Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
MyTrustID.EXE

Overview

General Information

Sample name:MyTrustID.EXE
Analysis ID:1541694
MD5:1f4bb0f2b9d26f2419fbb7e7ba860d03
SHA1:0ec525f5032f91544908aa957dc9fa9212d9ac7d
SHA256:0b4d29b13046032af8c92bff26283ac8522bc178e9b4428010030bd352c49e91
Infos:

Detection

Score:64
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Command shell drops VBS files
Queries sensitive system registry key value via command line tool
Sigma detected: Windows Shell/Scripting Application File Write to Suspicious Folder
Uses cmd line tools excessively to alter registry or file data
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for available system drives (often done to infect USB drives)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a start menu entry (Start Menu\Programs\Startup)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
Queries information about the installed CPU (vendor, model number etc)
Queries the volume information (name, serial number etc) of a device
Sigma detected: Recon Command Output Piped To Findstr.EXE
Sigma detected: Startup Folder File Write
Sigma detected: WSF/JSE/JS/VBA/VBE File Execution Via Cscript/Wscript
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses reg.exe to modify the Windows registry

Classification

  • System is w10x64_ra
  • MyTrustID.EXE (PID: 5556 cmdline: "C:\Users\user\Desktop\MyTrustID.EXE" MD5: 1F4BB0F2B9D26F2419FBB7E7BA860D03)
    • cmd.exe (PID: 6780 cmdline: cmd /c mytrustid.bat MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
      • conhost.exe (PID: 6788 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
      • net.exe (PID: 6856 cmdline: NET SESSION MD5: 31890A7DE89936F922D44D677F681A7F)
        • net1.exe (PID: 6876 cmdline: C:\Windows\system32\net1 SESSION MD5: 2EFE6ED4C294AB8A39EB59C80813FEC1)
      • cmd.exe (PID: 6660 cmdline: C:\Windows\system32\cmd.exe /c tasklist | find /I /C "MyTrustIDv1.exe" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • tasklist.exe (PID: 6716 cmdline: tasklist MD5: 0A4448B31CE7F83CB7691A2657F330F1)
        • find.exe (PID: 6696 cmdline: find /I /C "MyTrustIDv1.exe" MD5: 15B158BC998EEF74CFDD27C44978AEA0)
      • reg.exe (PID: 4400 cmdline: reg Query "HKLM\Hardware\Description\System\CentralProcessor\0" MD5: CDD462E86EC0F20DE2A1D781928B1B0C)
      • find.exe (PID: 2696 cmdline: find /i "x86" MD5: 15B158BC998EEF74CFDD27C44978AEA0)
      • reg.exe (PID: 6912 cmdline: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SKUs\.NETFramework,Version=v4.6.1" MD5: CDD462E86EC0F20DE2A1D781928B1B0C)
      • msiexec.exe (PID: 7012 cmdline: msiexec.exe /i MyTrustIDesktop.msi /passive /norestart MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • cscript.exe (PID: 7160 cmdline: cscript CreateShortcut.vbs MD5: CB601B41D4C8074BE8A84AED564A94DC)
      • MyTrustIDv1.exe (PID: 6360 cmdline: "C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe" MD5: 608308069F24F5134F2A7FD0FDEDDA8D)
  • msiexec.exe (PID: 6972 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7080 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 8CC76684883FA410DFF2F184C1945521 MD5: 9D09DC1EDA745A5F87553048E57620CF)
  • cleanup
No yara matches

System Summary

barindex
Source: File createdAuthor: Florian Roth (Nextron Systems): Data: EventID: 11, Image: C:\Windows\SysWOW64\cscript.exe, ProcessId: 7160, TargetFilename: C:\Users\Public\Desktop\MyTrustIDv1.lnk
Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems), frack113: Data: Command: C:\Windows\system32\cmd.exe /c tasklist | find /I /C "MyTrustIDv1.exe", CommandLine: C:\Windows\system32\cmd.exe /c tasklist | find /I /C "MyTrustIDv1.exe", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: cmd /c mytrustid.bat, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 6780, ParentProcessName: cmd.exe, ProcessCommandLine: C:\Windows\system32\cmd.exe /c tasklist | find /I /C "MyTrustIDv1.exe", ProcessId: 6660, ProcessName: cmd.exe
Source: File createdAuthor: Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research): Data: EventID: 11, Image: C:\Windows\System32\msiexec.exe, ProcessId: 6972, TargetFilename: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Source: Process startedAuthor: Michael Haag: Data: Command: cscript CreateShortcut.vbs, CommandLine: cscript CreateShortcut.vbs, CommandLine|base64offset|contains: r+, Image: C:\Windows\SysWOW64\cscript.exe, NewProcessName: C:\Windows\SysWOW64\cscript.exe, OriginalFileName: C:\Windows\SysWOW64\cscript.exe, ParentCommandLine: cmd /c mytrustid.bat, ParentImage: C:\Windows\SysWOW64\cmd.exe, ParentProcessId: 6780, ParentProcessName: cmd.exe, ProcessCommandLine: cscript CreateShortcut.vbs, ProcessId: 7160, ProcessName: cscript.exe
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: rundll32.exe C:\Windows\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\user\AppData\Local\Temp\IXP000.TMP\", EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\MyTrustID.EXE, ProcessId: 5556, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: MyTrustID.EXEVirustotal: Detection: 11%Perma Link
Source: MyTrustID.EXEStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: unknownHTTPS traffic detected: 103.140.139.135:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.140.139.135:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.140.139.135:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: MyTrustID.EXEStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: C:\Windows\System32\msiexec.exeFile opened: z:
Source: C:\Windows\System32\msiexec.exeFile opened: x:
Source: C:\Windows\System32\msiexec.exeFile opened: v:
Source: C:\Windows\System32\msiexec.exeFile opened: t:
Source: C:\Windows\System32\msiexec.exeFile opened: r:
Source: C:\Windows\System32\msiexec.exeFile opened: p:
Source: C:\Windows\System32\msiexec.exeFile opened: n:
Source: C:\Windows\System32\msiexec.exeFile opened: l:
Source: C:\Windows\System32\msiexec.exeFile opened: j:
Source: C:\Windows\System32\msiexec.exeFile opened: h:
Source: C:\Windows\System32\msiexec.exeFile opened: f:
Source: C:\Windows\System32\msiexec.exeFile opened: b:
Source: C:\Windows\System32\msiexec.exeFile opened: y:
Source: C:\Windows\System32\msiexec.exeFile opened: w:
Source: C:\Windows\System32\msiexec.exeFile opened: u:
Source: C:\Windows\System32\msiexec.exeFile opened: s:
Source: C:\Windows\System32\msiexec.exeFile opened: q:
Source: C:\Windows\System32\msiexec.exeFile opened: o:
Source: C:\Windows\System32\msiexec.exeFile opened: m:
Source: C:\Windows\System32\msiexec.exeFile opened: k:
Source: C:\Windows\System32\msiexec.exeFile opened: i:
Source: C:\Windows\System32\msiexec.exeFile opened: g:
Source: C:\Windows\System32\msiexec.exeFile opened: e:
Source: C:\Windows\SysWOW64\cscript.exeFile opened: c:
Source: C:\Windows\System32\msiexec.exeFile opened: a:
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: digitalid.msctrustgate.com
Source: global trafficDNS traffic detected: DNS query: mtid.msctrustgate.com
Source: unknownNetwork traffic detected: HTTP traffic on port 49709 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 49710 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49710
Source: unknownNetwork traffic detected: HTTP traffic on port 49704 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49709
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49704
Source: unknownHTTPS traffic detected: 103.140.139.135:443 -> 192.168.2.16:49704 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.140.139.135:443 -> 192.168.2.16:49709 version: TLS 1.2
Source: unknownHTTPS traffic detected: 103.140.139.135:443 -> 192.168.2.16:49710 version: TLS 1.2
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\586267.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI645B.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI64C9.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{A97F7040-544D-4857-B3ED-8ED1ED9AE368}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI6557.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{A97F7040-544D-4857-B3ED-8ED1ED9AE368}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{A97F7040-544D-4857-B3ED-8ED1ED9AE368}\_853F67D554F05449430E7E.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{A97F7040-544D-4857-B3ED-8ED1ED9AE368}\_A29A2B13E3315CB309EF12.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{A97F7040-544D-4857-B3ED-8ED1ED9AE368}\_FED9824324082FAB031DB2.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{A97F7040-544D-4857-B3ED-8ED1ED9AE368}\_58D1171B4CA0552DFB6D1D.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\586270.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\586270.msi
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSI645B.tmp
Source: MyTrustID.EXEStatic PE information: Resource name: RT_RCDATA type: Microsoft Cabinet archive data, many, 7144194 bytes, 2 files, at 0x2c +A "mytrustid.bat" +A "MyTrustIDesktop.msi", ID 3292, number 1, 259 datablocks, 0x1503 compression
Source: MyTrustID.EXEStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
Source: classification engineClassification label: mal64.evad.winEXE@29/111@2/5
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\Public\Desktop\MyTrustIDv1.lnk
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeMutant created: NULL
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeMutant created: \Sessions\1\BaseNamedObjects\MyTrustIDv1
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeMutant created: \Sessions\1\BaseNamedObjects\C__Trustgate_MyTrustID_logs__rolling
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6788:120:WilError_03
Source: C:\Users\user\Desktop\MyTrustID.EXEFile created: C:\Users\user\AppData\Local\Temp\IXP000.TMP
Source: C:\Users\user\Desktop\MyTrustID.EXEProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c mytrustid.bat
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cscript.exe cscript CreateShortcut.vbs
Source: MyTrustID.EXEStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\SysWOW64\tasklist.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT __PATH, ProcessId, CSName, Caption, SessionId, ThreadCount, WorkingSetSize, KernelModeTime, UserModeTime FROM Win32_Process
Source: C:\Windows\SysWOW64\cmd.exeFile read: C:\Program Files (x86)\desktop.ini
Source: C:\Users\user\Desktop\MyTrustID.EXEKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: MyTrustID.EXEVirustotal: Detection: 11%
Source: unknownProcess created: C:\Users\user\Desktop\MyTrustID.EXE "C:\Users\user\Desktop\MyTrustID.EXE"
Source: C:\Users\user\Desktop\MyTrustID.EXEProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c mytrustid.bat
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe NET SESSION
Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 SESSION
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c tasklist | find /I /C "MyTrustIDv1.exe"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find /I /C "MyTrustIDv1.exe"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find /i "x86"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SKUs\.NETFramework,Version=v4.6.1"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\msiexec.exe msiexec.exe /i MyTrustIDesktop.msi /passive /norestart
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 8CC76684883FA410DFF2F184C1945521
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cscript.exe cscript CreateShortcut.vbs
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe "C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe"
Source: C:\Users\user\Desktop\MyTrustID.EXEProcess created: C:\Windows\SysWOW64\cmd.exe cmd /c mytrustid.bat
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe NET SESSION
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c tasklist | find /I /C "MyTrustIDv1.exe"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find /i "x86"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SKUs\.NETFramework,Version=v4.6.1"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\msiexec.exe msiexec.exe /i MyTrustIDesktop.msi /passive /norestart
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cscript.exe cscript CreateShortcut.vbs
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe "C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe"
Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 SESSION
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find /I /C "MyTrustIDv1.exe"
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 8CC76684883FA410DFF2F184C1945521
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: apphelp.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: aclayers.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: mpr.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: sfc.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: sfc_os.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: cabinet.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: version.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: feclient.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: iertutil.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: wintypes.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: wintypes.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: wintypes.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: textshaping.dll
Source: C:\Users\user\Desktop\MyTrustID.EXESection loaded: advpack.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: edputil.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: urlmon.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: iertutil.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: appresolver.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: bcp47langs.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: slc.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sppc.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: pcacli.dll
Source: C:\Windows\SysWOW64\net.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\net.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\net.exeSection loaded: wkscli.dll
Source: C:\Windows\SysWOW64\net.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\net.exeSection loaded: samcli.dll
Source: C:\Windows\SysWOW64\net.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\net.exeSection loaded: iphlpapi.dll
Source: C:\Windows\SysWOW64\net1.exeSection loaded: samcli.dll
Source: C:\Windows\SysWOW64\net1.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\net1.exeSection loaded: dsrole.dll
Source: C:\Windows\SysWOW64\net1.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\net1.exeSection loaded: wkscli.dll
Source: C:\Windows\SysWOW64\net1.exeSection loaded: logoncli.dll
Source: C:\Windows\SysWOW64\net1.exeSection loaded: cryptbase.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\cmd.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: framedynos.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: dbghelp.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: wbemcomn.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: winsta.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: amsi.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\tasklist.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\find.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\find.exeSection loaded: ulib.dll
Source: C:\Windows\SysWOW64\find.exeSection loaded: fsutilext.dll
Source: C:\Windows\SysWOW64\reg.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\find.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\find.exeSection loaded: ulib.dll
Source: C:\Windows\SysWOW64\find.exeSection loaded: fsutilext.dll
Source: C:\Windows\SysWOW64\reg.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textshaping.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: sxs.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: vbscript.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: amsi.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: userenv.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: msasn1.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: cryptsp.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: rsaenh.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: cryptbase.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: msisip.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: wshext.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: scrobj.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: scrrun.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: linkinfo.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: ntshrui.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: srvcli.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: cscapi.dll
Source: C:\Windows\SysWOW64\cscript.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: mscoree.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: aclayers.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: mpr.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: sfc.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: sfc_os.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: version.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: uxtheme.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dwrite.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: msvcp140_clr0400.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: mswsock.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dnsapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dhcpcsvc6.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dhcpcsvc.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: winnsi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: rasadhlp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: fwpuclnt.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: secur32.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: sspicli.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: schannel.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: mskeyprotect.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: ntasn1.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: ncrypt.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: ncryptsslp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: msasn1.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: gpapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: urlmon.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: iertutil.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: srvcli.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: windowscodecs.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dwmapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: d3d9.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: d3d10warp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wtsapi32.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: winsta.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: powrprof.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: umpdc.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dataexchange.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: d3d11.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dcomp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dxgi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: resourcepolicyclient.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dxcore.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: textshaping.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: textinputframework.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: coremessaging.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: msctfui.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: uiautomationcore.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: propsys.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: d3dcompiler_47.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: msisip.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wshext.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: appxsip.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: opcservices.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: esdsip.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dpapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: etoken.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: netapi32.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: winscard.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dbghelp.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: devobj.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: samcli.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dbgcore.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: saclog.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wfapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: sacperfcounter.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: etokenhid.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: etvtokenengine.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dlpreel.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: sactokensimulator.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: saclog.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: wfapi.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: sacperfcounter.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: etokenhid.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: etvtokenengine.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: dlpreel.dll
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeSection loaded: sactokensimulator.dll
Source: C:\Windows\SysWOW64\tasklist.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll
Source: MyTrustID.EXEStatic file information: File size 7301120 > 1048576
Source: MyTrustID.EXEStatic PE information: Raw size of .rsrc is bigger than: 0x100000 < 0x6ee200
Source: MyTrustID.EXEStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: MyTrustID.EXEStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: MyTrustID.EXEStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: MyTrustID.EXEStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: MyTrustID.EXEStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: MyTrustID.EXEStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: MyTrustID.EXEStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: MyTrustID.EXEStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG

Persistence and Installation Behavior

barindex
Source: C:\Windows\SysWOW64\cmd.exeFile created: C:\Users\user\AppData\Local\Temp\IXP000.TMP\CreateShortcut.vbs
Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exe
Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exe
Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exe
Source: C:\Windows\SysWOW64\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.Concurrent.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\ICSharpCode.SharpZipLib.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Expressions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.NetworkInformation.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.ReaderWriter.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\InstallCertdll.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.NetTcp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\BouncyCastle.Crypto.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XmlSerializer.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\itextsharp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Tasks.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\Newtonsoft.Json.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.Encoding.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Http.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\st3ace.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Resources.ResourceManager.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Xml.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\Hardcodet.Wpf.TaskbarNotification.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.X509Certificates.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Trustgate\MyTrustID\drivers\Trustgate.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XDocument.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tracing.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.EventBasedAsync.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.WebHeaderCollection.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.WindowsRuntime.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Principal.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Algorithms.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Globalization.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Tasks.Parallel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Security.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\Pkcs11Interop.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\IDPrimeTokenEngine.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI64C9.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ObjectModel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.RegularExpressions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.IO.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Timer.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Contracts.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\st3ace_s.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Debug.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Queryable.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\st3csp11.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\32bit\eToken.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\CreateCSRdll.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.Lightweight.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Json.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Requests.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Trustgate\MyTrustID\drivers\Trustgate_s.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Duplex.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Parallel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tools.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.ILGeneration.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.Encoding.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\WebSockets.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Http.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Windows.Interactivity.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.Annotations.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Dynamic.Runtime.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Handles.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Encoding.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\log4net.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Numerics.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\Trustgate\MyTrustID\Uninstall.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI64C9.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MyTrustIDv1.lnk
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MyTrustIDv1.lnk
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyTrustID Apps
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyTrustID Apps\MyTrustIDv1.lnk
Source: C:\Users\user\Desktop\MyTrustID.EXERegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0
Source: C:\Users\user\Desktop\MyTrustID.EXERegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0
Source: C:\Users\user\Desktop\MyTrustID.EXERegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0
Source: C:\Users\user\Desktop\MyTrustID.EXERegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce wextract_cleanup0
Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\tasklist.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cscript.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\cscript.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess information set: NOOPENFILEERRORBOX

Malware Analysis System Evasion

barindex
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeMemory allocated: B70000 memory reserve | memory write watch
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeMemory allocated: 2720000 memory reserve | memory write watch
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeMemory allocated: 4720000 memory reserve | memory write watch
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeThread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeThread delayed: delay time: 922337203685477
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Expressions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.Concurrent.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\ICSharpCode.SharpZipLib.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.NetworkInformation.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.ReaderWriter.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\InstallCertdll.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.NetTcp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\BouncyCastle.Crypto.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XmlSerializer.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\itextsharp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Tasks.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.Encoding.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\Newtonsoft.Json.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Http.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\st3ace.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Resources.ResourceManager.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Xml.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\Hardcodet.Wpf.TaskbarNotification.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.X509Certificates.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Trustgate\MyTrustID\drivers\Trustgate.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XDocument.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tracing.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.EventBasedAsync.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.WebHeaderCollection.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Principal.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.WindowsRuntime.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Algorithms.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Globalization.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Security.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Tasks.Parallel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\Pkcs11Interop.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\IDPrimeTokenEngine.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ObjectModel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI64C9.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.RegularExpressions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.IO.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Timer.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Contracts.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\st3ace_s.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Debug.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Queryable.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\st3csp11.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\32bit\eToken.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\CreateCSRdll.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.Lightweight.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Json.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Requests.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Trustgate\MyTrustID\drivers\Trustgate_s.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Duplex.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Parallel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tools.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.ILGeneration.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.Encoding.Extensions.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\WebSockets.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Http.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Windows.Interactivity.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.Annotations.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Primitives.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Dynamic.Runtime.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Handles.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Encoding.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\Uninstall.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Numerics.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\Trustgate\MyTrustID\log4net.dllJump to dropped file
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe TID: 5952Thread sleep time: -922337203685477s >= -30000s
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe TID: 5952Thread sleep time: -922337203685477s >= -30000s
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeThread delayed: delay time: 922337203685477
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeThread delayed: delay time: 922337203685477
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
Source: C:\Windows\SysWOW64\tasklist.exeProcess token adjusted: Debug
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeProcess token adjusted: Debug
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeMemory allocated: page read and write | page guard
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\net.exe NET SESSION
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c tasklist | find /I /C "MyTrustIDv1.exe"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg Query "HKLM\Hardware\Description\System\CentralProcessor\0"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find /i "x86"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\reg.exe reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\.NETFramework\v4.0.30319\SKUs\.NETFramework,Version=v4.6.1"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\msiexec.exe msiexec.exe /i MyTrustIDesktop.msi /passive /norestart
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\cscript.exe cscript CreateShortcut.vbs
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe "C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe"
Source: C:\Windows\SysWOW64\net.exeProcess created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 SESSION
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\tasklist.exe tasklist
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\find.exe find /I /C "MyTrustIDv1.exe"
Source: C:\Windows\SysWOW64\reg.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Windows\SysWOW64\reg.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Windows\SysWOW64\reg.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Windows\SysWOW64\reg.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Windows\SysWOW64\reg.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Windows\SysWOW64\reg.exeRegistry key value queried: HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\0
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\SysWOW64\cscript.exeQueries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\log4net.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Threading.Tasks\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Threading.Tasks.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.Core.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Reflection\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Reflection.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Collections\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Collections.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ObjectModel\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ObjectModel.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Linq\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Linq.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\WebSockets.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\itextsharp.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ComponentModel.Composition\v4.0_4.0.0.0__b77a5c561934e089\System.ComponentModel.Composition.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\Hardcodet.Wpf.TaskbarNotification.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\Newtonsoft.Json.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Numerics\v4.0_4.0.0.0__b77a5c561934e089\System.Numerics.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Channels\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Channels.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Web\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Web.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.Serialization.Primitives\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Primitives.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Text.RegularExpressions\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Text.RegularExpressions.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemCore\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemCore.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\System.Windows.Interactivity.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Threading\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Threading.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Reflection.Extensions\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Reflection.Extensions.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Resources.ResourceManager\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Resources.ResourceManager.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Linq.Expressions\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Linq.Expressions.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguili.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguisli.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuii.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguisbi.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuiz.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguibl.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguibli.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemData\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemData.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Program Files (x86)\Trustgate\MyTrustID\Pkcs11Interop.dll VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation
Source: C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exeQueries volume information: C:\Windows\Fonts\segoeuib.ttf VolumeInformation
Source: C:\Windows\SysWOW64\cscript.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity Information12
Scripting
1
Replication Through Removable Media
1
Windows Management Instrumentation
12
Scripting
11
Process Injection
22
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System2
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts1
Command and Scripting Interpreter
21
Registry Run Keys / Startup Folder
21
Registry Run Keys / Startup Folder
1
Modify Registry
LSASS Memory2
Process Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
DLL Side-Loading
1
DLL Side-Loading
1
Disable or Modify Tools
Security Account Manager31
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook31
Virtualization/Sandbox Evasion
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script11
Process Injection
LSA Secrets1
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain Credentials124
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
File Deletion
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
MyTrustID.EXE3%ReversingLabs
MyTrustID.EXE11%VirustotalBrowse
SourceDetectionScannerLabelLink
58626a.rbf (copy)0%ReversingLabs
58626a.rbf (copy)0%VirustotalBrowse
58626b.rbf (copy)0%ReversingLabs
58626b.rbf (copy)0%VirustotalBrowse
58626c.rbf (copy)0%ReversingLabs
58626c.rbf (copy)0%VirustotalBrowse
58626d.rbf (copy)0%ReversingLabs
58626e.rbf (copy)0%ReversingLabs
58626f.rbf (copy)0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\32bit\eToken.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\BouncyCastle.Crypto.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.Core.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.Platform.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\userburn.Micro.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\CreateCSRdll.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\Hardcodet.Wpf.TaskbarNotification.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\ICSharpCode.SharpZipLib.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\IDPrimeTokenEngine.dll2%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\InstallCertdll.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe4%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\Newtonsoft.Json.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\Pkcs11Interop.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.Concurrent.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Collections.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.Annotations.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.EventBasedAsync.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Contracts.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tools.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.Tracing.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Dynamic.Runtime.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Globalization.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.IO.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Expressions.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Parallel.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.Queryable.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Linq.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Http.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.NetworkInformation.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Primitives.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.Requests.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Net.WebHeaderCollection.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ObjectModel.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.ILGeneration.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.Lightweight.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Emit.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Extensions.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Reflection.Primitives.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Resources.ResourceManager.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Extensions.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Handles.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.WindowsRuntime.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.InteropServices.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Numerics.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Json.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.Serialization.Xml.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Runtime.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Algorithms.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Encoding.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.Primitives.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Cryptography.X509Certificates.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Security.Principal.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Duplex.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Http.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.NetTcp.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Primitives.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Security.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.Encoding.Extensions.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Text.RegularExpressions.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Tasks.Parallel.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Threading.Timer.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Windows.Interactivity.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.ReaderWriter.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XDocument.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\System.Xml.XmlSerializer.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\Uninstall.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\WebSockets.dll0%ReversingLabs
C:\Program Files (x86)\Trustgate\MyTrustID\itextsharp.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
digitalid.msctrustgate.com
103.140.139.135
truefalse
    unknown
    mtid.msctrustgate.com
    127.0.0.1
    truefalse
      unknown
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      103.140.139.135
      digitalid.msctrustgate.comMalaysia
      133936X86NETWORK-AS-APX86NetworkSdnBhdMYfalse
      IP
      127.0.0.1
      Joe Sandbox version:41.0.0 Charoite
      Analysis ID:1541694
      Start date and time:2024-10-25 02:44:24 +02:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsinteractivecookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:24
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      Analysis Mode:stream
      Analysis stop reason:Timeout
      Sample name:MyTrustID.EXE
      Detection:MAL
      Classification:mal64.evad.winEXE@29/111@2/5
      Cookbook Comments:
      • Found application associated with file extension: .EXE
      • Exclude process from analysis (whitelisted): dllhost.exe, SgrmBroker.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 184.28.90.27
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, e16604.g.akamaiedge.net, ctldl.windowsupdate.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
      • Report size getting too big, too many NtOpenKeyEx calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • Report size getting too big, too many NtReadVirtualMemory calls found.
      • VT rate limit hit for: 58626d.rbf (copy)
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:AB61BD332D4C9178BC7BCBB415C72100
      SHA1:0EE4AD0B06BEFEF0F14803D948791529B2F813E5
      SHA-256:5F0F0F179FEF5D87C8629C4A40176A66BDBB6DAC70735D2937697AB515671CAC
      SHA-512:45D8D008457629E54399ED09B91AC2CC51A46DE5E0C9E696D22BF4CE0B87AA8E1237022A57AF8F18C44524D288CBBDF32C1FEDFDB9B6334FB686BAE7E6409F12
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............&... ...@....... ..............................$.....@..................................&..O....@..................`d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......8...#Strings....T.......#US.\.......#GUID...l...\...#Blob......................3................................................|...........(...........F....._.....*...............................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.E...C.L...K.L...........................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:A4C209F0CB8A1387172150A5238D3B99
      SHA1:3B549EDFF9FCC494AC515D4C31682A24999B3CFA
      SHA-256:1C28B8BFBA0729AEF5ED3D83FCACCAECB7FBCF9FB5F0A7D2D27291C4B2DAA07B
      SHA-512:15570915CB48DB47C49488F5FF2061B242806FBE9AAEBEE18A8DEB1ADB9CA86CA7AB1935E4C9700638708E6DDA40D249A8E76ED17E03437AD916CE44D4281F9A
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0.............J'... ...@....... ....................................@..................................&..O....@..|...............0d...`....................................................... ............... ..H............text...P.... ...................... ..`.rsrc...|....@......................@..@.reloc.......`......................@..B................,'......H.......P ..(...................x&......................................BSJB............v4.0.30319......l.......#~..P...h...#Strings............#US.........#GUID.......X...#Blob......................3................................................-.........................................D.....a...................V.....V.....V...!.V...).V...1.V...9.V...A.V...I.V.......................#.....+.....3.....;.A...C.H...K.H............................................. .......\.....
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9C8CAF4520DB3E518921CEBAFA603808
      SHA1:A9B83852F847F1F7B142BD5D0D1350FA8AF508DC
      SHA-256:8BEDF1CB0460A131A44886CB711600E42636E18EA771B9814CC482ED74B65AF1
      SHA-512:64C193711CBB31F960CE93B6945E497AF01A7E814BA094D714C39C9F155E98627A9E1DF28661A153483D0E859A5973E8B0A6406EC4B0B0DDDC5B937C350AF585
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............)... ...@....... ....................................@.................................8)..O....@..\...............(d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...\....@......................@..@.reloc.......`......................@..B................l)......H.......P ..h....................(......................................BSJB............v4.0.30319......l.......#~..h.......#Strings............#US.........#GUID.......X...#Blob......................3................................".....g...........................N...........3.....k...............................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.>...C.E...K.E............................................. .............
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:EBD3FF713B68750EEAA914829A723879
      SHA1:4F5051601C4E774066B8CBC8C494BF4C16ACF1D7
      SHA-256:5A021106748194463FCA0520083AE95C84BA0344387254C0EE97C5DFA6E11DBB
      SHA-512:A2DAE0D2D81B0B16C25DE2ACB6FCE07294A2B8375B9DCC822860703CF31B47F57FC0190C895D4EC32439D43173E9B3AF3C187CB4E2FAED811C67CBE63B557779
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............'... ...@....... ............................... ....@..................................'..O....@..................0d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..p.......#Strings....H.......#US.P.......#GUID...`...l...#Blob......................3................................................v.2.....2...^.2.....2.....2.....2.....2.....2.....2.................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.T...C.[...K.[...........................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:5D450EBC4BC80A6E94D969F5AFA5C7F8
      SHA1:C618EC70A3C40D6D5D3C706D210F0783E212E930
      SHA-256:73AED90C3344FEAD3A5C63731110BA3F22E205F1116076FC85A1E98AC4093ADD
      SHA-512:A39E8A1CDF5385C62140DFA3099F30C5F2903BC4767D9B99D90E02F9B234F2ECD7066D57B00EA1914D0D2E2943F44DAFD7CD10C1123CC1E570EDE85B35223595
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0.............f)... ...@....... ..............................q.....@..................................)..O....@..\...............Hd...`....................................................... ............... ..H............text...l.... ...................... ..`.rsrc...\....@......................@..@.reloc.......`......................@..B................H)......H.......P ..D....................(......................................BSJB............v4.0.30319......l.......#~..d...t...#Strings............#US.........#GUID.......T...#Blob......................3.................................................."....."...&."...x."...D."...].".....".....".....".....9...........................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.=...C.D...K.D.....................................B.....................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:9E75E2BDAD874AEA993001763276AD6F
      SHA1:5271A66BDF88C9A468E919B1052834DDECDFA7B5
      SHA-256:9FEA1CC1B18117A5A1097D8D0911AC2D1F6B095001CBB14E6C76A6D12E5F0F66
      SHA-512:62A6D062ED895594EBD1C89E5A84ADF5A4BB4ECB7B149D3FD6801D50043F8DD703445623D7B623149C812D2B960FA7CE08F4F18EFF85A8EBC3EA40F96AE0271A
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............*... ...@....... ...............................N....@..................................)..O....@..................Hd...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................<)......................................BSJB............v4.0.30319......l.......#~..l.......#Strings....x.......#US.........#GUID.......\...#Blob......................3................................!.................B...R.B...o.B.....B.....B.....B.....B.....B...,.B.....n...........[.....[.....[...!.[...).[...1.[...9.[...A.[...I.[.......................#.....+.....3.....;.C...C.J...K.J.....................................w.....................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:modified
      Size (bytes):56322
      Entropy (8bit):6.003394862226206
      Encrypted:false
      SSDEEP:
      MD5:446FA260C086799210C95CCA20EC4EB2
      SHA1:979D7AEC051CC255B502E81F6B3C47B3F2511D1D
      SHA-256:5A75A0ACE1F52111F8A84487E7B5DC3F0909DC6C7EBABBBDC923E4CF7231FE9E
      SHA-512:9F302869D48A5BE37DA525F9A68E587727FBA7B28415EAB8AAC97188B89CD0FC65D3260ED1D12249C65D6D313AAAB51F3786DE15845B31BE8728A76D92E1270D
      Malicious:false
      Reputation:unknown
      Preview:...@IXOS.@.....@..XY.@.....@.....@.....@.....@.....@......&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}..MyTrustID..MyTrustIDesktop.msi.@.....@.....@.....@......_853F67D554F05449430E7E.exe..&.{515A415D-AD11-4005-A4FD-AD810EC31437}.....@.....@.....@.....@.......@.....@.....@.......@......MyTrustID......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{C2294F64-FF6D-B70D-9232-C2B27053D3E5}&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}.@......&.{1CCD8267-01F6-9431-57D9-DE6F4D458FB4}&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}.@......&.{15512432-F9BC-C27D-E6C3-CB998551EC6D}&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}.@......&.{DC08770C-5C12-A045-E7BD-149A8796C731}&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}.@......&.{6FF127C0-AB47-F7FC-DD69-D59D3C9896FD}&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}.@......&.{6CBA979C-8854-EEE3-EB61-C0BC85E4B07D}&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}.@......&.{4F911721-02D0-BCE5-DDFB-E29EF
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):644152
      Entropy (8bit):6.793324516037024
      Encrypted:false
      SSDEEP:
      MD5:DEC7255F1EEC40FA6FB11B767BB1EDB1
      SHA1:4503EDD19428656F1B20ABDF736F30AFF769DA9E
      SHA-256:18D6F36D2021508A13F20EC6E395612DC6B96108FE009B63003A66CFB2D40D7D
      SHA-512:83F16F8E696DBF508F169AD1532EE9774253D0AD7D7AB72244F5A83AE86582B769023081992B90B823FC69B865FDAAC9C726F0F1FD0357C53500DAE2A183097D
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........F..x...x...x.J.8...x...x...x.J.a...x.Aj....x...y...x.L.....x..B...x..B....x..B....x.......x..B....x.Rich..x.................PE..L......W...........!................g........................................ ......a.....@.........................p...S_..............@...............8....... [......8.......................................................@....................text.............................. ..`.rdata...i.......j..................@..@.data....Z...@...(...,..............@....rsrc...@............T..............@..@.reloc..ha.......b...Z..............@..B........................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):2609152
      Entropy (8bit):5.824583171540262
      Encrypted:false
      SSDEEP:
      MD5:F0B3E112CE4807A28E2B5D66A840ED7F
      SHA1:54A6743781FD4CEB720331FCE92F16186931192D
      SHA-256:333903C7D22A27098E45FC64B77A264AA220605CFBD3E329C200D7E4B42C881C
      SHA-512:DC8EC9754C5E86F7E54E75FF3E5859C1B057F90E9C41788037B944A5DB2CB3B70060763D0EFCBE55EC595BCC47A9C0FF847A4876821470CA1659C31AFD5B0190
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...,.._...........!......'.. ........'.. ....'...@.. ........................(.....?G(.....................................d.'.W.....'.`.....................'...................................................... ............... ..H............text....'.. ....'................. ..`.rsrc...`.....'.......'.............@..@.reloc........'.......'.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):14848
      Entropy (8bit):5.317912087227824
      Encrypted:false
      SSDEEP:
      MD5:AB7867BD44B59879A59B5CB968E15668
      SHA1:78BDFF6642D5C04ADB0E66461AEE0553660B1C80
      SHA-256:36141745E29B73817CF38F8A298DCEE3DE8338B0A0ECF82284BB9F74831296ED
      SHA-512:00017413BC57C8AF8B657621A306A53B65241F8817DFE14DA7590366AD3BCC0A989ECB1E85963CAB2C837BE40529A2961B91A23EB7420C90E341C277A2FAA86F
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...`I.Y.........." ..0..0..........*O... ...`....... ....................................@..................................N..O....`...............................M............................................... ............... ..H............text...0/... ...0.................. ..`.rsrc........`.......2..............@..@.reloc...............8..............@..B.................O......H........(...$.................. M.......................................s.........~..........s.........*....0..f.......~....,.*......~....~....%-.&~...... ...s....%.....o....~....o....~....%-.&~......%...s....%..........*.s.........~......(...s.........*f.o.....o.....,o....o....*6..(....(...+*V.-.r...ps....z.o....*J.(.....(....o....*.0..............o....-..........*.*..{....*"..}....*N....&...%....(....*..s,...%.}$...%.}%...%.}#...( ...*...~'...%-.&~&...../...s!...%.'...(...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):83968
      Entropy (8bit):5.92989745056437
      Encrypted:false
      SSDEEP:
      MD5:A52BDECBC1B7625CB13C9385FAD4231B
      SHA1:614CB142FE219A056EFF7D9DFD4FC79049B29B98
      SHA-256:0AC08AC0A63F8424568F2BD6F13AAC242FAD6D508C6A7CB5D208F2C85A0CE11A
      SHA-512:8E117F6F70336DFD0BFBC2DA9E7B2962D69568C95BF9960D77DF24688C91048187F4769437D61453792FD6ECB8464ACFABB62959A140D9D108D157EC370AADBD
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...aI.Y.........." ..0..>...........]... ...`....... ...............................p....`..................................]..O....`..............................\\............................................... ............... ..H............text....=... ...>.................. ..`.rsrc........`.......@..............@..@.reloc...............F..............@..B.................]......H...............................[........................................{....*..{....*V.( .....}......}....*...0..;........u......,/(!....{.....{....o"...,.(#....{.....{....o$...*.*. ht.. )UU.Z(!....{....o%...X )UU.Z(#....{....o&...X*.0...........r...p......%..{.....................-.q.............-.&.+.......o'....%..{.....................-.q.............-.&.+.......o'....((...*6.~.....o)...*2.~....o*...*6.~.....o)...*2.~....o*...*...0..9........(....-..(....,..*.u......-.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):61952
      Entropy (8bit):5.834897784977097
      Encrypted:false
      SSDEEP:
      MD5:AA5F96C02B08D9B33322F3024058DD91
      SHA1:39C1BFF758D6974D90B4690B5911B4371ED91F19
      SHA-256:CDFD368E3616D8F380DCD6750F22DEFE24AADBC4AB99F6E0DAAEA9290AF96286
      SHA-512:5CEC444CB47C024F1395320AC1CBD5BC6FE8ECF5C70447F71462E85A66576E27801E3D817358FC8BBF050A752C4A51224DB3C0B763B62F3773B2C86C4269CFB7
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..._I.Y.........." ..0.................. ... ....... .......................`...........@.....................................O.... ..l....................@....................................................... ............... ..H............text........ ...................... ..`.rsrc...l.... ......................@..@.reloc.......@......................@..B........................H........b..D.............................................................(....*:.( .....(!...*>..(".....(!...*..{#...*"..}#...*.0../.......s$......}%.....}&....('...,.....(...s)...o*...*N....+...s)...o*...*..0..........s,......}-.....}......}/.......0...s)...o*...*&...(1...*.0..........s2......}3.....}4.....}5.......6...s)...o*...*&...(7...*.s8...%.}9...%.}:.....;...s)...(s...*"..(<...*R..%..=...s)...o*...*..(>...*B.('...,...(?...*B.('...,...(@...*....0..'.......sA......}B..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):23040
      Entropy (8bit):6.016852466199556
      Encrypted:false
      SSDEEP:
      MD5:01D564A7A5DCD8444FDC9BDC846A5B8C
      SHA1:CFF602D0C3139FDA1ADB47D3B092AC06D1AB349C
      SHA-256:3E0DC4126D542A515227284E5EA84CB0578B7936379FC6659346B8417D69E0E2
      SHA-512:9195CB0F06941C93F22035508915E9135BFEA100EDBE30EDCC58FA1E7F4C828A795878E1089EA60C7EF8F7524A33254F13F231A191DF33C915596474ED27AE6B
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......M...e...e...e....9..e..[....e..[....e..[....e..[....e..l....e...e..:e......e......e...U..e......e..Rich.e..................PE..L...4S._...........!.....4...:.......7.......P............................................@..........................`..P... a..................................$....Z..p............................[..@............P...............................text....2.......4.................. ..`.rdata.......P.......8..............@..@.data........p.......P..............@....rsrc................R..............@..@.reloc..$............T..............@..B........................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):45056
      Entropy (8bit):5.6056707762562175
      Encrypted:false
      SSDEEP:
      MD5:810105219D96749674C5BF31C82A3B09
      SHA1:0DE6E8B9834B4BB742E8CA90BDB02019A355A422
      SHA-256:4A2438ECFCAD3E6E7BB942ACF2C40FBE2C0D72E4982DF303AB5828AF26CA753E
      SHA-512:18FD5C687FA8BDB5E3F65CD9D86CEF452E32831D9711AF1A1FD7A9E053B914455C8F0DA23E1A22EDF0C24E9589F15E75F560B82DEDDD177A6050A230807B96AA
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Kn.V...........!..................... ........... ....................... ............`.....................................O.......X............................................................................ ............... ..H............text........ ...................... ..`.rsrc...X...........................@..@.reloc..............................@..B........................H........O...s...........................................................0..b............(....-P....=....s......o....o.......(.....o....o.......(....s....s............,..o.....~....*..........7R.......0..).......(.......(....-.#.......?*..( ......(!...*....0..).......(.......(....-.#.......?*..( ......("...*....0............s......o.....o...........o....-...(#....X...($.....+p.o.....3...(#......($.....(%...Y.Y..+J.o.....3...(#......(&.....(%...X.X..+$.o.....3...(#.....('...Y.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):198656
      Entropy (8bit):5.9179021547434365
      Encrypted:false
      SSDEEP:
      MD5:CC547565785085D77197950305FF88D6
      SHA1:E2D92D4139FF587C9AE02EF00E0579DA0A9C896A
      SHA-256:2C32B22249CA820844CB40305E6353E8CA2F52737E5F5EE13F6BB8B36ADE7263
      SHA-512:C096DF120453193D633E800CFBD86049327308F98FF05A042232048F2F9FF7F6143B7D7166214D030C030AE01652E673A6ECBA0A1623814739DD9181E7AEBFEA
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....QH..........." ..0.................. ... ....... .......................`......E.....`.................................u...O.... ..t....................@..........T............................................ ............... ..H............text........ ...................... ..`.rsrc...t.... ......................@..@.reloc.......@......................@..B........................H.......t....~............................................................(....*"..(....*&...( ...*&...(!...*2.r...p(....*"..(....*&...(....*&...(....*2.rE..p(....*"..(....*&...(....*&...(....*2.r...p(....*"..(....*&...(....*&...(....*J..r...p("...(....*v....(#.....(#.....(#...(....*....G...%...%.r...p.%...%.r...p.%....%.r+..p.%...($...(....*..(....*&...(....*&...(....*.0..)........{.........(%...t......|......(...+...3.*....0..)........{.........('...t......|......(...+...3.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):482360
      Entropy (8bit):6.710289960871951
      Encrypted:false
      SSDEEP:
      MD5:07088ACD148D865334EB9A5F7B7A2D2C
      SHA1:89518E939DDE23A8860039DEF4695E0A68C8A9E3
      SHA-256:1805DF2029D4581722E94C0CD4D3ABADD586F9225049E1BB86AF9AE283836B2C
      SHA-512:C45EFE1399A59752CEE523CA031B5B697591C31841428DCF818F1F7BB222C87E315B4B9B67B04878B9706D7B3173A0A0B5FB7B13819B695DD8960541A7E7A0A7
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 2%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........hR..;R..;R..;.e&;C..;.e$;X..;.e';...;...;S..;R..;S..;...;P..;4M";P..;R..;T..;..P;_..;4M;;"..;4M#;S..;4M ;S..;R.~;S..;4M%;S..;RichR..;........PE..L......W...........!.....................................................................@.............................q...$........0...............D..8....@..4J......8...........................@...@...............L............................text............................... ..`.rdata...!......."..................@..@.data....C..........................@....rsrc........0......................@..@.reloc...c...@...d..................@..B........................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):29184
      Entropy (8bit):6.186538552836002
      Encrypted:false
      SSDEEP:
      MD5:B10B382468971CCB7C6F6E43F5F6A103
      SHA1:2334067B12306DB2F2EC21D4C7AED8B3793345DD
      SHA-256:4A1D808AFCA4620A16F628E46D557C2609304FB22340D50DFC295491AAC40FCC
      SHA-512:F2064A968FDFC61589C79C1F0F02E76FA90CCF755009B536D9EE8531B0A68A34567C0B2FA6DB521856D4F1411EBF8339474DB8158F6DCFACCBB9D6CE3C995692
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........+1..J_..J_..J_..2...J_."[..J_."\..J_."Z..J_."^..J_.,^..J_..J^.J_.G#V..J_.G#_..J_.G#...J_.G#]..J_.Rich.J_.........PE..L...oS._...........!.....B...6.......F.......`............................................@..........................q..T....r..................................X....g..p............................g..@............`...............................text...5A.......B.................. ..`.rdata.......`... ...F..............@..@.data................f..............@....rsrc................j..............@..@.reloc..X............l..............@..B................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):250
      Entropy (8bit):5.818506374523169
      Encrypted:false
      SSDEEP:
      MD5:217BA4851844E9E3A11E6F53C7B42F4C
      SHA1:A72174F126FDB1945D1532449C467522467B7AD4
      SHA-256:2C60575D9662C53F7FE00A0BFB54CF7426ED9AD59A8142A835B3A58CE6EA38BA
      SHA-512:C140726ADDD66B8F9ECD18A3F789B23966352F663BF592826CBF07B87F46180D13F0C7838DDDCA65CE482FE66A7587B77C5117F02760263CC8BC5EDFFC629B6B
      Malicious:false
      Reputation:unknown
      Preview:<LicenseInfo>.. <LicenseKey>KQz71xjITSXfaNJR+oRVwD5r62avCflJhITIF+lX44I8oWyBhW3KN1kNWvnmAi3EjtFbBOotFr7Xiq/zPL3pA93voR9/WppKV41tXSfPhdcKiQWz7X8C0YQTfUWtv071dGHOzzyhzU1h1dJIED4lP1y5DcQRNQsQMhvl/NVmcWak1LIYkFQa9x1xvf76jzV0</LicenseKey>..</LicenseInfo>
      Process:C:\Windows\System32\msiexec.exe
      File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):722
      Entropy (8bit):4.719390226150669
      Encrypted:false
      SSDEEP:
      MD5:63C23DF34F506DEEB643318D3C582960
      SHA1:DC0F0DD6622EEEE9FE77BC9CE230A1161303D290
      SHA-256:1D417F12D209147F21DA564B665DAED74D7A39885FC3E39C070F2348ED60FDD5
      SHA-512:75C11AFF3CFD14B0A9ED0519D94B7A9C51ED87D432C34AA68326D89F1212A35481270958CC7D7B57E0E183BAC0D944E5773698A5B504E9CDE23639D0B00CFC1B
      Malicious:false
      Reputation:unknown
      Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <system.webServer>.. <staticContent>.. <mimeMap fileExtension=".html" mimeType="text/html"/>.. <mimeMap fileExtension=".css" mimeType="text/css"/>.. <mimeMap fileExtension=".ico" mimeType="image/x-icon"/>.. <mimeMap fileExtension=".jpg" mimeType="image/jpeg"/>.. <mimeMap fileExtension=".jpeg" mimeType="image/jpeg"/>.. <mimeMap fileExtension=".bmp" mimeType="image/bmp"/>.. <mimeMap fileExtension=".png" mimeType="image/png"/>.. <mimeMap fileExtension=".js" mimeType="text/javascript"/>.. <mimeMap fileExtension=".map" mimeType="application/json"/>.. </staticContent>.. </system.webServer>..</configuration>
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):2592256
      Entropy (8bit):6.349342333979024
      Encrypted:false
      SSDEEP:
      MD5:608308069F24F5134F2A7FD0FDEDDA8D
      SHA1:791CF581C3FDFD1ECCB9B3A4E44E2B373B82673E
      SHA-256:147829C889154833B32AF4BD4ADF81B34B69251BD4F50D1427A6A8D3D41A05A4
      SHA-512:A61D30050A10593B994EAD419FD15F6C42936CBF9EC04970256EBBBEAE892FD0F6C66591E63D65049DEDA9EAFCB240B750F1A36369FDAAC608D3C30B20F1704B
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 4%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."...0...$..........$$.. ...@$...@.. ........................(...........`.................................0$$.O....@$.......................'......#$.8............................................ ............... ..H............text.....$.. ....$................. ..`.rsrc........@$.......$.............@..@.reloc........'.......'.............@..B................d$$.....H.......hO...y......O...p...0[...........................................0............ 4......(*....+..*.0.................o+....+..*B.........o,....*...0..1.........o-...r...p $...........%...%....o....t.....+..*.....o/....*".(0....*:.r!..p(......*....0..r.........r7..po1.....(2...-..o3...rC..p(4...+......,..("...o%.....("....rM..po1....rW..po1...(5....r_..po1...(5...o&....*B.(6.......}....*..0............{.....+..*.0..9.........(2........,*.(7....o8.......ijo9.....o:.......
      Process:C:\Windows\System32\msiexec.exe
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):7472
      Entropy (8bit):5.2567712293742455
      Encrypted:false
      SSDEEP:
      MD5:89D33301F4F4C863D2A26EEC2F0CED29
      SHA1:9D9EE2B329C1C01A13F0133273885A926D05D76C
      SHA-256:D9B8A9220194DD492988482F72826E4FA4CBC84A7270EE43A3976634F1E47162
      SHA-512:2A7567A0AF3954FCD4075157327E3DF18E328944F13E0F35FBFC2EE52BE228521EC1D5C1422D175FE6586577CCF7153CC779B8372D7113163F97B2943194FAA2
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <section name="log4net" type="log4net.Config.Log4NetConfigurationSectionHandler, log4net" />.. </configSections>.. <log4net>.. <appender name="RollingLogFileAppender" type="log4net.Appender.RollingFileAppender">.. <lockingModel type="log4net.Appender.FileAppender+MinimalLock" />.. <file value="C:\\Trustgate\\MyTrustID\\logs\\" />.. <datePattern value="dd.MM.yyyy'.log'" />.. <staticLogFileName value="false" />.. <appendToFile value="true" />.. <rollingStyle value="Composite" />.. <maxSizeRollBackups value="10" />.. <maximumFileSize value="5MB" />.. <layout type="log4net.Layout.PatternLayout">.. <conversionPattern value="%date [%thread] %-5level %logger %line - %message%newline" />.. </layout>.. </appender>.. <root>.. <level value="ALL" />.. <appender-ref ref="RollingLogFileAppender" />.. </root>.. </log4net>.. <startup>..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):700336
      Entropy (8bit):5.9289057284451445
      Encrypted:false
      SSDEEP:
      MD5:6815034209687816D8CF401877EC8133
      SHA1:1248142EB45EED3BEB0D9A2D3B8BED5FE2569B10
      SHA-256:7F912B28A07C226E0BE3ACFB2F57F050538ABA0100FA1F0BF2C39F1A1F1DA814
      SHA-512:3398094CE429AB5DCDECF2AD04803230669BB4ACCAEF7083992E9B87AFAC55841BA8DEF2A5168358BD17E60799E55D076B0E5CA44C86B9E6C91150D3DC37C721
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0................. ........... ..............................f*....`.....................................O.......................................T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........z..<&..................<.........................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X.+....b...aX...X...2.....cY.....cY....cY...{...._..{........+,..{[....3...{Z......(....,...{Z...*..{\.......-..*...0...........-.r...ps....z.o......-.~....*.~....X...+....b..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):553216
      Entropy (8bit):5.940269664524611
      Encrypted:false
      SSDEEP:
      MD5:DC168852C8FDD85C68A8538A0CBBE217
      SHA1:A3F6F0F0017B1E972D2AFFA8B5DFE1CBD2D48566
      SHA-256:8A7EBB2AEBC0517FE671140900874A20622CCD09D1D4DF5FB755EDAE8264E888
      SHA-512:E313876980B0A34E5515685DB4114E57C7961F9938ABFCCE0CE10FEDB6EA856FB015F5ED8D37E001F4894135B1B97E8EA39D4398406CA61D80D1651ED76A08A3
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...q.._.........." ..0..:..........zW... ...`....... ..............................Q{....`.................................(W..O....`..0............D...-...........U............................................... ............... ..H............text...H9... ...:.................. ..`.rsrc...0....`.......<..............@..@.reloc...............B..............@..B................\W......H........m..T...................pU......................................2.(....(....*"..(....*6.(.....(....*J.(.....(....(....*6..(....(....*....0...........(.......(....U*6.(.....(....*6..(....(....*.0...........(.......(....R*6.(.....(....*6..(....(....*.0...........(.......(....Q*6.(.....(....*"..(....*&..(....Q*6.(.....(....*..0............(.......(........(....(.......(.......(......2...(.......(........(....(....+'r...p..(.......(........(....(....(.......(.......(.....
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20728
      Entropy (8bit):6.9344402861411885
      Encrypted:false
      SSDEEP:
      MD5:E84C5BCCC8B71D8EAD5639FF2D0C1742
      SHA1:41954F77FFF8375D1CA7F5AB1D7685FF0D7A0578
      SHA-256:7F4696B89B13603FC93225E0EA0C82FFCDF57587B45BBE9FC7435CF70CC716E1
      SHA-512:F701BC5444717B367235B5FE54E85AAA99BD7BBBC75FB3BDA9F411EE4598DA5AC4E82CD9FE88AFB419282C61F14229874B8147E72AF3AD1A2003022699DB9FB3
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............^'... ...@....... ..............................f.....@..................................'..O....@..x................>...`....................................................... ............... ..H............text...d.... ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B................@'......H.......P ..<....................&......................................BSJB............v4.0.30319......l.......#~..T...p...#Strings............#US.........#GUID.......`...#Blob......................3............................................................$...........B.....[.................v...................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.H...C.H...K.X.............q.....B.......................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30760
      Entropy (8bit):7.040745236586006
      Encrypted:false
      SSDEEP:
      MD5:73A344CD286372A7377038B78C6F2231
      SHA1:720126F0DDDCBB576E365A54E1F4B8CA68011D73
      SHA-256:A4EFF485C98D94717A2B7ABED9923E85E1E8AFBDDBD4EEEA107E3C3B6C9C4826
      SHA-512:8CA56AB3597FE82A34624B6779829211D9C89057EEAF23494F8668C4353DB0DB40C3A5ECAE76AD28D4AF0C76C34D72C0C272E676A5D49058840C1A6F9FC3C965
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0.............*(... ...@....... ....................................@..................................'..O....@..l...............(d...`....................................................... ............... ..H............text...0.... ...................... ..`.rsrc...l....@......................@..@.reloc.......`......................@..B.................(......H.......P ......................X'......................................BSJB............v4.0.30319......l.......#~..X...@...#Strings............#US.........#GUID.......X...#Blob......................3......................................................%.....B...........`.....y.........................x...........................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.?...C.F...K.F...........................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21768
      Entropy (8bit):6.869151816770907
      Encrypted:false
      SSDEEP:
      MD5:BDA020D6EED1A9A1A6D3A6ADC36DAEFB
      SHA1:4B174A271F5F395B60B2BA03B58089479AC2A7FD
      SHA-256:2C18BB8ECABF11EEFE8F24810E9E8601CB1B12BBF793D0562896453BF331A6A9
      SHA-512:89205E8BF2EE3689A53E0481778B0B9B42BDAA2C22E27C63484CB37579086F5A03EB3F61B68C9F3E47174FAAB689454F3A7D1537FDB1C1225CC0C6AE51BF7083
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............V+... ...@....... ..............................g.....@..................................+..O....@...................?...`....................................................... ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................8+......H.......P ..4....................*......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID.......l...#Blob......................3................................*.....................N.....~.....k.............................P.&................. ..... ..... ...!. ...). ...1. ...9. ...A. ...I. .......................#.....+.....3. ...;.U...C.U...K.e.............q.....F.................7...................h.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20760
      Entropy (8bit):6.946168036500629
      Encrypted:false
      SSDEEP:
      MD5:5C801967A26F45102F0CB1AB5E4265C3
      SHA1:3E40DC41C5F3CE325802D832503A3568C3633FEF
      SHA-256:836568BF041FFD17701E96B4726AB65DB613190F1CD4377D7F29D65562445942
      SHA-512:DC63CCCFD355BCC6D1B58ECB4ABD5A521886B75F30AE5E4792C3704A68FAA05CB24D3D991B9946B6C4C6CFB77B625C5F1248779D248063D36FDDFC28AEC358F8
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............'... ...@....... ..............................A.....@.................................<'..O....@...................?...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................p'......H.......P ..l....................&......................................BSJB............v4.0.30319......l.......#~..8.......#Strings............#US.........#GUID.......h...#Blob......................3......................................L.........9...................................P.....m.......4.................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.P...C.P...K.`.............q...........................................v.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.923708952415366
      Encrypted:false
      SSDEEP:
      MD5:795737168900413D4542A463BD9E2D1F
      SHA1:B824D1B145DE065C83C9515C19C4B2A7E88CF187
      SHA-256:D2E6A82AEAFF84E60A41F8514E61B0A3DC1643E8227737D09331AF127A8296C0
      SHA-512:228B5E13BC312C7C2135CE404F6922EEA1A6A478C1E4253BB85FF61A57696D908B37B200A96E64FBC06AA5BFC87619F9335448A7106CDCBDCC55E5755E778341
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ....................................`..................................&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US. .......#GUID...0.......#Blob......................3................................................,.................+.................C...........^.....{.........................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.I...C.O...K.z...S.z...[...............q.....n...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21232
      Entropy (8bit):6.891025465711431
      Encrypted:false
      SSDEEP:
      MD5:9D474C2B13B7C83FCE651A43795F873D
      SHA1:5F38E52645A0DD1928CA2C6E32D770A43AE9FBE8
      SHA-256:E23D2373AADE3F0242813A04AA00768091F20E1D58CDA3877B33D0D9711609AB
      SHA-512:3C791284A38611104DCA6E642BD22751E7B5A3F15DC374B5A715F20DDB598327F256C6D192C2BA0434E4E6118319642C4F6601050B43200BAE329BE8E9E010EB
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ................r(... ...@....... ....................................`................................. (..O....@...................>...`....................................................... ............... ..H............text...x.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................T(......H.......P ..P....................'......................................BSJB............v4.0.30319......l.......#~...... ...#Strings............#US.........#GUID...........#Blob......................3......................................z...............^...........a...........#...........h.................F...................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.P...C.V...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30304
      Entropy (8bit):7.1081973367756595
      Encrypted:false
      SSDEEP:
      MD5:AB61BD332D4C9178BC7BCBB415C72100
      SHA1:0EE4AD0B06BEFEF0F14803D948791529B2F813E5
      SHA-256:5F0F0F179FEF5D87C8629C4A40176A66BDBB6DAC70735D2937697AB515671CAC
      SHA-512:45D8D008457629E54399ED09B91AC2CC51A46DE5E0C9E696D22BF4CE0B87AA8E1237022A57AF8F18C44524D288CBBDF32C1FEDFDB9B6334FB686BAE7E6409F12
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............&... ...@....... ..............................$.....@..................................&..O....@..................`d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......8...#Strings....T.......#US.\.......#GUID...l...\...#Blob......................3................................................|...........(...........F....._.....*...............................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.E...C.L...K.L...........................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20704
      Entropy (8bit):6.924349667668396
      Encrypted:false
      SSDEEP:
      MD5:2FB1A681CD9639CACE8F7250E329B0D4
      SHA1:07A507E2EA06A81E228566EBB0BA6E0FE3AF5995
      SHA-256:9978868E847A483B01C925DBC6BD9AF411242234447884F9340551A0B272C8E4
      SHA-512:79BECB7042E9832DAC0D628FE8E454BA5C7FABB13E322C3079801B901209479CC2864F8C6C59C9C7C538AE60C4572B73A087BEED6693B80D18B49CE8CE0185AB
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ....................................`..................................&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................&......................................BSJB............v4.0.30319......l...t...#~......$...#Strings............#US.........#GUID...........#Blob......................3......................................t.........%.....\.................[...........s.....C.................@...................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.,...;.L...C.R...K.}...S.}...[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21232
      Entropy (8bit):6.878030783079058
      Encrypted:false
      SSDEEP:
      MD5:6A3A0874371F42E7B88FCA820526D71B
      SHA1:E7A1B0873BDA261D63546D47FC8831B65F96122E
      SHA-256:F4ECD0B9156B5ABC9F1127E88DB1DF06C3C147FE52303C3FA3A3284CAD340F5C
      SHA-512:274167FACCECE1E3B00D261738D5088BF12ED0E58156C7DBEA22109D3F8EE6EDB43BAE7BCA5D2B29EA930AC8250B1A3650EFFB41E8C37C87B2541A7025C40EBF
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............(... ...@....... ....................................@.................................<(..O....@..l................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...l....@......................@..@.reloc.......`......................@..B................p(......H.......P ..l....................'......................................BSJB............v4.0.30319......l...|...#~..........#Strings............#US.........#GUID.......\...#Blob......................3................................................~.......................(.....A.................n.G.................3.....3.....3...!.3...).3...1.3...9.3...A.3...I.3.......................#.....+.....3.....;.E...C.E...K.U.............q............................... .............
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21208
      Entropy (8bit):6.906892337193367
      Encrypted:false
      SSDEEP:
      MD5:B87EFB9B3D1EC1081479F457B264E4A1
      SHA1:2FACF94FF02A9E4C1F5F49A29E9A120FA0832946
      SHA-256:30DD071D011698C72F464D926E41C259CE69026B5FC6389E1B5C46FA38283B29
      SHA-512:A322CF89CC97C21E1FC7D7CFEB0A30933563AAA25F3E8FDDE34D8808067F903CD9A17590ECB9487F9EA058FCDC1849E6ECFBFD014258DEFDAF8B1CD97CA5DC46
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............r)... ...@....... ...............................-....@................................. )..O....@..T................>...`....................................................... ............... ..H............text...x.... ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B................T)......H.......P ..P....................(......................................BSJB............v4.0.30319......l.......#~..4.......#Strings............#US.........#GUID.......X...#Blob......................3..................................................................e.........../.................J.......#...........................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.A...C.A...K.Q.............q.....D.................,...................[.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.925762912674675
      Encrypted:false
      SSDEEP:
      MD5:5FFC78DEA11B1090764AC9AA4488612C
      SHA1:1E0EFE2850E0B2D5294050DF6CC29D28D1F35CC0
      SHA-256:4137AABCE118F9E96CF6DBA2738EBC63574173FDC05AED92C2D205D79191EF87
      SHA-512:6968C30BE35A9691C3437391CC545BBE387F296A686249E6751FB60B877D4B8364B932E3961959FFCBE24A2D5E979279EB369D9415A93BC0197CEE7936C197D0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............*'... ...@....... ....................................@..................................&..O....@..H................>...`....................................................... ............... ..H............text...0.... ...................... ..`.rsrc...H....@......................@..@.reloc.......`......................@..B.................'......H.......P ......................X&......................................BSJB............v4.0.30319......l.......#~..P...L...#Strings............#US.........#GUID.......T...#Blob......................3......................................!.........$.O...~.O.....O.....O.....O.....O...;.O...X.O.......................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.?...C.?...K.O.............q.....:......................... .......:.....
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30256
      Entropy (8bit):7.090969434577509
      Encrypted:false
      SSDEEP:
      MD5:875E1347C3708F290EC09B68D87A9436
      SHA1:8E255180B6FC2397DE180BAA0DF2A4AD97C16A8D
      SHA-256:F389A41500FBF4F24C48A5AE554ED6661EF763D8011C11758DA1DFC453B699C0
      SHA-512:00A9C69655F472E03F3B5127103E7681D77403A32188C739F42DCC78B375E69D9E71D3BED4102F674BB11CB3D404A307DB4A9E0F6F6F9CFBFD9ED2636F52E277
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0.............*'... ...@....... ...............................I....@..................................&..O....@..................0d...`....................................................... ............... ..H............text...0.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H.......P ......................X&......................................BSJB............v4.0.30319......l.......#~...... ...#Strings............#US.........#GUID.......P...#Blob......................3................................................7.U.....U.....U.....U.....U.....U.....U...N.U...k.U.................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.6...C.=...K.=.........................................................C.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):31280
      Entropy (8bit):7.0641094175254215
      Encrypted:false
      SSDEEP:
      MD5:184160940CA223DF851445BCD85EC39D
      SHA1:046BD548B54CE56AFFE3ACBA9A9D10970BD20CBB
      SHA-256:0C3786498F50B491F9DF13BEADC75E23A886C500582EDD2EB42E00FE02084D02
      SHA-512:6DD67C5CF9D9732B4F1FC8F7CFF9EBEB00FF6F4A7EB375362A1148CC9751D971ADE306DED6C515EDAACD6571D9C837901316758B8DE0A6816D37BEE3C6C0A78E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............+... ...@....... ...............................U....@..................................*..O....@..................0d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ......................@*......................................BSJB............v4.0.30319......l.......#~..$...X...#Strings....|.......#US.........#GUID.......\...#Blob......................3............................................................:...........X.....q........................./...........................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.D...C.K...K.K.....................................8.....................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.936540006800381
      Encrypted:false
      SSDEEP:
      MD5:A98C65EFA0FC24F7A2B66FF57A01CD24
      SHA1:F0254DFEE5B244D1D5E08C4744BFC92C1BF22E46
      SHA-256:5AEE6FFEF7FC5626587C38A552229383E25853D6F652CF6A93DA8BF863CEAC79
      SHA-512:9702704F4DA2D3FCF783A2B37C1BE1F72AE6ABDFBE7B1F044830F87E87DB0C9DA09E6810F794D6BEF616BE7903BB40FE702CECD2DE0643D91760B66D3DFB5A82
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................'... ...@....... ...............................b....`..................................&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P ......................8&......................................BSJB............v4.0.30319......l.......#~......(...#Strings....@.......#US.H.......#GUID...X.......#Blob......................3......................................................_.....x.................w.....(.....A.................\...................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.$...C.D...K.y...S.y...[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.932656588423688
      Encrypted:false
      SSDEEP:
      MD5:117289FDC646BC1BD749BF20BC1021E7
      SHA1:5BA971D98C0582A8C6C90DF94D611E7A19658430
      SHA-256:CF0E50CD49F31A314534A82848B481F640AD76F60445C90FC6FD607E2EF27886
      SHA-512:2D48445B90A0346549A282C8717BBFC91C6ABBAE4193B062532B438E0C63032B7724745D7B09DFE8AC69AFEF0C728C4B91A67C9E532E377A096836E158EE3085
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ..............................E.....`..................................&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US. .......#GUID...0.......#Blob......................3................................................\...........u.....t.................%.....>.................Y.......(...........................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.%...C.E...K.z...S.z...[...............q.....:...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20656
      Entropy (8bit):6.923076053397558
      Encrypted:false
      SSDEEP:
      MD5:C5EE67F2F15C9F430A4FBEDC90CA1232
      SHA1:B970B60CCB94FB3DF9F45B3E6BDD7959F227B599
      SHA-256:15C78E9E9BD1973B7697AFD649BBB4CDAC3FADED4CDD696598E518B4BB0B75A6
      SHA-512:EB87F8B927CFFFF97A7727D1DD976A21C2198781B731BBC777C1366F0664A667483A8158EA0AEE7D30D110132C4C90E2F4E53E8C61F151119E7442E61A7D4A9A
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ..............................E.....`.................................l&..O....@..<................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...<....@......................@..@.reloc.......`......................@..B.................&......H.......P .......................%......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3......................................................U.....n.................m...........7.................R.......,...........................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.....C.;...K.p...S.p...[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):44736
      Entropy (8bit):6.387255281301793
      Encrypted:false
      SSDEEP:
      MD5:BF5EACC8056B066B468738120647C6FF
      SHA1:BB595A610CC6D23DAA7CED35B32C10E14E845B49
      SHA-256:9D5B51841DB32E9706C58F197A41210DDE28A767B8ACECB0F9912F0F3763E5FF
      SHA-512:C49556FAFCB5A439EF4D4F34AD14B26891AEA8C972278FD1BC87E7A7F5A949346AEF9468EFBFA3B0D0D1E7A04C4D18C175DE4330B462DD9F877639C1C9B1B34A
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......X.........." ..0..f.............. ........... ...................................@.....................................O....................p...>..........H................................................ ............... ..H............text....e... ...f.................. ..`.rsrc................h..............@..@.reloc...............n..............@..B........................H........$..._...........................................................(c...*..*...jU.*..(q...*.*"..(....*"..(u...*..j*...0...................*..*..(....*..(....*..(....*..(....*...Q.*..0...................*...0...................*...0...................*...0...................*...0...................*...0...................*...0...................*...0...................*...0...................*...0...................*...0...................*..(;...*...0..................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21752
      Entropy (8bit):6.8579553448189365
      Encrypted:false
      SSDEEP:
      MD5:0581FA5E3E146689343D276D80A2C497
      SHA1:7F49F8A89ED9DA1996D7B1B1AE2A1ED6DA99A9AE
      SHA-256:D9D21E28EF1363367D9606A9FBC9A14E795653C322419C02DE4AE66584003B4D
      SHA-512:CC0950B8E7A9BFD83687F9CE6012EE4B31F9091186CF18AE14B7EB5CF95A407972B28333C8D734506C190E78CCA9FD79B24548F27FCCC8DB9ADBFC46E0005766
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............*... ...@....... ..............................Qb....@.................................h*..O....@..x................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................*......H.......P .......................)......................................BSJB............v4.0.30319......l...,...#~..........#Strings.... .......#US.(.......#GUID...8...`...#Blob......................3................................$.................W.....W.....W...c.W.....W...-.W.....W.....W...H...................L.....L.....L...!.L...).L...1.L...9.L...A.L...I.L.......................#.....+.....3.....;.H...C.H...K.X.............q.............................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21208
      Entropy (8bit):6.919458745073652
      Encrypted:false
      SSDEEP:
      MD5:F6F28FEF394A964AE2C80B3F9B9691CB
      SHA1:56A8ECEBEAA6574BA9983102C0F8BDD0C3AC0994
      SHA-256:08F79E007F7250ACF46D3EC4174E46558D5067B84D76E158C73EC14C0FE31705
      SHA-512:FA55D7D4A8189E76815AA6123368DB1C474A727B143B42B94A11F04AB4E065FD7312EA41D06878AA8FA9B9747A3423D08D8A0804A6FAB0776F75E88E2F64F0E6
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............)... ...@....... ....................................@..................................)..O....@..H................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...H....@......................@..@.reloc.......`......................@..B.................)......H.......P .......................)......................................BSJB............v4.0.30319......l.......#~..P.......#Strings....D.......#US.L.......#GUID...\...X...#Blob......................3..................................................................l...........6.................Q...................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.@...C.@...K.P.............q.............................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20688
      Entropy (8bit):6.928260203577834
      Encrypted:false
      SSDEEP:
      MD5:339445677D6D3311CD87E902FC91D13B
      SHA1:566CF7F9DA835B53F8E3BF1818E66E01288588BB
      SHA-256:8A9BEC81AAB09AA86101BC92E1FE623C7BF467AAA47AE8FD952370F628C65109
      SHA-512:DFF3CA51335841AB7BC5828C29EA8F2A45408F49187ED7F1D843803F0DE6F1926E0FBA0AB84BB3DD32BF7F0724AEEE2F313848F7D080F80DE14DFB308C85318E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............Z'... ...@....... ..............................v.....@..................................'..O....@..<................>...`....................................................... ............... ..H............text...`.... ...................... ..`.rsrc...<....@......................@..@.reloc.......`......................@..B................<'......H.......P ..8....................&......................................BSJB............v4.0.30319......l.......#~..d...h...#Strings............#US.........#GUID.......T...#Blob......................3......................................p.........N.................2.................e...............................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.>...C.>...K.N.............q.....%.......................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20728
      Entropy (8bit):6.89115410520229
      Encrypted:false
      SSDEEP:
      MD5:AF09364076B3729BCCAD5836685ADD97
      SHA1:08665854FA6E1C15A2BF92B68E0D6A6E3F2290EC
      SHA-256:0991EC7109C7E57D4C436A99CDF15A532A9FB39F9CC5DEE96EEEA4B6631D8ED3
      SHA-512:1B571057337E39C7C6E5CDB97B189C9E6817ABCEA31AB1406707E90B0317501B5BC27EC56336AFFC36AD22031226F1F6C8D0AE0F385F06C0194242A4F038C393
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............B&... ...@....... ...............................J....@..................................%..O....@...................>...`....................................................... ............... ..H............text...H.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................$&......H.......P .. ...................p%......................................BSJB............v4.0.30319......l...l...#~..........#Strings............#US.........#GUID.......`...#Blob......................3..................................................I...m.I.....I.....I.....I.....I...*.I...G.I.......................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.I...C.I...K.Y.............q.....[.....................................B.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30792
      Entropy (8bit):7.080975022669934
      Encrypted:false
      SSDEEP:
      MD5:90EF29AF0AC10626542D88C11147511F
      SHA1:9A385B6CDFFBF8EC4EC2BFB7DB4CCD268853EDB4
      SHA-256:A7F6B9BAD7D22F6EC878D2B5155C8F7256F64BCCAD8539B2FC52B04955ED8E00
      SHA-512:D7D85F43D8794225E2116CA223944CBDC5F948FD42788A8A029B1AF36252122A4FE58932DFF3F95F306C40F333857B48D603C0C748AE208F17D85A6B1ED5162F
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............(... ...@....... ..............................X.....@.................................`(..O....@..l...............Hd...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...l....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................'......................................BSJB............v4.0.30319......l...<...#~......x...#Strings.... .......#US.(.......#GUID...8...X...#Blob......................3..................................................I...%.I...B.I.....I...`.I...y.I.....I.....I.....I.....G...........................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.?...C.F...K.F.....................................P...................$.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20752
      Entropy (8bit):6.946896969155413
      Encrypted:false
      SSDEEP:
      MD5:93273EBC2F491E1A5ECB42E670F9A9A2
      SHA1:095C8A8725D1BFC0F61DABA7953BD496D702B338
      SHA-256:D65A28E99CD08E34780E8BD3CB69A1FF4939075614DB71A05AB4C6DA1F503DFB
      SHA-512:A49008C1DECB39E5B292D0AC51A6CAAB19CBB771754141AC9B381FD07A48673C068BD154082B968031FE8A4455972F42CDEC5D6ADF5B2F2FFF985D28AD6B900F
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................'... ...@....... ....................................`..................................&..O....@...................?...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P ......................D&......................................BSJB............v4.0.30319......l.......#~......8...#Strings....<.......#US.D.......#GUID...T.......#Blob......................3......................................J.........,.................+.................C...........^.....{.........................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3."...;.W...C.]...K.....S.....[...............q.....r...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20744
      Entropy (8bit):6.923479962458419
      Encrypted:false
      SSDEEP:
      MD5:EE7749C0AE0BF5DE3D19913F23DAD998
      SHA1:E610DB97F5AD300354CD6478B34FC4D9655581DC
      SHA-256:11BA759EF87622BDC96DF8BFC7148A450D01C8DD60FA03A53439552C7EC87B69
      SHA-512:20F70B27616EE1B1ACD0C529D543B1C7D0FDC49A8A665A2E86E5F90ABF3F3827FA7C013C41D76D1E4BE120A5C00413415A4B2AF868A80A4D4ABA64C83CB843E0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ................~&... ...@....... ..............................3E....`.................................,&..O....@...................?...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`&......H.......P ..\....................%......................................BSJB............v4.0.30319......l...P...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................R...........y.....y...9.y...:.y...Q.y.....y...!.y.....y...l.y.....y.......................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.<...C.g...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.91547420532875
      Encrypted:false
      SSDEEP:
      MD5:F71FCE21FE5F1DDACDE00E13A45D9656
      SHA1:CF812FC77124FDAC6299532F06C69F9461475B61
      SHA-256:BACEC8D38A741A6402C77132F2D67D58BC0123A5A1420AF4C22E6CE26E362488
      SHA-512:0639DACE1CB0737F0690B79A997EECDDF8CA74ED69DE8A13E2D42BE33038F952D3D287EEAB15E345C1F51EC552D266F2A2ACEA0C9FA8D6A76F9814F4A10703E8
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............&... ...@....... ...............................Z....@..................................&..O....@..P................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................&......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~..$...0...#Strings....T.......#US.\.......#GUID...l...X...#Blob......................3..................................................+...m.+.....+.....+.....+.....+...*.+...G.+.......................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.A...C.A...K.Q.............q............................... .............
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20720
      Entropy (8bit):6.920152062437649
      Encrypted:false
      SSDEEP:
      MD5:A3916AE69927AFB8330B3BDD1B4CFF0F
      SHA1:496B53DD1F63D3F7425BAF231304ABA1166F513A
      SHA-256:FBE15DEF32E68F19BC2E209173CE631EAA25ADB42C2A5FC83BE81DD0927161B7
      SHA-512:F94BFCC0560482E01643F91B1EBB2FF721C188685984483C122D68BFEDC8A68098D35882E035FB5F6E6EF6EDC8D4F886336C3CBB4D695879E0541D076544A60A
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ...............................O....`.................................\&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................%......................................BSJB............v4.0.30319......l...l...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................U...........v...,.v.....v.....v...+.v.....v.....v...C.v...^.v...{.v.......................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.&...;.F...C.{...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21232
      Entropy (8bit):6.870371668028369
      Encrypted:false
      SSDEEP:
      MD5:B59E1867AA6D0AA62056E0D6EDB9B137
      SHA1:3D8D5C35B20038F7219DEAA24A35B133D9E4DF65
      SHA-256:436C856B0B3465125FCE83779A9E5D49D96E646765091141EAD74EA413C9D3B2
      SHA-512:9B7C4B5DDF2E682248C04A9DFDD5B5AAAF95F933DB18954418FDF767DD9B1E12DE2A7A7A3078D0754B098E9DE8261C6EEFC70BC5F28EAC4B3153E3B51DF5FAEB
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................(... ...@....... ....................................`..................................'..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H.......P ......................D'......................................BSJB............v4.0.30319......l...$...#~..........#Strings....D.......#US.L.......#GUID...\.......#Blob......................3......................................n.........I.....J.............................a.....1.....|...............................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.P...C.V...K.....S.....[...............q.....m...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30760
      Entropy (8bit):7.086685048718698
      Encrypted:false
      SSDEEP:
      MD5:9C8CAF4520DB3E518921CEBAFA603808
      SHA1:A9B83852F847F1F7B142BD5D0D1350FA8AF508DC
      SHA-256:8BEDF1CB0460A131A44886CB711600E42636E18EA771B9814CC482ED74B65AF1
      SHA-512:64C193711CBB31F960CE93B6945E497AF01A7E814BA094D714C39C9F155E98627A9E1DF28661A153483D0E859A5973E8B0A6406EC4B0B0DDDC5B937C350AF585
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............)... ...@....... ....................................@.................................8)..O....@..\...............(d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...\....@......................@..@.reloc.......`......................@..B................l)......H.......P ..h....................(......................................BSJB............v4.0.30319......l.......#~..h.......#Strings............#US.........#GUID.......X...#Blob......................3................................".....g...........................N...........3.....k...............................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.>...C.E...K.E............................................. .............
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20736
      Entropy (8bit):6.932434859320068
      Encrypted:false
      SSDEEP:
      MD5:ED98B95A06327BE596569B33BCEEBF54
      SHA1:C5EAA053A68872F51CA9E215BF8A32C8302C5646
      SHA-256:30CA76D0BD86BC4FE043D37BB5C095885170BB7AF45047B1ED18F573521ADC5F
      SHA-512:A06C8B0D4B4F22E55AE179A60CFFB7CB0AF411F005E4412287CD7A74903457732AB795BCF0FBA7A41E7EDC19C0BBC85523F44C48D51AF8EECDBAC8F1AF98DEBB
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ....................................`..................................&..O....@...................?...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P ......................$&......................................BSJB............v4.0.30319......l...|...#~......8...#Strings.... .......#US.(.......#GUID...8.......#Blob......................3................................................ .....N.................o.....9.....e.....5.................T...................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.T...C.Z...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20712
      Entropy (8bit):6.934721926136644
      Encrypted:false
      SSDEEP:
      MD5:574A3B86C16829B547F9B672C9314C0B
      SHA1:2AF7E67F2A5EBD07AD4B08315A558276E89658F2
      SHA-256:5DCC3F7EDF245CDA2B26E9027D9D93CBEFC2E952FD8ED0DF4E045002D5783C76
      SHA-512:594B6205DD77F1673E669954AE196847F84E9D6CE754DE98ABB0166D7D4FFC5EAABD64483B104A34FCFFE16D5BC750036A226107A0A12245B4B31673682BA990
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............~'... ...@....... ...............................W....@.................................,'..O....@..`................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B................`'......H.......P ..\....................&......................................BSJB............v4.0.30319......l.......#~..p...x...#Strings............#US.........#GUID.......\...#Blob......................3......................................r.........6...................................M.....j.........................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.D...C.D...K.T.............q.....2.......................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.909954114781456
      Encrypted:false
      SSDEEP:
      MD5:5EB4940199C69F8B88D1C697C139F432
      SHA1:498191DCDEAF306AAEF73FF101413DC617DB2126
      SHA-256:6A7BE400465A949ADF0C2868C5EBDD8457856A9398050FD33437A5340240ADE7
      SHA-512:775B7B93C7BB93A358E70738E2A8830485E6E6FD2F6AC2D1C7641BA5F1022A07AE51DFC5137310BD7B621C99621F8905C35A20D6E63BB91ABFD95E9CF60CFF30
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............&... ...@....... ...............................~....@.................................T&..O....@..P................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................&......H.......P .......................%......................................BSJB............v4.0.30319......l...x...#~......0...#Strings............#US.........#GUID...,...X...#Blob......................3......................................`.........R.{.....{.....{...6.{.....{.....{...i.{.....{.......................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.A...C.A...K.Q.............q...........................................F.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20800
      Entropy (8bit):6.9822039641350795
      Encrypted:false
      SSDEEP:
      MD5:22C3211B41C6BED614CF52209628E706
      SHA1:5FEF8F8BF32C734F2893A27413EE9A211B235D39
      SHA-256:CC2934E5C51715D5B3E4420AB4355162EFE4914D26361E52798043901E5EF3DB
      SHA-512:EA59ABC3055EC2C04CC36E994BCC2ADC53903F31BB4FF4E33B531110C76F9AE8EB819030537C738EFB01413C3CFBBA02434A8A7E02FFA106155C652B5D668F19
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................'... ...@....... ..............................^[....`..................................'..O....@..L...............@?...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...L....@......................@..@.reloc.......`......................@..B.................'......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..,.......#Strings............#US.........#GUID...........#Blob......................3....................................../.........G.x.....x...d.x.....x.....x.....x.....x...y.x.....x.....x.......................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.,...;.a...C.g...K.....S.....[...............q.....1...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):23800
      Entropy (8bit):6.75991945084597
      Encrypted:false
      SSDEEP:
      MD5:32FF106466E4C63494FB15C2C7924A3E
      SHA1:1EA22FE0E1FDF7067892ED36BC8C90D5CBF668A0
      SHA-256:92CCB8A89B839FAE2A8AF3805FC16E9D4D3B553EDCA059C0F5D10CB873CC1125
      SHA-512:C74A05FF58DF95695CBAEB68D1DC86C41842FF4173F1E40C154C90D684008A186454ABF26CDFB4A7B8E871DA9F2C732F296E90BD90F26C75AD41953602AD4F10
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............2... ...@....... ...............................s....@..................................2..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................2......H.......P .......................2......................................BSJB............v4.0.30319......l.......#~......X...#Strings....H.......#US.P.......#GUID...`...`...#Blob......................3................................r.....a.............................................a.....~.........................n.....n.....n...!.n...).n...1.n...9.n...A.n...I.n.......................#.....+.....3.....;.I...C.I...K.Y.............q...........................................O.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.918322799480784
      Encrypted:false
      SSDEEP:
      MD5:C92F0425255FE3B7D3DA56B52464203D
      SHA1:F58CE337BEC2F2D35AF2F566934444F560CFD0E5
      SHA-256:5F4F4D4C4B8E571A0D82DFE7766BBA201A97C464D2E2EB5192D75794B963BB1B
      SHA-512:7EF54EF51ACA4E0F104B37FBB6B59A015C33838E88F9F003CE91B1053853C51966A555D503F6CEFB618DA6A1F3F3415D20D9ACB27B4A383DF4EE3B298A01686E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ....................................`.................................0&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................d&......H.......P ..`....................%......................................BSJB............v4.0.30319......l...t...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................D...........`.....`.....`.....`...+.`...,.`.....`...C.`...^.`...{.`.......................}.....}.....}...!.}...).}...1.}...9.}...A.}...I.}...Q.}...Y.}.......................#.....+.&...3.....;.A...C.v...K.|...S.|...[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20736
      Entropy (8bit):6.941661839342404
      Encrypted:false
      SSDEEP:
      MD5:1090F8B4E94AF848A54A64AB8CFCCF15
      SHA1:A4DB81CD5C100C5E488BF464AA7AF3C61F8FB9AB
      SHA-256:2B37A13109A9104DD1B1D2D4825B7DFA139978188EE427A88F474E521F8E2FB6
      SHA-512:443D01A758E89C71BA2FED5FAE655B4DD160E88A48EB19231950F0D44F757332880E3C09B2CC6F1793B3B647262EE87C345A8DB187696E148AA0AA66C3FAD380
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................'... ...@....... ....................................`..................................&..O....@...................?...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P ......................D&......................................BSJB............v4.0.30319......l.......#~......D...#Strings....@.......#US.H.......#GUID...X.......#Blob......................3......................................D.........,.................+.................C...........^.....{.........................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3. ...;.U...C.[...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30256
      Entropy (8bit):7.125924993328888
      Encrypted:false
      SSDEEP:
      MD5:EBD3FF713B68750EEAA914829A723879
      SHA1:4F5051601C4E774066B8CBC8C494BF4C16ACF1D7
      SHA-256:5A021106748194463FCA0520083AE95C84BA0344387254C0EE97C5DFA6E11DBB
      SHA-512:A2DAE0D2D81B0B16C25DE2ACB6FCE07294A2B8375B9DCC822860703CF31B47F57FC0190C895D4EC32439D43173E9B3AF3C187CB4E2FAED811C67CBE63B557779
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............'... ...@....... ............................... ....@..................................'..O....@..................0d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..p.......#Strings....H.......#US.P.......#GUID...`...l...#Blob......................3................................................v.2.....2...^.2.....2.....2.....2.....2.....2.....2.................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.T...C.[...K.[...........................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21248
      Entropy (8bit):6.862287983262007
      Encrypted:false
      SSDEEP:
      MD5:790167EFBD01A2D58F6D7F9DF53F4B0F
      SHA1:D97AFC3412755D5A0594645FA253883E6D331A49
      SHA-256:B3074E65F36A9354B1564760C91787C60BAC52AFF8FCD9E1B55DFB876BC8F9EA
      SHA-512:039A42BA2BA92C3C72703846CFD400B7F96E9A9D495C728894E0C5F93F79C0BF2AC05F573E0A847B361A336D55CC36567D86A1008C59014D627F3842F1E4DF21
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0............."(... ...@....... ....................................@..................................'..O....@...................?...`....................................................... ............... ..H............text...(.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ......................P'......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID.......`...#Blob......................3......................................H.........7...................................N.....k.........................{.....{.....{...!.{...).{...1.{...9.{...A.{...I.{.......................#.....+.....3.....;.K...C.K...K.[.............q.....x.......................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):38472
      Entropy (8bit):6.767818804480797
      Encrypted:false
      SSDEEP:
      MD5:469B0B8F124B0CD3BB4154820E7A6E4E
      SHA1:695D5D9BF7238F39AB08BCFE2DBBF7A6095F62AF
      SHA-256:5527EA385F5F46EF317221CC68B61DCAE41892B7B45D8CBF6453B7E920FBDDF9
      SHA-512:75A49560DDF4905964F787DA98BAA81D5D9809F71B8411F2AD12807E5C65AA645CF0CA1A12170D7E02F8B04A4E23013CA9EDECE4425ACFB2DC52E6CE66AB1E4E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..(..........RF... ...`....... ....................................@..................................F..O....`..L............2..Hd........................................................... ............... ..H............text...X&... ...(.................. ..`.rsrc...L....`.......*..............@..@.reloc...............0..............@..B................4F......H.......P ..0%...................E......................................BSJB............v4.0.30319......l.......#~..........#Strings.....#......#US..#......#GUID....#..T...#Blob......................3..................................................A.....A...3.A.....A.....A.....A...3.A.....A.....A.................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.;...C.B...K.B...........................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):39872
      Entropy (8bit):6.283940364650081
      Encrypted:false
      SSDEEP:
      MD5:82BBB4AB9A6A775D34BBBC93C2BD4EBB
      SHA1:413C96C3AE407532DB4C1CE3085A8F99675A8AD4
      SHA-256:F14DF3A548A8C43CFE7F60D325AC5E95D92C605F482BBEE17A39F98BCFCC7216
      SHA-512:22A56E6202CA6CEA3EB5695BB186593355A243BEC92A022D65B02E5222B0DCB9F1FDC6BD17E4963CF76D7FCD8A177D7A49D27AFF13C16BCD48DE9CB88BA18ED1
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...kb.X.........." ..0..L...........j... ........... ....................................@..................................j..O....................\...?...........i............................................... ............... ..H............text....J... ...L.................. ..`.rsrc................N..............@..@.reloc...............Z..............@..B.................j......H.......X&...)...........P..H...`i......................................r~....-.(2...s.........~....*..*.0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*2rI..p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2r9..p.(....*2rm..p.(....*2r...p.(....*2r...p.(....*2r;..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):23480
      Entropy (8bit):6.745210347664389
      Encrypted:false
      SSDEEP:
      MD5:5F859D35CA74D84CCE62533E086DC27F
      SHA1:A0F2C03CB813317460133DE80231D7B1FB62DCC5
      SHA-256:91C7C02D46F754193B3988C28050135C804E47DC3456D0C3DDE028AC0341FBE2
      SHA-512:EAB5017628E4C576A1076EAB0E906523987CD82E6ACCC5B01B19B048FAED81B6A4EE7C4D09454A7A9516F72A87A34D0C4CC83C74494F8854CC7D83583459DBFA
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...tb.X.........." ..0..............+... ...@....... ..............................26....@..................................*..O....@..p................?...`.......)............................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B.................*......H.......P ..,...................|)......................................BSJB............v4.0.30319......l...@...#~..........#Strings....8.......#US.@.......#GUID...P.......#Blob............T.........3..........................................!...........1...R.1...Z...........r.....".......a.....a...-.a.....a...z.a.....a.....a.....a.....K...&.a...Z.K...M.K.........K.K...@.{...........................!.....).....9.....A.....I.....Q.....Y.....a.....i.....q.....y......... .....&.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):22816
      Entropy (8bit):6.787311984913185
      Encrypted:false
      SSDEEP:
      MD5:ECAC83E551B639409899919D47CD7588
      SHA1:62A622557CC0D6FCED9C1A14BE28DBC39E9BD6FC
      SHA-256:5A6C8F69A8DEA8A775331273AAAE707EEE2A2743FB1498C3CC4DBAB679125D11
      SHA-512:FB618860626B72D6FCF959E35BF9B3785A8B0D01B29FC8931D0151EBF001DC4470CA55AC62D5CECFEC97FCD5973858185050E3EF414D1282B674CD880EA0E1B0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ub.X.........." ..0..............)... ...@....... ...............................0....@.................................c)..O....@.................. ?...`.......(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................((......................................BSJB............v4.0.30319......l...(...#~..........#Strings............#US.........#GUID.......,...#Blob......................3............................................................l.p...........A.....A.....A.....A...5.A...N.A.....A.....A...i.....R.A.................j.....j.....j...).j...1.j...9.j...A.j...I.j...Q.j...Y.j...a.j...i.j...q.j.......................#.....+.....3.....;.)...C.D...K.d...S.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):38872
      Entropy (8bit):6.259985051067165
      Encrypted:false
      SSDEEP:
      MD5:480CA4042FF3CBB3CDBB14EF0643C14D
      SHA1:4BEB5C11208AFFAD40BDAC6672A7B0B7B4558E7B
      SHA-256:132AE80C89F38750D1ADE43BD1E588F4D0971EA813B4DF5DCA5AF3C113E9E713
      SHA-512:7630BD40398FA55EEDAD8807CADCB7D0142717AE60073DC5187B9463824EEBAB993E8867AB3E43FCD34DE73F2990D58397008CB1880882569E83B22F5D6B3175
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|b.X.........." ..0..H...........f... ........... ....................................@.................................Ef..O....................X...?..........xe............................................... ............... ..H............text....F... ...H.................. ..`.rsrc................J..............@..@.reloc...............V..............@..B................yf......H........#...(...........L..X....d......................................r~....-.(8...s.........~....*..*.0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*2r1..p.(....*2r]..p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2rG..p.(....*2rq..p.(....*2r...p.(....*2r...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20712
      Entropy (8bit):6.914716992976391
      Encrypted:false
      SSDEEP:
      MD5:13D414FD8F0A2C9CD7DEEE51AA56E052
      SHA1:41440C4B4426BD9B035721FC53EBA1D9B540EB60
      SHA-256:16A59E600C2A6EBF78D35077D79CEE86DF9AB76DE7B6780E631C531F24269A7D
      SHA-512:2339DBA14FE8AEE60B23D1C1942A65A8C02EC371E65E02D4998F37522A3F6236B008041CF3F00B89A6F1015B42C6C6B7521F9BBDA63DD29B37E20ECC9EF9EDF0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ..............................%.....`.................................8&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................l&......H.......P ..h....................%......................................BSJB............v4.0.30319......l...l...#~..........#Strings............#US.........#GUID...........#Blob......................3................................................,.................+.................C...........^.....{.........................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.M...C.S...K.~...S.~...[...............q.....D...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20712
      Entropy (8bit):6.934520929656973
      Encrypted:false
      SSDEEP:
      MD5:E7708964BD7D1C3BF680B05B73482B88
      SHA1:7747152E7B2D7E45C898052BD162B98D52F4299C
      SHA-256:ED36FF40C7341C6146B297CFD91AAB3FEB40EDDD8A73E4DEA1D3932B68379DD8
      SHA-512:AA41AD690C2985041ED0BB0CB131F6BA438C4B77BDF9793D5E27FF916A5323AAC425629B53FCFFF47A283CC566C7FD5F8D143CFFE86D03FFD981D04212A79F64
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ...............................0....`..................................&..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~...... ...#Strings............#US.$.......#GUID...4.......#Blob......................3................................................V.................o..... .....9.....m.....=.................T.......+...........................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.N...C.T...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21216
      Entropy (8bit):6.873112333209616
      Encrypted:false
      SSDEEP:
      MD5:C069986DBA7E9348E06876CACFE32FCE
      SHA1:0B789FB92F342AFED9CA71EE72515825D83B598C
      SHA-256:2B62B03ED28226A7731DA2A820277BFC8EEA87A2BF1FE323650FA306294A2D14
      SHA-512:22971A0D1B61AC4152196116D6EE3D8DCDDA300C2172AA212F4EAB4BCB1C6D2C1D6A53B5550E5DFBB97CAC2F52D172DE3246720322A8985E95ECA59FB6147A34
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............^(... ...@....... ....................................@..................................(..O....@..`................>...`....................................................... ............... ..H............text...d.... ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B................@(......H.......P ..<....................'......................................BSJB............v4.0.30319......l... ...#~......@...#Strings............#US.........#GUID.......X...#Blob......................3..................................................................m...........7.................R.O.................I.....I.....I...!.I...).I...1.I...9.I...A.I...I.I.......................#.....+.....3.....;.C...C.C...K.S.............q.............................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21224
      Entropy (8bit):6.880584712333072
      Encrypted:false
      SSDEEP:
      MD5:5B0DF34EF446B6ADAFE495C15B31E7EA
      SHA1:DFCA9A8429BCF07AA08C8A3C8CB8AE10092414EC
      SHA-256:FB9330CC195C9B80EC37A074C6F8D08408355865911E1E354F490D216055D9A9
      SHA-512:3DFAE4CB77242EF9B4D32E5E7B148DAB5437B449C1209C808BD54CD6D9C7E4119AC996446AB6731B5B5F8FC80D66B30D8F4E3EFF94F95047A726CFCACFA69A5B
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................(... ...@....... ....................................`..................................'..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................'......H.......P ......................8'......................................BSJB............v4.0.30319......l.......#~..P.......#Strings....<.......#US.D.......#GUID...T.......#Blob......................3......................................~...............C.....D...........[.................+.....v...........(...................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.4...C.T...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):25848
      Entropy (8bit):6.6576971282907005
      Encrypted:false
      SSDEEP:
      MD5:2266594F7517AC059626A34881CFB5C2
      SHA1:D3E11E212047E271AD289A71C3FA78A49223309E
      SHA-256:B8DB57B8F90C88144F93320E16B8DBB37813A9175A000A02E7E0F1C3316307A5
      SHA-512:17491B1DC0B07C28CD480286C330468FF3FD5842CAD70F426D1444103A153F05ED48A864BB448906C372A78D626DC5EE826C6498EC881A082E972B5942AE119F
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................:... ...@....... ....................................`..................................9..O....@...............&...>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`.......$..............@..B.................9......H.......P ......................09......................................BSJB............v4.0.30319......l...D...#~..........#Strings....0.......#US.8.......#GUID...H.......#Blob......................3......................................e.............................................1...........L.....i.......>.................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.R...C.X...K.....S.....[...............q.....p...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21232
      Entropy (8bit):6.906318445293764
      Encrypted:false
      SSDEEP:
      MD5:D065C7A1DA4DFD81BCC712BC9A3050E1
      SHA1:8C31C82B97C8ADD6B4F6744565FAAEE580B0EF97
      SHA-256:C110B0D6D091835D858A7E7056F9D3BD0AF6F36DE61C3E30A747BF59F93953A9
      SHA-512:636B050E0BA063C50B92F974ECA6BD5E89C6A2158923821D8CD43086BAA76BE11B33FE13A7E7A6041B2171B2CCCDCF3D6D6CB34D74A690CCC38D706D8D5E712D
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................(... ...@....... ..............................4~....`..................................(..O....@...................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ...................... (......................................BSJB............v4.0.30319......l...D...#~......p...#Strings.... .......#US.(.......#GUID...8.......#Blob......................3......................................X.........,.................+.................C...........^.....{.........................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.P...C.V...K.....S.....[...............q.........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20736
      Entropy (8bit):6.891303075811866
      Encrypted:false
      SSDEEP:
      MD5:14352D7FC49E8A3A89935BF9A1E44292
      SHA1:6D944FD48BCDB2D9E1F3ED477614FD0CDA68F75A
      SHA-256:8A40BFA6AF6C5C11E7784C1CCBF6521A5AE4662B0B4764DEC5EA24BCFB34EDD2
      SHA-512:46A5C97CFDC9E24973ECDFBD097EE50F27AEF9AA050268584BEEAEE4476CE0EE6CC3E2CDA6A2C5D7777BEF9B6DED0271D84595B391A2CA58AE64B8C9D18A1F52
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0.............J&... ...@....... ....................................@..................................%..O....@...................?...`....................................................... ............... ..H............text...P.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................,&......H.......P ..(...................x%......................................BSJB............v4.0.30319......l...d...#~..........#Strings............#US.........#GUID.......`...#Blob......................3......................................V...........z...m.z.....z.....z.....z.....z...*.z...G.z.......................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.J...C.J...K.Z.............q............................... .....8.......
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30256
      Entropy (8bit):7.11014944348534
      Encrypted:false
      SSDEEP:
      MD5:A4C209F0CB8A1387172150A5238D3B99
      SHA1:3B549EDFF9FCC494AC515D4C31682A24999B3CFA
      SHA-256:1C28B8BFBA0729AEF5ED3D83FCACCAECB7FBCF9FB5F0A7D2D27291C4B2DAA07B
      SHA-512:15570915CB48DB47C49488F5FF2061B242806FBE9AAEBEE18A8DEB1ADB9CA86CA7AB1935E4C9700638708E6DDA40D249A8E76ED17E03437AD916CE44D4281F9A
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0.............J'... ...@....... ....................................@..................................&..O....@..|...............0d...`....................................................... ............... ..H............text...P.... ...................... ..`.rsrc...|....@......................@..@.reloc.......`......................@..B................,'......H.......P ..(...................x&......................................BSJB............v4.0.30319......l.......#~..P...h...#Strings............#US.........#GUID.......X...#Blob......................3................................................-.........................................D.....a...................V.....V.....V...!.V...).V...1.V...9.V...A.V...I.V.......................#.....+.....3.....;.A...C.H...K.H............................................. .......\.....
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30248
      Entropy (8bit):7.102245005139269
      Encrypted:false
      SSDEEP:
      MD5:1AF6A3F2E7CEC70719757112916EA16F
      SHA1:14797BF833894209E653920775FDAA9FED0BC17F
      SHA-256:F941EFB292D291998C27E98E74AD55C1B82CCE073143904352AAC7E78B501DB3
      SHA-512:ED0F570058DAA4663637CCC9D9084641BAB6F366AE15B860D0814A8FB80F3B7BB3697C2BAFAE3D7AD65EE49F1C604572C73E86AF8FA38B253AB1ECFB06E9D9BA
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............&... ...@....... ....................................@..................................&..O....@..................(d...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P ......................(&......................................BSJB............v4.0.30319......l.......#~..H.......#Strings....\.......#US.d.......#GUID...t...d...#Blob......................3................................................5.G.....G.....G.....G.....G.....G.....G...L.G...i.G.................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.K...C.R...K.R.........................................................@.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20736
      Entropy (8bit):6.934416006873891
      Encrypted:false
      SSDEEP:
      MD5:6E9A6303F54D569FDAE61BD52CF9C313
      SHA1:3DF929A52124BAC721064ACB60A0DDCC6E9CD03D
      SHA-256:68517ADE310AA4396CDB4D858AC10525FC1915B52915C01277A879CE53DA64D8
      SHA-512:0EF4844ACECE606F74C78C128943BB97A37C3002A968CF0EDBD986C7450C8A32331AD5760C2F9E22689B8EEC1535D2716D9A73363DA59E7F36A0D6C1112413CD
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." .................&... ...@....... ....................................`.................................x&..O....@...................?...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................&......H.......P .......................%......................................BSJB............v4.0.30319......l...|...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................v.........>.................=.................U.....%.....p..........."...................................!.....).....1.....9.....A.....I.....Q.....Y.........................#.....+.....3.....;.S...C.Y...K.....S.....[...............q.....V...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):31304
      Entropy (8bit):7.041897183018887
      Encrypted:false
      SSDEEP:
      MD5:9E75E2BDAD874AEA993001763276AD6F
      SHA1:5271A66BDF88C9A468E919B1052834DDECDFA7B5
      SHA-256:9FEA1CC1B18117A5A1097D8D0911AC2D1F6B095001CBB14E6C76A6D12E5F0F66
      SHA-512:62A6D062ED895594EBD1C89E5A84ADF5A4BB4ECB7B149D3FD6801D50043F8DD703445623D7B623149C812D2B960FA7CE08F4F18EFF85A8EBC3EA40F96AE0271A
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0..............*... ...@....... ...............................N....@..................................)..O....@..................Hd...`....................................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................<)......................................BSJB............v4.0.30319......l.......#~..l.......#Strings....x.......#US.........#GUID.......\...#Blob......................3................................!.................B...R.B...o.B.....B.....B.....B.....B.....B...,.B.....n...........[.....[.....[...!.[...).[...1.[...9.[...A.[...I.[.......................#.....+.....3.....;.C...C.J...K.J.....................................w.....................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):20696
      Entropy (8bit):6.909978113746904
      Encrypted:false
      SSDEEP:
      MD5:6B792DEE13D0F79C595A11527CC18F1A
      SHA1:868B6D89FC53B7EDDEFB66665B9D79A8606AF627
      SHA-256:B7BF3AAA74D4B6D2C29391EF60CA76A30E6C7E057EAF9B447BF82E4A72E07460
      SHA-512:B609AD13F898A1BEE18E02043F54067263F990B4C43BFAFE1AB10A0AD2B87378951C0B5BF1B0E9DD715B236147EE101A4940406F8B573F3593FE9A63DF36A3A7
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ................Z&... ...@....... ...............................$....`..................................&..O....@...................>...`....................................................... ............... ..H............text...`.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................<&......H.......P ..8....................%......................................BSJB............v4.0.30319......l...T...#~..........#Strings....t.......#US.|.......#GUID...........#Blob......................3......................................I.........-.d.....d.....d.....d.....d.....d.....d...D.d...a.d.......................................!.....).....1.....9.....A.....I.....Q.........................#.....+.....3.+...3.D...;.u...C.....K.....S...............q.....v...............
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):30792
      Entropy (8bit):7.087733077859821
      Encrypted:false
      SSDEEP:
      MD5:5D450EBC4BC80A6E94D969F5AFA5C7F8
      SHA1:C618EC70A3C40D6D5D3C706D210F0783E212E930
      SHA-256:73AED90C3344FEAD3A5C63731110BA3F22E205F1116076FC85A1E98AC4093ADD
      SHA-512:A39E8A1CDF5385C62140DFA3099F30C5F2903BC4767D9B99D90E02F9B234F2ECD7066D57B00EA1914D0D2E2943F44DAFD7CD10C1123CC1E570EDE85B35223595
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....A.].........." ..0.............f)... ...@....... ..............................q.....@..................................)..O....@..\...............Hd...`....................................................... ............... ..H............text...l.... ...................... ..`.rsrc...\....@......................@..@.reloc.......`......................@..B................H)......H.......P ..D....................(......................................BSJB............v4.0.30319......l.......#~..d...t...#Strings............#US.........#GUID.......T...#Blob......................3.................................................."....."...&."...x."...D."...].".....".....".....".....9...........................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.=...C.D...K.D.....................................B.....................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):55904
      Entropy (8bit):6.299047178318044
      Encrypted:false
      SSDEEP:
      MD5:580244BC805220253A87196913EB3E5E
      SHA1:CE6C4C18CF638F980905B9CB6710EE1FA73BB397
      SHA-256:93FBC59E4880AFC9F136C3AC0976ADA7F3FAA7CACEDCE5C824B337CBCA9D2EBF
      SHA-512:2666B594F13CE9DF2352D10A3D8836BF447EAF6A08DA528B027436BB4AFFAAD9CD5466B4337A3EAF7B41D3021016B53C5448C7A52C037708CAE9501DB89A73F0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...W."Q...........!.................... ........ ;. ...................................`.....................................K.......................`>..........H................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......,O...`..........pD......P ......................................g.=d.N:..K..=mU.....M......^.....@........h.pX..9.web.~M}.R9 l9..2.....1S...{^..Pn....8.6k...S.-.K..$uXpy....t.'.%u/...+VC6.(.....{....*...0..&........(..............s....o.....s....}....*...0..K........(.....{....o........,3..+&..( .........{.....o!............*..X...(....2.*..0..L........{.....o"...,=(#...(..................($...o%.......(&...o%.....('...s(...z*.0...........o).......E............d
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21216
      Entropy (8bit):6.894351716923277
      Encrypted:false
      SSDEEP:
      MD5:B048322228A9B0F74EA6A9CBFA00023F
      SHA1:B69EAC6A90511DFA4B1A465D8355D35446C5C853
      SHA-256:71EAFA06AF9BE451BD0ED6A3D68D5E61236D5D215E42B377E5F3EC708C909FB7
      SHA-512:ECBCF24A5C38210C88259606D6FC8BEADF016072F06FEBCBF35451BE7C9B534219B85858C92F1D2539747FF7FBD32F55E814A56EFABA6219AFA712DE551E00B8
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............(... ...@....... ..............................>M....@..................................(..O....@..T................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................(......H.......P ...................... (......................................BSJB............v4.0.30319......l.......#~......H...#Strings....`.......#US.h.......#GUID...x...X...#Blob......................3..................................................^.....^...I.^.....^...g.^.....^.....^.....^.......................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.B...C.B...K.R.............q.......................&...................,.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21200
      Entropy (8bit):6.85265137305525
      Encrypted:false
      SSDEEP:
      MD5:90E3877B7B62B3BAC5DCEF907F4BF088
      SHA1:18E95054F42323825BAF846882147391992800CA
      SHA-256:24EF11CAEB680771B640DE94FAE9A1190AE049F5927E34A6122EB0E626091C71
      SHA-512:0C7DE42C449AA7A848FD597B3F09BC2851075918AF97813E2325BE759D3F813D78C50DAB9EAD926F69D85C35F4E3C1C1C4FA87725F85D61D537CCE23EFBEB0BD
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............(... ...@....... ....................................@..................................'..O....@..H................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...H....@......................@..@.reloc.......`......................@..B.................'......H.......P ......................D'......................................BSJB............v4.0.30319......l...t...#~..........#Strings............#US.........#GUID.......T...#Blob......................3......................................U.........X.{.....{.....{...<.{.....{.....{...o.{.....{...!...................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.?...C.?...K.O.............q.............................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):21216
      Entropy (8bit):6.894289264830931
      Encrypted:false
      SSDEEP:
      MD5:3E60C170F93A49573F08F0E1D01D8C79
      SHA1:115684A691B94A7B636D9F5CCA3D9B1AACBD034D
      SHA-256:71BC77B49A577871FE6B9B343886BAC9870084DDBDB6A82C43893BABA8C02859
      SHA-512:C5B36A55049796352721228CDBD7B895C3C62EE71C21D42CB6B93B0D7C7022281714E09EDFE4DAC340266802020AB0B0CA7D64B4F7E873F9F6A2994E1CE6669D
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...).<V.........." ..0..............(... ...@....... ...............................A....@..................................(..O....@..`................>...`....................................................... ............... ..H............text........ ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................(......................................BSJB............v4.0.30319......l...t...#~......|...#Strings....\.......#US.d.......#GUID...t...X...#Blob......................3......................................h.........8...........a.....O.............................4...................................!.....).....1.....9.....A.....I.........................#.....+.....3.....;.C...C.C...K.S.............q.............................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):4608
      Entropy (8bit):3.7665668658749603
      Encrypted:false
      SSDEEP:
      MD5:FF32D851B381C1D1077C18605EE945A1
      SHA1:87A7C7C11167C6BEB00730AE73E5458C2463844A
      SHA-256:D436F876E00AF353E454A3497813EE8EB24E43A7B6055B87987E5C6CFB3DC87C
      SHA-512:78004E4FD8A76F92F2173C5D49CAC82F7CDC400E3F72A9A6A9055A9B138A9F321CEF7AD0A1CA67C4F77D79D67BBAB1340E41355B5AB4A5E200CBB4675F837937
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............(... ...@....... ....................................`.................................i(..O....@..x....................`.......'..8............................................ ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................(......H........ ..............................................................z..}.....(.......(......(.....*..0...........r...p...(.....*.0..+.........,..{.......+....,...{....o........(.....*6..s....}....*...BSJB............v4.0.30319......l...\...#~..........#Strings............#US.........#GUID.......(...#Blob...........W..........3..................................................&.........3...........Q.h.........y.;.....;.....;.....;...S.;...l.;.....;...e.{...C.{.....;.......
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):32256
      Entropy (8bit):5.4140625465178145
      Encrypted:false
      SSDEEP:
      MD5:F784E6C6E373551F1D5F8BB8D33E8E0E
      SHA1:CEC40581B64B01F4C3808C635C42FC86BAB20FB3
      SHA-256:6F1A18469F125B3B19F1A0181BCE848AAFEF13AFC0949D97BF693C62BEAB875F
      SHA-512:1C46CE087FE25BA35E06718934B7DAD70087278EFBECF665A8FB1A4190357860C880B2CA44BD48450D8F981AE78019BE6798EA071D19BB615CE305F8594DD555
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....u.c.........." ..0..v.............. ........... ....................................`.....................................O...................................\................................................ ............... ..H............text....u... ...v.................. ..`.rsrc................x..............@..@.reloc...............|..............@..B.......................H........B...Q.............................................................}.....(........}.....s....}....*..0..i...........}....~........s....}.....{....o.....~....r...p..<...(....o......(..........rK..p..<...(.......s7...z*...........LM...........(.....*.0..^........~........s....}.....{....o......(......{....o....t?...o.....~....r...p..<...(....o.......+..*n..{...........s.....o....&*...0............(2....r ..p.s.......o......o......,]..o ....o!...o"...o#.....rF..p.s......
      Process:C:\Windows\System32\msiexec.exe
      File Type:HTML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):2666
      Entropy (8bit):4.857811752809092
      Encrypted:false
      SSDEEP:
      MD5:AF1D66B7C6177994C082F8B5B3C7202D
      SHA1:1CD8AA4FF99FD99A97249934EDB88DD9E7035796
      SHA-256:B488B63C8F6A0C173505803B2293D618FD4A198119E2D972323F0D4609E5B0E8
      SHA-512:67EEF28295CA4FE1EC943A035719DF98DE25E3A0785D847D4E27B4713A319B7FE6BCBFC9C53EEDE6407C126A69FB59CAD9931009C5B3A78D40DE06646367E8E6
      Malicious:false
      Reputation:unknown
      Preview:.<!doctype html>..<html>..<head>.. <meta content="text/html;charset=utf-8" http-equiv="Content-Type" />.. <meta content="utf-8" http-equiv="encoding" />.. <meta name="viewport" content="width=device-width, initial-scale=0.5, maximum-scale=0.5, user-scalable=0" />.. <meta name="apple-mobile-web-app-capable" content="yes" />.. <meta name="apple-mobile-web-app-status-bar-style" content="black" />.. <title>Web Socket Demo</title>.. <style type="text/css">.. * { margin: 0; padding: 0; box-sizing: border-box; }.. body { font: 13px Helvetica, Arial; }.. form { background: #000; padding: 3px; position: fixed; bottom: 0; width: 100%; }.. form input { border: 0; padding: 10px; width: 90%; margin-right: .5%; }.. form button { width: 9%; background: rgb(130, 200, 255); border: none; padding: 10px; }.. #messages { list-style-type: none; margin: 0; padding: 0; }.. #messages li { padding: 5px 10px; }.. #messages li:nth-chi
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):2621440
      Entropy (8bit):6.147708413144167
      Encrypted:false
      SSDEEP:
      MD5:76C287DA754A64E43E1344C120959D11
      SHA1:7612DB16C4C151D0B3952F6EEA97C00572C3B197
      SHA-256:787CC3CE50A7464710D04917D3FE69E51E300AC23B8D4424C03F4E55BE107599
      SHA-512:72AE0E3016EBFB93DB52B732FF26E1A66659139ED07CC708D9705E91CA6624A62F3A0AA84C04217B61883439453C578769B217874316EB39EF8BFC65DB4F5473
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....G_...........!......'.. ........'.. ....(...... .......................@(.......(...@.................................<.'.O.....(...................... (...................................................... ............... ..H............text.....'.. ....'................. ..`.rsrc.........(.......'.............@..@.reloc....... (.......'.............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):293074
      Entropy (8bit):5.12600132038836
      Encrypted:false
      SSDEEP:
      MD5:38D13785D176A90B6A1A153082CE45AB
      SHA1:CFB5379E8399D3DF989670CA653CDDEB58BC8339
      SHA-256:9E277E93187DE26FDE0A08C620655BE9B2465377AAB0D1F353361F7D8E13F43C
      SHA-512:AAEC2B62741915FC9081CF975AE3E9550C9112E9E5A2EA2829C3798A7E12C6F01407F89C5FE9F7785C8F386236E531C496ADA30D0BD20DBDB7D246CD3FE3E9F9
      Malicious:false
      Reputation:unknown
      Preview:/*!.. * jQuery JavaScript Library v1.11.1.. * http://jquery.com/.. *.. * Includes Sizzle.js.. * http://sizzlejs.com/.. *.. * Copyright 2005, 2014 jQuery Foundation, Inc. and other contributors.. * Released under the MIT license.. * http://jquery.org/license.. *.. * Date: 2014-05-01T17:42Z.. */....(function( global, factory ) {.....if ( typeof module === "object" && typeof module.exports === "object" ) {....// For CommonJS and CommonJS-like environments where a proper window is present,....// execute the factory and get jQuery....// For environments that do not inherently posses a window with a document....// (such as Node.js), expose a jQuery-making factory as module.exports....// This accentuates the need for the creation of a real window....// e.g. var jQuery = require("jquery")(window);....// See ticket #14549 for more info....module.exports = global.document ?.....factory( global, true ) :.....function( w ) {......if ( !w.document ) {.......throw new Error( "jQuery requires a windo
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):270336
      Entropy (8bit):5.578971164961494
      Encrypted:false
      SSDEEP:
      MD5:5C1C94140A2F815F64117DBB63A4477A
      SHA1:9A79E9C6325E20E5C10E654908D6FD923A25229B
      SHA-256:55B2FE686BC8F739CE845D1689FD08CBCA20381C8E0D2417185D1A0018D8A938
      SHA-512:502E77236418AFAC1D9A15D9840B3B6872440F8A1601706E7A4B0E98A62D0DE70C3ACD192D53D5C29994D1E088FAB07C7E299AB7F6B3232A858CC8782D283084
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....v=..........." ..0...... ......~.... ... ....... .......................`......?.....`.................................,...O.... .......................@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):878592
      Entropy (8bit):6.545712240081286
      Encrypted:false
      SSDEEP:
      MD5:E3B5D677BCFE8D1C17725A57FBCCF206
      SHA1:BA5D3E95BEAF2B32E0CA622EA82FD2ED0445F36C
      SHA-256:E4B755AED60D859024458E1963366E17392D3B43DD6B4AAE8BF43927D30A9F86
      SHA-512:3D27E1EC0D11884CBD5BBB1E46986390A7D0DA06D831A60D6FD9C60CF33632951C34341EDA08178CAEBE757039D10991A2B5BD0B54D1522CDF775801AD8F99A0
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Jj+^..E...E...E..s....E.).>...E...D.=.E..s....E..s....E..s....E..Y....E..s....E.Rich..E.........PE..L...K.\]...........!................................................................................................P...................|....................@...{..@...............................p...@............................................text............................... ..`.rdata..............................@..@.data............r..................@...ve_share,...........................@....rsrc...|............$..............@..@.reloc.......@......................@..B................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):48128
      Entropy (8bit):5.787809558210488
      Encrypted:false
      SSDEEP:
      MD5:32ED3BED1ADCCF7A765406A88C1E8E38
      SHA1:B3728AD271B36C3CC8E0B2C77D4ED0BBF830E95E
      SHA-256:7C062329835C528928357FEC772F9A7A6DBD8943A59EFD3A108831DBC3067C94
      SHA-512:9EBD42DEED37AFD709CBB4EA3212301DB49107897464E8E285CA2B6F4CA5EB441FF8112E13A8C841FCDF072C997599A3807FFE01866E89F578D5F172873FA9A1
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......b.w.&f..&f..&f....b.#f..&f..Df..84..bf..84../f..84..=f..84..'f..84..'f..84..'f..Rich&f..........................PE..d...b.wJ.........." .....l...L.......$...............................................z.................................................P......<....................................................................................................................text....j.......l.................. ..`.rdata..0'.......(...p..............@..@.data...x$..........................@....pdata..............................@..@.rsrc...............................@..@.reloc..H...........................@..B................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1290696
      Entropy (8bit):6.151502759848908
      Encrypted:false
      SSDEEP:
      MD5:86B651B5AB68CF00E7BC497290846053
      SHA1:FA60217C2E5100F19228C5411EEEED96C6DC7C9A
      SHA-256:005ED207471EF8F0001C0E093A62DCF7CBF637B58F3D5AD35E51CA491A1D85B8
      SHA-512:6ECFB79F124CAE430FEB8ED5A7CA74E5C5D9BA0820E843D4B54B1A31EF46B6E753BDA4EEB54092E77B07255E8EBD87BABACE6EECBBE2E6AFA0D4AE8554DA511B
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........I..{'..{'..{'...\..{'...J..{'..4...{'......{'..)...{'...\..{'..{&..y'.....~{'.....G{'......{'..)...{'......{'.Rich.{'.........................PE..d.... \.........." .....8...^.......a...............................................=......................................................h...........d....................0..H....]...............................................P.........@....................text....6.......8.................. ..`.rdata..]d...P...f...<..............@..@.data............N..................@....pdata..............................@..@ve_shareH...........................@....rsrc...d...........................@..@.reloc...E...0...F...T..............@..B........................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows icon resource - 1 icon, -40x256, 32 bits/pixel
      Category:dropped
      Size (bytes):228414
      Entropy (8bit):2.122478318000402
      Encrypted:false
      SSDEEP:
      MD5:CA7FDFF661A974BC770D1572F177ED42
      SHA1:0A6E034721EC1E286FE5771A2733ECB36B011203
      SHA-256:B66584E9CB39ED41018AE2A87DFECC16E782109CE7F46A7A841DE7A9C392EB90
      SHA-512:02F741062A8A51DC63F3186905DF376CE6EAE8257C4E1601399C06AB4F20FBC27A7C75FD30A079D26576454BF76173286B4C4C3CFD9209AB877F6E73A8C98B39
      Malicious:false
      Reputation:unknown
      Preview:............ .(|......(............. ......`.............................................................................................................................................................................................................................................................................................................................................................................................................................................................%...........%..................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows icon resource - 1 icon, -40x256, 32 bits/pixel
      Category:dropped
      Size (bytes):228414
      Entropy (8bit):3.6902473380407703
      Encrypted:false
      SSDEEP:
      MD5:B243E6E529793C50E774766726AA0241
      SHA1:F6ADE2E87E058F4E53B27FBDB4352E3E3B52A000
      SHA-256:ED30CAB32A5CFAEBBB826CED234C86BE1C11C4E457E39A8801FE19F80ECF7A84
      SHA-512:B1086E90E517C8C0B0D574CF52955804519D1FBDB9ECAB4554A1C6E71343AC17DCF48A0213F2D47A67ACC0B6F53879254AA998FE94838725FBBAF3C43F9C5C80
      Malicious:false
      Reputation:unknown
      Preview:............ .(|......(............. ......`................................................................................................................................................................................................................................................................................................................................................................................................................................................S...I.......d1..o...o...c1......G...Q.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:ASCII text, with very long lines (9772), with no line terminators
      Category:dropped
      Size (bytes):9772
      Entropy (8bit):5.996176228148865
      Encrypted:false
      SSDEEP:
      MD5:FCA5CF4840A844422D39B57F81497830
      SHA1:BA2D7D15D02C76AA393CB27CC79EDA41809931BB
      SHA-256:91CD988960DE06E8A557A4BB243CACBCDC4A4AF249847E9F59C71C5442B7D798
      SHA-512:945AFA8F553D7BB6626E1A148EA63C82F6CFB30CC24E9484C6ABD58A7A9B1CF84961DB5EAC7C202AFEA4D833EABECA0210A2B5FD83BB059B9A0E1B445195DC9B
      Malicious:false
      Reputation:unknown
      Preview:QWPXj7CM3FBW/HSFUypyRorWXzUyqMtu7Jnn1Pr+RBow431tktJEy8ExsNkhcz/Y+dd6pzSxV/ewacOoDOnBwk9eG5QhIinPE6oF/EHo8pk9XNFOoZR3w/SVdMNaEzHAGJHRt8iX4JWqr4lK8lIutwRHCY6bA1FBBMfKXwvzpB0/ZuXWPP9k5qppgnlLz0bDiG4Yo8QSMm5RgrC0ZcxJlyx6DlmvVh2IG2Xw0UQNY40G6gb2px5NjOJeHWP6J601iSzvQRWhnq4iT1Po2Z26uTh35UsXAcx79nzLRqEnWH6CuBONoA5nxDJeVupwA3fCo2OgQqnyjeGHRXH7yZ7e2oABvHvYDMGLYRzsEhjOu8E7Xm3fGeAtH8rGr/oX5Lky/y+vF6RCLHAb7NM2JAiv/T4YwcBjRyppGPQIRAE7kfCb9n+v3l7n4ApUvqaXDkihx9rAUIuf2dDH2Pl0GEIjNI0bGuP9rs1gCYTzQXmQpCt8Iy9A90ClWUMXnpOYFtWiYUXkgHGgvuR1TcJpUuUIANemSBTPX6h9VjvYx/Z7BCwVnCCk6XjFcXUOCtLhraAb/Rrq5KokhFAojS/qPYXQ+JF1yK4djy14/UH+SuLie70aC0EhXEUY2LB0+ZH/6MOkpgTtMl6KXcC4AvRTYd7K5nme5i7t7adnEdy5bYPLZVC6rUwrdmKkklEPhTeCH3pp0YQK9yAwg3l6xIDOl3diUjpyDwB7qgymU6oaYcM+xd6O4qcjFcZN6wDsNeyRXU++y6xmQ8O5hNvGkFxmgUizHHnLCd+1Zpq/Hnw3CLrbY5SAgG8Ql13DfWdQPYRVAuFJgZj0lDByUHYGlRrTP0m68Kg0ubLCdpMJVXcdbNO5ECghmzpCox9fFXwlKySvL/Ku2hrOo6YThfiVdIRTj1uqtqAKHOnyWQke8fnwzxdybm2Hc+XsF7t+5ZrJ+Clwd4gVD7qQAGCdZhsSADuhWNvjl3Rp4mMBPlZI0IClKzyF
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
      Category:dropped
      Size (bytes):2635
      Entropy (8bit):2.645239680479132
      Encrypted:false
      SSDEEP:
      MD5:A79B69DF36A3B71CEBB60DB1C58D5C83
      SHA1:47AE658B5486F8BC5EEF4D4B0934B47F66AC2336
      SHA-256:071B28B256EE086FB778A1C16FF5D65D246D9504C39F213EC54EAD004473BE4F
      SHA-512:D5985B455BE5BCD6A051AB73E06F64B3B49C31745E4A9D75D195844C98538B9BA0BDECD8AA6D8B3533F8833724B82BF4B71EE5ECEB9B7D524A46D7B6702910D9
      Malicious:false
      Reputation:unknown
      Preview:L..................F.P...........................................................P.O. .:i.....+00.../C:\...................V.1.....YY....Windows.@......OwHYY......3......................W..W.i.n.d.o.w.s.....\.1.....YY....Installer.D......O.IYY................................I.n.s.t.a.l.l.e.r.......1.....YY....{A97F7~1..~......YY..YY.......\........................{.A.9.7.F.7.0.4.0.-.5.4.4.D.-.4.8.5.7.-.B.3.E.D.-.8.E.D.1.E.D.9.A.E.3.6.8.}.......2.>|..YY..!._58D11~1.EXE..h......YY..YY..............................._.5.8.D.1.1.7.1.B.4.C.A.0.5.5.2.D.F.B.6.D.1.D...e.x.e.......f.....\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.A.9.7.F.7.0.4.0.-.5.4.4.D.-.4.8.5.7.-.B.3.E.D.-.8.E.D.1.E.D.9.A.E.3.6.8.}.\._.5.8.D.1.1.7.1.B.4.C.A.0.5.5.2.D.F.B.6.D.1.D...e.x.e.+.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.T.r.u.s.t.g.a.t.e.\.M.y.T.r.u.s.t.I.D.\.W.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.A.9.7.F.7.0.4.0.-.5.4.4.D.-.4.8.5.7.-.B.3.E.D.-.8.E.D.1.E.D.9.A.E.3.6.8.}.\
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
      Category:dropped
      Size (bytes):2635
      Entropy (8bit):2.6428419967606454
      Encrypted:false
      SSDEEP:
      MD5:7497E4E0E252E93C1711A4E35CBDEBFC
      SHA1:F6A2E6ECA49414D2F369EE85DDEED91407A43F81
      SHA-256:6601D4B22C5223C948CBF8AF481794ACF5AE567A42130FD4F42936290FBF9B17
      SHA-512:88DC80278C66D6B294223B2C6B288FBECBD2AFDC58112EB44FAD5EDB10EAC482C2E6F82D9DDA34E76DCBC25FC08D5A4F5AEFDDBC12237A0244CE5402C821ED84
      Malicious:false
      Reputation:unknown
      Preview:L..................F.P...........................................................P.O. .:i.....+00.../C:\...................V.1.....YY....Windows.@......OwHYY......3......................W..W.i.n.d.o.w.s.....\.1.....YY....Installer.D......O.IYY................................I.n.s.t.a.l.l.e.r.......1.....YY....{A97F7~1..~......YY..YY.......\........................{.A.9.7.F.7.0.4.0.-.5.4.4.D.-.4.8.5.7.-.B.3.E.D.-.8.E.D.1.E.D.9.A.E.3.6.8.}.......2.>|..YY..!._FED98~1.EXE..h......YY..YY............................`.._.F.E.D.9.8.2.4.3.2.4.0.8.2.F.A.B.0.3.1.D.B.2...e.x.e.......f.....\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.A.9.7.F.7.0.4.0.-.5.4.4.D.-.4.8.5.7.-.B.3.E.D.-.8.E.D.1.E.D.9.A.E.3.6.8.}.\._.F.E.D.9.8.2.4.3.2.4.0.8.2.F.A.B.0.3.1.D.B.2...e.x.e.+.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.T.r.u.s.t.g.a.t.e.\.M.y.T.r.u.s.t.I.D.\.W.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.A.9.7.F.7.0.4.0.-.5.4.4.D.-.4.8.5.7.-.B.3.E.D.-.8.E.D.1.E.D.9.A.E.3.6.8.}.\
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1159512
      Entropy (8bit):6.178652162918622
      Encrypted:false
      SSDEEP:
      MD5:AE1A2936D1FB7F7768D6D7449850D200
      SHA1:5B506D40FBC08E32E7A8905849DB47BA0A9DC990
      SHA-256:685C82F774700600CC299186204410D9F36511FFB7DC44386CCC7703F50A319D
      SHA-512:8BC1E40A5B023B774421D03437CA93DD37725435C83E93FA55FB2561B9571E37F82EB954320170345727043F5F5C0B302B3547F9E4C48409B08D89250811F60C
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......#...gv..gv..gv.....ev..@..`v...9..fv..n...lv..y$..dv..@..zv..gv...t..n....v..n....v..n...fv..y$..fv..n...fv..Richgv..........................PE..d......R.........." ................T........................................p.......c..................................................9...@...,.......P...............X.... ..........................................................p.......@....................text............................... ..`.rdata..I...........................@..@.data............J..................@....pdata..............................@..@ve_shareH...........................@....rsrc...P...........................@..@.reloc...B... ...D...T..............@..B........................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):256
      Entropy (8bit):7.171569531114784
      Encrypted:false
      SSDEEP:
      MD5:9A0F612F85DCB9EA7F594FE64998F272
      SHA1:30A1FB7027FA2D28B7ACA4029726EF2143CF469E
      SHA-256:5F4D520A34BDFA3996D9FDE8C2CE65871F8970D76E23201001D8AC5247D68FC7
      SHA-512:54F71603F79BEBBFD6E41FB9EFA10A0892C1A4448B684C9940B162CA33DFD959AFA81A864701E57DF1ADD628D1BEE606D75CD6FEFA0B0E2A791DEC042E61B254
      Malicious:false
      Reputation:unknown
      Preview:..d<E.LL.~0.F4Eh:X..HE..M.b).D....V.P.B.U?..0q..~).W..........1..t.|G~....UG.V?...vY..c.f.9.I.q..#p[f... an.4.H.f....t...S&....b.......@......).n.O...w.K...O.!...m..: ..q8.........ok{;;...}............l.L.>a..v.<.[.ku.m.fW..n..qh..il...s..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):10752
      Entropy (8bit):4.951784664876952
      Encrypted:false
      SSDEEP:
      MD5:6B27956BA886EE230281D205E09E91A9
      SHA1:D5C7D9297DF241B52573D03185A66528A84F5488
      SHA-256:3DF383F4B0195620BADC0BB9F5E1D86EBDB4975B60DA4B910A26FEE9B4AF474F
      SHA-512:E7B9D770EF04DDA2C2CF144C218851B2B933D59395CAFF6594E70D0D71DB4A78319A51BCBD3479668AB7DAD56ACEE4A24CC3C4206186AD6CC91F5314A498212A
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......../..N...N...N..wm.N...Q...N...N.N...Q.N...h...N..JH.N..rn.N..Rich.N..........................PE..L...pN`J...........!......................... ...............................`.......(...............................#..P.... ..P....@.......................P....................................................... ...............................text...h........................... ..`.rdata.. .... ......................@..@.data... ....0......................@....rsrc........@....... ..............@..@.reloc..f....P.......&..............@..B................................................................................................................................................................................................................................................................................................................................
      Process:C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe
      File Type:CSV text
      Category:modified
      Size (bytes):1124
      Entropy (8bit):5.527180835234962
      Encrypted:false
      SSDEEP:
      MD5:D4E39733B489D378A89DAD5ABF0C9DB9
      SHA1:24E382C03E4F21314FB4F8777536F08684AC500E
      SHA-256:BA23A726237D3FE29417F4000D48926DCAA51AB0747E4097AE5B8829D2E8D9B3
      SHA-512:838EC2B5FB1FF0C517E1ABB027DF8D7EA54716595AE149276EC36FAFC0296594518DFE8AAD81B767A4420E2AFFCD422551654DD05BB37BF58BDF1C32594D526D
      Malicious:false
      Reputation:unknown
      Preview:2024-10-24 20:45:01,824 [1] ERROR MyTrustIDv1.Bootstrapper 0 - OnStartUp Exception : {"Args":[]}..2024-10-24 20:45:01,920 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - license Key : KQz71xjITSXfaNJR+oRVwD5r62avCflJhITIF+lX44I8oWyBhW3KN1kNWvnmAi3EjtFbBOotFr7Xiq/zPL3pA93voR9/WppKV41tXSfPhdcKiQWz7X8C0YQTfUWtv071dGHOzzyhzU1h1dJIED4lP1y5DcQRNQsQMhvl/NVmcWak1LIYkFQa9x1xvf76jzV0..2024-10-24 20:45:01,936 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - Project Name : ..2024-10-24 20:45:01,936 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - Date End : 07/07/7777 00:00:00..2024-10-24 20:45:01,936 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - Storage : 1..2024-10-24 20:45:01,968 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - Local Sign : 0..2024-10-24 20:45:01,968 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - Sign Limit : 10..2024-10-24 20:45:01,968 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - LoadAndRetrieve : 0..2024-10-24 20:45:01,984 [1] INFO MyTrustIDv1.Helper.LicenseStatus 0 - AutoDetect
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Archive, ctime=Tue Jan 10 07:12:02 2023, mtime=Thu Oct 24 23:44:59 2024, atime=Tue Jan 10 07:12:02 2023, length=2592256, window=hide
      Category:dropped
      Size (bytes):1244
      Entropy (8bit):4.6072329265669305
      Encrypted:false
      SSDEEP:
      MD5:673A78C8F83A8C603C265F5700E66906
      SHA1:AD0311ECB3F19539300102E23832EB28086AC6D2
      SHA-256:A118037A8EDCEEAB5F56900707E9F6D7D5987235AC7F4E89366FC24885764497
      SHA-512:CB457F4DD6ECADE4F2BCDBA116202A4B0A10354F8558081147A944B520AAEA370F0999766F88B23FEF1146596E6CB4ADCF497CDF583EAFE9F8F85404A2596042
      Malicious:true
      Reputation:unknown
      Preview:L..................F.... ....u.7.$...4..w&...u.7.$....'..........................P.O. .:i.....+00.../C:\.....................1.....YY....PROGRA~2.........O.IYY......................V.....#...P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....\.1.....YY....TRUSTG~1..D......YY..YY..............................T.r.u.s.t.g.a.t.e.....\.1.....YY....MYTRUS~1..D......YY..YY............................. .M.y.T.r.u.s.t.I.D.....l.2...'.*V.A .MYTRUS~1.EXE..P......*V.AYY.......Z........................M.y.T.r.u.s.t.I.D.v.1...e.x.e.......i...............-.......h..............J.....C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe..@.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.T.r.u.s.t.g.a.t.e.\.M.y.T.r.u.s.t.I.D.\.M.y.T.r.u.s.t.I.D.v.1...e.x.e.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.T.r.u.s.t.g.a.t.e.\.M.y.T.r.u.s.t.I.D.........*................@Z|...K.J.........`.......X.......745773...........hT..CrF.f4... ..............%..h
      Process:C:\Windows\SysWOW64\msiexec.exe
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):152
      Entropy (8bit):5.038757123363281
      Encrypted:false
      SSDEEP:
      MD5:CCB860553902094F48B6D91DBAE56FDD
      SHA1:0A9909816F156632C0C8718725853F48A81FA0BC
      SHA-256:7D10AEA89090852F80436F2C5EB025DF6BE018D8C7E27CAF46131446E6ABDCCD
      SHA-512:BE344E0E9567E469FCD46E5166310779E69B092CD6B55256CFC4525287F2A0F6E52463967C58C5609D81FBAEC27422264F1C1C62E7327DD31FF7DD9920A3339C
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0"?>..<configuration>...<startup><supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.5.2"/>...</startup>..</configuration>..
      Process:C:\Windows\SysWOW64\cmd.exe
      File Type:ASCII text, with CRLF line terminators
      Category:modified
      Size (bytes):317
      Entropy (8bit):5.143301581319301
      Encrypted:false
      SSDEEP:
      MD5:7108F0361192D029D913EAC0C3178F3C
      SHA1:EC395EC35651FFF9BA82510566480709B2B454DC
      SHA-256:28791861AAAE814CCDDEAFC2A3493DA5A60BCB83A235DEFB3FE95CE430B7C68E
      SHA-512:421F1152F44521B12D0AA61210D8A06C0F4577CCE1B4E00840A4891A54B09EE2236C082CD9DF17EAA2DC1C9C4BA85B524241D847C06554F93B89379EF1D7DA4F
      Malicious:true
      Reputation:unknown
      Preview:Set oWS = WScript.CreateObject("WScript.Shell") ..sLinkFile = "C:\Users\Public\Desktop\MyTrustIDv1.lnk" ..Set oLink = oWS.CreateShortcut(sLinkFile) ..oLink.TargetPath = "C:\Program Files (x86)\Trustgate\MyTrustID\MyTrustIDv1.exe" ..oLink.WorkingDirectory = "C:\Program Files (x86)\Trustgate\MyTrustID" ..oLink.Save ..
      Process:C:\Users\user\Desktop\MyTrustID.EXE
      File Type:DOS batch file, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):6345
      Entropy (8bit):5.277533323684584
      Encrypted:false
      SSDEEP:
      MD5:9DB75019E3F2C2ECEACB58E22DF1043C
      SHA1:87699929880256D059937C68FDB967B436F4E05A
      SHA-256:0B50B14DBC2F9CFAC84DCE6965037915B2BD720EDECC98359A367BFB5C659CCA
      SHA-512:907C1C56257B57A44D14B943F04C31DAB566C33330DF3DF5E2AEC356AA9A72D0004E2D37742DDE4378F9A6A373513D835B28D14384C1652F028080A9A7576D9B
      Malicious:false
      Reputation:unknown
      Preview:@Echo off..color 0A....ECHO # # ####### ### ###### ..ECHO ## ## # # # ##### # # #### ##### # # # ..ECHO # # # # # # # # # # # # # # # # ..ECHO # # # # # # # # # #### # # # # ..ECHO # # # # ##### # # # # # # # ..ECHO # # # # # # # # # # # # # # ..ECHO # # # # # # #### #### # ### ###### ..echo:..echo:..NET SESSION >nul 2>&1..IF %ERRORLEVEL% EQU 0 (.. goto :Status ..) ELSE (.. echo ######## ######## ######## ####### ######## .. echo ## ## ## ## ## ## ## ## ## .. echo ## ## ## ## ## ## ## ## ## .. echo ###### ######## ######## ## ## ######## .. echo ## ## ## ## ## ## ## ## ## .. echo ## ## ## ## ## ## ## ## ## .. echo ######## ## ## ## ## ####### ## ##
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Create Time/Date: Mon Jun 21 08:00:00 1999, Name of Creating Application: Windows Installer, Security: 1, Code page: 1252, Template: Intel;1033, Number of Pages: 200, Revision Number: {515A415D-AD11-4005-A4FD-AD810EC31437}, Title: MyTrustID, Subject: Version 1.1, Author: MSC Trustgate.com Sdn Bhd, Comments: This application is develop by MSC Trustgate.com Sdn Bhd, Number of Words: 2, Last Saved Time/Date: Mon Jan 9 20:13:53 2023, Last Printed: Mon Jan 9 20:13:53 2023
      Category:dropped
      Size (bytes):8450048
      Entropy (8bit):7.729982787074363
      Encrypted:false
      SSDEEP:
      MD5:5AE5BE34CB87D27B44ED5486127F41CC
      SHA1:FEE672E924E53FEEB1E2E76812A1FCF38ABDC073
      SHA-256:3D92E646A101E82013F7E92AD22A7BFF172EE185028CF0E0196DDC778E27F98B
      SHA-512:776CDE216D08938A2FE62E98485E3B0593BE001AFC8DCC2B6B1806485884A35C8A72540E086BEA540808252643EB754BE702F42ABBDD71B3E4A760F3CFA5B11C
      Malicious:false
      Reputation:unknown
      Preview:......................>...................................8.......z...........{...............................................................W...X...Y...Z.......$...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...........Z................................................................................................................... ...!..."...#...$...%...&...'...(...)...*...+...,...-......./...0...1...2...3...4...5...6...7...F.......:...;...<...=...>...?...@...A...B...C...D...Y.......G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...V...W...X...[...........\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t.......v...w...x...y...z...
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):305152
      Entropy (8bit):6.504247783181216
      Encrypted:false
      SSDEEP:
      MD5:684F2D21637CB5835172EDAD55B6A8D9
      SHA1:5EAC3B8D0733AA11543248B769D7C30D2C53FCDB
      SHA-256:DA1FE86141C446921021BB26B6FE2BD2D1BB51E3E614F46F8103FFAD8042F2C0
      SHA-512:7B626C2839AC7DF4DD764D52290DA80F40F7C02CB70C8668A33AD166B0BCB0C1D4114D08A8754E0AE9C0210129AE7E885A90DF714CA79BD946FBD8009848538C
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......|U..84..84..84...Z..;4......;4...U..<4....0.54....2..4....3.%4...Y..j4...Y..)4...Y..-4......#4..84..f5...Z..$4...Z..94...Z>.94...Z..94..Rich84..........PE..L...p..a.........."!.....N...v...............`......................................O.....@..........................Z..:.......................................l....(..T...........................X(..@............................................text....L.......N.................. ..`.data...<....`.......R..............@....idata...............b..............@..@.rsrc................r..............@..@.reloc..l........0...x..............@..B................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):971782
      Entropy (8bit):3.9773329145706704
      Encrypted:false
      SSDEEP:
      MD5:6EA5A3BF60E1CD539883BBE7BA276E9B
      SHA1:F39BAF9D715611B7CA8FA49982C2D98063F07811
      SHA-256:30FF962CDF7C2A57C21A1E728E319703FB14ABC72467757EEDEE2636D59DDB9F
      SHA-512:19B4BD88AE5BCF0B1171B2279ADA22FE78D42AC3EC5CACC19976EC2A01E5E9F899B61100D5E8F6B0B7A1FB7ABB279AA819B9036ABC06D116A3D72B16EE3BB2E8
      Malicious:false
      Reputation:unknown
      Preview:...@IXOS.@.....@..XY.@.....@.....@.....@.....@.....@......&.{A97F7040-544D-4857-B3ED-8ED1ED9AE368}..MyTrustID..MyTrustIDesktop.msi.@.....@.....@.....@......_853F67D554F05449430E7E.exe..&.{515A415D-AD11-4005-A4FD-AD810EC31437}.....@.....@.....@.....@.......@.....@.....@.......@......MyTrustID......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@l....@.....@.]....&.{C2294F64-FF6D-B70D-9232-C2B27053D3E5}I.C:\Program Files (x86)\Trustgate\MyTrustID\System.ServiceModel.Duplex.dll.@.......@.....@.....@......&.{1CCD8267-01F6-9431-57D9-DE6F4D458FB4}7.C:\Program Files (x86)\Trustgate\MyTrustID\st3csp11.dll.@.......@.....@.....@......&.{15512432-F9BC-C27D-E6C3-CB998551EC6D}P.C:\Program Files (x86)\Trustgate\MyTrustID\System.ComponentModel.Annotations.dll.@.......@.....@.....@......&.{DC08770C-5C12-A045-E7BD-149A8796C731}I.C:\Program Files (x86)\Trustgate\MyTrustID\System.Diagnostics.
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.1671377009427568
      Encrypted:false
      SSDEEP:
      MD5:81AC2C7FC8E864028ABFD62E888B5338
      SHA1:FAB39D10C22219C78501D198F65D6BBCC46A8E49
      SHA-256:6A66BF30EEE1739DA52CDD1CA13DAFD9C955113C900A5DCD5D5CCA11B715C1C1
      SHA-512:8E02F64AA9105801A8115B1ED21331700FED8CA33DD177409836B4C3882C9B1531E081B7D5660996752F4F21D3AB2C35231F8A3054ED0314D6E5C712EFF67ADE
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows icon resource - 1 icon, -40x256, 32 bits/pixel
      Category:dropped
      Size (bytes):228414
      Entropy (8bit):3.6901975391224604
      Encrypted:false
      SSDEEP:
      MD5:9B86A04A7F92C012B782C22129910284
      SHA1:86A9FDC306DADAC812E305C5A1F92A55B8C281B3
      SHA-256:0BAA5B3B40EB4E03F9D488688FA98FA83B2495C3EDC9618A4A85B626A308410D
      SHA-512:3589B1745723478D037ED5263920CE5168B918E0568E69085C62CEF5F0B1335049F3894F01CBDE4135D6094F228344DCB4FB60FAC1A83909CF3B6A8032D044B1
      Malicious:false
      Reputation:unknown
      Preview:............ .(|......(............. .......................................................................................................................................................................................................................................................................................................................................................................................................................................................S...I.......d1..o...o...c1......G...Q.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):454234
      Entropy (8bit):5.356172233044458
      Encrypted:false
      SSDEEP:
      MD5:CB5F1D7B1FC935130AF23301AB0E7AE3
      SHA1:BF1DE7DFC3A845F3527B3A29822429033F77A1F8
      SHA-256:B4C2C2E7469634F740A196069F4FFE87360442FAA934B113EE1BFC1B95F71ECC
      SHA-512:F863DDF3654C961A61FDA76EAE9325886F4CB0B3AE93110208E6518C4D57A1D33F032BC8B0EFB0F2EB08457D903E45B3BAB8A9592E7B2A640F335B2CBD2F4629
      Malicious:false
      Reputation:unknown
      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):24576
      Entropy (8bit):1.833481735366168
      Encrypted:false
      SSDEEP:
      MD5:3150257B8576D3C4136055993C44D50A
      SHA1:AE12212755BB529431A60D5C1DB5CFDA1A38A337
      SHA-256:8766C60549EC4BB45D454AE93F1F358F2D3EB398E324F7F4C73AD27253975E61
      SHA-512:B56842B7F05C5B98C8BE1F9B07D83685FD9CC2AD831390B4C7FACFC4E6E220E398F5A8470ECCED5930AFEA005A29504E41C5EA78475853ACBCF4F73652529428
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Reputation:unknown
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):0.07437259497127073
      Encrypted:false
      SSDEEP:
      MD5:7E99972E9D7D05792063D0CF22B78428
      SHA1:35839F5E3999ED2D7FA4BF796C5F12A3FFBF1391
      SHA-256:1A15C26121B717430D5643FCD95CF97E48437FCBD424FA351EC88728FA270E30
      SHA-512:C9644C30FCBA9EE70DA02B6081F08503A2F543A81EC75D35FB5C0B5C4D552DBE86519B78A818DDF723FFD66417C343981A8E9784A8894D3B07D444EF1083FD27
      Malicious:false
      Reputation:unknown
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):49152
      Entropy (8bit):1.20038972886914
      Encrypted:false
      SSDEEP:
      MD5:588D35511D6E33D72EB64AA7E8833251
      SHA1:F73CE6672A8C13F7C5DD233A757C9F30EEF29E3D
      SHA-256:CCD6A5492F9BE6D450678DEC0EAA71B350ECA1DB57709E661E553CFD0C1B69DE
      SHA-512:FD15573078BD893D1B85D85163C95DA13D9B74ED2EA2C5CF98A505EF624795F03B943D8E5063A1431AB3FFA973DD14684B0C7E0A68322176C874F02B77DC3BD4
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):69632
      Entropy (8bit):0.3187933968102696
      Encrypted:false
      SSDEEP:
      MD5:8C9505A273FC99039096FEFBEB79716A
      SHA1:F6EED599848949F53C7865CDADCED8F6859250BF
      SHA-256:2AD99F3D91AB4B92EA6A4E16927BF84951A0DB19EA77E485284F8471B43791D3
      SHA-512:895F3307A34BB4107077C77C6C75874719D8454FB3754BE9D4B24EC89B6AD1C90337BABB008B9BD858873B9C9DBC67A3399E1F5878B80A57C07B38AC867ECF0B
      Malicious:false
      Reputation:unknown
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\SysWOW64\net1.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):37
      Entropy (8bit):3.6408290408368487
      Encrypted:false
      SSDEEP:
      MD5:768165E0ABF16BF3056836D5431A7296
      SHA1:9FB3196BE60E49BFC319EBD9E0B103954D711E34
      SHA-256:B44C505B721E93E2A596577018CC65B993CD632B9FE7620A4B3DB54031AFFF5D
      SHA-512:1250EC40BA20F39A5B9A3AAFD45C63CB6F1BF48B89ACCE1F885470C936FB48A803081943C68458BA1ADCE92D5FE79D3E45682285F56ECB29884D41974269992D
      Malicious:false
      Reputation:unknown
      Preview:There are no entries in the list.....
      File type:PE32 executable (GUI) Intel 80386, for MS Windows
      Entropy (8bit):7.996223052086757
      TrID:
      • Win32 Executable (generic) a (10002005/4) 99.96%
      • Generic Win/DOS Executable (2004/3) 0.02%
      • DOS Executable Generic (2002/1) 0.02%
      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
      File name:MyTrustID.EXE
      File size:7'301'120 bytes
      MD5:1f4bb0f2b9d26f2419fbb7e7ba860d03
      SHA1:0ec525f5032f91544908aa957dc9fa9212d9ac7d
      SHA256:0b4d29b13046032af8c92bff26283ac8522bc178e9b4428010030bd352c49e91
      SHA512:d02b65506c55cf2d9b7120ccdc44aec738f34dad80e6d0dd667b9948851958188eae90799d916bea26a574ee23a2ad0172212f2471e0627cb8ddfc99ee3bfae8
      SSDEEP:98304:oHaT0WVxMdBjaTQIybPRJLNL6kQnxZn9tPR+1nnf0OlvP2tFHBxhmkxK9:XTM3eTQIybHQXfP2rhOvhxcUK9
      TLSH:4B7633DAEEC08CB1F4B06BB0A4FA529E5B3F3DF6C078567D1368A5406730206DAB4B55
      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Of.{...(...(...(.l.)...(.l.)...(.l.)...(.l.)...(...(...(.l.)...(.l\(...(.l.)...(Rich...(........PE..L...!V.:.................d.
      Icon Hash:3b6120282c4c5a1f
      Entrypoint:0x406a00
      Entrypoint Section:.text
      Digitally signed:false
      Imagebase:0x400000
      Subsystem:windows gui
      Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
      Time Stamp:0x3A1E5621 [Fri Nov 24 11:50:57 2000 UTC]
      TLS Callbacks:
      CLR (.Net) Version:
      OS Version Major:10
      OS Version Minor:0
      File Version Major:10
      File Version Minor:0
      Subsystem Version Major:10
      Subsystem Version Minor:0
      Import Hash:646167cce332c1c252cdcb1839e0cf48
      Instruction
      call 00007F8251752F45h
      jmp 00007F8251752845h
      push 00000058h
      push 00407268h
      call 00007F8251752FE7h
      xor ebx, ebx
      mov dword ptr [ebp-20h], ebx
      lea eax, dword ptr [ebp-68h]
      push eax
      call dword ptr [0040A184h]
      mov dword ptr [ebp-04h], ebx
      mov eax, dword ptr fs:[00000018h]
      mov esi, dword ptr [eax+04h]
      mov edi, ebx
      mov edx, 004088ACh
      mov ecx, esi
      xor eax, eax
      lock cmpxchg dword ptr [edx], ecx
      test eax, eax
      je 00007F825175285Ah
      cmp eax, esi
      jne 00007F8251752849h
      xor esi, esi
      inc esi
      mov edi, esi
      jmp 00007F8251752852h
      push 000003E8h
      call dword ptr [0040A188h]
      jmp 00007F8251752819h
      xor esi, esi
      inc esi
      cmp dword ptr [004088B0h], esi
      jne 00007F825175284Ch
      push 0000001Fh
      call 00007F8251752D75h
      pop ecx
      jmp 00007F825175287Ch
      cmp dword ptr [004088B0h], ebx
      jne 00007F825175286Eh
      mov dword ptr [004088B0h], esi
      push 004010CCh
      push 004010C0h
      call 00007F82517529A0h
      pop ecx
      pop ecx
      test eax, eax
      je 00007F8251752859h
      mov dword ptr [ebp-04h], FFFFFFFEh
      mov eax, 000000FFh
      jmp 00007F8251752979h
      mov dword ptr [004081E4h], esi
      cmp dword ptr [004088B0h], esi
      jne 00007F825175285Dh
      push 004010BCh
      push 004010B4h
      call 00007F8251752F33h
      pop ecx
      pop ecx
      mov dword ptr [000088B0h], 00000000h
      NameVirtual AddressVirtual Size Is in Section
      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_IMPORT0xa28c0xb4.idata
      IMAGE_DIRECTORY_ENTRY_RESOURCE0xc0000x6ee048.rsrc
      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
      IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
      IMAGE_DIRECTORY_ENTRY_BASERELOC0x6fb0000x888.reloc
      IMAGE_DIRECTORY_ENTRY_DEBUG0x14100x54.text
      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
      IMAGE_DIRECTORY_ENTRY_TLS0x00x0
      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x10080x40.text
      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_IAT0xa0000x288.idata
      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
      .text0x10000x62c40x6400d3b080bd7b514f812cbee16da52b0c4cFalse0.5751171875data6.301659763150869IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      .data0x80000x1a480x2007b9890a93c0516bb070e1170cfde54d5False0.609375data4.970639543960129IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .idata0xa0000x10520x12003906fab55f211460c4a4a799648be3c7False0.4142795138888889data5.0224249304912405IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .rsrc0xc0000x6ef0000x6ee200387d7e785d0877187fa0829d78fed721unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .reloc0x6fb0000x8880xa00f081b23c3aa39325c504c02cdcd1422dFalse0.7515625data6.273787441603385IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
      NameRVASizeTypeLanguageCountryZLIB Complexity
      AVI0xcb300x2e1aRIFF (little-endian) data, AVI, 272 x 60, 10.00 fps, video: RLE 8bppEnglishUnited States0.2713099474665311
      RT_ICON0xf94c0x668Device independent bitmap graphic, 48 x 96 x 4, image size 1152EnglishUnited States0.3225609756097561
      RT_ICON0xffb40x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishUnited States0.41263440860215056
      RT_ICON0x1029c0x1e8Device independent bitmap graphic, 24 x 48 x 4, image size 288EnglishUnited States0.4569672131147541
      RT_ICON0x104840x128Device independent bitmap graphic, 16 x 32 x 4, image size 128EnglishUnited States0.5574324324324325
      RT_ICON0x105ac0xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsEnglishUnited States0.6223347547974414
      RT_ICON0x114540x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishUnited States0.7369133574007221
      RT_ICON0x11cfc0x6c8Device independent bitmap graphic, 24 x 48 x 8, image size 576, 256 important colorsEnglishUnited States0.783410138248848
      RT_ICON0x123c40x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsEnglishUnited States0.3829479768786127
      RT_ICON0x1292c0xd9d2PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0004662673505254
      RT_ICON0x203000x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.5300829875518672
      RT_ICON0x228a80x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.6137429643527205
      RT_ICON0x239500x988Device independent bitmap graphic, 24 x 48 x 32, image size 2400EnglishUnited States0.703688524590164
      RT_ICON0x242d80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.425531914893617
      RT_DIALOG0x247400x2f2dataEnglishUnited States0.4389920424403183
      RT_DIALOG0x24a340x2f2dataEnglishGreat Britain0.4389920424403183
      RT_DIALOG0x24d280x1b0dataEnglishUnited States0.5625
      RT_DIALOG0x24ed80x1b0dataEnglishGreat Britain0.5625
      RT_DIALOG0x250880x166dataEnglishUnited States0.5223463687150838
      RT_DIALOG0x251f00x166dataEnglishGreat Britain0.5223463687150838
      RT_DIALOG0x253580x1c0dataEnglishUnited States0.5446428571428571
      RT_DIALOG0x255180x1c0dataEnglishGreat Britain0.5424107142857143
      RT_DIALOG0x256d80x130dataEnglishUnited States0.5526315789473685
      RT_DIALOG0x258080x130dataEnglishGreat Britain0.5526315789473685
      RT_DIALOG0x259380x120dataEnglishUnited States0.5763888888888888
      RT_DIALOG0x25a580x120dataEnglishGreat Britain0.5763888888888888
      RT_STRING0x25b780x8cMatlab v4 mat-file (little endian) l, numeric, rows 0, columns 0EnglishUnited States0.6214285714285714
      RT_STRING0x25c040x8cMatlab v4 mat-file (little endian) l, numeric, rows 0, columns 0EnglishGreat Britain0.6214285714285714
      RT_STRING0x25c900x520dataEnglishUnited States0.4032012195121951
      RT_STRING0x261b00x526dataEnglishGreat Britain0.40440060698027314
      RT_STRING0x266d80x5ccdataEnglishUnited States0.36455525606469
      RT_STRING0x26ca40x5cedataEnglishGreat Britain0.3654104979811575
      RT_STRING0x272740x4b0dataEnglishUnited States0.385
      RT_STRING0x277240x4b0dataEnglishGreat Britain0.385
      RT_STRING0x27bd40x44adataEnglishUnited States0.3970856102003643
      RT_STRING0x280200x442dataEnglishGreat Britain0.39908256880733944
      RT_STRING0x284640x3cedataEnglishUnited States0.36858316221765913
      RT_STRING0x288340x3ccdataEnglishGreat Britain0.3683127572016461
      RT_RCDATA0x28c000x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
      RT_RCDATA0x28c080x6d0302Microsoft Cabinet archive data, many, 7144194 bytes, 2 files, at 0x2c +A "mytrustid.bat" +A "MyTrustIDesktop.msi", ID 3292, number 1, 259 datablocks, 0x1503 compressionEnglishUnited States0.9883565902709961
      RT_RCDATA0x6f8f0c0x4dataEnglishUnited States3.0
      RT_RCDATA0x6f8f100x24dataEnglishUnited States0.8611111111111112
      RT_RCDATA0x6f8f340x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
      RT_RCDATA0x6f8f3c0x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
      RT_RCDATA0x6f8f440x4dataEnglishUnited States3.0
      RT_RCDATA0x6f8f480x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
      RT_RCDATA0x6f8f500x4dataEnglishUnited States3.0
      RT_RCDATA0x6f8f540x15ASCII text, with no line terminatorsEnglishUnited States1.380952380952381
      RT_RCDATA0x6f8f6c0x4dataEnglishUnited States3.0
      RT_RCDATA0x6f8f700xadataEnglishUnited States1.8
      RT_RCDATA0x6f8f7c0x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
      RT_RCDATA0x6f8f840x7ASCII text, with no line terminatorsEnglishUnited States2.142857142857143
      RT_GROUP_ICON0x6f8f8c0xbcdataEnglishUnited States0.6117021276595744
      RT_VERSION0x6f90480x408dataEnglishUnited States0.42151162790697677
      RT_VERSION0x6f94500x414dataEnglishGreat Britain0.42432950191570884
      RT_MANIFEST0x6f98640x7e2XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.3761149653121903
      DLLImport
      ADVAPI32.dllGetTokenInformation, RegDeleteValueA, RegOpenKeyExA, RegQueryInfoKeyA, FreeSid, OpenProcessToken, RegSetValueExA, RegCreateKeyExA, LookupPrivilegeValueA, AllocateAndInitializeSid, RegQueryValueExA, EqualSid, RegCloseKey, AdjustTokenPrivileges
      KERNEL32.dll_lopen, _llseek, CompareStringA, GetLastError, GetFileAttributesA, GetSystemDirectoryA, LoadLibraryA, DeleteFileA, GlobalAlloc, GlobalFree, CloseHandle, WritePrivateProfileStringA, IsDBCSLeadByte, GetWindowsDirectoryA, SetFileAttributesA, GetProcAddress, GlobalLock, LocalFree, RemoveDirectoryA, FreeLibrary, _lclose, CreateDirectoryA, GetPrivateProfileIntA, GetPrivateProfileStringA, GlobalUnlock, ReadFile, SizeofResource, WriteFile, GetDriveTypeA, lstrcmpA, SetFileTime, SetFilePointer, FindResourceA, CreateMutexA, GetVolumeInformationA, ExpandEnvironmentStringsA, GetCurrentDirectoryA, FreeResource, GetVersion, SetCurrentDirectoryA, GetTempPathA, LocalFileTimeToFileTime, CreateFileA, SetEvent, TerminateThread, GetVersionExA, LockResource, GetSystemInfo, CreateThread, ResetEvent, LoadResource, ExitProcess, GetModuleHandleW, CreateProcessA, FormatMessageA, GetTempFileNameA, DosDateTimeToFileTime, CreateEventA, GetExitCodeProcess, FindNextFileA, LocalAlloc, GetShortPathNameA, MulDiv, GetDiskFreeSpaceA, EnumResourceLanguagesA, GetTickCount, GetSystemTimeAsFileTime, GetCurrentThreadId, GetCurrentProcessId, QueryPerformanceCounter, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStartupInfoW, Sleep, FindClose, GetCurrentProcess, FindFirstFileA, WaitForSingleObject, GetModuleFileNameA, LoadLibraryExA
      GDI32.dllGetDeviceCaps
      USER32.dllSetWindowLongA, GetDlgItemTextA, DialogBoxIndirectParamA, ShowWindow, MsgWaitForMultipleObjects, SetWindowPos, GetDC, GetWindowRect, DispatchMessageA, GetDesktopWindow, CharUpperA, SetDlgItemTextA, ExitWindowsEx, MessageBeep, EndDialog, CharPrevA, LoadStringA, CharNextA, EnableWindow, ReleaseDC, SetForegroundWindow, PeekMessageA, GetDlgItem, SendMessageA, SendDlgItemMessageA, MessageBoxA, SetWindowTextA, GetWindowLongA, CallWindowProcA, GetSystemMetrics
      msvcrt.dll_controlfp, ?terminate@@YAXXZ, _acmdln, _initterm, __setusermatherr, _except_handler4_common, memcpy, _ismbblead, __p__fmode, _cexit, _exit, exit, __set_app_type, __getmainargs, _amsg_exit, __p__commode, _XcptFilter, memcpy_s, _vsnprintf, memset
      COMCTL32.dll
      Cabinet.dll
      VERSION.dllGetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA
      Language of compilation systemCountry where language is spokenMap
      EnglishUnited States
      EnglishGreat Britain