Windows Analysis Report
int_duca.exe

Overview

General Information

Sample name: int_duca.exe
Analysis ID: 1559466
MD5: 134c17a4367f255176249227e7db0bae
SHA1: 98eb94e8a809b073e8b878bc164cc74efe873d0c
SHA256: 7c36ec7327b0879d33f4c579412770712e2a29f46324468dc48ceb857b3b909f
Infos:

Detection

Score: 9
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Detected potential crypto function
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: COM Hijacking via TreatAs
Sigma detected: Use Short Name Path in Command Line
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Source: int_duca.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File opened: c:\int_duca\msvcr100.dll Jump to behavior
Source: Binary string: e:\pb126\BUILD\UNICODE\PBVM126.pdb source: PBVMfb5c.rra.3.dr
Source: Binary string: e:\pb126\BUILD\UNICODE\PBODB126.pdb source: pbodf9e5.rra.3.dr
Source: Binary string: E:\pb126\build\unicode\PBUIS126.pdb source: pbUIfab0.rra.3.dr
Source: Binary string: e:\pb126\BUILD\UNICODE\pbo10126.pdb source: pbo1f9c6.rra.3.dr
Source: Binary string: E:\pb126\build\unicode\PBUIS126.pdb source: pbUIfab0.rra.3.dr
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_004014C2 wsprintfA,FindFirstFileA,FindClose, 0_2_004014C2
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_004050D5 lstrcpyA,lstrcpyA,lstrcatA,lstrcatA,DeleteFileA,DeleteFileA,FindFirstFileA,lstrcpyA,lstrcatA,lstrcatA,lstrcpyA,lstrcatA,DeleteFileA,FindNextFileA,FindClose,lstrcpyA,lstrlenA,RemoveDirectoryA, 0_2_004050D5
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00458620 CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 2_2_00458620
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0042A298 __EH_prolog,FindFirstFileA,FindClose, 2_2_0042A298
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045256E __EH_prolog,FindFirstFileA,FindNextFileA,FindNextFileA,FindNextFileA,FindClose, 2_2_0045256E
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045A9E4 __EH_prolog,FindFirstFileA,FindClose,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose,RemoveDirectoryA,FindClose,DeleteFileA, 2_2_0045A9E4
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0044ACA8 __EH_prolog,FindFirstFileA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044ACA8
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00428EA6 __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose, 2_2_00428EA6
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00429025 __EH_prolog,FindFirstFileA,FileTimeToLocalFileTime,FileTimeToDosDateTime,FindNextFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, 2_2_00429025
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0044B21F __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044B21F
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00458620 CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 3_2_00458620
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00428EA6 __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose, 3_2_00428EA6
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00429025 __EH_prolog,FindFirstFileA,FileTimeToLocalFileTime,FileTimeToDosDateTime,FindNextFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, 3_2_00429025
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0042A298 __EH_prolog,FindFirstFileA,FindClose, 3_2_0042A298
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045256E __EH_prolog,FindFirstFileA,FindNextFileA,FindNextFileA,FindNextFileA,FindClose, 3_2_0045256E
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045A9E4 __EH_prolog,FindFirstFileA,FindClose,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose,RemoveDirectoryA,FindClose,DeleteFileA, 3_2_0045A9E4
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0044ACA8 __EH_prolog,FindFirstFileA,FindNextFileA,SafeArrayCopy,FindClose, 3_2_0044ACA8
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0044B21F __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,SafeArrayCopy,FindClose, 3_2_0044B21F
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\Temp\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\ Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00458869 InternetReadFile,SetLastError, 2_2_00458869
Source: duca59d.rra.3.dr String found in binary or memory: http://aca-web.gencat.cat/acDAT
Source: duca474.rra.3.dr String found in binary or memory: http://aca-web.gencat.cat/sig/rest/INTERN/CERCADOR/MapServer//query?geometry=&DAT
Source: duca59d.rra.3.dr String found in binary or memory: http://web.gencat.cat/ca/tramits/tramits-temes/Declaracio-de-lUs-i-la-Contaminacio-de-lAigua-DUCA?ca
Source: dataf6d8.rra.3.dr String found in binary or memory: http://www.installengine.com/engine/
Source: duca59d.rra.3.dr String found in binary or memory: https://acanet.gencat.cat/geco/establiments/login.aspInternetgetcontextservice
Source: duca59d.rra.3.dr String found in binary or memory: https://web.gencat.cat/ca/tramits/trDAT
Source: duca59d.rra.3.dr String found in binary or memory: https://web.gencat.cat/ca/tramits/tramits-temes/Peticio-genericahyperlinktourl
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00442FC7 __EH_prolog,SysAllocString,SysFreeString,WritePrivateProfileStringA,GetVersionExA,RegCreateKeyExA,RegQueryValueExA,wsprintfA,lstrcpyA,lstrlenA,RegSetValueExA,RegCloseKey,ExitWindowsEx,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 2_2_00442FC7
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00442FC7 __EH_prolog,SysAllocString,SysFreeString,WritePrivateProfileStringA,GetVersionExA,RegCreateKeyExA,RegQueryValueExA,wsprintfA,lstrcpyA,lstrlenA,RegSetValueExA,RegCloseKey,ExitWindowsEx,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 3_2_00442FC7
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_004124E8 0_2_004124E8
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_0040FD34 0_2_0040FD34
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_0040D3CF 0_2_0040D3CF
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_0040F7D6 0_2_0040F7D6
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_004600B0 2_2_004600B0
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00462482 2_2_00462482
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00454689 2_2_00454689
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00457AA7 2_2_00457AA7
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00454689 3_2_00454689
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_004600B0 3_2_004600B0
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00462482 3_2_00462482
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00457AA7 3_2_00457AA7
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: String function: 0045C1CC appears 1905 times
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: String function: 00416F93 appears 52 times
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: String function: 0045BBB5 appears 114 times
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: String function: 0045BD44 appears 61 times
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: String function: 0045C2F8 appears 44 times
Source: temp.000.1.dr Static PE information: Resource name: PUBLICKEY type: b.out overlay separate pure segmented executable V2.3 186 286 286 386 Large Text Large Data Huge Objects Enabled
Source: mdacf774.rra.3.dr Static PE information: Resource name: RT_RCDATA type: Microsoft Cabinet archive data, many, 7802465 bytes, 16 files, at 0x1830 +A "cabinet.dll" +RA "advpack.dll", flags 0x4, ID 17544, number 1, extra bytes 6144 in head, 261 datablocks, 0x1503 compression
Source: pbo1f9c6.rra.3.dr Static PE information: Resource name: RT_STRING type: DOS executable (COM, 0x8C-variant)
Source: pborf9f5.rra.3.dr Static PE information: Resource name: RT_STRING type: DOS executable (COM, 0x8C-variant)
Source: pbshfa14.rra.3.dr Static PE information: Resource name: RT_STRING type: x86 executable not stripped
Source: pbshfa14.rra.3.dr Static PE information: Resource name: None type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: int_duca.exe, 00000000.00000000.1696070391.000000000041A000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenamestub32i.exe vs int_duca.exe
Source: int_duca.exe Binary or memory string: OriginalFilenamestub32i.exe vs int_duca.exe
Source: int_duca.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: clean9.winEXE@8/340@0/0
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_00402388 GetLastError,FormatMessageA, 0_2_00402388
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00442FC7 __EH_prolog,SysAllocString,SysFreeString,WritePrivateProfileStringA,GetVersionExA,RegCreateKeyExA,RegQueryValueExA,wsprintfA,lstrcpyA,lstrlenA,RegSetValueExA,RegCloseKey,ExitWindowsEx,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 2_2_00442FC7
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00442FC7 __EH_prolog,SysAllocString,SysFreeString,WritePrivateProfileStringA,GetVersionExA,RegCreateKeyExA,RegQueryValueExA,wsprintfA,lstrcpyA,lstrlenA,RegSetValueExA,RegCloseKey,ExitWindowsEx,ExitWindowsEx,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 3_2_00442FC7
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_00405C6C GetModuleHandleA,GetProcAddress,lstrcpyA,lstrcatA,GetDiskFreeSpaceExA,GetLastError,GetDiskFreeSpaceA, 0_2_00405C6C
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Code function: 1_2_00405F89 lstrcpyA,__setjmp3,CoCreateInstance,CoCreateInstance,Sleep,CoCreateInstance, 1_2_00405F89
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_00405416 FindResourceA,LoadResource,LockResource,LocalAlloc,CreatePalette,LocalFree, 0_2_00405416
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\ Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\Public\Desktop\e-DUCA.lnk Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File created: C:\Users\user\AppData\Local\Temp\plfE16B.tmp Jump to behavior
Source: int_duca.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe File read: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.ini Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: duca59d.rra.3.dr Binary or memory string: update d_dcca_capcalera set estat_dcca ='C' where codest =0 and num_dcca =0 :;JK
Source: duca59d.rra.3.dr Binary or memory string: UPDATE d_dcca_preu set coef_innovacio=1 WHERE coef_innovacio IS NULL;
Source: duca59d.rra.3.dr Binary or memory string: select * from ;d_dcca_ciasALTER TABLE d_dcca_cias ADD COLUMN cabal_anuaDAT*
Source: duca59d.rra.3.dr Binary or memory string: select * from ;d_dcca_ciasALTER TABLE d_dcca_cias ADD COLUMN cabal_anual DOUBLEsetsqlselect
Source: Setup.exe String found in binary or memory: -InstallShield
Source: C:\Users\user\Desktop\int_duca.exe File read: C:\Users\user\Desktop\int_duca.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\int_duca.exe "C:\Users\user\Desktop\int_duca.exe"
Source: C:\Users\user\Desktop\int_duca.exe Process created: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe "C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe"
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServer
Source: unknown Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe C:\PROGRA~2\COMMON~1\INSTAL~1\Engine\6\INTEL3~1\IKernel.exe -Embedding
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /REGSERVER
Source: C:\Users\user\Desktop\int_duca.exe Process created: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe "C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServer Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe "C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iKernel.exe" /REGSERVER Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: lz32.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: riched32.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: acspecfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: mscms.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: msi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: coloradapterclient.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acspecfc.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mscms.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coloradapterclient.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acspecfc.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mscms.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coloradapterclient.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acspecfc.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mscms.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ddraw.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: coloradapterclient.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: dciman32.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00020424-0000-0000-C000-000000000046}\InprocServer32 Jump to behavior
Source: e-DUCA.lnk.3.dr LNK file: ..\..\..\int_duca\intduca.exe
Source: C:\Users\user\Desktop\int_duca.exe File written: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.ini Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: int_duca.exe Static file information: File size 26890785 > 1048576
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File opened: c:\int_duca\msvcr100.dll Jump to behavior
Source: Binary string: e:\pb126\BUILD\UNICODE\PBVM126.pdb source: PBVMfb5c.rra.3.dr
Source: Binary string: e:\pb126\BUILD\UNICODE\PBODB126.pdb source: pbodf9e5.rra.3.dr
Source: Binary string: E:\pb126\build\unicode\PBUIS126.pdb source: pbUIfab0.rra.3.dr
Source: Binary string: e:\pb126\BUILD\UNICODE\pbo10126.pdb source: pbo1f9c6.rra.3.dr
Source: Binary string: E:\pb126\build\unicode\PBUIS126.pdb source: pbUIfab0.rra.3.dr
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_00405DF9 LoadLibraryA,GetProcAddress,lstrlenA,lstrlenA,lstrlenA, 0_2_00405DF9
Source: objeee9a.rra.3.dr Static PE information: section name: .orpc
Source: odbcf8fb.rra.3.dr Static PE information: section name: .sdbid
Source: pbshfa14.rra.3.dr Static PE information: section name: .textidx
Source: pbshfa14.rra.3.dr Static PE information: section name: CONST
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_00408928 push eax; ret 0_2_00408946
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_004081B0 push eax; ret 0_2_004081DE
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Code function: 1_2_00407AB0 push eax; ret 1_2_00407ADE
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045A03A pushad ; retn 0046h 2_2_0045A03B
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045C1CC push eax; ret 2_2_0045C1EA
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045C360 push eax; ret 2_2_0045C38E
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00406AAF push esp; ret 2_2_00406ABE
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0041BC2A pushfd ; ret 2_2_0041BC2B
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045C1CC push eax; ret 3_2_0045C1EA
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045C360 push eax; ret 3_2_0045C38E
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0046E458 push ebp; retf 3_2_0046E46C
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00406AAF push esp; ret 3_2_00406ABE
Source: msvcfc85.rra.3.dr Static PE information: section name: .text entropy: 6.909044922675825
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\PBVM126.DLL (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\libjtml.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\libjutils.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\temp.000 Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbtrfaa0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\msvcp100.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbdwe126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\unzip.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pborf9f5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctoree5c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\_IsRes.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\atl1fc56.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\unzif8ac.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbjvf9b6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscreed9.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\intd3c8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbtra126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\zip.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objeee9a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\msvcfc85.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{E66DF05C-F85B-4711-A050-6A0F738964E0}\Setuf6f7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\odbcf8fb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbdpl126.DLL (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbjvm126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\libjf8cc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbacc126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\zipf764.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\isrt.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuseee9a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iuser.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\PBVMfb5c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{E66DF05C-F85B-4711-A050-6A0F738964E0}\Setup.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\msvcfc66.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\mdacf774.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbo1f9c6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbshr126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\isrtf0bd.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbodf9e5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\atl100.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbdwf90a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\intduca.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\nlwnsck.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ctor.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\libjcc.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbUIfab0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\libjf8bc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbo10126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\odbcjt32.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbodb126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\mdac_typ_es.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbdpfc46.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\_IsRf0ec.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbacf90a.rra Jump to dropped file
Source: C:\Users\user\Desktop\int_duca.exe File created: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbshfa14.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\objectps.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\libjf8db.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbUIS126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\nlwnf8eb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\msvcr100.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: c:\int_duca\pbora126.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\temp.000 Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctoree5c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objeee9a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuseee9a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscreed9.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\isrtf0bd.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\_IsRf0ec.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\Program Files (x86)\InstallShield Installation Information\{E66DF05C-F85B-4711-A050-6A0F738964E0}\Setuf6f7.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\zipf764.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\mdacf774.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\unzif8ac.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\libjf8bc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\libjf8cc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\libjf8db.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\nlwnf8eb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\odbcf8fb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbacf90a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbdwf90a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbjvf9b6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbo1f9c6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbodf9e5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pborf9f5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbshfa14.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbtrfaa0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbUIfab0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\PBVMfb5c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\pbdpfc46.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\atl1fc56.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\msvcfc66.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\msvcfc85.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe File created: C:\int_duca\intd3c8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00458426 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 2_2_00458426
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\PBVM126.DLL (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\libjutils.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\libjtml.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbtrfaa0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\msvcp100.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbdwe126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\unzip.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pborf9f5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\_IsRes.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\ctoree5c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\atl1fc56.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\unzif8ac.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbjvf9b6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscreed9.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\intd3c8.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbtra126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\zip.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\objeee9a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\msvcfc85.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\odbcf8fb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbdpl126.DLL (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbjvm126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbacc126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\libjf8cc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\zipf764.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\isrt.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\iuseee9a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\iuser.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\PBVMfb5c.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\msvcfc66.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\mdacf774.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbo1f9c6.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbshr126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\isrtf0bd.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbodf9e5.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\atl100.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbdwf90a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\intduca.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\nlwnsck.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\ctor.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\libjcc.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbUIfab0.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\libjf8bc.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbo10126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\odbcjt32.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbodb126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\IScript\iscript.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\mdac_typ_es.exe (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbdpfc46.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E66DF05C-F85B-4711-A050-6A0F738964E0}\_IsRf0ec.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbacf90a.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\Program Files (x86)\Common Files\InstallShield\engine\6\Intel 32\objectps.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\pbshfa14.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\libjf8db.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbUIS126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: C:\int_duca\nlwnf8eb.rra Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\msvcr100.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Dropped PE file which has not been started: c:\int_duca\pbora126.dll (copy) Jump to dropped file
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe API coverage: 6.0 %
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_004014C2 wsprintfA,FindFirstFileA,FindClose, 0_2_004014C2
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_004050D5 lstrcpyA,lstrcpyA,lstrcatA,lstrcatA,DeleteFileA,DeleteFileA,FindFirstFileA,lstrcpyA,lstrcatA,lstrcatA,lstrcpyA,lstrcatA,DeleteFileA,FindNextFileA,FindClose,lstrcpyA,lstrlenA,RemoveDirectoryA, 0_2_004050D5
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00458620 CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 2_2_00458620
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0042A298 __EH_prolog,FindFirstFileA,FindClose, 2_2_0042A298
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045256E __EH_prolog,FindFirstFileA,FindNextFileA,FindNextFileA,FindNextFileA,FindClose, 2_2_0045256E
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045A9E4 __EH_prolog,FindFirstFileA,FindClose,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose,RemoveDirectoryA,FindClose,DeleteFileA, 2_2_0045A9E4
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0044ACA8 __EH_prolog,FindFirstFileA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044ACA8
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00428EA6 __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose, 2_2_00428EA6
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00429025 __EH_prolog,FindFirstFileA,FileTimeToLocalFileTime,FileTimeToDosDateTime,FindNextFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, 2_2_00429025
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0044B21F __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,SafeArrayCopy,FindClose, 2_2_0044B21F
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00458620 CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 3_2_00458620
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00428EA6 __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose, 3_2_00428EA6
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_00429025 __EH_prolog,FindFirstFileA,FileTimeToLocalFileTime,FileTimeToDosDateTime,FindNextFileA,FindClose,FileTimeToLocalFileTime,FileTimeToDosDateTime, 3_2_00429025
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0042A298 __EH_prolog,FindFirstFileA,FindClose, 3_2_0042A298
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045256E __EH_prolog,FindFirstFileA,FindNextFileA,FindNextFileA,FindNextFileA,FindClose, 3_2_0045256E
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045A9E4 __EH_prolog,FindFirstFileA,FindClose,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,FindClose,RemoveDirectoryA,FindClose,DeleteFileA, 3_2_0045A9E4
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0044ACA8 __EH_prolog,FindFirstFileA,FindNextFileA,SafeArrayCopy,FindClose, 3_2_0044ACA8
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0044B21F __EH_prolog,FindFirstFileA,lstrcmpA,lstrcmpA,lstrcmpA,FindNextFileA,SafeArrayCopy,FindClose, 3_2_0044B21F
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\Temp\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\Desktop\int_duca.exe File opened: C:\Users\user\ Jump to behavior
Source: int_duca.exe Binary or memory string: qEMutA
Source: IKernel.exe, 00000003.00000002.1841334437.0000000003BC0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: IKernel.exe, 00000002.00000002.1727003885.00000000008AE000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllL
Source: int_duca.exe, 00000000.00000002.1903812038.00000000023A0000.00000004.00001000.00020000.00000000.sdmp Binary or memory string: ilva76\OneDrive - DXC Production\Desktop\VMware-Compartida\aca_eDuca_4.17\InstallShield\eDuca_con_Evolutivo4_17\Installshield package\02 - projecte - nou_v.4.5\Media\COMPLET\Disk Images
Source: IKernel.exe, 00000003.00000002.1837603773.00000000005EF000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000004.00000002.1733998599.0000000000574000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\AppData\Local\Temp\pftE20A.tmp\Disk1\Setup.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_00405DF9 LoadLibraryA,GetProcAddress,lstrlenA,lstrlenA,lstrlenA, 0_2_00405DF9
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_004061FB GetProcessHeap,HeapAlloc, 0_2_004061FB
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_0040CC52 SetUnhandledExceptionFilter, 0_2_0040CC52
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_0040CC64 SetUnhandledExceptionFilter, 0_2_0040CC64
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045E8EA SetUnhandledExceptionFilter, 2_2_0045E8EA
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045E8FC SetUnhandledExceptionFilter, 2_2_0045E8FC
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045E8EA SetUnhandledExceptionFilter, 3_2_0045E8EA
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 3_2_0045E8FC SetUnhandledExceptionFilter, 3_2_0045E8FC
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_0045B905 GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,GetCurrentProcess,OpenProcessToken,GetLastError,GetTokenInformation,GetTokenInformation,GetLastError,GetTokenInformation,AllocateAndInitializeSid,EqualSid,FreeSid, 2_2_0045B905
Source: IKernel.exe Binary or memory string: OPTYPE_PROGMAN
Source: Setup.exe, 00000001.00000002.1829545321.00000000007ED000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.1724138543.000000000078C000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.1724064024.0000000000784000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN_FIELDS
Source: Setup.exe, 00000001.00000002.1829545321.00000000007ED000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.1724138543.000000000078C000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.1724064024.0000000000784000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN_FIELDS%H
Source: IKernel.exe, 00000003.00000002.1837702067.00000000005FC000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.1836411010.00000000005FB000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.1835835192.00000000005F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: BOPTYPE_PROGMAN
Source: IKernel.exe, 00000003.00000002.1837702067.00000000005FC000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.1836411010.00000000005FB000.00000004.00000020.00020000.00000000.sdmp, IKernel.exe, 00000003.00000003.1835835192.00000000005F1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: B`OPTYPE_PROGMAN
Source: IKernel.exe, 00000002.00000002.1726601366.0000000000482000.00000008.00000001.01000000.00000007.sdmp, IKernel.exe, 00000002.00000000.1724761190.0000000000482000.00000008.00000001.01000000.00000007.sdmp, IKernel.exe, 00000003.00000000.1727866716.0000000000482000.00000008.00000001.01000000.00000007.sdmp Binary or memory string: ISGlobalOpTypesTableISLOG_VERSION_INFOOPTYPE_FILEOPTYPE_SHELLOPTYPE_REGISTRYOPTYPE_PROGMANOPTYPE_INIOPTYPE_FILEREGISLOGDB_USER_PROPERTIES
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe Code function: 2_2_00429477 GetSystemTime,SystemTimeToFileTime,SystemTimeToFileTime,SystemTimeToFileTime, 2_2_00429477
Source: C:\Users\user\Desktop\int_duca.exe Code function: 0_2_00408947 EntryPoint,GetVersion,GetCommandLineA,GetStartupInfoA,GetModuleHandleA, 0_2_00408947
No contacted IP infos