mM.r.h..8..q..X..k!...j..xn...l...W`..r.+.R..J........c.T.}......cz..<43..@.c..rH...|..V.....K.mN.........k....,..4OL..5..M.tm%=.U.t-7.w....k.R.....c...-].5~..]2..5...GA..[..={.5..].=(.$}.\.9..5...MWu..[#.....F..j.F...d...,..MWu.7..3......$.......G.t.....=;N<_:[......0.,1.y.\.Z.|..%..>}...q.s....y.#p......!-.;.6!o.KO..E.6...........<..c..9_B....y....im...b...Xn.....)t9Q...........V.WMtP. .P..Z.&..KR.ac......IEND.B`.
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):1614736
                                                              Entropy (8bit):7.587788693865472
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:27A052A559D18C7A5823AA55D41A1A14
                                                              SHA1:50F398EF91B20AA9E9179C805E62CD995941DE2B
                                                              SHA-256:A0F34A8BBAD9BA7BCBAD63E7F1E382C37BCC27114A2B7EEEC390B4E0F4071AAA
                                                              SHA-512:766244A215F4FD37F009B13E954E3DA6CAFF7E7C33BD51CE0654BBBBB225916B8384CD0F08918A8ED1C5AC33EC46EF8272F125C3D7F3C34CED7F79CD02250A9B
                                                              Malicious:false
                                                              Antivirus:
                                                              • Antivirus: ReversingLabs, Detection: 0%
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9.o.}k..}k..}k.....wk......k.....ek../...nk../...ik../...Vk..t...xk..t...lk..}k..(j......6k......|k..}k...k......|k..Rich}k..........PE..L...2p.].....................X......q.............@..........................0............@.........................................................({..h(.......=..0p..T....................p.......j..@...................4|.......................text............................... ..`.rdata..`...........................@..@.data...............................@....wixburn8...........................@..@.rsrc...............................@..@.reloc...=.......>..................@..B........................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Articulate 360, Author: Articulate Global, LLC, Keywords: Installer, Comments: This installer database contains the logic and data required to install Articulate 360., Template: Intel;1033, Revision Number: {C5D0A98E-A4FF-4ADA-8410-5E4BAF9F113F}, Create Time/Date: Thu Jun 13 18:18:00 2024, Last Saved Time/Date: Thu Jun 13 18:18:00 2024, Number of Pages: 405, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                              Category:dropped
                                                              Size (bytes):21942272
                                                              Entropy (8bit):7.986500498203743
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:9AD0A2B63668CD1F296D024406A97BF6
                                                              SHA1:6CC4F86DD636F2D9E0677A9CCABFCE7773E85B1C
                                                              SHA-256:5C17C2604055456111C0A3BE3F17F092007AE4A9000D074CE0C59315F019CDEE
                                                              SHA-512:DA6A6C39BC8BEA088211360956865EB976D74AD0658C64D204ED72C89FB3955C485C2BAFBE54F187CEB83903450B23BF4190B7A858D3267C68AAD4271470926B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\Temp\{914F5AF4-8B16-4747-92C9-4C43E5F8FA86}\.cr\articulate-360.exe
                                                              File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Category:dropped
                                                              Size (bytes):13853648
                                                              Entropy (8bit):7.995252036325378
                                                              Encrypted:true
                                                              SSDEEP:
                                                              MD5:9882A328C8414274555845FA6B542D1E
                                                              SHA1:AB4A97610B127D68C45311DEABFBCD8AA7066F4B
                                                              SHA-256:510FC8C2112E2BC544FB29A72191EABCC68D3A5A7468D35D7694493BC8593A79
                                                              SHA-512:C08D1AA7E6E6215A0CEE2793592B65668066C8C984B26675D2B8C09BC7FEE21411CB3C0A905EAEE7A48E7A47535FA777DE21EEB07C78BCA7BF3D7BB17192ACF2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......c...'.u.'.u.'.u.......u.....[.u.....?.u...v.4.u...q.4.u...p...u.....".u....6.u.'.t.v.u...p.l.u....&.u.'..%.u...w.&.u.Rich'.u.........................PE..L......Z.....................v......m.............@..........................p......!.....@..............................................;...........;..8(...0...=.. t..T...................tt......@n..@...................$........................text.............................. ..`.rdata..............................@..@.data...@...........................@....wixburn8...........................@..@.tls................................@....gfids..............................@..@.rsrc....;.......<..................@..@.reloc...=...0...>..................@..B........................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):69632
                                                              Entropy (8bit):0.35852407573003653
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D3770C24A40CB4DA99203E5D5D63FB96
                                                              SHA1:D3C9EF6D6FBC763F6BE03FF6B6C965CF196F1ADD
                                                              SHA-256:FF7BE1981B23858B0B769E49D28ED065A02D913C3CE871CF8CE73B7833720E70
                                                              SHA-512:360FB0CB0ADD81643964CB027269E0A27A730E10FCBDCB2C832C3CC982EC4597880315FF95B35B3BFEC795FA5161206065DF54714F377236018ECF27E43C3454
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):32768
                                                              Entropy (8bit):1.232561821874389
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:CE0678D568DEA4C5F1590F3A30AEBB6C
                                                              SHA1:87C2DEA064F6BD00C501F5E81B3C92BB4B72489A
                                                              SHA-256:B74F50CD3E1622C5260089E84E8CC730287792112B77C441E37DAD664F9684BC
                                                              SHA-512:A78F7979BCA98DBBE2F4E3F1E9EE71E7F3A1103348EA92FBD7A3C839079485A968D2ACB34F54186058C115ABA20813299DC6116C6C7CAC86B7DBB76620BBD01B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):32768
                                                              Entropy (8bit):0.10342421288411675
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:AC1E65CEBD254CE1869F3A2EE4A96806
                                                              SHA1:C3F1FDEAB639D744A0F5DF02391ECA507548D98F
                                                              SHA-256:81F96E1A5954840850864FC0C676B2B82C96E85DDDA7D57E770863B54DA97190
                                                              SHA-512:2A7CD51AA2E1376E9CDC7211A902FFA4833391AE75B86CBAA40EF217A6609389519B0851637D8C7F752F9714F245CE94874E860B169933ED8BBD0790761B1E70
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):32768
                                                              Entropy (8bit):0.10228607613592977
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:12136771E7AE5475D9727073E913D132
                                                              SHA1:52D2C21EF17DD136BF1B02ECC77E28B9B4885F4D
                                                              SHA-256:D0778B596993353D383111C37114D8D0950ED0A38242594C08D1BDF91F259C67
                                                              SHA-512:B4F4F8F1CC2A6FEEE075EA177DE53D0C1088EF5696EF347CA4B39D7B15D1206BBC7D1E754526F7B1DB99538FC3939068D42D71BC95503EDA9A395FA763BCD8D2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):32768
                                                              Entropy (8bit):1.23582268130671
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B4E47B5CD6C9C1112587F1E286EA2576
                                                              SHA1:68AA7369F561BBADBAA206EE9071F2EF55B1D9CD
                                                              SHA-256:9BB19805F883C5C59F4309FE7159B88088A261B432D226B284290B95735AA3B2
                                                              SHA-512:7D1BA2911106EB9DF7B8806A63A4BAF341262A1A379E274105161542944A2249CD8D3C6C041662903FA720CC14480404D628522F2C355984D255A81627038541
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):69632
                                                              Entropy (8bit):0.13244448059974132
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:0721EB23B53B7997C34D5534A0FC8C9F
                                                              SHA1:BC1C1EB33CC1F333E8B9A62C4E69C3480D342130
                                                              SHA-256:E2F6D2E4890BC6EDD10F29C93EE6566956231706FCBA07E59ED87CC14356D52E
                                                              SHA-512:53F83954BB3102F7557900AEE5A74003E60C5AF77DB38C8D0A9E3EAB36AE1E75B1DC14B5EDDB15873933EC1101983E54C80E9C247DA78540B40B0F2891ADC5F2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):512
                                                              Entropy (8bit):0.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                              SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                              SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                              SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):49152
                                                              Entropy (8bit):1.2510112970820841
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:923269DB712BDE048D89A7E3AD4A4FC3
                                                              SHA1:A3CCDF714EAE45A550BD7EF7414DF4B485A390B0
                                                              SHA-256:57C727E5F7D6EBDB0C74061E17173BFCCDE7EEFB6BB78977CE7FDEBC982DB794
                                                              SHA-512:BDD3C2EE396F1D43B3E05F384E2BF8AB2EF0BB87DBF0332DB0E342BE18DD88143CB0CF0D3D88868C0AA4C26452A23A5325A1FCAFA354B7F1245BA46E1D1A1DA3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):69632
                                                              Entropy (8bit):0.1342239795052044
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3156E704246B08A7E0D1F3BB8FC1F861
                                                              SHA1:42A826F48D6FD577F6CDE4388A9A9FDCB7CD5ACA
                                                              SHA-256:DE4918133D91515281757D221142F9C9FABE9DAA54ED43CC238193DF4956A2BD
                                                              SHA-512:119823375389D28107B0DE7922653181AD615F54A1902184B055DF7803482A37F72A31E49DA59334A57E5444B0DE2E009F43870F04B2310B3972ADEF3C8D8B09
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:data
                                                              Category:dropped
                                                              Size (bytes):32768
                                                              Entropy (8bit):0.0766507441609212
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D81D9C6D0968B45D1815483B70FF347F
                                                              SHA1:B34D7CAE312D7EE10E7C1EB7633BD98F2A8A22D5
                                                              SHA-256:00D2F7A37247CD69DBCA9C7289053875E52E4CBDAD287EBBF9C5D0DC91250E8C
                                                              SHA-512:6C0F96D6ECA49695F87348379BC5FBF2900C31B43AF617FF4DCE1361348607587806403945354F51211AE7B73E645F86188A40781DFAE3C58419FF50EB7E65AA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):24576
                                                              Entropy (8bit):1.9175069902791546
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:45CF1E48190E41E98F42E64DC40AA4D3
                                                              SHA1:B547FBF1606E8794E7C92265C7EF1BB2E294D4E4
                                                              SHA-256:5AA8803278155F6B1B5D7BB415E6BC22F0E783A1D9ACA8E19B7B45C6007FE550
                                                              SHA-512:8636A104BB2907E18D5284833D4CD345913F6DA825BD7773F00624ACE4312366B2BF5EE08BD83784A311557C116E341CEE83C0E6EC438BC733EF7E3CE3494DD7
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):20480
                                                              Entropy (8bit):1.540565597861552
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:32E773CC2EE7D6FF99AB46FDD755ECA1
                                                              SHA1:CB8A2ABC4F71D341D3D3AC2B1422AAC55FBDC621
                                                              SHA-256:B106A8DAAC5E759A2B0F95A10F5F63C3FFE54B919F8236A24C45DFB56A8A0E9F
                                                              SHA-512:272A77AF77B05FBA95DDA3A16FCE0AF5C42DB8B65FE80CC28B3F3BDDEE2E4C8D0F1ADB44C13F4C4C5092D90F05B1E7D4CB4BB1110FDA7686F8589BE3D5DA8DCA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Windows\System32\msiexec.exe
                                                              File Type:Composite Document File V2 Document, Cannot read section info
                                                              Category:dropped
                                                              Size (bytes):20480
                                                              Entropy (8bit):1.5441481359223377
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:E1D34AA1EAA172F1B7E564CE8015C7C6
                                                              SHA1:B44386F7E25FEA31209E83094FA7265AB0815547
                                                              SHA-256:2EB3095A5B1172C384B0C396FFFDEA1E5AA0E03E92A430F8E3D17EDC6C01CE55
                                                              SHA-512:2EED7B6F765691483DC536AA512A4DAA1AA7D203D738123B86EF31F5FA57187DC49D1CE9B570FC813938B98006EC1579B60F4BE07C46C984A2D9BA6B19A011AF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (9762), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):9762
                                                              Entropy (8bit):5.56504814362583
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A2E93CDA340D22B3E032CFE29A0271A0
                                                              SHA1:AFFBEA8DDA13340CA5A25A06C6DF17535F019605
                                                              SHA-256:E4580E4DEDE2F4595649502C097EC7FAE012E7C98C8D323CB95D4FF2ED734487
                                                              SHA-512:FD3D6C669669A1EB7971A6028369C934171E646D067F01A30BE58C880A23B00BE4B29D8603E74CE985C3F4CF88A3E37249DB9C6250E6F162273FF3A9E25DA4B6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/chunks/568-a37877debfb19805.js
                                                              Preview:(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[568],{29367:function(e){"use strict";let t=new Set(["ENOTFOUND","ENETUNREACH","UNABLE_TO_GET_ISSUER_CERT","UNABLE_TO_GET_CRL","UNABLE_TO_DECRYPT_CERT_SIGNATURE","UNABLE_TO_DECRYPT_CRL_SIGNATURE","UNABLE_TO_DECODE_ISSUER_PUBLIC_KEY","CERT_SIGNATURE_FAILURE","CRL_SIGNATURE_FAILURE","CERT_NOT_YET_VALID","CERT_HAS_EXPIRED","CRL_NOT_YET_VALID","CRL_HAS_EXPIRED","ERROR_IN_CERT_NOT_BEFORE_FIELD","ERROR_IN_CERT_NOT_AFTER_FIELD","ERROR_IN_CRL_LAST_UPDATE_FIELD","ERROR_IN_CRL_NEXT_UPDATE_FIELD","OUT_OF_MEM","DEPTH_ZERO_SELF_SIGNED_CERT","SELF_SIGNED_CERT_IN_CHAIN","UNABLE_TO_GET_ISSUER_CERT_LOCALLY","UNABLE_TO_VERIFY_LEAF_SIGNATURE","CERT_CHAIN_TOO_LONG","CERT_REVOKED","INVALID_CA","PATH_LENGTH_EXCEEDED","INVALID_PURPOSE","CERT_UNTRUSTED","CERT_REJECTED","HOSTNAME_MISMATCH"]);e.exports=e=>!t.has(e&&e.code)},91012:function(e,t,r){"use strict";var n=r(85893),i=r(66123),a=r(28784),o=r(94687),s=r.n(o);let{NEXT_PUBLIC_ARTICULATE_TERMS_OF_USE_UR
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (7796), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):7796
                                                              Entropy (8bit):5.344891491025456
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:DA6C1F57443258E089C61307E9888C0A
                                                              SHA1:522F046E210E643F84092A77AC96AC28BC538451
                                                              SHA-256:92723793778670C3FC98B43EDE3F76659BE759794E5D4BDA1F520CAB5D3FAB1F
                                                              SHA-512:D3024D05D902D3916B5745BF4E761240137F45C460B5AEE8BA551A17882F0AB459C939B013109D20779123D7246FF7A25B2B8F6C31F8AFE9CB6B6827B44514F0
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/css/2d00d55d6eea628a.css
                                                              Preview:.AgreeTerms_linkText__xjQj9{line-height:2;color:#6a737c;font-family:lato;font-size:1.3rem;font-size:1.2rem;text-decoration:underline}.AgreeTerms_linkText__xjQj9:hover,.AgreeTerms_linkText__xjQj9:visited{color:#6a737c}.AgreeTerms_text__JxygM{color:#6a737c;font-family:lato;font-size:1.2rem;line-height:2;max-width:100%;width:41rem}.CheckBox_boxChecked__JI3KP{color:#313537;display:flex;flex-wrap:wrap}.CheckBox_boxUnchecked__r8lsp{color:#6a737c;display:flex;flex-wrap:wrap}.CheckBox_checkMarkIcon__7fujA{border:.1rem solid #6a737c;flex-shrink:0;height:2rem;margin-right:1rem;width:2rem}.CheckBox_checkbox__0ixDE:checked+.CheckBox_checkMarkIcon__7fujA path{stroke:#4a4a4a}.CheckBox_checkbox__0ixDE:focus-visible+.CheckBox_checkMarkIcon__7fujA{border-color:#52b4e6}.CheckBox_checkbox__0ixDE{cursor:pointer;height:2rem;opacity:0;position:absolute;width:2rem}.CheckBox_checkMarkIconError__Pjv55{border-color:#ac3336}.CheckBox_container__3Nf5c{color:#313537;cursor:pointer;display:flex;font-family:lato;fon
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:JSON data
                                                              Category:dropped
                                                              Size (bytes):48
                                                              Entropy (8bit):4.198934896284056
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:23693DC9A96ACD79C441EDF6EDE7566D
                                                              SHA1:3743F6F0110C3587827705E514E9EEBAD303E509
                                                              SHA-256:3ECBE22E502BB505DE8029ACBDDAC50705DCD826883B2241484B3C5020565499
                                                              SHA-512:EF5B8B6BD03F1C6C8594D5FFC778380A8767890C281D36CABE4F178A1C46BFE6C14A76A18ABA13AEE1C17FCF24FC026155B34A98243C8A64374FBACB4D1C8975
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{"token":"6408445b-dba6-4153-ae5c-b39b81104e4a"}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):43
                                                              Entropy (8bit):4.301508290129998
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:AD8B6F08655797587CDEC719A94EFE59
                                                              SHA1:182ADF5A140796F81E930649D05654DBF22FD5B7
                                                              SHA-256:77D5FE96DEFD6C8C1E3B0466B4827CF83DC7E5C727A10177E115D25132FA86F6
                                                              SHA-512:519A8EA7CE2ED8661CC72D58BC0C02E721EF8E64608F4D2E26A56A970D43EBBF21BDF579C543EE1DFD667DA8F87467C60111A3E6D246D435A5C2D066AB88EFA3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://googleads.g.doubleclick.net/pagead/viewthroughconversion/663970415/?random=1729587437881&cv=11&fst=1729587437881&bg=ffffff&guid=ON&async=1&gtm=45be4ah0v872251761z871205897za201zb71205897&gcd=13l3l3l3l1l1&dma=0&tag_exp=101686685~101823848~101836706&u_w=1280&u_h=1024&url=https%3A%2F%2Fid.articulate.com%2F&hn=www.googleadservices.com&frm=0&tiba=Articulate%20-%20Sign%20In&npa=0&us_privacy=1-N-&pscdl=noapi&auid=1169443646.1729587436&uaa=x86&uab=64&uafvl=Google%2520Chrome%3B117.0.5938.149%7CNot%253BA%253DBrand%3B8.0.0.0%7CChromium%3B117.0.5938.149&uamb=0&uam=&uap=Windows&uapv=10.0.0&uaw=0&fledge=1&rfmt=3&fmt=4
                                                              Preview:window['google_noFurtherRedirects'] = true;
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):20
                                                              Entropy (8bit):3.8464393446710154
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:3FC327CC2C1588C43EED8DE4060A169C
                                                              SHA1:55EE9B87F81DA697F0B59D07FAF010D4DB3586F9
                                                              SHA-256:7404F92B3CCDDA7A2EC298170FD427095D8DE3BED1F8BDF95D10295146175C75
                                                              SHA-512:5DC917B5B060467379B5886ABBFB2AFE63D172C5E3B4A75395724B36F4656C606864516FCA7026497148EA55DA999B79FA1E4A7556E28CD1697B6680BA89879B
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://content-autofill.googleapis.com/v1/pages/ChVDaHJvbWUvMTE3LjAuNTkzOC4xNDkSEAkgHb-XiwqqFBIFDYOoWz0=?alt=proto
                                                              Preview:Cg0KCw2DqFs9GgQIZBgC
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (7726)
                                                              Category:downloaded
                                                              Size (bytes):335212
                                                              Entropy (8bit):5.606800804019483
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C34B118860186F82D6D81CFF748F723F
                                                              SHA1:15FDEA16C76576B8C567791DB9EE588C40C8BD16
                                                              SHA-256:8B96263D5598FCE84AD14F34BB680718204AA42BF0AADC34E3C08E2714BCDF4F
                                                              SHA-512:1F0AAFF1702A9A7307CDCD094B17B06F06C6865A2137DFD8212ADF8829AC58447BAAEEAB558E50B33D1F3D467E8AA808E1E83DA61019B4A60C66C89EF6D6BA3C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://www.googletagmanager.com/gtag/js?id=G-FX3HXD9SHZ&l=dataLayer&cx=c
                                                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"3",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":19,"vtp_value":true,"tag_id":106},{"function":"__ogt_dma","priority":19,"vtp_delegationMode":"ON","vtp_dmaDefault":"DENIED","tag_id":108},{"function":"__ogt_1p_data_v2","priority":19,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECT
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (2356)
                                                              Category:dropped
                                                              Size (bytes):248954
                                                              Entropy (8bit):5.536303409206278
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:2482437145B0F85858567A6E69C38744
                                                              SHA1:611BE4450BD06F26931982C393133A8A174294C2
                                                              SHA-256:706D2E2E6AB89765AC03BDAE9ABE279DE803F2EEF1A364B89A743B9099A27765
                                                              SHA-512:07028FABCA2F235226FACFA42F44B8BE50AA5BF249744AD48A2D7816F471441FD58847874B79B09DC8DB7510401AD482DFF38F51485183E8EDFC9D5EA0AAA260
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"}],. "tags":[{"function":"__rep","vtp_containerId":"AW-663970415","vtp_remoteConfig":["map","enhanced_conversions",["map"]],"tag_id":1},{"function":"__ccd_pre_auto_pii","vtp_instanceDestinationId":"AW-663970415","tag_id":3}],. "predicates":[{"function":"_eq","arg0":["macro",0],"arg1":"gtm.js"},{"function":"_eq","arg0":["macro",0],"arg1":"gtm.init"}],. "rules":[[["if",0],["add",0]],[["if",1],["add",1]]].},."runtime":[ [50,"__ccd_pre_auto_pii",[46,"a"],[50,"q",[46,"s"],[52,"t",[16,[15,"s"],"userData"]],[52,"u",[30,[18,[2,[15,"t"],"indexOf",[7,"@gmail."]],[27,1]],[18,[2,[15,"t"],"indexOf",[7,"@googlemail."]],[27,1]]]],[36,[0,[0,[0,[0,[0,[0,[16,[15,"s"],"tagName"],":"],[16,[15,"s"],"isVisible"]],":"],[17,[15,"t"],"length"]],":"],[15,"u"]]]],[52,"b",[13,[41,"$0"],[3,"$0",["require","internal.getFlags"]],["$0"]]],[52,"c",["require","internal.setPr
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (358)
                                                              Category:downloaded
                                                              Size (bytes):534
                                                              Entropy (8bit):5.024078119209118
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:635EB28EFCCCD0ADC7259F035D859446
                                                              SHA1:5FDA4726AD26DAC19D6D7A005FB7784C7600C0E9
                                                              SHA-256:56EE1E2611AF1828A330EC300C7BB7C19E5BF3DF378B46EF361CE42587378FCD
                                                              SHA-512:AEBBB84165DB8FA80FB7E1910E5CB069E6F4A8721DC71D723B550698CD788A32D4AE070AA0295FC3BB8084517D5492DE0987E61214CAD1A58780060E5B6F540A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://cdn.articulate.com/fontawesome/kit/css/regular.min.css
                                                              Preview:/*!. * Font Awesome Pro 6.4.0 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license (Commercial License). * Copyright 2023 Fonticons, Inc.. */.:host,:root{--fa-style-family-classic:"Font Awesome 6 Pro";--fa-font-regular:normal 400 1em/1 "Font Awesome 6 Pro"}@font-face{font-family:"Font Awesome 6 Pro";font-style:normal;font-weight:400;font-display:block;src:url(../webfonts/fa-regular-400.woff2) format("woff2"),url(../webfonts/fa-regular-400.ttf) format("truetype")}.fa-regular,.far{font-weight:400}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Unicode text, UTF-8 text, with very long lines (8317)
                                                              Category:downloaded
                                                              Size (bytes):8528
                                                              Entropy (8bit):5.24500620261903
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:74633838CF49AEDFA85D6CA594E24DBB
                                                              SHA1:14B61C1D14D37C8BF70FFEE6E7F4C83064F7BE05
                                                              SHA-256:9DCE6B1E71916BBA6D8E815C7F669A94460AF90B904DB9AD9458495F4EF29BA9
                                                              SHA-512:961BF74AA2528526AE8DD1284ABDAF87BF2F675A47BEA836DCAFC6CC8A32BB0E3E4A46655D49EB0533F4EB4ED765FEB45F09C5A2EF0492F519FCB83A4A7FC17E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/chunks/358-2762942c7a1ced9a.js
                                                              Preview:(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[358],{94184:function(t,e){var r;/*!..Copyright (c) 2018 Jed Watson...Licensed under the MIT License (MIT), see..http://jedwatson.github.io/classnames.*/!function(){"use strict";var n={}.hasOwnProperty;function u(){for(var t=[],e=0;e<arguments.length;e++){var r=arguments[e];if(r){var o=typeof r;if("string"===o||"number"===o)t.push(r);else if(Array.isArray(r)){if(r.length){var c=u.apply(null,r);c&&t.push(c)}}else if("object"===o){if(r.toString!==Object.prototype.toString&&!r.toString.toString().includes("[native code]")){t.push(r.toString());continue}for(var i in r)n.call(r,i)&&r[i]&&t.push(i)}}}return t.join(" ")}t.exports?(u.default=u,t.exports=u):void 0!==(r=(function(){return u}).apply(e,[]))&&(t.exports=r)}()},77550:function(t,e,r){"use strict";r.d(e,{Z:function(){return a}});var n=r(81353),u=r(12155),o=r(35643),c=function(){function t(t,e){this.xf=e,this.f=t,this.found=!1}return t.prototype["@@transducer/init"]=o.Z.init,t.pro
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:JSON data
                                                              Category:dropped
                                                              Size (bytes):41
                                                              Entropy (8bit):4.07391321234758
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:8C11E15DB0F3E1EA036EDBA78ABF1151
                                                              SHA1:72F74F85AA08C65E9927B8D53916A7C45A102D44
                                                              SHA-256:AA011ED383CB780028A85CAAA0DDA67DCE19B0F4BC596F4F708D1857015C1362
                                                              SHA-512:985C2D0148E254CA3386C955DB8F18C02639F156D0FF565BADA0CF91E52A691C504FAEA3A109F9D7CDB4A9C1F6CF48B343EEEEC5803941AE56599411388E4B9A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{"url":"https://scout.us2.salesloft.com"}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (7726)
                                                              Category:dropped
                                                              Size (bytes):335210
                                                              Entropy (8bit):5.606850125735175
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:031719321799AA2CD48298F3448B65B4
                                                              SHA1:9AC71DB2CA5D2EAF0236B5AC09C536D54BB67C1C
                                                              SHA-256:273E8334FE0B6702277401BC21EC148063BD343C0E3BBA9821F443DB6154E144
                                                              SHA-512:18074CD53A9BDA2DBBEBD2225AEE4C27BB845BCE573DE15403CF1C2EB60BA2FCC1C2E9188D529EB465CE919E73171371D17D6FDAF679BC932E8DE0C812398977
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"3",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":19,"vtp_value":true,"tag_id":106},{"function":"__ogt_dma","priority":19,"vtp_delegationMode":"ON","vtp_dmaDefault":"DENIED","tag_id":108},{"function":"__ogt_1p_data_v2","priority":19,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SELECTOR","vtp_autoEmailEnabled":true,"vtp_postalCodeValue":"","vtp_lastNameValue":"","vtp_phoneType":"CSS_SELECTOR","vtp_phoneValue":"","vtp_streetType":"CSS_SELECTOR","vtp_autoPhoneEnabled":false,"vtp_postalCodeType":"CSS_SELECT
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (5191), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):5191
                                                              Entropy (8bit):5.206693871502905
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:09787304BCAF8E749DA5B5E26F5995CE
                                                              SHA1:ECFCBBE9F527BCA6D3F8EBDFAED51E74173578F2
                                                              SHA-256:71BB5AB80621684CEF70B176CA0BE49A540CE020B5A4780F5B5B9A1D5D97368A
                                                              SHA-512:DCC572F074498EEA8424767690CB6B4916C2CE174732C0C21D23F2AB4D108BBD9CED545FBE16C504DADC2FE861CD2B3A5D6459DB678AF2E26580C6EC981E09A3
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/css/54576ec8590cd1a8.css
                                                              Preview:@font-face{font-family:Lato;font-style:normal;font-display:swap;font-weight:100;src:local("Lato Thin "),local("Lato-Thin"),url(/_next/static/media/lato-latin-100.e6168f23.woff2) format("woff2"),url(/_next/static/media/lato-latin-100.6c58bfe2.woff) format("woff")}@font-face{font-family:Lato;font-style:italic;font-display:swap;font-weight:100;src:local("Lato Thin italic"),local("Lato-Thinitalic"),url(/_next/static/media/lato-latin-100italic.dadd9939.woff2) format("woff2"),url(/_next/static/media/lato-latin-100italic.d3901625.woff) format("woff")}@font-face{font-family:Lato;font-style:normal;font-display:swap;font-weight:300;src:local("Lato Light "),local("Lato-Light"),url(/_next/static/media/lato-latin-300.d50c00d5.woff2) format("woff2"),url(/_next/static/media/lato-latin-300.b0d3cf62.woff) format("woff")}@font-face{font-family:Lato;font-style:italic;font-display:swap;font-weight:300;src:local("Lato Light italic"),local("Lato-Lightitalic"),url(/_next/static/media/lato-latin-300italic.657
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Unicode text, UTF-8 text, with very long lines (41169)
                                                              Category:downloaded
                                                              Size (bytes):41172
                                                              Entropy (8bit):5.505998162296305
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:0AA5002702487976D570A640C408EBA5
                                                              SHA1:48930F22A2396DF313CCDFCB91CAC20E38F2B06B
                                                              SHA-256:4E8276AEA0A3C7FE3600E6718C7F484D49C347C8D5763D89BE95900D526A14DA
                                                              SHA-512:37A9D609DB21EE1E696CB437C02F0F6410925EB10B6353C0CDF95DB265E342F0BC3D2AE1851D209E4517D978B7CCBE8AD56F98247FA865AE405FAFD4D2E62CDA
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://snap.licdn.com/li.lms-analytics/insight.min.js
                                                              Preview:!function(){"use strict";function n(n,t,e){return t in n?Object.defineProperty(n,t,{value:e,enumerable:!0,configurable:!0,writable:!0}):n[t]=e,n}var t,e,r,i,o={ADVERTISING:"ADVERTISING",ANALYTICS_AND_RESEARCH:"ANALYTICS_AND_RESEARCH",FUNCTIONAL:"FUNCTIONAL"},a="GUEST",u="MEMBER",c=0,l=1,d=2,s=(n(t={},a,"li_gc"),n(t,u,"li_mc"),t),f=function vr(){var n=arguments.length>0&&arguments[0]!==undefined?arguments[0]:null,t=arguments.length>1&&arguments[1]!==undefined?arguments[1]:null,e=arguments.length>2&&arguments[2]!==undefined?arguments[2]:null,r=arguments.length>3&&arguments[3]!==undefined?arguments[3]:null;for(var i in function(n,t){if(!(n instanceof t))throw new TypeError("Cannot call a class as a function")}(this,vr),n=n||{},this.consentAvailable=!1,this.issuedAt=t,this.userMode=e,this.optedInConsentMap={},o)n[i]=n[i]||c,n[i]!==c&&(this.consentAvailable=!0),this.optedInConsentMap[i]=n[i]===l||n[i]===c&&r===l},v=(e=[o.ADVERTISING,o.ANALYTICS_AND_RESEARCH,o.FUNCTIONAL],r=[c,l,d,c],i=new R
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (11427)
                                                              Category:downloaded
                                                              Size (bytes):308400
                                                              Entropy (8bit):5.609457835773629
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:4DEF109BE084692010D2DAEE6DF6E8DA
                                                              SHA1:2E9981C575A921CCB28E0CA7ED036FA174177403
                                                              SHA-256:F929C4AA866B839F167F042CFDB187138EE57A518E4722534A9F7F2F768DC6FA
                                                              SHA-512:0C1406F3CB1F3110F2B112545790A1A5F52A43AEB9FE18CF22561172474679CA1D04878E65A7A5C77BE4AE276ED4E20A65E48785F4F63A2B353B752ACB96DBD6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://www.googletagmanager.com/gtag/js?id=G-0LXMVHBMX2&cx=c&_slc=1
                                                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"3",. . "macros":[{"function":"__e"},{"function":"__c","vtp_value":""},{"function":"__c","vtp_value":0}],. "tags":[{"function":"__ogt_ga_send","priority":17,"vtp_value":true,"tag_id":108},{"function":"__ogt_referral_exclusion","priority":17,"vtp_includeConditions":["list","articulate\\.com"],"tag_id":110},{"function":"__ogt_session_timeout","priority":17,"vtp_sessionMinutes":30,"vtp_sessionHours":0,"tag_id":111},{"function":"__ogt_dma","priority":17,"vtp_delegationMode":"ON","vtp_dmaDefault":"DENIED","tag_id":112},{"function":"__ogt_1p_data_v2","priority":17,"vtp_isAutoEnabled":true,"vtp_autoCollectExclusionSelectors":["list",["map","exclusionSelector",""]],"vtp_isEnabled":true,"vtp_cityType":"CSS_SELECTOR","vtp_manualEmailEnabled":false,"vtp_firstNameType":"CSS_SELECTOR","vtp_countryType":"CSS_SELECTOR","vtp_cityValue":"","vtp_emailType":"CSS_SELECTOR","vtp_regionType":"CSS_SE
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:JSON data
                                                              Category:dropped
                                                              Size (bytes):2
                                                              Entropy (8bit):1.0
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:99914B932BD37A50B983C5E7C90AE93B
                                                              SHA1:BF21A9E8FBC5A3846FB05B4FA0859E0917B2202F
                                                              SHA-256:44136FA355B3678A1146AD16F7E8649E94FB4FC21FE77E8310C060F61CAAFF8A
                                                              SHA-512:27C74670ADB75075FAD058D5CEAF7B20C4E7786C83BAE8A32F626F9782AF34C9A33C2046EF60FD2A7878D378E29FEC851806BBD9A67878F3A9F1CDA4830763FD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (18222), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):18222
                                                              Entropy (8bit):5.356633823198119
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:51E064774EC5590098F3DD6A9F5C362F
                                                              SHA1:B0A4D13E39D472E21142365684E6DAAF86AA3E51
                                                              SHA-256:A1987E73713B1E646A708787563A385BF73198B0FAA4715FB2DB78ADD92043DA
                                                              SHA-512:759B119F1E4A440954F8C2783BA84C1D20110BEA074F013549C306D22E57FDD518317A646E448454C49CD846E12E1B814962AEB6790906B701C3DDBBB00E82FD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/chunks/700-0c0a7f349015eefd.js
                                                              Preview:(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[700],{23851:function(e,t,c){"use strict";var n=c(85893),r=c(44611),a=c.n(r);let i=e=>{let{children:t,titleText:c}=e;return(0,n.jsxs)("div",{children:[(0,n.jsx)("h1",{className:a().title,children:c}),(0,n.jsx)("p",{className:a().subHeader,children:t})]})};t.Z=i},99409:function(e,t,c){"use strict";var n=c(85893),r=c(66123),a=c(49216),i=c.n(a);let{NEXT_PUBLIC_ARTICULATE_TERMS_OF_USE_URI:s,NEXT_PUBLIC_WWW_URI:o}=(0,r.xk)(),l=()=>(0,n.jsx)("nav",{className:i().footer,children:(0,n.jsxs)("ul",{children:[(0,n.jsxs)("li",{children:["\xa9 ",new Date().getFullYear()," Articulate Global, LLC"]}),(0,n.jsx)("li",{children:(0,n.jsx)("a",{href:s,target:"_blank",children:"Terms"})}),(0,n.jsx)("li",{children:(0,n.jsx)("a",{href:"".concat(o,"/trust/privacy"),target:"_blank",children:"Privacy"})}),(0,n.jsx)("li",{children:(0,n.jsx)("a",{href:"#",onClick:()=>Osano.cm.showDrawer("osano-cm-dom-info-dialog-open"),children:"Cookie Preferences"})})]})});
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (65201)
                                                              Category:dropped
                                                              Size (bytes):141074
                                                              Entropy (8bit):5.268626197706269
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C0D21CF3BE111341CB36153EC9177E9A
                                                              SHA1:0169229D7F67571A18A62DDCBD91E4F873045D02
                                                              SHA-256:AD2AA3AC062CDEF13AF1C2E28C6E95E36732484BD756FB6194A105B61AF7C057
                                                              SHA-512:2F73EA0B027B234BE3EC507BAFF41F9CD24D4C60CE2A737D95C190E3730F395E14539EB642A0A20E86F5A80FC890DC7757B00D4CF13387B87C6B2C69D49F0DDC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:"use strict";(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[774],{64448:function(e,n,t){/**. * @license React. * react-dom.production.min.js. *. * Copyright (c) Facebook, Inc. and its affiliates.. *. * This source code is licensed under the MIT license found in the. * LICENSE file in the root directory of this source tree.. */var r,l,a,u,o,i,s=t(67294),c=t(63840);function f(e){for(var n="https://reactjs.org/docs/error-decoder.html?invariant="+e,t=1;t<arguments.length;t++)n+="&args[]="+encodeURIComponent(arguments[t]);return"Minified React error #"+e+"; visit "+n+" for the full message or use the non-minified dev environment for full errors and additional helpful warnings."}var d=new Set,p={};function m(e,n){h(e,n),h(e+"Capture",n)}function h(e,n){for(p[e]=n,e=0;e<n.length;e++)d.add(n[e])}var g=!("undefined"==typeof window||void 0===window.document||void 0===window.document.createElement),v=Object.prototype.hasOwnProperty,y=/^[:A-Z_a-z\u00C0-\u00D6\u00D8-\u00F6\u00F8-\u02FF\u0
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (17992)
                                                              Category:downloaded
                                                              Size (bytes):345489
                                                              Entropy (8bit):5.576124276723984
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:FB54694670661AD7D81EBF5EDB6466D7
                                                              SHA1:17730F7BB18F505748F30DE23449200925951D17
                                                              SHA-256:7DB2E1EA220D1B9A6DAB180215273EC4F3D7E8903CC5F1A73DE46BF2C0AB0AAD
                                                              SHA-512:FBB86B5B33BC260651DA4C2CC0953C69AFBCE0F3CC3DD63C11CD2FC5A8F0693225140056C089CD1057863DB1BE07DDC35E079D44C18304E74E07DBAB4F7179D6
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://www.googletagmanager.com/gtm.js?id=GTM-K9R2NB
                                                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. . (function(w,g){w[g]=w[g]||{};. w[g].e=function(s){return eval(s);};})(window,'google_tag_manager');. .(function(){..var data = {."resource": {. "version":"104",. . "macros":[{"function":"__v","vtp_name":"nojscript","vtp_dataLayerVersion":2},{"function":"__e"},{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__r"},{"function":"__cid"},{"function":"__smm","vtp_setDefaultValue":true,"vtp_input":["macro",4],"vtp_defaultValue":"NOTRACK","vtp_map":["list",["map","key","GTM-WJDFT6","value","UA-68728-6"],["map","key","GTM-K9R2NB","value","UA-68728-1"],["map","key","GTM-M3QKPX","value","UA-68728-6"]]},{"function":"__r"},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__v","vtp_name":"action","vtp_dataLayerVersion":2},{"function":"__v","vtp_name":"category","vtp_dataLayerVersion":2},
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (65536), with no line terminators
                                                              Category:dropped
                                                              Size (bytes):101524
                                                              Entropy (8bit):5.354983223653281
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F8253F2D6D5828A497F3265F564115A0
                                                              SHA1:02D3643CAA9F0D3B83F53D3C6F3DBC853C9798FC
                                                              SHA-256:89FEA76A18AF4BC91D315DE23C77CA2B1EDAADD1FF4782088D76888FD8D3B687
                                                              SHA-512:0DF901BDDE7948D6775F4E93D19FB64E5A2EF7E167AFEAF7392FFDC82417367F3D3C344FEA42F20E603EEFB358C2CC9E3A79892A4BBD1E81A666F027CB472697
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[179],{60932:function(e,t){"use strict";function r(e,t,r,n,a,o,i){try{var l=e[o](i),s=l.value}catch(e){r(e);return}l.done?t(s):Promise.resolve(s).then(n,a)}function n(e){return function(){var t=this,n=arguments;return new Promise(function(a,o){var i=e.apply(t,n);function l(e){r(i,a,o,l,s,"next",e)}function s(e){r(i,a,o,l,s,"throw",e)}l(void 0)})}}Object.defineProperty(t,"Z",{enumerable:!0,get:function(){return n}})},6495:function(e,t){"use strict";function r(){return(r=Object.assign||function(e){for(var t=1;t<arguments.length;t++){var r=arguments[t];for(var n in r)Object.prototype.hasOwnProperty.call(r,n)&&(e[n]=r[n])}return e}).apply(this,arguments)}function n(){return r.apply(this,arguments)}Object.defineProperty(t,"Z",{enumerable:!0,get:function(){return n}})},92648:function(e,t){"use strict";function r(e){return e&&e.__esModule?e:{default:e}}Object.defineProperty(t,"Z",{enumerable:!0,get:function(){return r}})},91598:function(
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (5960), with no line terminators
                                                              Category:dropped
                                                              Size (bytes):5960
                                                              Entropy (8bit):5.026744862224883
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:7C98CF8F4D3A8F2BBBE56080E487E390
                                                              SHA1:18FF6C2F5E6889569A2198B3F29C3D8278B87A9B
                                                              SHA-256:CBD3445CF704A2C09E9CA5ADC1C41460FA1E977F495C4D7E0F22CED197F15C4D
                                                              SHA-512:CE3448818DDFFB059134F5D71680ADC2CE8146F0E7583E826CA42A3967BCF90A6DB26E561BF8D85311DE1706AFFD21B628C9D79997CB778220C5CD2D72CF64AD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:"use strict";(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[378],{59211:function(n,t,r){var e=(0,r(93993).Z)(function(n){return function(){return n}});t.Z=e},9821:function(n,t,r){r.d(t,{Z:function(){return c}});var e=r(71387),u=r(93993),i=r(53459),o=(0,u.Z)(function(n){return(0,i.Z)(n)?n.split("").reverse().join(""):Array.prototype.slice.call(n,0).reverse()});function c(){if(0==arguments.length)throw Error("compose requires at least one argument");return e.Z.apply(this,o(arguments))}},8969:function(n,t,r){r.d(t,{Z:function(){return e}});function e(n,t){switch(n){case 0:return function(){return t.apply(this,arguments)};case 1:return function(n){return t.apply(this,arguments)};case 2:return function(n,r){return t.apply(this,arguments)};case 3:return function(n,r,e){return t.apply(this,arguments)};case 4:return function(n,r,e,u){return t.apply(this,arguments)};case 5:return function(n,r,e,u,i){return t.apply(this,arguments)};case 6:return function(n,r,e,u,i,o){return t.apply(thi
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Unicode text, UTF-8 text, with very long lines (1145), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):1165
                                                              Entropy (8bit):4.798567672943429
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:0AD83F76C16B370F5489E6996D9CC4BF
                                                              SHA1:B1942AE09EBEB3E5BF9EF2478F37E616EBF8A759
                                                              SHA-256:FC3B1643A1FE3422BE01B5C78FD90C638C145E723F72261109459E5FEF6CD614
                                                              SHA-512:8877FD13E7B54D567841A3DCC0B9EF050A858E3B13F6379153C8E880B9FCF82DCC5A136EE9133AF465A8B71692584C92168948056FBC7E810149C7A8CC680D6A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://cdn.articulate.com/fontawesome/kit/css/custom-icons.min.css
                                                              Preview:@charset "utf-8";.fak.fa-articulate:before,.fa-kit.fa-articulate:before{content:"."}.fak.fa-copy-regular:before,.fa-kit.fa-copy-regular:before{content:"."}.fak.fa-padding-bottom:before,.fa-kit.fa-padding-bottom:before{content:"."}.fak.fa-padding-left:before,.fa-kit.fa-padding-left:before{content:"."}.fak.fa-padding-left-right:before,.fa-kit.fa-padding-left-right:before{content:"."}.fak.fa-padding-right:before,.fa-kit.fa-padding-right:before{content:"."}.fak.fa-padding-top:before,.fa-kit.fa-padding-top:before{content:"."}.fak.fa-padding-top-bottom:before,.fa-kit.fa-padding-top-bottom:before{content:"."}.fak.fa-rise-com:before,.fa-kit.fa-rise-com:before{content:"."}.fak.fa-rise-com-2:before,.fa-kit.fa-rise-com-2:before{content:"."}.fak,.fa-kit{-moz-osx-font-smoothing:grayscale;-webkit-font-smoothing:antialiased;display:var(--fa-display,inline-block);font-variant:normal;text-rendering:auto;font-family:Font Awesome Kit;font-style:normal;line-height:1}@font-face{font-fam
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (1591), with no line terminators
                                                              Category:dropped
                                                              Size (bytes):1591
                                                              Entropy (8bit):5.200077094126522
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C100F2C3502BDD0325C847522B695EEB
                                                              SHA1:C6D8D054CB401BD50D77A3D237647209CC2BB729
                                                              SHA-256:56D784859DD6FEC35EBE85E8ACF3C6DBF90FF38E1DB6E0184F36EBDA462D34E8
                                                              SHA-512:B8C41B5614B8378671E442E1EBA9C9B9801E1C203E9C46A4818EF482283F28F81F568BC46A80016C4B3F8AAD5DAB0E23550A9B6E39F7FBED07F5882415566954
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:!function(){"use strict";var e,n,r,t,o={},u={};function i(e){var n=u[e];if(void 0!==n)return n.exports;var r=u[e]={exports:{}},t=!0;try{o[e](r,r.exports,i),t=!1}finally{t&&delete u[e]}return r.exports}i.m=o,e=[],i.O=function(n,r,t,o){if(r){o=o||0;for(var u=e.length;u>0&&e[u-1][2]>o;u--)e[u]=e[u-1];e[u]=[r,t,o];return}for(var f=1/0,u=0;u<e.length;u++){for(var r=e[u][0],t=e[u][1],o=e[u][2],c=!0,l=0;l<r.length;l++)f>=o&&Object.keys(i.O).every(function(e){return i.O[e](r[l])})?r.splice(l--,1):(c=!1,o<f&&(f=o));if(c){e.splice(u--,1);var a=t();void 0!==a&&(n=a)}}return n},i.n=function(e){var n=e&&e.__esModule?function(){return e.default}:function(){return e};return i.d(n,{a:n}),n},i.d=function(e,n){for(var r in n)i.o(n,r)&&!i.o(e,r)&&Object.defineProperty(e,r,{enumerable:!0,get:n[r]})},i.g=function(){if("object"==typeof globalThis)return globalThis;try{return this||Function("return this")()}catch(e){if("object"==typeof window)return window}}(),i.o=function(e,n){return Object.prototype.hasOwn
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (2343)
                                                              Category:dropped
                                                              Size (bytes):52916
                                                              Entropy (8bit):5.51283890397623
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:575B5480531DA4D14E7453E2016FE0BC
                                                              SHA1:E5C5F3134FE29E60B591C87EA85951F0AEA36EE1
                                                              SHA-256:DE36E50194320A7D3EF1ACE9BD34A875A8BD458B253C061979DD628E9BF49AFD
                                                              SHA-512:174E48F4FB2A7E7A0BE1E16564F9ED2D0BBCC8B4AF18CB89AD49CF42B1C3894C8F8E29CE673BC5D9BC8552F88D1D47294EE0E216402566A3F446F04ACA24857A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:(function(){/*.. Copyright The Closure Library Authors.. SPDX-License-Identifier: Apache-2.0.*/.var n=this||self,p=function(a,b){a=a.split(".");var c=n;a[0]in c||"undefined"==typeof c.execScript||c.execScript("var "+a[0]);for(var d;a.length&&(d=a.shift());)a.length||void 0===b?c=c[d]&&c[d]!==Object.prototype[d]?c[d]:c[d]={}:c[d]=b};function q(){for(var a=r,b={},c=0;c<a.length;++c)b[a[c]]=c;return b}function u(){var a="ABCDEFGHIJKLMNOPQRSTUVWXYZ";a+=a.toLowerCase()+"0123456789-_";return a+"."}var r,v;.function aa(a){function b(k){for(;d<a.length;){var m=a.charAt(d++),l=v[m];if(null!=l)return l;if(!/^[\s\xa0]*$/.test(m))throw Error("Unknown base64 encoding at char: "+m);}return k}r=r||u();v=v||q();for(var c="",d=0;;){var e=b(-1),f=b(0),h=b(64),g=b(64);if(64===g&&-1===e)return c;c+=String.fromCharCode(e<<2|f>>4);64!=h&&(c+=String.fromCharCode(f<<4&240|h>>2),64!=g&&(c+=String.fromCharCode(h<<6&192|g)))}};var w={},y=function(a){w.TAGGING=w.TAGGING||[];w.TAGGING[a]=!0};var ba=Array.isArray,c
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:dropped
                                                              Size (bytes):20
                                                              Entropy (8bit):3.384183719779189
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:67C39AC430E3AE5B225573FB513202FE
                                                              SHA1:B2DF1199C0BCD7AAFF22B2984043D992F9CEC93E
                                                              SHA-256:BF3FEA0EADD92B125F85594941718F4FFC8F9FF971A4522C621334839C249DBB
                                                              SHA-512:EDEE59401822B40A4462B685364057CF9A2E1059CE345A46D8D7835A73D9EBE52ABFA821707AFBA6A283E90BE9009185B96F0B69D77799AF3084837EAB480F97
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:2024-10-22T08:57:19Z
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (2356)
                                                              Category:downloaded
                                                              Size (bytes):248956
                                                              Entropy (8bit):5.5363338588036655
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:753BA3CFF3D224D596DF587A3E0399E6
                                                              SHA1:803AE8D0E8F191AAE829AECAE6445E71D3448853
                                                              SHA-256:BBB2E75FFACBBA4BAD21D05E99CE45DD95FF02F72A1D8CC6833628218EE2CBF6
                                                              SHA-512:706DF006F9E44A4BB86154CE3FB1C5F15954B9E8D9644D85F153BDEA94311AF6C9E1339828DEA913AA60A65CACD56AA02A8019E3DB60540F9EE7A6B4701E2F5D
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://www.googletagmanager.com/gtag/destination?id=AW-663970415&l=dataLayer&cx=c
                                                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. .(function(){..var data = {."resource": {. "version":"1",. . "macros":[{"function":"__e"}],. "tags":[{"function":"__rep","vtp_containerId":"AW-663970415","vtp_remoteConfig":["map","enhanced_conversions",["map"]],"tag_id":1},{"function":"__ccd_pre_auto_pii","vtp_instanceDestinationId":"AW-663970415","tag_id":3}],. "predicates":[{"function":"_eq","arg0":["macro",0],"arg1":"gtm.js"},{"function":"_eq","arg0":["macro",0],"arg1":"gtm.init"}],. "rules":[[["if",0],["add",0]],[["if",1],["add",1]]].},."runtime":[ [50,"__ccd_pre_auto_pii",[46,"a"],[50,"q",[46,"s"],[52,"t",[16,[15,"s"],"userData"]],[52,"u",[30,[18,[2,[15,"t"],"indexOf",[7,"@gmail."]],[27,1]],[18,[2,[15,"t"],"indexOf",[7,"@googlemail."]],[27,1]]]],[36,[0,[0,[0,[0,[0,[0,[16,[15,"s"],"tagName"],":"],[16,[15,"s"],"isVisible"]],":"],[17,[15,"t"],"length"]],":"],[15,"u"]]]],[52,"b",[13,[41,"$0"],[3,"$0",["require","internal.getFlags"]],["$0"]]],[52,"c",["require","internal.setPr
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (3151), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):3151
                                                              Entropy (8bit):5.109494391917324
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:72ED826A0BA8E483428E8E8E963503C4
                                                              SHA1:B325F38D4B93924C0402F1525904EA5E657CF475
                                                              SHA-256:0D8DAEB44C9D6A17EF9A2D4F79689B0CEBE097312EC55E3752F13FA61144C05E
                                                              SHA-512:B34D1397DCD865E38DCA32BCF083747060AA60C8B00CA684C873950CAECE6A8C3F31FBF3D57E5EE349F4CC4B3CBEBB2DB541DF19ACA4754C1809002F5DDAD340
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/AFLVkD6SwwfZ5SCgk1FbD/_buildManifest.js
                                                              Preview:self.__BUILD_MANIFEST=function(s,e,c,r,t){return{__rewrites:{beforeFiles:[],afterFiles:[{source:"/:region(eu)/errors/reach-access",destination:"/errors/reach-access?region=:region"},{source:"/:region(eu)/bridge-redirect",destination:"/bridge-redirect?region=:region"},{source:"/api/:region(eu)/bridge-validation",destination:"/api/bridge-validation?region=:region"},{source:"/:region(eu)?/reach360",destination:"/loading-reach-360?region=:region"},{source:"/:region(eu)/subscription-selection",destination:"/subscription-selection?region=:region"},{source:"/oauth2/default/v1/authorize",destination:"/api/authorize"},{source:"/redirect/:product*",destination:"/api/redirect/:product*"},{source:"/community/signout",destination:"/api/community/signout"}],fallback:[]},"/":[s,c,e,r,"static/css/2d00d55d6eea628a.css","static/chunks/pages/index-77b862ce64a38a5a.js"],"/404":[t,"static/chunks/pages/404-0a4d0a548b1ed258.js"],"/_error":["static/chunks/pages/_error-991947e26236a508.js"],"/bridge-redirect":
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:HTML document, ASCII text
                                                              Category:downloaded
                                                              Size (bytes):4650
                                                              Entropy (8bit):2.9458855390606242
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A0CBC82C3C7BCE3B368E2118B3CB29D3
                                                              SHA1:F962C6CDC8FD2F423A765C3C1FA4AD979B18B81D
                                                              SHA-256:0DCEFA0B117FA5DC44EEFA92D2BF221F3455B29354CC940F144BB268100FC116
                                                              SHA-512:9A8607FF9AE95609205A5273B3AD3C3BA450B344A34B0CDB73E866397DF860DC2F645A412BA89BABD43ACE7BE320CBFDE83297FD6A70FD224D22C251931750FD
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://cmp.osano.com/
                                                              Preview:<html>. <head>. <script>. if (window !== window.top) {. var GET_STORAGE = 'GET_STORAGE';. var CLEAR_STORAGE = 'CLEAR_STORAGE';. var RECEIVE_STORAGE = 'RECEIVE_STORAGE';. var UPDATE_STORAGE = 'UPDATE_STORAGE';. var VALIDATE_IFRAME = 'VALIDATE_IFRAME';. var VALIDATE_IFRAME_RESPONSE = 'VALIDATE_IFRAME_RESPONSE';.. window.addEventListener(. 'message',. function (event) {. var expDate = undefined;. var data = event.data;. if (typeof data !== 'string') {. return;. }. (origin = event.origin),. (source = event.source),. (splitData = data.split('|'));. try {. j = JSON.parse(data);.
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (17992)
                                                              Category:dropped
                                                              Size (bytes):345528
                                                              Entropy (8bit):5.576392317822437
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:767ECC56A1624B378E128F647AFC80B7
                                                              SHA1:A27AD3569D465AECA399F9A5B74D582E3E4C8208
                                                              SHA-256:7A8E532F9CAF9B0517BD650EDF9855B1ED6362ABAD8070A1F598673B38F8DA1E
                                                              SHA-512:6E7438144A730C785362728AA1B92276BFD4606CAEBDDE8AD05959650FF57A8C6CA228C5965DE6EECEF112EF5D7DF26C85422AE46F2931D93EC3BE60F7C5C3A2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:.// Copyright 2012 Google Inc. All rights reserved.. . (function(w,g){w[g]=w[g]||{};. w[g].e=function(s){return eval(s);};})(window,'google_tag_manager');. .(function(){..var data = {."resource": {. "version":"104",. . "macros":[{"function":"__v","vtp_name":"nojscript","vtp_dataLayerVersion":2},{"function":"__e"},{"function":"__u","vtp_component":"URL","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__r"},{"function":"__cid"},{"function":"__smm","vtp_setDefaultValue":true,"vtp_input":["macro",4],"vtp_defaultValue":"NOTRACK","vtp_map":["list",["map","key","GTM-WJDFT6","value","UA-68728-6"],["map","key","GTM-K9R2NB","value","UA-68728-1"],["map","key","GTM-M3QKPX","value","UA-68728-6"]]},{"function":"__r"},{"function":"__u","vtp_component":"PATH","vtp_enableMultiQueryKeys":false,"vtp_enableIgnoreEmptyQueryParam":false},{"function":"__v","vtp_name":"action","vtp_dataLayerVersion":2},{"function":"__v","vtp_name":"category","vtp_dataLayerVersion":2},
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (3475), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):3475
                                                              Entropy (8bit):5.556976648862282
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:814EEF53D94005EFFDCF8BCE68EBB091
                                                              SHA1:E0BF13BAC642017266A65AD7F777B3B637F7EF7B
                                                              SHA-256:BDF17BBC969AB00A35FDA17633CBA39DA4575C25DF3F6AFD69DE7B42FBF74056
                                                              SHA-512:02AB3D3D456B0E92D201890FE4B2A719727E2C340BEBA981F436605E48E0A5CED654C00536CC0A4C93AA2CAC672F12F2AA416BAA08D893D350CBBE7DD3C7CF6E
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/chunks/pages/index-77b862ce64a38a5a.js
                                                              Preview:(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[405],{75557:function(e,t,n){(window.__NEXT_P=window.__NEXT_P||[]).push(["/",function(){return n(85901)}])},25677:function(e,t,n){"use strict";n.d(t,{EQ:function(){return o},UP:function(){return u},g_:function(){return l},mn:function(){return i},u$:function(){return s},uf:function(){return a}});var r=n(10580);let a=(0,r.Z)(/\d/),i=(0,r.Z)(/[a-z]/),l=(0,r.Z)(/[A-Z]/),u=e=>e.length>7,o=e=>a(e)&&i(e)&&l(e)&&u(e),s=(0,r.Z)(/^(([^<>()[\]\\.,;:\s@"]+(\.[^<>()[\]\\.,;:\s@"]+)*)|(".+"))@((\[[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}])|(([a-zA-Z\-0-9]+\.)+[a-zA-Z]{2,}))$/)},85901:function(e,t,n){"use strict";n.r(t),n.d(t,{__N_SSP:function(){return S}});var r=n(85893),a=n(87066),i=n(9821),l=n(36808),u=n.n(l),o=n(9008),s=n.n(o),m=n(67294),c=n(11163),d=n(91012),f=n(98694),_=n(44242),p=n(47597),b=n(55444),x=n(8543),h=n(92990),g=n(71600),w=n(58546),Z=n.n(w),j=n(4077),k=n(28784),E=n(25677);let N=()=>{let e=(0,c.useRouter)(),{t}=(0,k.$G)(["co
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Unicode text, UTF-8 text, with very long lines (51384), with no line terminators
                                                              Category:dropped
                                                              Size (bytes):51385
                                                              Entropy (8bit):5.293328685395304
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:6626C1362840EBFC8F48294E8F023E18
                                                              SHA1:4EC0DFB37C3E536C1B5EC04B68C9846FDBAF9EEF
                                                              SHA-256:AABC88A6DB8B22022F96CA88E4F0A7BE426ABEF2B35169A71515A2D55246402A
                                                              SHA-512:B037A19B52C1047198EC7F19E99066054E454964380E2354239834260D11248E617D6759B944DDF39A25B883C8F430603D8E13097396E2DEDA9BB6905C1CD42A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:function UET(o){this.stringExists=function(n){return n&&n.length>0};this.domain="bat.bing.com";this.domainCl="bat.bing.net";this.URLLENGTHLIMIT=4096;this.pageLoadEvt="pageLoad";this.customEvt="custom";this.pageViewEvt="page_view";o.Ver=o.Ver!==undefined&&(o.Ver==="1"||o.Ver===1)?1:2;this.uetConfig={};this.uetConfig.consent={enabled:!1,adStorageAllowed:!0,adStorageUpdated:!1,hasWaited:!1,waitForUpdate:0,enforced:!1};this.uetConfig.tcf={enabled:!1,vendorId:1126,hasLoaded:!1,timeoutId:null,gdprApplies:undefined,adStorageAllowed:undefined,measurementAllowed:undefined,personalizationAllowed:undefined};this.uetConfig.cusig={hasLoaded:!1,timeoutId:null,blob:{}};this.beaconParams={};this.supportsCORS=this.supportsXDR=!1;this.paramValidations={string_currency:{type:"regex",regex:/^[a-zA-Z]{3}$/,error:"{p} value must be ISO standard currency code"},number:{type:"num",digits:3,max:999999999999},integer:{type:"num",digits:0,max:999999999999},hct_los:{type:"num",digits:0,max:30},date:{type:"regex",
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced
                                                              Category:downloaded
                                                              Size (bytes):608
                                                              Entropy (8bit):7.529815580852982
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:70AB3503A1A488723E7DEDFE0E412A4D
                                                              SHA1:7E0B08B82ED21E276E095DAA7D2D6D66ECB802AB
                                                              SHA-256:CB7F953FD7A1D969F8F7295164DA3457F6FC68FE55B2845F36A34A424EAE58FE
                                                              SHA-512:16E7E45ABD628C3D0582D0852A982C2EAD0D03FB5348820570D04315ACD9DD10D3E93768F66532659916C26B4E34FA08E60B994B52E63B6E37CBD27A30A0942A
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/favicon.ico
                                                              Preview:.PNG........IHDR... ... .....szz....'IDATX...;kTA..._......D..I!"b..b!ba!... ......Y.v..B,.B..Vi. .B,D|6>...D.a]c1Y.{....f....^.....y.^Ip..F#.qe...`uDz7........42.q..F..qD~.c...~.G........q...s.(...-,+N..l.jI....pV?..0.M....6...O03....c.#..>k;8U...5...E.2f....!.................JV......,...D|t...0..6k|..8!{.D....N.\.;+. .E......#."F......]X.)P.K.%..Pn..7|..k......5...=..........$..)].(-.#k....*...V!..X....5..U..Y.L.].G.O"~V..&.....@.R..R.Zx.1\......kd...a...u.2..O.......0 ...1..P....)..$.Y...A.uMk...0.T..&...L...&..xW.. LL...Hh@i....Z.+....}....&H..q.N.(.....a5G.b......IEND.B`.
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:JSON data
                                                              Category:dropped
                                                              Size (bytes):69
                                                              Entropy (8bit):4.694772644870419
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D728BBDA77A36C0663C68E19156462CF
                                                              SHA1:C4B83EB689D2526832C0232177D078AEB852EA14
                                                              SHA-256:3881EF9625D12290E8FB8B827D601701BB16DFA5DA2D031CE3940D05E9E5F249
                                                              SHA-512:201F205393276339EF79CD6B9535B0F2D62CB369C7BD012F34D15DFA7E9A7E5EEAF1A94002AA1C4AEA6E6A4F3DB968F06EC29A022D484AFC5031B28D2F9A1B71
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:{"isoCode":"US","threeCharCountry":"USA","clientIp":"173.254.250.76"}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Unicode text, UTF-8 text, with very long lines (63162), with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):175200
                                                              Entropy (8bit):4.883748356689584
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:EF699021EC10A04ED012D5F2932BCFB4
                                                              SHA1:78B74A5518DEF71E055C0EA47356C64ACD5ACC52
                                                              SHA-256:F406A4839BA8AC522AFFBE2DF791453B26A0780648DC27AF9AA232640CF712E2
                                                              SHA-512:DB20EF021CBFEC5B3313B01FCB2E86CDB2C37E37FB68B87873C71B787FFDF89F96AE54E4A233DD413E3EA283B800EC6D794B95B82D35D1CE392D1F1449A7F1F2
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://cdn.articulate.com/fontawesome/kit/css/fontawesome.min.css
                                                              Preview:@charset "utf-8";.fa{font-family:var(--fa-style-family,"Font Awesome 6 Pro");font-weight:var(--fa-style,900)}.fa,.fa-classic,.fa-sharp,.fas,.fa-solid,.far,.fa-regular,.fasr,.fal,.fa-light,.fasl,.fat,.fa-thin,.fad,.fa-duotone,.fass,.fa-sharp-solid,.fab,.fa-brands{-moz-osx-font-smoothing:grayscale;-webkit-font-smoothing:antialiased;display:var(--fa-display,inline-block);font-variant:normal;text-rendering:auto;font-style:normal;line-height:1}.fas,.fa-classic,.fa-solid,.far,.fa-regular,.fal,.fa-light,.fat,.fa-thin{font-family:"Font Awesome 6 Pro"}.fab,.fa-brands{font-family:"Font Awesome 6 Brands"}.fad,.fa-classic.fa-duotone,.fa-duotone{font-family:"Font Awesome 6 Duotone"}.fass,.fasr,.fasl,.fa-sharp{font-family:"Font Awesome 6 Sharp"}.fass,.fa-sharp{font-weight:900}.fa-1x{font-size:1em}.fa-2x{font-size:2em}.fa-3x{font-size:3em}.fa-4x{font-size:4em}.fa-5x{font-size:5em}.fa-6x{font-size:6em}.fa-7x{font-size:7em}.fa-8x{font-size:8em}.fa-9x{font-size:9em}.fa-10x{font-size:10em}.fa-2xs{vertica
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (65473)
                                                              Category:dropped
                                                              Size (bytes):301855
                                                              Entropy (8bit):5.511134151589409
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:C7E897C9A015BE42DE235B6DD8BC24E4
                                                              SHA1:357E3D1993738DA2DB1DB862B6EB75ED7CAE9036
                                                              SHA-256:A1FC1F8DEF932EBD414D8CCEF13298FC7269CAEBAF7EE71DE609314CBFAC33F2
                                                              SHA-512:65AC8FF78B8683D15565A61D394ACBC17466A95DC61DA5DB6D58DB09B15E4F93A551D40B12A4FF262BC3B8A3775CEB03AB9689E189ACB120A0FA4058CF3D16E4
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:/*! For license information please see osano.js.LICENSE.txt */.(()=>{var e={5289:()=>{!function(){var e=/\[object (Boolean|Number|String|Function|Array|Date|RegExp)\]/;function t(t){return null==t?String(t):(t=e.exec(Object.prototype.toString.call(Object(t))))?t[1].toLowerCase():"object"}function r(e,t){return Object.prototype.hasOwnProperty.call(Object(e),t)}function o(e){if(!e||"object"!=t(e)||e.nodeType||e==e.window)return!1;try{if(e.constructor&&!r(e,"constructor")&&!r(e.constructor.prototype,"isPrototypeOf"))return!1}catch(n){return!1}for(var o in e);return void 0===o||r(e,o)}function n(e,t,r){this.b=e,this.f=t||function(){},this.d=!1,this.a={},this.c=[],this.e=function(e){return{set:function(t,r){a(s(t,r),e.a)},get:function(t){return e.get(t)}}}(this),i(this,e,!r);var o=e.push,n=this;e.push=function(){var t=[].slice.call(arguments,0),r=o.apply(e,t);return i(n,t),r}}function i(e,r,n){for(e.c.push.apply(e.c,r);!1===e.d&&0<e.c.length;){if("array"==t(r=e.c.shift()))e:{var i=r,c=e.a;i
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):77
                                                              Entropy (8bit):4.37144473219773
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:B6652DF95DB52FEB4DAF4ECA35380933
                                                              SHA1:65451D110137761B318C82D9071C042DB80C4036
                                                              SHA-256:6F5B4AA00D2F8D6AED9935B471806BF7ACEF464D0C1D390260E5FE27F800C67E
                                                              SHA-512:3390C5663EF9081885DF8CDBC719F6C2F1597A4E25168529598097E9472608A4A62EC7F7E0BC400D22AAC81BF6EA926532886E4DC6E4E272D3B588490A090473
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/AFLVkD6SwwfZ5SCgk1FbD/_ssgManifest.js
                                                              Preview:self.__SSG_MANIFEST=new Set,self.__SSG_MANIFEST_CB&&self.__SSG_MANIFEST_CB();
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:JSON data
                                                              Category:downloaded
                                                              Size (bytes):48
                                                              Entropy (8bit):4.339661719245796
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:EA945654AC51335933F014C9C3746D11
                                                              SHA1:32678D0458F324D8A9CD1A6BCA191F8028689E8A
                                                              SHA-256:2F480953565905F85F973989FCE17AF139108D4DF456B5AEA260499BAF919935
                                                              SHA-512:9607D68D754EFCA9C5D117CC1683CE15898CD3EABEDE541F5EFEF5CC58BF9A16641D475F4753554D66E9F6EC9C511A4E2A33C5B8B0C443132DFABA00C7628FCC
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://scout.salesloft.com/i
                                                              Preview:{"token":"1f0af122-7f9a-43bd-b769-975e97802ae0"}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Web Open Font Format (Version 2), TrueType, length 23484, version 1.0
                                                              Category:downloaded
                                                              Size (bytes):23484
                                                              Entropy (8bit):7.990679247611318
                                                              Encrypted:true
                                                              SSDEEP:
                                                              MD5:B4D2C4C39853EE244272C04999B230BA
                                                              SHA1:C82E22DDE9716C40BA20E6C7ED03A1B66556DE15
                                                              SHA-256:C3C0D3F472358AAC78455515C4800771426770C22698E2486D39FDB5505634E1
                                                              SHA-512:D315D6A4E28BB125128D3A4D99FE120E383061D367341F06C4B74A589B4CA29C516CBC8D23DDD37267A1E4497C74FD58B1DFFD39CB70348B8A3EA3D48237F8EF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/media/lato-latin-400.cc2c3b4a.woff2
                                                              Preview:wOF2......[........,..[\..........................z.p.`..D....e........]..B..6.$..v. .....E.K...%...v.D...G#Z.C)...(:.....P.N...I...2...f..Dl...Q.l.l...}.Fka.]{.Vs<0.D."*Q.JLagB.m...K."-<HT.v.\0..<..u....e..w......U...n...x.@.D.$..q...Zy..8...].><...i%....P.....gR.....pE..;....N7.(......@,2..1.P.@...9].M7.ss......U.^....V..Go.T7.3.O....%......6$-..i..b..2H*.Q.)s......o...!....%I..Y]h...7.....m.M|Xz?.....g...r...Q..UUlV........s..^.....`p...*...h..9.5.:e.:.*...N.d3.G.[t.....0............N.j...V....j.Kdz.^...-.3..^.'..........eI...D...7U@.O*....d...".....;..}.."T.\0I..........o.<.D4'Er........[..s5....]v.I.D3..>.X.__[=...+1). m.t~...-.f......Cu.Z]um.B..L.8...Z..o../....a.......p..\......N).1B../y*...^.L.g...e.$k.....*\..p..":...R..~..DE.D..y..]O......B.......n.|.V.p.r6.Rmi.Q...n.##$FJ..T...f....<.u.:gS..8...h...6B..........D..Q"........w7.....Y.3.Z.uNc...|f......b.M].o.|.<....p.X."*..-.Jx.;...!.`..D.t..'s;...t..n.`.s..Fv..O..Z .(...ju....{......S.$...$d..
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with CRLF line terminators
                                                              Category:downloaded
                                                              Size (bytes):369
                                                              Entropy (8bit):4.590817929815233
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:35DB82FB180E5BCD0BDBE6D93BB22FBF
                                                              SHA1:1177FAC2BF250D1669453585A2151F4186A87AA3
                                                              SHA-256:80057B238A62F569F8361C0C724FC6CA5EF4EC6EEE8C15D1FC3D19932BEE1A7C
                                                              SHA-512:3DFB6E8B1D37F7522DD860C4E1E4F2BC1A9E3164CED13B07C005C6FFD307062213FD577C2C3CCD31E3DDC887F2B8F3D3D7F658823F766D7F401A63D99ECEB9E7
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://bat.bing.com/p/action/5422584.js
                                                              Preview:(function(w,d,c,k,a,b,t,e) {.. var cs = d.currentScript;.. if (cs) {.. var uo = cs.getAttribute('data-ueto');.. if (uo && w[uo] && typeof w[uo].setUserSignals === 'function') {.. w[uo].setUserSignals({'co': c, 'kc': k, 'at': a, 'bi': b, 'dt': t, 'ec': e});.. }.. }..})(window, document, 'us', true, true, false, false, false);..
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (350)
                                                              Category:downloaded
                                                              Size (bytes):526
                                                              Entropy (8bit):5.026267471816935
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:F3BD073FDE5B88A9B5F177DF66ACA88C
                                                              SHA1:881D0E25BFC3EDD18E62BA70D150C009D09D7D81
                                                              SHA-256:5375C3E81A71BA0B9DCD4E957753E28034AB2337A8701ECE9824991CEB80A5FC
                                                              SHA-512:277B8566A374648E6605C1B66AF98C70A1A1655343D93129FBFB23F18D33B1AF883F5CF4DC89F52331AB864EB8E0B93D108D9DDD1C71D62F83463A50EC8DFFA9
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://cdn.articulate.com/fontawesome/kit/css/light.min.css
                                                              Preview:/*!. * Font Awesome Pro 6.4.0 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license (Commercial License). * Copyright 2023 Fonticons, Inc.. */.:host,:root{--fa-style-family-classic:"Font Awesome 6 Pro";--fa-font-light:normal 300 1em/1 "Font Awesome 6 Pro"}@font-face{font-family:"Font Awesome 6 Pro";font-style:normal;font-weight:300;font-display:block;src:url(../webfonts/fa-light-300.woff2) format("woff2"),url(../webfonts/fa-light-300.ttf) format("truetype")}.fa-light,.fal{font-weight:300}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (6105), with no line terminators
                                                              Category:dropped
                                                              Size (bytes):6105
                                                              Entropy (8bit):5.238378421291859
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:D74CC4825C8E333B2116DA3FCC649DB1
                                                              SHA1:B48D09A14C1CD6333F1D2D811675B771F2A38A00
                                                              SHA-256:4A007AF67F716C30C8848AB0AD0BFAAB8A5FCF3E36DEDF918B59C9429D522440
                                                              SHA-512:FBAD39A642A7AF5167B8F1AB37510B83817CD90E19C3286CA6B76A1CC8C383E45216C1C8F8A03A10916C21960FF625F67A059017ABD5834F17B2BC9E41CCB4C8
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:!function(t){function e(i){if(n[i])return n[i].exports;var o=n[i]={i:i,l:!1,exports:{}};return t[i].call(o.exports,o,o.exports,e),o.l=!0,o.exports}var n={};e.m=t,e.c=n,e.i=function(t){return t},e.d=function(t,n,i){e.o(t,n)||Object.defineProperty(t,n,{configurable:!1,enumerable:!0,get:i})},e.n=function(t){var n=t&&t.__esModule?function(){return t.default}:function(){return t};return e.d(n,"a",n),n},e.o=function(t,e){return Object.prototype.hasOwnProperty.call(t,e)},e.p="",e(e.s=5)}([function(t,e,n){"use strict";Object.defineProperty(e,"__esModule",{value:!0});var i={get:function(t){for(var e=t+"=",n=decodeURIComponent(document.cookie),i=n.split(";"),o=0;o<i.length;o++){var u=i[o].trim();if(0==u.indexOf(e))return u.substring(e.length,u.length)}return null},set:function(t,e,n){var i=new Date;i.setTime(i.getTime()+24*n*60*60*1e3);var o="expires="+i.toUTCString();document.cookie=t+"="+e+";"+o+";path=/"}};e.default=i},function(t,e,n){"use strict";function i(t,e){var n=new XMLHttpRequest;n.on
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (64232)
                                                              Category:downloaded
                                                              Size (bytes):324193
                                                              Entropy (8bit):4.583780049598347
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:AE7F4540A959D36623949EEC567D583E
                                                              SHA1:89D62D34D6D588A2F4173121EA646B4C905B12B6
                                                              SHA-256:D174726AF34C2F8AEB58504508A87EC48BFC3AA83EC600327430E08C325A57B9
                                                              SHA-512:4315ED0A312245BC94D744E98567451C8887585D9EA71E45B835A2E9DFFD68FD4A04FDD8DF8C80A451A15FFA21E13ED17331B9EF62E78C8C4E99E9423AAF44B7
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://cdn.articulate.com/fontawesome/kit/css/duotone.min.css
                                                              Preview:/*!. * Font Awesome Pro 6.4.2 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license (Commercial License). * Copyright 2023 Fonticons, Inc.. */.:host,:root{--fa-style-family-duotone:"Font Awesome 6 Duotone";--fa-font-duotone:normal 900 1em/1 "Font Awesome 6 Duotone"}@font-face{font-family:"Font Awesome 6 Duotone";font-style:normal;font-weight:900;font-display:block;src:url(../webfonts/fa-duotone-900.woff2) format("woff2"),url(../webfonts/fa-duotone-900.ttf) format("truetype")}.fa-duotone,.fad{position:relative;font-weight:900;letter-spacing:normal}.fa-duotone:before,.fad:before{position:absolute;color:var(--fa-primary-color,inherit);opacity:var(--fa-primary-opacity,1)}.fa-duotone:after,.fad:after{color:var(--fa-secondary-color,inherit)}.fa-duotone.fa-swap-opacity:before,.fa-duotone:after,.fa-swap-opacity .fa-duotone:before,.fa-swap-opacity .fad:before,.fad.fa-swap-opacity:before,.fad:after{opacity:var(--fa-secondary-opacity,.4)}.fa-duotone.fa-swap-opacit
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with very long lines (350)
                                                              Category:downloaded
                                                              Size (bytes):526
                                                              Entropy (8bit):5.024185968129175
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:73A62F12F33293AFE2ADF38B7A3FB214
                                                              SHA1:CF11919E4836562DC274BA21502FE14FD18F0CF1
                                                              SHA-256:85F2570BC2E8B08CBCB970AEF4727A675139B424A95970C3CE3FCA048165B5B8
                                                              SHA-512:099915539275EE3FFBA5E8E2E7999B6DF9DAF297A7BD804A7FCABA87402C2794346DBA58FAD5A23AE61D659D77F1EE02177AD68C1C11952CD3290CAE760FBAA7
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://cdn.articulate.com/fontawesome/kit/css/solid.min.css
                                                              Preview:/*!. * Font Awesome Pro 6.4.0 by @fontawesome - https://fontawesome.com. * License - https://fontawesome.com/license (Commercial License). * Copyright 2023 Fonticons, Inc.. */.:host,:root{--fa-style-family-classic:"Font Awesome 6 Pro";--fa-font-solid:normal 900 1em/1 "Font Awesome 6 Pro"}@font-face{font-family:"Font Awesome 6 Pro";font-style:normal;font-weight:900;font-display:block;src:url(../webfonts/fa-solid-900.woff2) format("woff2"),url(../webfonts/fa-solid-900.ttf) format("truetype")}.fa-solid,.fas{font-weight:900}
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Web Open Font Format (Version 2), TrueType, length 22992, version 1.0
                                                              Category:downloaded
                                                              Size (bytes):22992
                                                              Entropy (8bit):7.989133666514762
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:1EFBD38AA76DDAE2580FEDF378276333
                                                              SHA1:8A49976F2470BA2A1DB6144245355D3B889312E4
                                                              SHA-256:8D3CA80FA271E94B0C36CF3053B0F806B7A42BB3395B424C99DC0BD218F0AC20
                                                              SHA-512:DD16EFD323A38DAD99A105E7443546E112FF42158018C885091DF498C8C5B88C4D83737B4887332EA54EF3A83483E660C783073C4CE61FCA4098D24AAC05ED6C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://id.articulate.com/_next/static/media/lato-latin-700.10278b9b.woff2
                                                              Preview:wOF2......Y........8..Yp..........................B.p.`..D....e.....d.....B..6.$..v. .....E.K.....7S........hD..s.O$Hrf ......f....T..>h?G5..2r.!........"....K.{:{.Va|........D%*1...,:. .}...43...d..n.....a~1L....4U..>....|.x..t.N.zG..4.L"YBL.R..T0..N.....1.ku..+/...1....B]Uu.$...W..<...../..zm.@A...... ...Vfh.u..~."...Y$~'..R.T..-.:.l/...k../........jl..'.{.*?e..fx....,...T.3.i?....B...^..Ey.%....Ns.A...+........<=9Z.YmN.\".......L2.........".....*...@Ju..J00+...|W.m.3...Au..o...[..Hb-Sm:L..$./*.k..&3.H..U%.@.......j....M....8.:......5......+n..6b#z.l..16b#z.T.E...0..(V..._..o.Fj..x@....L..+.Y6./...)..u.#.=....}.3.*.@,...E~..s)..{B..Q.\...#...a....w.....Q..fb..`m..c....._......E.q....@.%.u<I....z.._.XU%@.&=.=W...(.......o_..d.k,..=....(....W.Z..b...s....lJ.Jz...|k.=.4w..P0.qI9P..T....oa........3.$..............!..z'...?@S...U.ij..Og.u:YoY.ol......A..l..u....._J.. ...@......G.a.p.X.....T.u>..F...)..zR.*..t...R*..?.Y..A..n...TqO...q9.S...m...d.(.I..'Q....
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:ASCII text, with no line terminators
                                                              Category:downloaded
                                                              Size (bytes):20
                                                              Entropy (8bit):3.2841837197791888
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:A1C8E2C36FD57992BA6E26E7AEDD793F
                                                              SHA1:50223F53E26760FEA2D59504065A361F3FFA9911
                                                              SHA-256:0B30589FA4B71AC1C24D5514A147CFA23183C5EA78B0F09F5A53ECD5B71A4DB3
                                                              SHA-512:3BE9C7D6FD6F6E56F6644E60D4F998F4583F3EC7FFFA44826D3432D789702D870694547BBABE3D44C25233BCD59A0AB6747A47DF4467D4E32605095648C45B3C
                                                              Malicious:false
                                                              Reputation:unknown
                                                              URL:https://api.articulate.com/id/v1/time
                                                              Preview:2024-10-22T08:57:18Z
                                                              Process:C:\Program Files\Google\Chrome\Application\chrome.exe
                                                              File Type:Unicode text, UTF-8 text, with very long lines (65528), with no line terminators
                                                              Category:dropped
                                                              Size (bytes):907757
                                                              Entropy (8bit):6.202001020510152
                                                              Encrypted:false
                                                              SSDEEP:
                                                              MD5:5CFDEC6E636C31A963618EF98646C067
                                                              SHA1:F1395AB3F9514415D052D1E2F941AB56DC26EA6E
                                                              SHA-256:F6E015C10F1C1D0DF52829CAF1BC280D3991D1A01AC43D608C42CA145C50BF06
                                                              SHA-512:9BDDBB7EA79332EA08F1653F9D672AA11075F32E3AA7D08AC5F2A0FF7BBDDA2FB143EF79FADBD60A7995FC4B757A5E1FECC101635630A05B69CDAA3DBA20D1AF
                                                              Malicious:false
                                                              Reputation:unknown
                                                              Preview:(self.webpackChunk_N_E=self.webpackChunk_N_E||[]).push([[888],{67228:function(e){function a(e,a){(null==a||a>e.length)&&(a=e.length);for(var n=0,t=Array(a);n<a;n++)t[n]=e[n];return t}e.exports=a},22858:function(e){function a(e){if(Array.isArray(e))return e}e.exports=a},23646:function(e,a,n){var t=n(67228);function r(e){if(Array.isArray(e))return t(e)}e.exports=r},81506:function(e){function a(e){if(void 0===e)throw ReferenceError("this hasn't been initialised - super() hasn't been called");return e}e.exports=a},48926:function(e){function a(e,a,n,t,r,i,o){try{var s=e[i](o),u=s.value}catch(e){n(e);return}s.done?a(u):Promise.resolve(u).then(t,r)}function n(e){return function(){var n=this,t=arguments;return new Promise(function(r,i){var o=e.apply(n,t);function s(e){a(o,r,i,s,u,"next",e)}function u(e){a(o,r,i,s,u,"throw",e)}s(void 0)})}}e.exports=n},34575:function(e){function a(e,a){if(!(e instanceof a))throw TypeError("Cannot call a class as a function")}e.exports=a},93913:function(e){funct
                                                              File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                              Entropy (8bit):7.997299732474313
                                                              TrID:
                                                              • Win32 Executable (generic) a (10002005/4) 99.96%
                                                              • Generic Win/DOS Executable (2004/3) 0.02%
                                                              • DOS Executable Generic (2002/1) 0.02%
                                                              • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                              File name:articulate-360.exe
                                                              File size:36'620'184 bytes
                                                              MD5:f1d670108f566db99dfbc0b91c2ad2a2
                                                              SHA1:fb758a61a196de45a42c781fad5f77dd6f21bdcd
                                                              SHA256:9c4c3f2396efcf50c10ff0f162626635058bd9e26b03249474097a61b61e492f
                                                              SHA512:4b754c33cd018738f942f6be3b13853cdb686f1bfa36f35b072d6622483f1a881f071c6585606472a0e5faaf17915faf9554e8f589cf4e73e72e942ff78824aa
                                                              SSDEEP:786432:Vvw0pnQWwDKBljGVjOBSNWJafgBPc59QiL1XeKT35Zl6HRSGVaiNIgrVnC:1pnQWwDelXBRJa44NBXee35ZYHRSeaS6
                                                              TLSH:C88733F29548463BD6A22437B475DE746E66B128124088B2D6CCFC2E3E770A35BFF641
                                                              File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9.o.}k..}k..}k......wk.......k......ek../...nk../...ik../...Vk..t...xk..t...lk..}k..(j......6k......|k..}k...k......|k..Rich}k.
                                                              Icon Hash:8ab34d96b2b291b3
                                                              Entrypoint:0x42df71
                                                              Entrypoint Section:.text
                                                              Digitally signed:true
                                                              Imagebase:0x400000
                                                              Subsystem:windows gui
                                                              Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
                                                              DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                              Time Stamp:0x5D807032 [Tue Sep 17 05:33:38 2019 UTC]
                                                              TLS Callbacks:
                                                              CLR (.Net) Version:
                                                              OS Version Major:5
                                                              OS Version Minor:1
                                                              File Version Major:5
                                                              File Version Minor:1
                                                              Subsystem Version Major:5
                                                              Subsystem Version Minor:1
                                                              Import Hash:42d651751c1d75ed4fa8fe71751854ff
                                                              Signature Valid:true
                                                              Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                                                              Signature Validation Error:The operation completed successfully
                                                              Error Number:0
                                                              Not Before, Not After
                                                              • 23/10/2023 02:00:00 19/01/2027 00:59:59
                                                              Subject Chain
                                                              • CN="ARTICULATE GLOBAL, LLC", O="ARTICULATE GLOBAL, LLC", L=New York, S=New York, C=US
                                                              Version:3
                                                              Thumbprint MD5:9E05BA2A25D648D7EC0F403B3519C17D
                                                              Thumbprint SHA-1:2B085C5DB04B1F69D42C3E2F4E224A6495A335B5
                                                              Thumbprint SHA-256:1C15D255B6F719D44564A430FFCC88BAC578CC98FEBE35D493506D26A247ECF8
                                                              Serial:08D1EA95918861FC591E8F0B612D3A2D
                                                              Instruction
                                                              call 00007FE75884792Fh
                                                              jmp 00007FE75884726Fh
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              mov eax, dword ptr [esp+08h]
                                                              mov ecx, dword ptr [esp+10h]
                                                              or ecx, eax
                                                              mov ecx, dword ptr [esp+0Ch]
                                                              jne 00007FE7588473FBh
                                                              mov eax, dword ptr [esp+04h]
                                                              mul ecx
                                                              retn 0010h
                                                              push ebx
                                                              mul ecx
                                                              mov ebx, eax
                                                              mov eax, dword ptr [esp+08h]
                                                              mul dword ptr [esp+14h]
                                                              add ebx, eax
                                                              mov eax, dword ptr [esp+08h]
                                                              mul ecx
                                                              add edx, ebx
                                                              pop ebx
                                                              retn 0010h
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              int3
                                                              cmp cl, 00000040h
                                                              jnc 00007FE758847407h
                                                              cmp cl, 00000020h
                                                              jnc 00007FE7588473F8h
                                                              shrd eax, edx, cl
                                                              shr edx, cl
                                                              ret
                                                              mov eax, edx
                                                              xor edx, edx
                                                              and cl, 0000001Fh
                                                              shr eax, cl
                                                              ret
                                                              xor eax, eax
                                                              xor edx, edx
                                                              ret
                                                              push ebp
                                                              mov ebp, esp
                                                              jmp 00007FE7588473FFh
                                                              push dword ptr [ebp+08h]
                                                              call 00007FE75884D7D8h
                                                              pop ecx
                                                              test eax, eax
                                                              je 00007FE758847401h
                                                              push dword ptr [ebp+08h]
                                                              call 00007FE75884D861h
                                                              pop ecx
                                                              test eax, eax
                                                              je 00007FE7588473D8h
                                                              pop ebp
                                                              ret
                                                              cmp dword ptr [ebp+08h], FFFFFFFFh
                                                              je 00007FE758847CF4h
                                                              jmp 00007FE758847CD1h
                                                              push ebp
                                                              mov ebp, esp
                                                              push dword ptr [ebp+08h]
                                                              call 00007FE758847D0Dh
                                                              pop ecx
                                                              pop ebp
                                                              ret
                                                              push ebp
                                                              mov ebp, esp
                                                              test byte ptr [ebp+08h], 00000001h
                                                              push esi
                                                              mov esi, ecx
                                                              mov dword ptr [esi], 0046030Ch
                                                              je 00007FE7588473FCh
                                                              push 0000000Ch
                                                              push esi
                                                              call 00007FE7588473CDh
                                                              pop ecx
                                                              Programming Language:
                                                              • [ C ] VS2008 SP1 build 30729
                                                              • [IMP] VS2008 SP1 build 30729
                                                              NameVirtual AddressVirtual Size Is in Section
                                                              IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IMPORT0x680b40xb4.rdata
                                                              IMAGE_DIRECTORY_ENTRY_RESOURCE0x6d0000x315d8.rsrc
                                                              IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_SECURITY0x22e9f300x2868
                                                              IMAGE_DIRECTORY_ENTRY_BASERELOC0x9f0000x3dd0.reloc
                                                              IMAGE_DIRECTORY_ENTRY_DEBUG0x670300x54.rdata
                                                              IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_TLS0x670840x18.rdata
                                                              IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x66a100x40.rdata
                                                              IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_IAT0x4a0000x3e0.rdata
                                                              IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x67c340x100.rdata
                                                              IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                              IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                              NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                              .text0x10000x48ff70x49000c66f549d5fc7d10a5f63350701c6b3f9False0.5367883133561644data6.572059575788497IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                              .rdata0x4a0000x1f7600x1f8005a2f02dbbbda51cfac50fb52cea6d11bFalse0.30963231646825395data5.137524712720983IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                              .data0x6a0000x16fc0xa008fe8ba25b04a7beb04c2ab2d5e9ea736False0.27265625data3.1551613029957557IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                              .wixburn0x6c0000x380x20029184b23babf01d5bc2669b2e4147aa2False0.130859375data0.7499625244532455IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                              .rsrc0x6d0000x315d80x31600829c907e727646aed838b3bebf46a31bFalse0.32235957278481014data5.081965788561533IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                              .reloc0x9f0000x3dd00x3e007cc10e0060080262550138057fd6b87dFalse0.8069556451612904data6.788270717274864IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                              NameRVASizeTypeLanguageCountryZLIB Complexity
                                                              RT_ICON0x6d4a80x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 640EnglishUnited States0.3225806451612903
                                                              RT_ICON0x6d7900x128Device independent bitmap graphic, 16 x 32 x 4, image size 192EnglishUnited States0.47635135135135137
                                                              RT_ICON0x6d8b80x1628Device independent bitmap graphic, 64 x 128 x 8, image size 4608EnglishUnited States0.29231311706629054
                                                              RT_ICON0x6eee00xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2688EnglishUnited States0.3763326226012793
                                                              RT_ICON0x6fd880x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1152EnglishUnited States0.49684115523465705
                                                              RT_ICON0x706300x568Device independent bitmap graphic, 16 x 32 x 8, image size 320EnglishUnited States0.5166184971098265
                                                              RT_ICON0x70b980x75ecPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9985755929508414
                                                              RT_ICON0x781840x94a8Device independent bitmap graphic, 96 x 192 x 32, image size 38016EnglishUnited States0.15813537944082404
                                                              RT_ICON0x8162c0x67e8Device independent bitmap graphic, 80 x 160 x 32, image size 26560EnglishUnited States0.1744736842105263
                                                              RT_ICON0x87e140x5488Device independent bitmap graphic, 72 x 144 x 32, image size 21600EnglishUnited States0.18345656192236598
                                                              RT_ICON0x8d29c0x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.19555975436939066
                                                              RT_ICON0x914c40x3a48Device independent bitmap graphic, 60 x 120 x 32, image size 14880EnglishUnited States0.20951742627345846
                                                              RT_ICON0x94f0c0x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.23195020746887968
                                                              RT_ICON0x974b40x1a68Device independent bitmap graphic, 40 x 80 x 32, image size 6720EnglishUnited States0.25576923076923075
                                                              RT_ICON0x98f1c0x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.29620075046904315
                                                              RT_ICON0x99fc40x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400EnglishUnited States0.3528688524590164
                                                              RT_ICON0x9a94c0x6b8Device independent bitmap graphic, 20 x 40 x 32, image size 1680EnglishUnited States0.34767441860465115
                                                              RT_ICON0x9b0040x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.17819148936170212
                                                              RT_MESSAGETABLE0x9b46c0x2840dataEnglishUnited States0.28823757763975155
                                                              RT_GROUP_ICON0x9dcac0x102dataEnglishUnited States0.6395348837209303
                                                              RT_VERSION0x9ddb00x354dataEnglishUnited States0.4448356807511737
                                                              RT_MANIFEST0x9e1040x4d2XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1174), with CRLF line terminatorsEnglishUnited States0.47568881685575365
                                                              DLLImport
                                                              ADVAPI32.dllRegCloseKey, RegOpenKeyExW, OpenProcessToken, AdjustTokenPrivileges, LookupPrivilegeValueW, InitiateSystemShutdownExW, GetUserNameW, RegQueryValueExW, RegDeleteValueW, CloseEventLog, OpenEventLogW, ReportEventW, ConvertStringSecurityDescriptorToSecurityDescriptorW, DecryptFileW, CreateWellKnownSid, InitializeAcl, SetEntriesInAclW, ChangeServiceConfigW, CloseServiceHandle, ControlService, OpenSCManagerW, OpenServiceW, QueryServiceStatus, SetNamedSecurityInfoW, CheckTokenMembership, AllocateAndInitializeSid, SetEntriesInAclA, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegSetValueExW, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, RegDeleteKeyW, RegCreateKeyExW, GetTokenInformation, CryptDestroyHash, CryptHashData, CryptCreateHash, CryptGetHashParam, CryptReleaseContext, CryptAcquireContextW, QueryServiceConfigW
                                                              USER32.dllPeekMessageW, PostMessageW, IsWindow, WaitForInputIdle, PostQuitMessage, GetMessageW, TranslateMessage, MsgWaitForMultipleObjects, PostThreadMessageW, GetMonitorInfoW, MonitorFromPoint, IsDialogMessageW, LoadCursorW, LoadBitmapW, SetWindowLongW, GetWindowLongW, GetCursorPos, MessageBoxW, CreateWindowExW, UnregisterClassW, RegisterClassW, DefWindowProcW, DispatchMessageW
                                                              OLEAUT32.dllVariantInit, SysAllocString, VariantClear, SysFreeString
                                                              GDI32.dllDeleteDC, DeleteObject, SelectObject, StretchBlt, GetObjectW, CreateCompatibleDC
                                                              SHELL32.dllCommandLineToArgvW, SHGetFolderPathW, ShellExecuteExW
                                                              ole32.dllCoUninitialize, CoInitializeEx, CoInitialize, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CLSIDFromProgID, CoInitializeSecurity
                                                              KERNEL32.dllGetCPInfo, GetOEMCP, IsValidCodePage, CloseHandle, CreateFileW, GetProcAddress, LocalFree, HeapSetInformation, GetLastError, GetModuleHandleW, FormatMessageW, lstrlenA, lstrlenW, MultiByteToWideChar, WideCharToMultiByte, LCMapStringW, Sleep, GetLocalTime, GetModuleFileNameW, ExpandEnvironmentStringsW, GetTempPathW, GetTempFileNameW, CreateDirectoryW, GetFullPathNameW, CompareStringW, GetCurrentProcessId, WriteFile, SetFilePointer, LoadLibraryW, GetSystemDirectoryW, CreateFileA, HeapAlloc, HeapReAlloc, HeapFree, HeapSize, GetProcessHeap, FindClose, GetCommandLineA, GetCurrentDirectoryW, RemoveDirectoryW, SetFileAttributesW, GetFileAttributesW, DeleteFileW, FindFirstFileW, FindNextFileW, MoveFileExW, GetCurrentProcess, GetCurrentThreadId, InitializeCriticalSection, DeleteCriticalSection, ReleaseMutex, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, CreateProcessW, GetVersionExW, VerSetConditionMask, FreeLibrary, EnterCriticalSection, LeaveCriticalSection, GetSystemTime, GetNativeSystemInfo, GetModuleHandleExW, GetWindowsDirectoryW, GetSystemWow64DirectoryW, GetCommandLineW, VerifyVersionInfoW, GetVolumePathNameW, GetDateFormatW, GetUserDefaultUILanguage, GetSystemDefaultLangID, GetUserDefaultLangID, GetStringTypeW, ReadFile, SetFilePointerEx, DuplicateHandle, InterlockedExchange, InterlockedCompareExchange, LoadLibraryExW, CreateEventW, ProcessIdToSessionId, OpenProcess, GetProcessId, WaitForSingleObject, ConnectNamedPipe, SetNamedPipeHandleState, CreateNamedPipeW, CreateThread, GetExitCodeThread, SetEvent, WaitForMultipleObjects, InterlockedIncrement, InterlockedDecrement, ResetEvent, SetEndOfFile, SetFileTime, LocalFileTimeToFileTime, DosDateTimeToFileTime, CompareStringA, GetExitCodeProcess, SetThreadExecutionState, CopyFileExW, MapViewOfFile, UnmapViewOfFile, CreateMutexW, CreateFileMappingW, GetThreadLocale, FindFirstFileExW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetStdHandle, GetConsoleCP, GetConsoleMode, FlushFileBuffers, DecodePointer, WriteConsoleW, GetModuleHandleA, GlobalAlloc, GlobalFree, GetFileSizeEx, CopyFileW, VirtualAlloc, VirtualFree, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, SystemTimeToFileTime, GetSystemInfo, VirtualProtect, VirtualQuery, GetComputerNameW, SetCurrentDirectoryW, GetFileType, GetACP, ExitProcess, GetStdHandle, InitializeCriticalSectionAndSpinCount, SetLastError, RtlUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, RaiseException, LoadLibraryExA
                                                              RPCRT4.dllUuidCreate
                                                              Language of compilation systemCountry where language is spokenMap
                                                              EnglishUnited States