Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
build.msi

Overview

General Information

Sample name:build.msi
Analysis ID:1575142
MD5:69e06e5438dbf3a22fb6ef3315ffa43d
SHA1:78dbc3e5e0a5e3df39011948755ef02429768ef1
SHA256:27adf3443ba52e71223895bf961f7116bc0ce95fb639f970dde4df392ed0adfb
Tags:msiuser-smica83
Infos:

Detection

Score:68
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus detection for URL or domain
Suricata IDS alerts for network traffic
Bypasses PowerShell execution policy
Sigma detected: Script Interpreter Execution From Suspicious Folder
Sigma detected: Suspicious Script Execution From Temp Folder
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: Change PowerShell Policies to an Insecure Level
Sigma detected: Msiexec Initiated Connection
Sigma detected: Suspicious MsiExec Embedding Parent
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

  • System is w10x64
  • msiexec.exe (PID: 6752 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\build.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 6832 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 6936 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82 MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • powershell.exe (PID: 6308 cmdline: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue." MD5: C32CA4ACFCC635EC1EA6ED8A34DF5FAC)
        • conhost.exe (PID: 6328 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems): Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 6936, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 6308, ProcessName: powershell.exe
Source: Process startedAuthor: Florian Roth (Nextron Systems), Max Altgelt (Nextron Systems), Tim Shelton: Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 6936, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 6308, ProcessName: powershell.exe
Source: Process startedAuthor: frack113: Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 6936, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 6308, ProcessName: powershell.exe
Source: Network ConnectionAuthor: frack113: Data: DestinationIp: 104.131.68.180, DestinationIsIpv6: false, DestinationPort: 443, EventID: 3, Image: C:\Windows\SysWOW64\msiexec.exe, Initiated: true, ProcessId: 6936, Protocol: tcp, SourceIp: 192.168.2.12, SourceIsIpv6: false, SourcePort: 49711
Source: Process startedAuthor: frack113: Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 6936, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 6308, ProcessName: powershell.exe
Source: Process startedAuthor: Roberto Rodriguez @Cyb3rWard0g (rule), oscd.community (improvements): Data: Command: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, NewProcessName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, OriginalFileName: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 6936, ParentProcessName: msiexec.exe, ProcessCommandLine: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue.", ProcessId: 6308, ProcessName: powershell.exe
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-14T14:18:05.281226+010028292021A Network Trojan was detected192.168.2.1249711104.131.68.180443TCP
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-12-14T14:18:05.275559+010028225211Domain Observed Used for C2 Detected104.131.68.180443192.168.2.1249711TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: https://puta-key.com/licenseUser.phpxAvira URL Cloud: Label: malware
Source: https://puta-key.com/licenseUser.phpAvira URL Cloud: Label: malware
Source: unknownHTTPS traffic detected: 104.131.68.180:443 -> 192.168.2.12:49711 version: TLS 1.2
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdb source: build.msi, 5cd3be.msi.2.dr
Source: Binary string: C:\jslave\ws\release-release-11.2\CEP\builds\native\binaries\windows\x64\Release\CEPHtmlEngine\CEPHtmlEngine.pdbyp source: CEPHtmlEngine.exe.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdbk source: build.msi, MSICC5.tmp.2.dr, 5cd3be.msi.2.dr
Source: Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: api-ms-win-core-sysinfo-l1-1-0.dll.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdbj source: build.msi, 5cd3be.msi.2.dr
Source: Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: api-ms-win-crt-stdio-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: api-ms-win-crt-conio-l1-1-0.dll.2.dr
Source: Binary string: libGLESv2.dll.pdb source: libGLESv2.dll.2.dr
Source: Binary string: C:\jslave\ws\release-release-11.2\CEP\builds\native\binaries\windows\x64\Release\CEPHtmlEngine\CEPHtmlEngine.pdb source: CEPHtmlEngine.exe.2.dr
Source: Binary string: api-ms-win-crt-math-l1-1-0.pdb source: api-ms-win-crt-math-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-core-util-l1-1-0.pdb source: api-ms-win-core-util-l1-1-0.dll.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdb source: build.msi, MSICC5.tmp.2.dr, 5cd3be.msi.2.dr
Source: Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: api-ms-win-crt-environment-l1-1-0.dll.2.dr
Source: Binary string: D:\git-sdk-64-build-installers\usr\src\MINGW-packages\mingw-w64-git\src\git\git-bash.pdb source: git-bash.exe.2.dr
Source: Binary string: d:\a01\_work\12\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: vcruntime140.dll.2.dr
Source: Binary string: api-ms-win-crt-private-l1-1-0.pdb source: api-ms-win-crt-private-l1-1-0.dll.2.dr
Source: Binary string: oneds.dll.pdb source: oneds.dll.2.dr
Source: Binary string: d:\a01\_work\12\s\\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: msvcp140.dll.2.dr
Source: Binary string: api-ms-win-core-profile-l1-1-0.pdb source: api-ms-win-core-profile-l1-1-0.dll.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: build.msi, MSIDC39.tmp.2.dr, MSIDCF8.tmp.2.dr, MSIDC69.tmp.2.dr, 5cd3be.msi.2.dr
Source: Binary string: libGLESv2.dll.pdb+pZ o source: libGLESv2.dll.2.dr
Source: Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: api-ms-win-crt-heap-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-crt-time-l1-1-0.pdb source: api-ms-win-crt-time-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-crt-string-l1-1-0.pdb source: api-ms-win-crt-string-l1-1-0.dll.2.dr
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

Networking

barindex
Source: Network trafficSuricata IDS: 2822521 - Severity 1 - ETPRO MALWARE Malicious SSL Certificate Detected (Linux.Rex Scanner) : 104.131.68.180:443 -> 192.168.2.12:49711
Source: Network trafficSuricata IDS: 2829202 - Severity 1 - ETPRO MALWARE MSIL/Zbrain PUP/Stealer Installer UA : 192.168.2.12:49711 -> 104.131.68.180:443
Source: Joe Sandbox ViewASN Name: DIGITALOCEAN-ASNUS DIGITALOCEAN-ASNUS
Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: puta-key.com
Source: unknownHTTP traffic detected: POST /licenseUser.php HTTP/1.1Content-Type: application/x-www-form-urlencoded; charset=utf-8User-Agent: AdvancedInstallerHost: puta-key.comContent-Length: 37Cache-Control: no-cache
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/1452
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/1452expand_integer_pow_expressionsThe
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/2152
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/2152skip_vs_constant_register_zeroIn
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/3246
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/3246allow_clear_for_robust_resource_initSome
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/3682
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/3682GL_USES_FRAG_COLORGL_USES_FRAG_DATA_SECONDARY_COLORGL_USES_SECONDARGL_USES_F
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/5007
Source: libGLESv2.dll.2.drString found in binary or memory: http://anglebug.com/5007disable_anisotropic_filteringDisable
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://apache.org/xml/UnknownNSUCS40UCS-40UCS_41UTF-32ISO-10646-UCS-4UCS-4
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://apache.org/xml/messages/XML4CErrors#FIXEDEBCDIC-CP-USIBM037IBM1047IBM1140IBM01140CCSID01140CP
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://apache.org/xml/messages/XMLDOMMsgxml
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://apache.org/xml/messages/XMLValidityWINDOWS-1252XERCES-XMLCH
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertEVCodeSigningCA-SHA2.crt0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertHighAssuranceEVRootCA.crt0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: libGLESv2.dll.2.drString found in binary or memory: http://crbug.com/398694
Source: libGLESv2.dll.2.drString found in binary or memory: http://crbug.com/398694Disable
Source: libGLESv2.dll.2.drString found in binary or memory: http://crbug.com/941620
Source: libGLESv2.dll.2.drString found in binary or memory: http://crbug.com/941620allow_translate_uniform_block_to_structured_bufferThere
Source: git-bash.exe.2.drString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
Source: git-bash.exe.2.drString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0V
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://crl.globalsign.com/gsgccr45codesignca2020.crl0
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://crl.globalsign.com/root-r3.crl0G
Source: powershell.exe, 00000007.00000002.2509088230.0000000007039000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.microsoft
Source: git-bash.exe.2.drString found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
Source: git-bash.exe.2.drString found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
Source: git-bash.exe.2.drString found in binary or memory: http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0t
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl3.digicert.com/EVCodeSigningSHA2-g1.crl07
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl4.digicert.com/DigiCertHighAssuranceEVRootCA.crl0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl4.digicert.com/EVCodeSigningSHA2-g1.crl0K
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: git-bash.exe.2.drString found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
Source: git-bash.exe.2.drString found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
Source: git-bash.exe.2.drString found in binary or memory: http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#
Source: libstream_out_chromaprint_plugin.dll.2.drString found in binary or memory: http://gcc.gnu.org/bugs.html):
Source: powershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://nuget.org/NuGet.exe
Source: git-bash.exe.2.drString found in binary or memory: http://ocsp.comodoca.com0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://ocsp.digicert.com0
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://ocsp.digicert.com0A
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, CEPHtmlEngine.exe.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://ocsp.digicert.com0C
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://ocsp.digicert.com0H
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://ocsp.digicert.com0I
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://ocsp.digicert.com0O
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://ocsp.digicert.com0X
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://ocsp.globalsign.com/gsgccr45codesignca20200V
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://ocsp.globalsign.com/rootr30;
Source: git-bash.exe.2.drString found in binary or memory: http://ocsp.sectigo.com0
Source: powershell.exe, 00000007.00000002.2504293590.00000000049F6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://pesterbdd.com/images/Pester.png
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://relaxng.org/ns/structure/1.0
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://s.symcb.com/universal-root.crl0
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://s.symcd.com06
Source: powershell.exe, 00000007.00000002.2504293590.00000000048A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45codesignca2020.crt0=
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://secure.globalsign.com/cacert/root-r3.crt06
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://stackoverflow.com/questions/14695988/dom-exception-5-invalid-character-error-on-valid-base64-
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: http://ts-ocsp.ws.symantec.com0;
Source: powershell.exe, 00000007.00000002.2504293590.00000000049F6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0.html
Source: libstream_out_standard_plugin.dll.2.dr, libstream_out_setid_plugin.dll.2.dr, libstream_out_display_plugin.dll.2.dr, axvlc.dll.2.dr, libstream_out_transcode_plugin.dll.2.dr, libstream_out_gather_plugin.dll.2.dr, libstream_out_es_plugin.dll.2.dr, libstream_out_record_plugin.dll.2.dr, CEPHtmlEngine.exe.2.dr, npvlc.dll.2.dr, libstream_out_duplicate_plugin.dll.2.dr, libstream_out_bridge_plugin.dll.2.dr, libstream_out_chromaprint_plugin.dll.2.dr, libstream_out_autodel_plugin.dll.2.dr, libstream_out_smem_plugin.dll.2.dr, libstream_out_mosaic_bridge_plugin.dll.2.drString found in binary or memory: http://www.digicert.com/CPS0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://www.digicert.com/ssl-cps-repository.htm0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://www.domain.dom/ca-crl.pem
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://www.info-zip.org/
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: http://www.info-zip.org/zip-bug.html;
Source: npvlc.dll.2.drString found in binary or memory: http://www.videolan.org/vlc/
Source: powershell.exe, 00000007.00000002.2504293590.00000000048A1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://aka.ms/pscore6
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: https://cc-api-data-stage.adobe.io/ingest/
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: https://cc-api-data.adobe.io/ingest/
Source: libGLESv2.dll.2.drString found in binary or memory: https://chromium.googlesource.com/angle/angle/
Source: powershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/
Source: powershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/Icon
Source: powershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://contoso.com/License
Source: libGLESv2.dll.2.drString found in binary or memory: https://crbug.com/593024
Source: libGLESv2.dll.2.drString found in binary or memory: https://crbug.com/593024select_view_in_geometry_shaderThe
Source: libGLESv2.dll.2.drString found in binary or memory: https://crbug.com/650547
Source: libGLESv2.dll.2.drString found in binary or memory: https://crbug.com/650547call_clear_twiceUsing
Source: libGLESv2.dll.2.drString found in binary or memory: https://crbug.com/655534
Source: libGLESv2.dll.2.drString found in binary or memory: https://crbug.com/655534use_system_memory_for_constant_buffersCopying
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: https://d.symcb.com/cps0%
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: https://d.symcb.com/rpa0
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: https://d.symcb.com/rpa0.
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: https://github.com
Source: powershell.exe, 00000007.00000002.2504293590.00000000049F6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://github.com/Pester/Pester
Source: powershell.exe, 00000007.00000002.2504293590.00000000050CA000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://go.micro
Source: powershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://nuget.org/nuget.exe
Source: build.msi, 5cd3be.msi.2.drString found in binary or memory: https://puta-key.com/licenseUser.phpx
Source: git-bash.exe.2.drString found in binary or memory: https://sectigo.com/CPS0
Source: libstream_out_chromaprint_plugin.dll.2.drString found in binary or memory: https://streams.videolan.org/upload/
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: https://www.digicert.com/CPS0
Source: smartgit-updater.exe.2.dr, smartgit.exe.2.drString found in binary or memory: https://www.globalsign.com/repository/0
Source: CEPHtmlEngine.exe.2.drString found in binary or memory: https://www.openssl.org/docs/faq.html
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49711
Source: unknownNetwork traffic detected: HTTP traffic on port 49711 -> 443
Source: unknownHTTPS traffic detected: 104.131.68.180:443 -> 192.168.2.12:49711 version: TLS 1.2
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5cd3bb.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDB6C.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDBEA.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDC39.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDC69.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDCC8.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDCF8.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIFB3F.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{0CF3B4A2-1F02-44A2-B594-48889D7BF089}Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICA5.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICC5.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5cd3be.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\5cd3be.msiJump to behavior
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSIDB6C.tmpJump to behavior
Source: CEPHtmlEngine.exe.2.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: npvlc.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_mosaic_bridge_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_rtp_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: chrome_elf.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libvlccore.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: Qt5Gui.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_autodel_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: axvlc.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_chromecast_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_dummy_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_transcode_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_record_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_bridge_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_gather_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: Qt5Core.dll.2.drStatic PE information: Number of sections : 13 > 10
Source: libstream_out_duplicate_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_smem_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_stats_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_display_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: git-bash.exe.2.drStatic PE information: Number of sections : 13 > 10
Source: libstream_out_cycle_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_setid_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_standard_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_es_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_description_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: libstream_out_chromaprint_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: git-cmd.exe.2.drStatic PE information: Number of sections : 13 > 10
Source: libstream_out_delay_plugin.dll.2.drStatic PE information: Number of sections : 12 > 10
Source: api-ms-win-crt-multibyte-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-filesystem-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-convert-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-math-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-string-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-heap-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-conio-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-runtime-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-rtlsupport-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-environment-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-process-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-sysinfo-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-private-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-stdio-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-util-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-synch-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-timezone-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-string-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-synch-l1-2-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-core-profile-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-locale-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: api-ms-win-crt-time-l1-1-0.dll.2.drStatic PE information: No import functions for PE file found
Source: build.msiBinary or memory string: OriginalFilenameAICustAct.dllF vs build.msi
Source: build.msiBinary or memory string: OriginalFilenameDataUploader.dllF vs build.msi
Source: build.msiBinary or memory string: OriginalFilenamePowerShellScriptLauncher.dllF vs build.msi
Source: Qt5Core.dll.2.drStatic PE information: Section: /4 ZLIB complexity 0.9890509136652542
Source: classification engineClassification label: mal68.evad.winMSI@7/146@2/1
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\CML17AA.tmpJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeMutant created: NULL
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6328:120:WilError_03
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\TEMP\~DF55F28CB966FD39D7.TMPJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\TenantRestrictions\PayloadJump to behavior
Source: oneds.dll.2.drBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
Source: oneds.dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_docsize'(docid INTEGER PRIMARY KEY, size BLOB);
Source: oneds.dll.2.drBinary or memory string: CREATE TABLE IF NOT EXISTS %Q.'%q_stat'(id INTEGER PRIMARY KEY, value BLOB);
Source: oneds.dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_segdir'(level INTEGER,idx INTEGER,start_block INTEGER,leaves_end_block INTEGER,end_block INTEGER,root BLOB,PRIMARY KEY(level, idx));
Source: oneds.dll.2.drBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
Source: oneds.dll.2.drBinary or memory string: CREATE TABLE %Q.'%q_segments'(blockid INTEGER PRIMARY KEY, block BLOB);
Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\build.msi"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."Jump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.ui.immersive.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: samcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: atlthunk.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wininet.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: schannel.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: dpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: atl.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: version.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wldp.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: amsi.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: userenv.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: profapi.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: msisip.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: wshext.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: appxsip.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: opcservices.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: secur32.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeSection loaded: uxtheme.dllJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
Source: build.msiStatic file information: File size 51524608 > 1048576
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdb source: build.msi, 5cd3be.msi.2.dr
Source: Binary string: C:\jslave\ws\release-release-11.2\CEP\builds\native\binaries\windows\x64\Release\CEPHtmlEngine\CEPHtmlEngine.pdbyp source: CEPHtmlEngine.exe.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdbk source: build.msi, MSICC5.tmp.2.dr, 5cd3be.msi.2.dr
Source: Binary string: api-ms-win-core-sysinfo-l1-1-0.pdb source: api-ms-win-core-sysinfo-l1-1-0.dll.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\DataUploader.pdbj source: build.msi, 5cd3be.msi.2.dr
Source: Binary string: api-ms-win-crt-stdio-l1-1-0.pdb source: api-ms-win-crt-stdio-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-crt-conio-l1-1-0.pdb source: api-ms-win-crt-conio-l1-1-0.dll.2.dr
Source: Binary string: libGLESv2.dll.pdb source: libGLESv2.dll.2.dr
Source: Binary string: C:\jslave\ws\release-release-11.2\CEP\builds\native\binaries\windows\x64\Release\CEPHtmlEngine\CEPHtmlEngine.pdb source: CEPHtmlEngine.exe.2.dr
Source: Binary string: api-ms-win-crt-math-l1-1-0.pdb source: api-ms-win-crt-math-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-core-util-l1-1-0.pdb source: api-ms-win-core-util-l1-1-0.dll.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\PowerShellScriptLauncher.pdb source: build.msi, MSICC5.tmp.2.dr, 5cd3be.msi.2.dr
Source: Binary string: api-ms-win-crt-environment-l1-1-0.pdb source: api-ms-win-crt-environment-l1-1-0.dll.2.dr
Source: Binary string: D:\git-sdk-64-build-installers\usr\src\MINGW-packages\mingw-w64-git\src\git\git-bash.pdb source: git-bash.exe.2.dr
Source: Binary string: d:\a01\_work\12\s\\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: vcruntime140.dll.2.dr
Source: Binary string: api-ms-win-crt-private-l1-1-0.pdb source: api-ms-win-crt-private-l1-1-0.dll.2.dr
Source: Binary string: oneds.dll.pdb source: oneds.dll.2.dr
Source: Binary string: d:\a01\_work\12\s\\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: msvcp140.dll.2.dr
Source: Binary string: api-ms-win-core-profile-l1-1-0.pdb source: api-ms-win-core-profile-l1-1-0.dll.2.dr
Source: Binary string: C:\ReleaseAI\win\Release\custact\x86\AICustAct.pdb source: build.msi, MSIDC39.tmp.2.dr, MSIDCF8.tmp.2.dr, MSIDC69.tmp.2.dr, 5cd3be.msi.2.dr
Source: Binary string: libGLESv2.dll.pdb+pZ o source: libGLESv2.dll.2.dr
Source: Binary string: api-ms-win-crt-heap-l1-1-0.pdb source: api-ms-win-crt-heap-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-crt-time-l1-1-0.pdb source: api-ms-win-crt-time-l1-1-0.dll.2.dr
Source: Binary string: api-ms-win-crt-string-l1-1-0.pdb source: api-ms-win-crt-string-l1-1-0.dll.2.dr
Source: api-ms-win-core-sysinfo-l1-1-0.dll.2.drStatic PE information: 0x89DFC772 [Mon Apr 20 12:02:58 2043 UTC]
Source: axvlc.dll.2.drStatic PE information: section name: .buildid
Source: axvlc.dll.2.drStatic PE information: section name: /4
Source: libvlccore.dll.2.drStatic PE information: section name: .buildid
Source: libvlccore.dll.2.drStatic PE information: section name: /4
Source: npvlc.dll.2.drStatic PE information: section name: .buildid
Source: npvlc.dll.2.drStatic PE information: section name: /4
Source: libstream_out_autodel_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_autodel_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_bridge_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_bridge_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_chromaprint_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_chromaprint_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_chromecast_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_chromecast_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_cycle_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_cycle_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_delay_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_delay_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_description_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_description_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_display_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_display_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_dummy_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_dummy_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_duplicate_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_duplicate_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_es_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_es_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_gather_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_gather_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_mosaic_bridge_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_mosaic_bridge_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_record_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_record_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_rtp_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_rtp_plugin.dll.2.drStatic PE information: section name: /4
Source: chrome_elf.dll.2.drStatic PE information: section name: .00cfg
Source: chrome_elf.dll.2.drStatic PE information: section name: .crthunk
Source: chrome_elf.dll.2.drStatic PE information: section name: .gehcont
Source: chrome_elf.dll.2.drStatic PE information: section name: .oldntma
Source: chrome_elf.dll.2.drStatic PE information: section name: CPADinfo
Source: UnRar.exe.2.drStatic PE information: section name: _RDATA
Source: libstream_out_setid_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_setid_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_smem_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_smem_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_standard_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_standard_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_stats_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_stats_plugin.dll.2.drStatic PE information: section name: /4
Source: libstream_out_transcode_plugin.dll.2.drStatic PE information: section name: .buildid
Source: libstream_out_transcode_plugin.dll.2.drStatic PE information: section name: /4
Source: oneds.dll.2.drStatic PE information: section name: .00cfg
Source: oneds.dll.2.drStatic PE information: section name: .retplne
Source: oneds.dll.2.drStatic PE information: section name: _RDATA
Source: libGLESv2.dll.2.drStatic PE information: section name: .00cfg
Source: libGLESv2.dll.2.drStatic PE information: section name: _RDATA
Source: Qt5Core.dll.2.drStatic PE information: section name: /4
Source: Qt5Core.dll.2.drStatic PE information: section name: /20
Source: Qt5Core.dll.2.drStatic PE information: section name: /30
Source: Qt5Gui.dll.2.drStatic PE information: section name: /4
Source: Qt5Gui.dll.2.drStatic PE information: section name: /14
Source: vcruntime140.dll.2.drStatic PE information: section name: _RDATA
Source: smartgit-updater.exe.2.drStatic PE information: section name: .xdata
Source: git-bash.exe.2.drStatic PE information: section name: .xdata
Source: git-bash.exe.2.drStatic PE information: section name: .debug
Source: git-cmd.exe.2.drStatic PE information: section name: .xdata
Source: git-cmd.exe.2.drStatic PE information: section name: .debug
Source: MSICC5.tmp.2.drStatic PE information: section name: .fptable
Source: MSIDB6C.tmp.2.drStatic PE information: section name: .fptable
Source: MSIDBEA.tmp.2.drStatic PE information: section name: .fptable
Source: MSIDC39.tmp.2.drStatic PE information: section name: .fptable
Source: MSIDC69.tmp.2.drStatic PE information: section name: .fptable
Source: MSIDCC8.tmp.2.drStatic PE information: section name: .fptable
Source: MSIDCF8.tmp.2.drStatic PE information: section name: .fptable
Source: MSIFB3F.tmp.2.drStatic PE information: section name: .fptable
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 7_2_02C23EBA push eax; ret 7_2_02C23EC9
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 7_2_02C23FE5 push esp; iretd 7_2_02C24059
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeCode function: 7_2_02C23FA5 push esp; retf 7_2_02C23FC9
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-sysinfo-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDCC8.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDBEA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\msvcp140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-timezone-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICC5.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Gui.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-cmd.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-math-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-stdio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDC69.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-util-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140_1.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-locale-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\oneds.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libGLESv2.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_dummy_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-time-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-process-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_bridge_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\axvlc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\npvlc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_smem_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-filesystem-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_mosaic_bridge_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_delay_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_transcode_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-conio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromecast_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-rtlsupport-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_gather_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDCF8.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIFB3F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-environment-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-private-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-multibyte-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-convert-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\jvm.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_standard_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDC39.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\chrome_elf.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDB6C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\UnRar.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_autodel_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgitc.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_record_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_display_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromaprint_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_rtp_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-heap-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmlEngine.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_stats_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_description_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_es_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-bash.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\libvlccore.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_setid_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit-updater.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-profile-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_cycle_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-runtime-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_duplicate_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDCC8.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDBEA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDCF8.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIFB3F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICC5.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDC69.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDC39.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDB6C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 3001Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeWindow / User API: threadDelayed 1644Jump to behavior
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-sysinfo-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIDCC8.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIDBEA.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\msvcp140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-timezone-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSICC5.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Gui.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-cmd.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-math-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-stdio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIDC69.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-util-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-2-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140_1.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-locale-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-string-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\oneds.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libGLESv2.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_dummy_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-time-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-process-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_bridge_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\axvlc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_smem_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\npvlc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-filesystem-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_mosaic_bridge_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_delay_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_transcode_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-conio-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-rtlsupport-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromecast_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Core.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_gather_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIDCF8.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIFB3F.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-environment-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-private-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-multibyte-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-convert-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\jvm.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_standard_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIDC39.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\chrome_elf.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIDB6C.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\UnRar.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_autodel_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgitc.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_record_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_display_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromaprint_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_rtp_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmlEngine.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_stats_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-heap-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_description_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_es_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-bash.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\libvlccore.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_setid_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit-updater.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-profile-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-runtime-l1-1-0.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_cycle_plugin.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_duplicate_plugin.dllJump to dropped file
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5744Thread sleep count: 3001 > 30Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5516Thread sleep count: 1644 > 30Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5784Thread sleep time: -2767011611056431s >= -30000sJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe TID: 5848Thread sleep time: -922337203685477s >= -30000sJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: jdk.attach.jmod.2.drBinary or memory string: n/QBclasses/sun/tools/attach/VirtualMachineImpl$PipedInputStream.class
Source: jdk.attach.jmod.2.drBinary or memory string: Lclasses/sun/tools/attach/VirtualMachineImpl.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: classes/com/sun/tools/attach/VirtualMachineDescriptor.class
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/VirtualMachineImpl$PipedInputStream.class
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/HotSpotAttachProvider$HotSpotVirtualMachineDescriptor.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: n/QTclasses/sun/tools/attach/HotSpotAttachProvider$HotSpotVirtualMachineDescriptor.class
Source: jdk.attach.jmod.2.drBinary or memory string: B4Iclasses/sun/tools/attach/VirtualMachineImpl$PipedInputStream.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: n/Q;classes/com/sun/tools/attach/VirtualMachineDescriptor.class
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/VirtualMachineImpl.class
Source: jdk.attach.jmod.2.drBinary or memory string: classes/com/sun/tools/attach/VirtualMachine.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/HotSpotVirtualMachine.class
Source: jdk.attach.jmod.2.drBinary or memory string: n/Q1classes/com/sun/tools/attach/VirtualMachine.class
Source: jdk.attach.jmod.2.drBinary or memory string: (classes/sun/tools/attach/HotSpotAttachProvider$HotSpotVirtualMachineDescriptor.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/HotSpotAttachProvider$HotSpotVirtualMachineDescriptor.class
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/HotSpotVirtualMachine.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: n/Q4classes/sun/tools/attach/HotSpotVirtualMachine.class
Source: jdk.attach.jmod.2.drBinary or memory string: T-4G3classes/sun/tools/attach/HotSpotVirtualMachine.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: classes/com/sun/tools/attach/VirtualMachine.class
Source: jdk.attach.jmod.2.drBinary or memory string: n/Q1classes/sun/tools/attach/VirtualMachineImpl.class
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/VirtualMachineImpl.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: classes/com/sun/tools/attach/VirtualMachineDescriptor.classPK
Source: jdk.attach.jmod.2.drBinary or memory string: classes/sun/tools/attach/VirtualMachineImpl$PipedInputStream.classPK
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeProcess token adjusted: DebugJump to behavior

HIPS / PFW / Operating System Protection Evasion

barindex
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe -noprofile -noninteractive -executionpolicy bypass -file "c:\users\user\appdata\local\temp\pssd9b.ps1" -propfile "c:\users\user\appdata\local\temp\msid88.txt" -scriptfile "c:\users\user\appdata\local\temp\scrd89.ps1" -scriptargsfile "c:\users\user\appdata\local\temp\scrd8a.txt" -propsep " :<->: " -linesep " <<:>> " -testprefix "_testvalue."
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe -noprofile -noninteractive -executionpolicy bypass -file "c:\users\user\appdata\local\temp\pssd9b.ps1" -propfile "c:\users\user\appdata\local\temp\msid88.txt" -scriptfile "c:\users\user\appdata\local\temp\scrd89.ps1" -scriptargsfile "c:\users\user\appdata\local\temp\scrd8a.txt" -propsep " :<->: " -linesep " <<:>> " -testprefix "_testvalue."Jump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Data\v4.0_4.0.0.0__b77a5c561934e089\System.Data.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\ VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\System32\CatRoot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Microsoft-Windows-Client-Features-Package0313~31bf3856ad364e35~amd64~~10.0.19041.1949.cat VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.PowerShell.Commands.Management\v4.0_3.0.0.0__31bf3856ad364e35\Microsoft.PowerShell.Commands.Management.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceProcess\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformationJump to behavior
Source: C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
1
Command and Scripting Interpreter
1
DLL Side-Loading
11
Process Injection
21
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local System1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts1
PowerShell
Boot or Logon Initialization Scripts1
DLL Side-Loading
21
Virtualization/Sandbox Evasion
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable Media2
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)11
Process Injection
Security Account Manager21
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive3
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS1
Application Window Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Software Packing
LSA Secrets11
Peripheral Device Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Timestomp
Cached Domain Credentials12
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
DLL Side-Loading
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
File Deletion
Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
build.msi0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmlEngine.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Core.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Gui.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\UnRar.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-profile-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-rtlsupport-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-string-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-synch-l1-2-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-sysinfo-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-timezone-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-core-util-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-conio-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-convert-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-environment-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-filesystem-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-heap-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-locale-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-math-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-multibyte-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-private-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-process-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-runtime-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-stdio-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-string-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\api-ms-win-crt-time-l1-1-0.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\axvlc.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\chrome_elf.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-bash.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\git-cmd.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\libvlccore.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\msvcp140.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\npvlc.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit-updater.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgit.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\smartgitc.exe0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\jvm.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libGLESv2.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_autodel_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_bridge_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromaprint_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_chromecast_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_cycle_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_delay_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_description_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_display_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_dummy_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_duplicate_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_es_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_gather_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_mosaic_bridge_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_record_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_rtp_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_setid_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_smem_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_standard_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_stats_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\libstream_out_transcode_plugin.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\stream_out\oneds.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140.dll0%ReversingLabs
C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\vcruntime140_1.dll0%ReversingLabs
C:\Windows\Installer\MSICC5.tmp0%ReversingLabs
C:\Windows\Installer\MSIDB6C.tmp0%ReversingLabs
C:\Windows\Installer\MSIDBEA.tmp0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://anglebug.com/21520%Avira URL Cloudsafe
https://crbug.com/5930240%Avira URL Cloudsafe
http://crbug.com/398694Disable0%Avira URL Cloudsafe
https://crbug.com/6505470%Avira URL Cloudsafe
http://crbug.com/9416200%Avira URL Cloudsafe
http://anglebug.com/32460%Avira URL Cloudsafe
http://www.domain.dom/ca-crl.pem0%Avira URL Cloudsafe
http://crbug.com/3986940%Avira URL Cloudsafe
https://puta-key.com/licenseUser.phpx100%Avira URL Cloudmalware
http://anglebug.com/36820%Avira URL Cloudsafe
https://puta-key.com/licenseUser.php100%Avira URL Cloudmalware
https://crbug.com/6555340%Avira URL Cloudsafe
http://anglebug.com/14520%Avira URL Cloudsafe
http://anglebug.com/3682GL_USES_FRAG_COLORGL_USES_FRAG_DATA_SECONDARY_COLORGL_USES_SECONDARGL_USES_F0%Avira URL Cloudsafe
NameIPActiveMaliciousAntivirus DetectionReputation
puta-key.com
104.131.68.180
truetrue
    unknown
    NameMaliciousAntivirus DetectionReputation
    https://puta-key.com/licenseUser.phptrue
    • Avira URL Cloud: malware
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    http://crbug.com/398694DisablelibGLESv2.dll.2.drfalse
    • Avira URL Cloud: safe
    unknown
    http://crbug.com/941620allow_translate_uniform_block_to_structured_bufferTherelibGLESv2.dll.2.drfalse
      high
      https://crbug.com/650547call_clear_twiceUsinglibGLESv2.dll.2.drfalse
        high
        http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0git-bash.exe.2.drfalse
          high
          http://ocsp.sectigo.com0git-bash.exe.2.drfalse
            high
            http://crl.microsoftpowershell.exe, 00000007.00000002.2509088230.0000000007039000.00000004.00000020.00020000.00000000.sdmpfalse
              high
              https://github.comCEPHtmlEngine.exe.2.drfalse
                high
                http://anglebug.com/5007libGLESv2.dll.2.drfalse
                  high
                  https://contoso.com/Licensepowershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpfalse
                    high
                    http://anglebug.com/3246allow_clear_for_robust_resource_initSomelibGLESv2.dll.2.drfalse
                      high
                      https://chromium.googlesource.com/angle/angle/libGLESv2.dll.2.drfalse
                        high
                        https://aka.ms/pscore6powershell.exe, 00000007.00000002.2504293590.00000000048A1000.00000004.00000800.00020000.00000000.sdmpfalse
                          high
                          http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#git-bash.exe.2.drfalse
                            high
                            http://www.info-zip.org/zip-bug.html;CEPHtmlEngine.exe.2.drfalse
                              high
                              http://apache.org/xml/messages/XML4CErrors#FIXEDEBCDIC-CP-USIBM037IBM1047IBM1140IBM01140CCSID01140CPCEPHtmlEngine.exe.2.drfalse
                                high
                                http://www.videolan.org/vlc/npvlc.dll.2.drfalse
                                  high
                                  https://streams.videolan.org/upload/libstream_out_chromaprint_plugin.dll.2.drfalse
                                    high
                                    http://crbug.com/398694libGLESv2.dll.2.drfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://contoso.com/powershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpfalse
                                      high
                                      https://nuget.org/nuget.exepowershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpfalse
                                        high
                                        https://crbug.com/650547libGLESv2.dll.2.drfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        http://anglebug.com/5007disable_anisotropic_filteringDisablelibGLESv2.dll.2.drfalse
                                          high
                                          http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namepowershell.exe, 00000007.00000002.2504293590.00000000048A1000.00000004.00000800.00020000.00000000.sdmpfalse
                                            high
                                            https://puta-key.com/licenseUser.phpxbuild.msi, 5cd3be.msi.2.drfalse
                                            • Avira URL Cloud: malware
                                            unknown
                                            https://crbug.com/593024select_view_in_geometry_shaderThelibGLESv2.dll.2.drfalse
                                              high
                                              http://anglebug.com/2152libGLESv2.dll.2.drfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://nuget.org/NuGet.exepowershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpfalse
                                                high
                                                http://anglebug.com/3682libGLESv2.dll.2.drfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://sectigo.com/CPS0git-bash.exe.2.drfalse
                                                  high
                                                  https://www.openssl.org/docs/faq.htmlCEPHtmlEngine.exe.2.drfalse
                                                    high
                                                    http://pesterbdd.com/images/Pester.pngpowershell.exe, 00000007.00000002.2504293590.00000000049F6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                      high
                                                      https://crbug.com/593024libGLESv2.dll.2.drfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://www.apache.org/licenses/LICENSE-2.0.htmlpowershell.exe, 00000007.00000002.2504293590.00000000049F6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                        high
                                                        https://crbug.com/655534use_system_memory_for_constant_buffersCopyinglibGLESv2.dll.2.drfalse
                                                          high
                                                          https://go.micropowershell.exe, 00000007.00000002.2504293590.00000000050CA000.00000004.00000800.00020000.00000000.sdmpfalse
                                                            high
                                                            http://apache.org/xml/messages/XMLValidityWINDOWS-1252XERCES-XMLCHCEPHtmlEngine.exe.2.drfalse
                                                              high
                                                              http://www.domain.dom/ca-crl.pemCEPHtmlEngine.exe.2.drfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              http://anglebug.com/3246libGLESv2.dll.2.drfalse
                                                              • Avira URL Cloud: safe
                                                              unknown
                                                              https://contoso.com/Iconpowershell.exe, 00000007.00000002.2507208729.0000000005907000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                high
                                                                http://crbug.com/941620libGLESv2.dll.2.drfalse
                                                                • Avira URL Cloud: safe
                                                                unknown
                                                                http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#git-bash.exe.2.drfalse
                                                                  high
                                                                  http://gcc.gnu.org/bugs.html):libstream_out_chromaprint_plugin.dll.2.drfalse
                                                                    high
                                                                    https://github.com/Pester/Pesterpowershell.exe, 00000007.00000002.2504293590.00000000049F6000.00000004.00000800.00020000.00000000.sdmpfalse
                                                                      high
                                                                      http://crl.sectigo.com/SectigoRSATimeStampingCA.crl0tgit-bash.exe.2.drfalse
                                                                        high
                                                                        http://stackoverflow.com/questions/14695988/dom-exception-5-invalid-character-error-on-valid-base64-CEPHtmlEngine.exe.2.drfalse
                                                                          high
                                                                          http://apache.org/xml/UnknownNSUCS40UCS-40UCS_41UTF-32ISO-10646-UCS-4UCS-4CEPHtmlEngine.exe.2.drfalse
                                                                            high
                                                                            http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0ygit-bash.exe.2.drfalse
                                                                              high
                                                                              http://anglebug.com/2152skip_vs_constant_register_zeroInlibGLESv2.dll.2.drfalse
                                                                                high
                                                                                http://crt.sectigo.com/SectigoRSATimeStampingCA.crt0#git-bash.exe.2.drfalse
                                                                                  high
                                                                                  http://anglebug.com/1452libGLESv2.dll.2.drfalse
                                                                                  • Avira URL Cloud: safe
                                                                                  unknown
                                                                                  http://www.info-zip.org/CEPHtmlEngine.exe.2.drfalse
                                                                                    high
                                                                                    http://anglebug.com/3682GL_USES_FRAG_COLORGL_USES_FRAG_DATA_SECONDARY_COLORGL_USES_SECONDARGL_USES_FlibGLESv2.dll.2.drfalse
                                                                                    • Avira URL Cloud: safe
                                                                                    unknown
                                                                                    http://relaxng.org/ns/structure/1.0CEPHtmlEngine.exe.2.drfalse
                                                                                      high
                                                                                      http://apache.org/xml/messages/XMLDOMMsgxmlCEPHtmlEngine.exe.2.drfalse
                                                                                        high
                                                                                        https://crbug.com/655534libGLESv2.dll.2.drfalse
                                                                                        • Avira URL Cloud: safe
                                                                                        unknown
                                                                                        • No. of IPs < 25%
                                                                                        • 25% < No. of IPs < 50%
                                                                                        • 50% < No. of IPs < 75%
                                                                                        • 75% < No. of IPs
                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                        104.131.68.180
                                                                                        puta-key.comUnited States
                                                                                        14061DIGITALOCEAN-ASNUStrue
                                                                                        Joe Sandbox version:41.0.0 Charoite
                                                                                        Analysis ID:1575142
                                                                                        Start date and time:2024-12-14 14:16:52 +01:00
                                                                                        Joe Sandbox product:CloudBasic
                                                                                        Overall analysis duration:0h 7m 13s
                                                                                        Hypervisor based Inspection enabled:false
                                                                                        Report type:full
                                                                                        Cookbook file name:default.jbs
                                                                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                        Number of analysed new started processes analysed:9
                                                                                        Number of new started drivers analysed:0
                                                                                        Number of existing processes analysed:0
                                                                                        Number of existing drivers analysed:0
                                                                                        Number of injected processes analysed:0
                                                                                        Technologies:
                                                                                        • HCA enabled
                                                                                        • EGA enabled
                                                                                        • AMSI enabled
                                                                                        Analysis Mode:default
                                                                                        Analysis stop reason:Timeout
                                                                                        Sample name:build.msi
                                                                                        Detection:MAL
                                                                                        Classification:mal68.evad.winMSI@7/146@2/1
                                                                                        EGA Information:Failed
                                                                                        HCA Information:
                                                                                        • Successful, ratio: 100%
                                                                                        • Number of executed functions: 11
                                                                                        • Number of non-executed functions: 0
                                                                                        Cookbook Comments:
                                                                                        • Found application associated with file extension: .msi
                                                                                        • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                                                                        • Excluded IPs from analysis (whitelisted): 172.202.163.200, 13.107.246.63
                                                                                        • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                        • Execution Graph export aborted for target powershell.exe, PID 6308 because it is empty
                                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                                        • VT rate limit hit for: build.msi
                                                                                        TimeTypeDescription
                                                                                        08:18:06API Interceptor4x Sleep call for process: powershell.exe modified
                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                        104.131.68.180java.exeGet hashmaliciousTinbaBrowse
                                                                                        • uyhgqunqkxnx.pw/EiDQjNbWEQ/
                                                                                        No context
                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                        DIGITALOCEAN-ASNUSsvhost.vbsGet hashmaliciousUnknownBrowse
                                                                                        • 157.245.101.141
                                                                                        https://google.co.ve/url?6q=tlqq0rdJLi6z73yh&rct=tTPvvq6xRyj7Y00xDjnlx9kIjusucT&sa=t&url=amp/s%2fwdsoft.com.br%2f7yoya/ngr2j14j20ovor/ZGF2aWQucm90aGJ1cm5AcXVpbHRlcmNoZXZpb3QuY29tGet hashmaliciousHTMLPhisherBrowse
                                                                                        • 46.101.100.125
                                                                                        https://shinybnb.ch/wp-includes/ms_doc.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                        • 134.209.237.210
                                                                                        https://url.uk.m.mimecastprotect.com/s/M6w3C3217fpmROkSqhLIQi7Bl?domain=google.co.veGet hashmaliciousHTMLPhisherBrowse
                                                                                        • 46.101.100.125
                                                                                        System.exeGet hashmaliciousQuasarBrowse
                                                                                        • 165.227.31.192
                                                                                        Client-built.exeGet hashmaliciousQuasarBrowse
                                                                                        • 67.205.154.243
                                                                                        j87MOFviv4.lnkGet hashmaliciousUnknownBrowse
                                                                                        • 157.245.101.141
                                                                                        DvGZE4FU02.lnkGet hashmaliciousUnknownBrowse
                                                                                        • 157.245.101.141
                                                                                        j3z5kxxt52.lnkGet hashmaliciousUnknownBrowse
                                                                                        • 157.245.101.141
                                                                                        zpbiw0htk6.lnkGet hashmaliciousUnknownBrowse
                                                                                        • 157.245.101.141
                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                        37f463bf4616ecd445d4a1937da06e19TN78WX7nJU.exeGet hashmaliciousLummaCBrowse
                                                                                        • 104.131.68.180
                                                                                        XIaCqh1vRm.exeGet hashmaliciousLummaCBrowse
                                                                                        • 104.131.68.180
                                                                                        PO_0099822111ORDER.jsGet hashmaliciousRemcosBrowse
                                                                                        • 104.131.68.180
                                                                                        QQx0tdFC0b.exeGet hashmaliciousLummaCBrowse
                                                                                        • 104.131.68.180
                                                                                        7VfKPMdmiX.exeGet hashmaliciousUnknownBrowse
                                                                                        • 104.131.68.180
                                                                                        7VfKPMdmiX.exeGet hashmaliciousUnknownBrowse
                                                                                        • 104.131.68.180
                                                                                        Setup.msiGet hashmaliciousUnknownBrowse
                                                                                        • 104.131.68.180
                                                                                        file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, Stealc, VidarBrowse
                                                                                        • 104.131.68.180
                                                                                        file.exeGet hashmaliciousLummaC, Amadey, Credential Flusher, LummaC Stealer, PureLog Stealer, Stealc, VidarBrowse
                                                                                        • 104.131.68.180
                                                                                        file.exeGet hashmaliciousAmadey, Credential Flusher, LummaC Stealer, Stealc, Vidar, XmrigBrowse
                                                                                        • 104.131.68.180
                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                        C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Gui.dllsetup.msiGet hashmaliciousUnknownBrowse
                                                                                          setup.msiGet hashmaliciousUnknownBrowse
                                                                                            Xih96kXne2.msiGet hashmaliciousUnknownBrowse
                                                                                              setup.msiGet hashmaliciousUnknownBrowse
                                                                                                0Q9vOYCeed.msiGet hashmaliciousUnknownBrowse
                                                                                                  f1kqfrs9ME.msiGet hashmaliciousUnknownBrowse
                                                                                                    tArE72wLqu.msiGet hashmaliciousUnknownBrowse
                                                                                                      52bwxFx7YB.msiGet hashmaliciousUnknownBrowse
                                                                                                        Uvaz36EMnI.msiGet hashmaliciousUnknownBrowse
                                                                                                          C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\Qt5Core.dllsetup.msiGet hashmaliciousUnknownBrowse
                                                                                                            setup.msiGet hashmaliciousUnknownBrowse
                                                                                                              Xih96kXne2.msiGet hashmaliciousUnknownBrowse
                                                                                                                setup.msiGet hashmaliciousUnknownBrowse
                                                                                                                  0Q9vOYCeed.msiGet hashmaliciousUnknownBrowse
                                                                                                                    f1kqfrs9ME.msiGet hashmaliciousUnknownBrowse
                                                                                                                      tArE72wLqu.msiGet hashmaliciousUnknownBrowse
                                                                                                                        52bwxFx7YB.msiGet hashmaliciousUnknownBrowse
                                                                                                                          Uvaz36EMnI.msiGet hashmaliciousUnknownBrowse
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:modified
                                                                                                                            Size (bytes):25767
                                                                                                                            Entropy (8bit):5.8556437325303925
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:768:82VYuTiZGUuoKDo4T3Fms+YErF8X1hDCdRiwQpx/lMYWZh2:PVYuTiIUuoKDo4T3Fms+YErF8X1hOdRw
                                                                                                                            MD5:3BDC23DE400A6A87488F3C6538DDF3FD
                                                                                                                            SHA1:479BB30C10D44C75E4BCF44E7E6B5E7260336E7F
                                                                                                                            SHA-256:568AE00BDFDC6F82C6B1B0D9E946CC83E98D257D704AB4B03B753B8A6A2D0E35
                                                                                                                            SHA-512:4E4CF6E129C32A4DAF1BAA7AEDBD12467EA719EA3A074CC5509F8F6B72FFAB5281E3A6ABBDEBE6008E1623709594980F77D12031D9FF7780199F2032B4F8F346
                                                                                                                            Malicious:false
                                                                                                                            Reputation:low
                                                                                                                            Preview:...@IXOS.@.....@EB.Y.@.....@.....@.....@.....@.....@......&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}..Niwp App..build.msi.@.....@.....@.....@......icon_15.exe..&.{FF6FBE99-0B7D-4FE7-A5BF-AA69254A8889}.....@.....@.....@.....@.......@.....@.....@.......@......Niwp App......Rollback..Rolling back action:....RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{89BA0234-ECD1-4530-8410-DE14A82C9A6A}&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}.@......&.{095BE648-CEBF-4E68-A76A-76A3ED057C9C}&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}.@......&.{8CFDFB52-4805-4BC0-83B1-0AE6F0BF8F4B}&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}.@......&.{7D965C96-6AC9-4D41-A354-03670BE7C96D}&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}.@......&.{4C833F3A-2BFC-4D04-B58A-F771BA32881A}&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}.@......&.{E4896264-3F7D-436B-A486-5E2988920E67}&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}.@......&.{CBD30E4C-5A55-4351-BA79-C9BED39E5061}&.{0CF3B4A2-1F02-44A2-B
                                                                                                                            Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1360
                                                                                                                            Entropy (8bit):5.41995772187153
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24:3qWSeUo4KmZjKbmODod6emN1s4RPQoU99t7J0gt/NK3R8cyiagSVbV:6WSeR4xym7jms4RIoU99tK8NWR8cy3Vx
                                                                                                                            MD5:C4A8DB61B94C2088F07EED9BA7076435
                                                                                                                            SHA1:536FCD91252597455A50F834DB37E01E981A5EE8
                                                                                                                            SHA-256:FE8054D25C12D1FEA4149BDF70347D047C2559743C49463C73158D8A26E3BFA3
                                                                                                                            SHA-512:DEB6C188E236F1243058FF708C9B8AB2CBAB8C0543BA13A2967597A1D750ABC885B147C0DAC4E096A304971D7B48BFAF4D706EE154AF3216A9EDEF302A4B3E72
                                                                                                                            Malicious:false
                                                                                                                            Reputation:low
                                                                                                                            Preview:@...e................................................@..........P................1]...E...........(.Microsoft.PowerShell.Commands.ManagementH...............o..b~.D.poM......... .Microsoft.PowerShell.ConsoleHost0.................Vn.F..kLsw..........System..4...............<."..Ke@...j..........System.Core.D...............4..7..D.#V.............System.Management.Automation<...............i..VdqF...|...........System.Configuration4.................%...K... ...........System.Xml..4..................~..2K..}...0........System.Data.<................t.,.lG....M...........System.Management...@................z.U..G...5.f.1........System.DirectoryServicesH................WY..2.M.&..g*(g........Microsoft.PowerShell.Security...L.................*gQ?O.....x5.......#.Microsoft.Management.Infrastructure.8..................1...L..U;V.<}........System.Numerics.<...............V.}...@...i...........System.Transactions.P...............8..{...@.e..."4.......%.Microsoft.PowerShell.Com
                                                                                                                            Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):60
                                                                                                                            Entropy (8bit):4.038920595031593
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                            MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                            SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                            SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                            SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                            Malicious:false
                                                                                                                            Reputation:high, very likely benign file
                                                                                                                            Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                            Process:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                            File Type:ASCII text, with no line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):60
                                                                                                                            Entropy (8bit):4.038920595031593
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:Si2NPqzAYMLAKVpKGOyzKtFS:SnqbKAKWGX
                                                                                                                            MD5:D17FE0A3F47BE24A6453E9EF58C94641
                                                                                                                            SHA1:6AB83620379FC69F80C0242105DDFFD7D98D5D9D
                                                                                                                            SHA-256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
                                                                                                                            SHA-512:5B592E58F26C264604F98F6AA12860758CE606D1C63220736CF0C779E4E18E3CEC8706930A16C38B20161754D1017D1657D35258E58CA22B18F5B232880DEC82
                                                                                                                            Malicious:false
                                                                                                                            Preview:# PowerShell test file to determine AppLocker lockdown mode
                                                                                                                            Process:C:\Windows\SysWOW64\msiexec.exe
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with no line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):92
                                                                                                                            Entropy (8bit):2.9456001152728497
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:Qi8dsqFlbYplfl1r3LDlYplf955:Qi8dsAEL/DOLN
                                                                                                                            MD5:A27B4D87402A31DD9770A28B3A8E9A4A
                                                                                                                            SHA1:8179877A4478E75F0F81B30751F23D7028CD04BF
                                                                                                                            SHA-256:73C6A8BF298CD8C11A140BEC609163EE715602D252381675F21D8A89E5BCF524
                                                                                                                            SHA-512:A452A89BC2D63FC15840C221F61CDE778877A8434E67B918CEB1302C4386976B736164490864FB19B6DF5B648CD90A08462D4418D25969B421FD74BC24C395A2
                                                                                                                            Malicious:true
                                                                                                                            Preview:..G.r.i.n.v.A.q.o.i. .:.<.-.>.:. . .<.<.:.>.>. .S.r.a.T.r.i.m. .:.<.-.>.:. .0. .<.<.:.>.>. .
                                                                                                                            Process:C:\Windows\SysWOW64\msiexec.exe
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):6668
                                                                                                                            Entropy (8bit):3.5127462716425657
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:96:5Wb5VNkKmeHn/V2BVrIovmgNlGjxcj6BngOcvjb:5WbyZ/gVyvb
                                                                                                                            MD5:30C30EF2CB47E35101D13402B5661179
                                                                                                                            SHA1:25696B2AAB86A9233F19017539E2DD83B2F75D4E
                                                                                                                            SHA-256:53094DF6FA4E57A3265FF04BC1E970C10BCDB3D4094AD6DD610C05B7A8B79E0F
                                                                                                                            SHA-512:882BE2768138BB75FF7DDE7D5CA4C2E024699398BAACD0CE1D4619902402E054297E4F464D8CB3C22B2F35D3DABC408122C207FACAD64EC8014F2C54834CF458
                                                                                                                            Malicious:true
                                                                                                                            Preview:..p.a.r.a.m.(..... . .[.a.l.i.a.s.(.".p.r.o.p.F.i.l.e.".).]. . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.O.u.t.F.i.l.e.P.a.t.h..... .,.[.a.l.i.a.s.(.".p.r.o.p.S.e.p.".).]. . . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.K.V.S.e.p.a.r.a.t.o.r..... .,.[.a.l.i.a.s.(.".l.i.n.e.S.e.p.".).]. . . . . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.m.s.i.P.r.o.p.L.i.n.e.S.e.p.a.r.a.t.o.r..... .,.[.a.l.i.a.s.(.".s.c.r.i.p.t.F.i.l.e.".).]. . . . .[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. .[.s.t.r.i.n.g.]. .$.u.s.e.r.S.c.r.i.p.t.F.i.l.e.P.a.t.h..... .,.[.a.l.i.a.s.(.".s.c.r.i.p.t.A.r.g.s.F.i.l.e.".).].[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.f.a.l.s.e.).].[.s.t.r.i.n.g.]. .$.u.s.e.r.S.c.r.i.p.t.A.r.g.s.F.i.l.e.P.a.t.h..... .,.[.P.a.r.a.m.e.t.e.r.(.M.a.n.d.a.t.o.r.y.=.$.t.r.u.e.).]. . . . . . . . . . . . . . . . . . . . . . . . . .
                                                                                                                            Process:C:\Windows\SysWOW64\msiexec.exe
                                                                                                                            File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):254
                                                                                                                            Entropy (8bit):3.5609540385848644
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:QVl4wk79idK3fYlGds6lKMCaN+KiVmMdl49rMTl0x1LlG7JidK3fMlOD+sMC1:QV2fUqs6Kas/d29rMT9NYm1
                                                                                                                            MD5:9B38565D104B51442E90E90AA2BF7AF8
                                                                                                                            SHA1:16D7616BF3AFB3E7D8E8C531D42E278AF11BA6F5
                                                                                                                            SHA-256:1EA96062089FDEB81C7A03F510FBB323D0B8088E68E82DA186D8F4646CB5F18D
                                                                                                                            SHA-512:BF8E48CF7512FF20F2F935D1D26183723B0EC3D563242935CB358C34204471643527659AEB5C2D7D123438131EF505006D6059110BBBA78ABC850B93927152AF
                                                                                                                            Malicious:true
                                                                                                                            Preview:..$.o.i.e.w.f.h.c. .=. .A.I._.G.e.t.M.s.i.P.r.o.p.e.r.t.y. .".G.r.i.n.v.A.q.o.i.".....$.i.u.e.s.a.g.h. .=. .[.u.i.n.t.3.2.].(.$.o.i.e.w.f.h.c. .-.r.e.p.l.a.c.e. .'.a.'.,. .'.'.).....A.I._.S.e.t.M.s.i.P.r.o.p.e.r.t.y. .".S.r.a.T.r.i.m.". .$.i.u.e.s.a.g.h.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:MS Windows icon resource - 9 icons, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel, -128x-128, 32 bits/pixel
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):186509
                                                                                                                            Entropy (8bit):6.243379907710166
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:1536:yIZtjRNSg5FwgIeAWqoZB87MIHeeYsDURu9P3wPmdoy4g/gzmufhCSF7Wc5F10OM:y+tSFRWqoZ4Z7su9oPvy/GmekbO48K
                                                                                                                            MD5:28D2B0E32176328B04393545A600684E
                                                                                                                            SHA1:EFB8FB9BF597269BAFCDFBA098AC57A27B94CCC3
                                                                                                                            SHA-256:91B054F2B45104570597CD65CA88C4FCAB4071A96AEF7D5103A4D8126109576D
                                                                                                                            SHA-512:A99385EDA5881224BF2C154FCFD4964489E95F91A7F5EFA8BFA07150866C995C73B7B176D80E2C540A9E1F7CECAA56C2F92FB130C66507FD0D51B1969C6FDB99
                                                                                                                            Malicious:false
                                                                                                                            Preview:............ .7`............ .(....`..``.... ......h..HH.... ..T......@@.... .(B..%R..00.... ..%..M... .... ............... ............... .h...%....PNG........IHDR.............\r.f....pHYs..........o.d.. .IDATx..K.,.u&.Ef....~\..d...iQ.E.1.Lj0c{...cy..0..7......^..^.R.xg..1.............5-..dw.~........<^..D.....6...7."N......'"3.#..HG:..t.#..HG:..t.#..HG:..t.#..HG:..t.#..HG:..t.#..HG:..t.#..HG:..t.#..HG:..t.#..HG:..t.#..HG:..t.#..H.%u......*....K.^..<d.G:.SJ..........?....U.A..W.........7..C.y.#=.4.....O...?.............W....HG..................{..P......'.x......M.,.h.].R*l...x.....J...s....h. .S,.%.u..A..=*.F.6.6r.a=I...&...Gp..).....AQ..!e$P..byL .$....L"....@..........m&..9L..h......1..p...e.@._}...d6%0......./(...c._..E....h0D.3.@..=.y.....F..@!...(.^g..".F.@Ir.L.H...._C.o.#.e...S..<..l.A<[..;....9$t.t.+.b.LZ..*.X.P..I.D..zE........!.........[..D......,...B....n..+...o=......7..Vk.8.U....l..8^>)....P(..]R.......2Bo...e.^....-)Q..7B1.uZ<..K.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.077213957707642
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:Efg9oKq+5ZdFzjVfuFo5SG1OpKI5cpNFA:EkoHmdFvVfu9papNFA
                                                                                                                            MD5:94E14F09CF2B0C323B5498FCDFBD87BB
                                                                                                                            SHA1:3830C61266C051DF2EA8884447670A96633112FC
                                                                                                                            SHA-256:79B35C4A81FE05298793E2BD26D11AD31E5AF8425A3F988F8EBECC40C507CC68
                                                                                                                            SHA-512:F9CAD086601136D35F52FF7B811A6A88E7715A2DC7C462F58E12E248F046F11D70C3733963666DF16D65A89B4D51F62D60CBB2F4937ED810DED5E5D0F154E8BF
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(........................................................................................f..f..f..f..f..f..f.............................f.f.ff.ff.f3.33.3.f..f..f..f..f..f..............f....f.ff.ff.f3.3.f..............f..............f.......f.ff.ff.f.f..............f..............f..f..f..f..f..f..f..............f..........................................................................................f..f..f..3..3......................................f..f..f..3.........................................f..f..f.......................................................f..f..f..f..f..f..f..............f..............f.f.ff.ff.f3.33.3.f..............f..............f....f.ff.ff.f3.3.f..............f..............f.......f.ff.ff.f.f..f..f..f..f..f..............f..f..f..f..f..f..f............................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.0781299846620236
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffAXLBHv9XGMpqHMy5tpqhpqbxJqhpqHvqhpqHvqhcMpqHMy5tpqhpqbxWeJ1:EfI9lGhZ5Zd1lhZ5ZYmVfuFo5SGaI
                                                                                                                            MD5:42B56855A6EE8F2EC4E185A2D93B52D5
                                                                                                                            SHA1:526096590A35AC4CD54D98D364223DC136C4003E
                                                                                                                            SHA-256:447D013B727783C6601BF03DFB640289FAEDF4861C6F7654070D46F8C34CAB68
                                                                                                                            SHA-512:D2279F3D5DB2ACE704F8B71747AD7EEBA92E4F87D0942F6870234757A855EDDBA703AFDD79AD660694E0D85AC0EA86B4195B119C6BCD32FEADD3B806E419EDF4
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(................................................................................................................f..f..f..f..f..f..f.............................f.f.ff.ff.f3.33.3.f..............f..f..f..f..f..f....f.ff.ff.f3.3.f..............f..............f.......f.ff.ff.f.f..............f..............f..f..f..f..f..f..f..............f..............f..f..f..f..f..f..f..............f..............f.f.ff.ff.f3.33.3.f..............f..f..f..f..f..f....f.ff.ff.f3.3.f..............f..............f.......f.ff.ff.f.f..............f..............f..f..f..f..f..f..f.........................................................f..f..f..3..3......................................f..f..f..3.........................................f..f..f..............................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4084984
                                                                                                                            Entropy (8bit):6.21477530396318
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:49152:UxyIstTOi4SwdjKND5VEVfGkFU1N82eMQIk+vTz6/H4GIP6bJye8Px:UxwtCqIVfGkS1Nl26fATbA
                                                                                                                            MD5:42F0DC166D6605E3FB9238172D8FFE4F
                                                                                                                            SHA1:1FD4F862676457BAEEB0AA28FD05EF52CB4DBA2B
                                                                                                                            SHA-256:322CDEE2378C15EE4A81A2AA6389483E61B055C9C4C455DAC4D17EEE2400D853
                                                                                                                            SHA-512:62D389A5C78DA607D210D4E86598C5F7A144F88B3F5F7CFD742A3401BEC88D5BA8A6A97A52EF8205848BACA4CBA36211E7F0615DBB7B7005E5D3B14E195105E0
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...................................X...........!..L.!This program cannot be run in DOS mode....$.......................4.......Z.................................................^.................h...T....^........................T......T......T.X.......0.....T......Rich............................PE..d......`..........".......#..:,.....0."........@..............................P......Z>...`..................................................W7.X.....O. i....L.|$...8>......pO.... .3.p.....................3.(.....3.8.............#..............................text...L.#.......#................. ..`.rdata........#.......#.............@..@.data.........7..p....7.............@....pdata..|$....L..&....;.............@..@.rsrc... i....O..j...6=.............@..@.reloc......pO.......=.............@..B........................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.9483459356843928
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffIXDHz9DXw3u6+6Ycl06Y2t0SXOt0AaoPxYoO2SDAzpG:EfQHFw3u6+dcCd26AHpoPuoO2SAA
                                                                                                                            MD5:6119E2D64124ED562DE92B79964589C2
                                                                                                                            SHA1:64C12D62B54B63C8BF083FE44164A2C4241BDCB7
                                                                                                                            SHA-256:BCC0C02A6EC0D443D73803823CAA6E6E34E9FBFFE82D8D54AFA742AF0FF89587
                                                                                                                            SHA-512:9C6920758968B2FEFBFBFDBDDC8CF4AC6643BBB719A2E24021046BB739A5242CF85AF15EFC4A2157FECC7DADA2CEFF29C298650108BB81EA5363119660FFB9C7
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(............................................................................................................................................................................................................................................................................................f..3..3..........f..f..f..f..f..f..f............f..f..3..........f.f.ff.f3.33.33.3.f............f..f..3..........f.f.ff.f...f.f3.3.f............f..f..f..........f.......f.f...3.3.f............f..f..f..........f....f.ff.ff.f....f...............f..f..........f..........f.ff.f.................f..f..........f..f..f..f..f..f..f..................f....................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.05699630427599
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:EfgCX3u03u5N8FioAoRSISqYoqoqoI6ZZ6Q:EbX3u03u5N8F1Rrrl
                                                                                                                            MD5:1AD4A4586336189A8A2D80D069A67D3F
                                                                                                                            SHA1:0FB2B75A662E29E5ADD94DB861751E8069B3FC4B
                                                                                                                            SHA-256:93E22781B25453EDB49345FADCDC3EB18336E69D2B5BA425DD346D9B36A9C490
                                                                                                                            SHA-512:8C6209A10CE41C65BB6F4809DF0B19D9E2AEBA311F0F19F90286C5550548D809B3681F5B4165CD905F46490FBA7553CCD30C80EB48927B375991390CB5C7A45B
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(............................................................................................................................................f..3..3.........ff.ff.........f..3..3...........f..f..3............ff.........f..f..3...........f..f..f.......................f..f..f..............f..f..........................f..f.................f.............................f.......................................................................................................................................................................................................................f...........f......................................f.....f............................................f............................................f.....f......................................f...........f..................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.058854696679015
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:EfglVfuFo5SGaCtuH6HBgF6HhxfuFo5SGaI:E4Vfu/q9hxfu/I
                                                                                                                            MD5:6792D705A8BC023BC27717A63000903A
                                                                                                                            SHA1:76CCFF5E77DA47842A6F99A50F46526BD02A6D2A
                                                                                                                            SHA-256:7E9A67FE279E9C691E377225ABE8EE53507690DAF44183E716BABF21AFF9F6D6
                                                                                                                            SHA-512:722850726DA3A4E75F793A9F56F30FF40D5FA5E51B67E881EEC39FD21FC7DB9E80AEC4A26E81AE248E3EF08AE0D38699B1342BA2121A71C41685D9EAE4317D69
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(............................................................................................................................................f..f..f..3..3......................................f..f..f..3.........................................f..f..f.................................................................................................................f...........f............ff.ff.....................f.....f..................ff........................f............................................f.....f......................................f...........f.....................................................f..f..f..3..3......................................f..f..f..3.........................................f..f..f..............................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.701024237893803
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffy+B6QXxqQm/cccccccPl6gtarQUyliamwem44wem44wem44wem4Femk8JaE:EfF6QUJMl6goEUuRqqqUzN
                                                                                                                            MD5:45B3B46C7B13D56C5EE96988F20903A0
                                                                                                                            SHA1:C9D79F8A589468D5AC8FB0A948AB3DD92EBA74EE
                                                                                                                            SHA-256:D089CA028AC2AC5023E71A566F1D4F92B451752DEF86E8BB960C0FF6ED9B5AF2
                                                                                                                            SHA-512:717D5215B1EC1A40972F62EA782061824ECB6A936F8883708444C0F338D001E3C0C56AE5442AFE9B95483A6B2E6BF1963DE0B1F30AA95D281B3DE027663E7F8F
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(..........................................................................................................................................................................f...........f......................................f.....f............................................f............................................f.....f...............ff.ff.ff.ff............f...........f.....................ff..............................................ff..............................................ff..............................................ff.........................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.2023915485583316
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffdipXLqiMcRHv9imrclpBrc5t2Oy5t6y5twlIW5texqy5tA8y5tpBgnDiI2+:EfE5zJ06c5c5ET5B5CX5Y95ep5BhHFXI
                                                                                                                            MD5:88310A434CA4F0B6EAC11EEF5DB9F729
                                                                                                                            SHA1:F450FBBD8BDAA3E02ECD9B8415F5727B872E660E
                                                                                                                            SHA-256:B8C2BCC4B83D1C3598694DCABEF1BF0DDD98E3EE66DA83A2B4BC3168F62712EA
                                                                                                                            SHA-512:981901047BAC0E5386DD111016EE53CD97BB16001086A5BF9CE0365B2161680DD9C832091049FF04AC049FCCC8225E12E33AA285B19A8F741A2F7D4AE2292051
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(....................................................................................................................................................3............................................3..3..3........f..f..f..f..f..f..f.................3...........f.f.ff.f3.33.33.3.f.............................f.f.ff.ff.ff.f3.3.f.............................f....f.ff.ff.f3.3.f.....f..f..f..f..f..f..f.....f....f.ff.ff.f3.3.f.....f.f.ff.f3.33.33.3.f.....f....f.ff.ff.ff.f.f.....f.f.ff.ff.ff.f3.3.f.....f..........f.ff.f.f.....f....f.ff.ff.f3.3.f.....f..f..f..f..f..f..f.....f....f.ff.ff.f3.3.f.............................f....f.ff.ff.ff.f.f...........3.................f..........f.ff.f.f........3..3..3..............f..f..f..f..f..f..f...........3................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.9694221227788473
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlfflrD3XTMrnVMsXnMsjqHMsXkMxnvTMqXsqTMqjqMqTMqXDqTMPJTIsTPqMsi:EfN34rusMWsHxgKslAlKBPuWjt
                                                                                                                            MD5:D5BEC74C9D29B35809EF4F0CBDF27949
                                                                                                                            SHA1:5315151300CB0520B80A48A6D00D955BF8C9CE56
                                                                                                                            SHA-256:8B42D86F2A8693D4EDEB0A3FDD4A18054D01674399702A03B732D320F9085BB6
                                                                                                                            SHA-512:1A669C07370C755F00D2FEDA57EE8A6DF406F8285D23073167C768038BD1AD50B28280574C594CB0E89A05CBE6F6D91075242EF2484A19AE06EE79941C5716B8
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(.............................................fffffffffffffffffffffffffffffffffffffff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff.............................................fff...................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.04386646975616
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:EfgQ1X3uwP3u5x08GiohoRS7SSYvC6bDc5rK7Nd:ElX3uwP3u5x08G7YvC6bDsK7Nd
                                                                                                                            MD5:E62D2FC076CC2D0C92838484C2F5EC6C
                                                                                                                            SHA1:132872719DB0703396A853D688C0F2AF82BE3B62
                                                                                                                            SHA-256:C00189FA68D6F3936102DF62FDF13177A5E8C8094D69DC019E8D95612D8056A5
                                                                                                                            SHA-512:7364CB0C341973C4EE34D4BF8EB8208EBB6E38B64CFF6AFA78AAB7E0784A5317BDB47AD313E4495A86C34B9E4B02413BBE9EB92DA1AE2658F9C0B949479D60E8
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(............................................................................................................................................f..3..3..........f............f..3..3...........f..f..3..........f..f.........f..f..3...........f..f..f..........f............f..f..f..............f..f..........f...............f..f.................f..........f..................f............................f...............................................f................................3........f..f..f..f..f.......................3..3..3.....f.f.f3.33.3.f..........................3........f.f.ff.f3.3.f...................................f.f.ff.ff.f.f...................................f....f.ff.f.f...................................f.......f.f.f...................................f..f..f..f..f...................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.2928423029965486
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:EfSwBQOIIbL8od9ljo5AfRkGMT4qoz5qXcoHLrRkGYd:EFBQOIIbLZlgAGJLr8d
                                                                                                                            MD5:E8AE00D4FCEE69FF0E59E9F246123B34
                                                                                                                            SHA1:BB20005D97259217192FE75D9C70A03D766703F7
                                                                                                                            SHA-256:BBF7D0E278F26B193860206AF9D9C72BD521F0BFF64B7F693673E1541B91C839
                                                                                                                            SHA-512:E6B0D21C3C8A05B3723135FD50F9873423DE00CEE881AC3CB645039C6658B3B0CB5EBAF3AD23AD6B94C5C9733639A2F2AA1C64F485D71D23DDF851F2B86DA7AF
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(...............................................................................3............................................3..3..3...............f..f..3..3..3..3.............3..................f..f..f........3...................................f..f..f..f..3...................................f........f..3.......f..f..f.....................f..f..f..f..3......3.33.3.f...........................f..f..f.......f.3.3.f............f.................f..f......f.f3.3.f............f.........................f.f.f3.3.f...............f..f..f..f.f....f.ff.ff.ff.f3.3.f...............f........f.f.....f..f.f.ff.ff.f.f...............f..f..f..f.f.............f.ff.f.f.....................f..f.f..f..f..f..f..f..f..f........................f..f...........................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.041173704120979
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:Efgl0GfuFoseSGar9lSt5NYQVfuFo5SGaI:E40Gfu77ZQtVVfu/I
                                                                                                                            MD5:3E5A0DDD80541905D6E012FD5FB54AAC
                                                                                                                            SHA1:899AA2A1AF047B4F244CB7974E3702E17EB1893A
                                                                                                                            SHA-256:4B22C5AFDA48173FB581D02099E4D5CFEBA1B859431E380F6F5FA6FE1FD24856
                                                                                                                            SHA-512:D009ED6EB2D29F1151AE4FB8AB9B56A7FAFB71ED0291F0C1379A530AAA8E62EEFDDA303CC3B67F767DB4A6FC873A521F36D69C15D8FEEC56BCA0FC82ECE635A5
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(......................................................................................................................3.....................f..f..f..3..3..........3..3..3.....................f..f..f..3.............3...........................f..f..f.......................................................................................................f..f..f..f..f..f..f..............f..............f.f.ff.ff.f3.33.3.f...........f..f..f..f..f..f..f....f.ff.ff.f3.3.f.............................f.......f.ff.ff.f.f.............................f..f..f..f..f..f..f.........................................................f..f..f..3..3......................................f..f..f..3.........................................f..f..f..............................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.7920940508231251
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlff+E7EmgRjEU82ZEAmplb2/EAw3b2kEM+bplVTRWEAmplhWXJgz7gtZH5gpoC:Ef7gatezdriqWZHMoV/G3h
                                                                                                                            MD5:D2F9E78F10840D37678EF86E3E9CBBCA
                                                                                                                            SHA1:2FBE06ACCB4F5AD6CC305E66BE35CBF38B04DD4C
                                                                                                                            SHA-256:A37E249C985417B809CEA95C12194791E4C3CBE8466AD30C9E257DB6A0682C6B
                                                                                                                            SHA-512:4C4149503C1DEF1D0AA341A5DCB62460C17E9AD49DF9EC7FBB46D2130C7DFF4914C02F12F5F85E1EF51ED32B042334B72910FE031D05D4E5AA1A1DBE0E4F1DC1
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(.............................................................................................................................................................3f...........................................3f....3f.....................................3f..........3f...............................3f................3f.........................3f......................3f......................3f.3f.3f..........3f.3f.3f............................3f..........3f.............................................................................................................................f..f..f..f..f..3..3..3.............................f..f..f..f..f..f..3...................................f..f..f..f..f...............................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.767441642011123
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffwXDeEMNO9nEmgRC3u5sEUgy679EDF867qEAwfU649EAwfD14sEAmplroVnr:Ef4SO3gw3uHyX8os6vr1mNoOocASH2
                                                                                                                            MD5:503FE8AAF5EF0DFBEDA0C7C1E7DF35FC
                                                                                                                            SHA1:2353F20E68F3B9D52B3113CCBACA4AF8CE55A15D
                                                                                                                            SHA-256:A603FD88099F1750A8A63D13FC9A0B5482491474A01F4EBC47F6F140AB74B722
                                                                                                                            SHA-512:E0CEF289D0154B24420E99A58C142D9A701529E4A0EF94F4209E132D5034B12C7674A53988EB4D06C97BDB85D6A7B5B003017DB74DBBB01C69D24451DF0938A3
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(.......................................................................................................................................................................................................................................................3f.3f........................................3f....3f........f..3..3......................3f.......3f.3f.....f..f..3...................3f....................f..f..3................3f.......................f..f..f...................3f....................f..f..f......................3f.......3f.3f........f..f.........................3f....3f...........f..f............................3f.3f..............f............................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.7773627109619747
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffaXDHzpMNoH3u1mgRZt6uyut6LpXtoctMspo3hpoxAppSjMNozvg:EfCHpkg3u1mglbA5fo3foxaSjkcI
                                                                                                                            MD5:597A57FAF7DEBC6939633649BADD8B5C
                                                                                                                            SHA1:391877AC897A654BD43B1C2E1D0CA709F2393E40
                                                                                                                            SHA-256:A4615B719F974075BBA1D807B09B66280ABB43D64C323BCC1E6BF0064E14C4E2
                                                                                                                            SHA-512:490A46AE7F8047B49516941DDBA615482360886ED2411AB7620EB3A17996F11490A819FA73D55B9943CF75DD04B62EEBEF030BE64FBDE84A3A74D7C62D0253C5
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(...................................................................................................................................................................................................................................................................3f.3f..........................f..3..3..........3f....3f.......................f..f..3.......3f.3f.......3f....................f..f..3......................3f.................f..f..f.........................3f..............f..f..f......................3f....................f..f.......3f.3f.......3f.......................f..f..........3f....3f.............................f..........3f.3f...............................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.7773627109619747
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffKXJgz7gtZH5gpoo7gp/G0gzpAEAmplhWEM+bplVTRkEro2/EAwf7ZEAwfIG:EfyqWZHMoV/G3z1zdyiz
                                                                                                                            MD5:42A0A5876AC111B2257709A0B0F0C8E6
                                                                                                                            SHA1:8410A2FAA04029B53050DF53676D3C8DC721BE75
                                                                                                                            SHA-256:B68648513775B572AE1ABF0F2F8DC7A9443FFF9A35F4CD0C4479688849E47D06
                                                                                                                            SHA-512:064041F543391F189E214C96F44701A1D9F86CC6BB17D6DE256BB09F87715C72783C679709DE0260F8B37BF6D5CF9E9D01BF97F387BCBD1E4DEAF27EFC8ED0DD
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(..................................................................................................................................................................................................................................................f..f..f..f..f..3..3..3.............................f..f..f..f..f..f..3...................................f..f..f..f..f...............................................................................3f..........3f............................3f.3f.3f..........3f.3f.3f......................3f......................3f.........................3f................3f...............................3f..........3f.....................................3f....3f...........................................3f........................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.4010336083343535
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:Efb3Pcfcbc5Xc5B3fgv5XNWXL0XLLrW9fdL+BusZtR:EbPyqQM6NsLKLLr2flfsZtR
                                                                                                                            MD5:86EE731789B64420405A0C7F9F2C25AB
                                                                                                                            SHA1:899FD10D70805F36F609A5DFA02FBAEF0A25BDFD
                                                                                                                            SHA-256:60BFDFC9E75345A4FD5C722E2497381719E1C3A1943D7A6A708257899A72F2D7
                                                                                                                            SHA-512:9D4BF54FAF8E44D78B577E699E132B34F98A3EFB05F6C01D0F5878D08416E5A4BC88E3D03AAC98A120CB799896A99423359AC506A72057857F4515C7586D02E6
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(...........................................................................................f..f..f..f..f..f..f..f..f..f..f..f..f...........f.f.ff.f3.33.33.3.f.f.ff.f3.33.33.3.f...........f.f.ff.ff.ff.f3.3.f.f.ff.ff.ff.f3.3.f...........f....f.f.f..f..f..f..f..f..f.f.f3.3.f...........f....f.f.f.f.ff.f3.33.33.3.f.f.f3.3.f...........f....f.f.f.f.ff.ff.ff.f3.3.f.f.ff.f.f...........f........f....f.f.3.f.f3.3.f.f.ff.f.f...........f..f..f..f.....3..3..3.3.3.f..f..f..f...........f.f.ff.f.f....f.f.3.f.f3.3.f.3.33.3.f...........f.f.ff.f.f....f.ff.ff.ff.f.f.f.f3.3.f...........f....f.f.f..........f.ff.f.f.f.f3.3.f...........f....f.f.f..f..f..f..f..f..f.f.f3.3.f...........f....f.ff.ff.ff.f.f....f.ff.ff.ff.f.f...........f..........f.ff.f.f..........f.ff.f.f...........f..f..f..f..f..f..f..f..f..f..f..f..f.......
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, image size 768, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.3831318937888808
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlfs9jGXpvCUEmgljFEmUljFEm4FEAbFEyugFEAbFEyugFEAbFEyugFEAbFEMR1:EflJgl3UBMukukuODnz
                                                                                                                            MD5:660A80AC32A7DE07D46A906AD18C3A20
                                                                                                                            SHA1:CD9379B1DB39CA72B88E8E8978C45487814015FC
                                                                                                                            SHA-256:93533944518985344DB7F532E201FBA5833CDCBD0A6637C9CC43B4D992C3BC31
                                                                                                                            SHA-512:D6DFFACA0E873EFB2656843EB3A7A58286100EE10043EB29E86C407AE14AFC719071747FF8F44D0D0ED33287AF29B489FB59CAF52BF0E4736A97518E1CC47447
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(.......................................................................................................................................................3f...........................................3f....3f........................................3f..............................................3f.......3f........................................3f..............................................3f.......3f........................................3f..............................................3f.......3f........................................3f..............................................3f.......3f........................................3f..............................................3f.....fff..........................................fff.ff..........................................f..f..f............
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, image size 768, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.2652819025197999
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlfsBXAXUQjHnX24XdX48qXMcu8BjsXHjSjnXMjsXHj9X+jqXhjDXgcrXAX7:EfQAUc24t4NPufIzhX1bbA7
                                                                                                                            MD5:4C933C02D87761BA3BD654FAB9830A3C
                                                                                                                            SHA1:12D3F5C476176E02906E0E9B8F04070E1BFB1EA9
                                                                                                                            SHA-256:03962A990EB2359DE6258816EB7EFEDBD75D8AB511DA62AD5B8656078F42A1FF
                                                                                                                            SHA-512:E78A36896A9E264413A7320C46E670869754CE694B84781DB56835FAD663015408C6D2E9812E3E8B76508EE5EFA93BB14701EF14089BEEA7C861D0D2D20A594D
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):7442360
                                                                                                                            Entropy (8bit):6.552193329590098
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:98304:vIBxuKe1WAIIaUtXf4Pju4I38BWGny6gPBereJsv6tWKFdu9CJ54+1jYKi2:va+IpNHtiBPJsv6tWKFdu9CJ5ljZ
                                                                                                                            MD5:3DC9596998EBAC48A1EA9D5557649EEB
                                                                                                                            SHA1:16115408BAB17885AD9BF95810DBD7A35F159E4A
                                                                                                                            SHA-256:3880E50AB6E204B9FBC2952FF39411A530612DDCBD82C296D916065F37B755E6
                                                                                                                            SHA-512:7A6641B3F8BCFBE165AEB8F7477F931188E58A72BAE63DFE2BA1C86736CDC6C7F6C86C0D433BADB64F3C799202A2F5439EAB0F04362B5B882F7F5C346F9765F9
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Joe Sandbox View:
                                                                                                                            • Filename: setup.msi, Detection: malicious, Browse
                                                                                                                            • Filename: setup.msi, Detection: malicious, Browse
                                                                                                                            • Filename: Xih96kXne2.msi, Detection: malicious, Browse
                                                                                                                            • Filename: setup.msi, Detection: malicious, Browse
                                                                                                                            • Filename: 0Q9vOYCeed.msi, Detection: malicious, Browse
                                                                                                                            • Filename: f1kqfrs9ME.msi, Detection: malicious, Browse
                                                                                                                            • Filename: tArE72wLqu.msi, Detection: malicious, Browse
                                                                                                                            • Filename: 52bwxFx7YB.msi, Detection: malicious, Browse
                                                                                                                            • Filename: Uvaz36EMnI.msi, Detection: malicious, Browse
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.........W.......!...$..2...W..8............2....f..........................X.....F.q...@... .......................Q.......V..4....W.8.................... W..a...........................xC.....................4.V.|............................text.....2.......2.................`.P`.data...0.....2.......2.............@.p..rdata..(.....3.......2.............@.`@/4............D......pD.............@..@/20......j...@H..l... H.............@.0@.bss.....7....Q.......................`..edata........Q.......Q.............@.0@.idata...4....V..6...HV.............@.0..CRT....,.....V......~V.............@.0..tls..........W.......V.............@.0..rsrc...8.....W.......V.............@.0..reloc...a... W..b....V.............@.0B/30...........X.......W.............@.0B........................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):10025108
                                                                                                                            Entropy (8bit):6.557228014843588
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:98304:t+ysdIiPAgcsxId4UlbrqmH2Vgn4G5wXAsxwo+34v3e/KfiP8EEi88tV/ky:tpC1xnUlSmHk3Q3P4v3e/5jd8c
                                                                                                                            MD5:B6B0178576EE844019D0F2FA214DF8C8
                                                                                                                            SHA1:6BB884F83BEAC17F42597160D321D4AD2BD3C6C2
                                                                                                                            SHA-256:455E4487B294C9648F2F4852AB68BA5D45E880BD1E8CF3D27E58150C2AEDB20C
                                                                                                                            SHA-512:E214E6232D4F2469769AF243B01CDE10E72EF1ACDAD1E92FE1E9CF7B74FD127831BC223A3AD983695F35E4EADFAFF49110948D63E085C551094F534E33E04AB4
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Joe Sandbox View:
                                                                                                                            • Filename: setup.msi, Detection: malicious, Browse
                                                                                                                            • Filename: setup.msi, Detection: malicious, Browse
                                                                                                                            • Filename: Xih96kXne2.msi, Detection: malicious, Browse
                                                                                                                            • Filename: setup.msi, Detection: malicious, Browse
                                                                                                                            • Filename: 0Q9vOYCeed.msi, Detection: malicious, Browse
                                                                                                                            • Filename: f1kqfrs9ME.msi, Detection: malicious, Browse
                                                                                                                            • Filename: tArE72wLqu.msi, Detection: malicious, Browse
                                                                                                                            • Filename: 52bwxFx7YB.msi, Detection: malicious, Browse
                                                                                                                            • Filename: Uvaz36EMnI.msi, Detection: malicious, Browse
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.........t.;......!...$.RV...t..j...........pV....f..........................u......C....@... ......................`k......@r......@s.8....................Ps..k..........................T.\.....................`Tr. ............................text....PV......RV.................`.P`.data........pV......VV.............@.`..rdata..<.....V......pV.............@.`@/4..........@^.......^.............@.0@.bss....Ti....j.......................`..edata.......`k.......j.............@.0@.idata.......@r.......q.............@.0..CRT....,.... s.......r.............@.0..tls.........0s.......r.............@.0..rsrc...8....@s.......r.............@.0..reloc...k...Ps..l....r.............@.0B/14...........u.......t.............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.3644380727352345
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:Efb/POR7UdoKu+doKH4doho62o0uh2o0H32oh9Y+hYX3ihG1Z:EzPOR7UJu+JH42QuhQH3HBhG39Z
                                                                                                                            MD5:E658179CF655D9BAADAFA7FA9A8AD916
                                                                                                                            SHA1:F102194122C401DC1217C72B107F486E01F141DD
                                                                                                                            SHA-256:FA1FB4AE6A51DF3295EDDCAB8D19CB9B0B4139FC78A85DFAEFEF24B501DD2385
                                                                                                                            SHA-512:4CDA72F54A2C4A03F218F3774EEC5B1298A640143472B93D76CC7C08C339B008A34E764DA0F4D64B23F55B1E0BC4F26015235AF9C3F9384CFD17FD6B6201EB2D
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(...............................................................................................................................................f..f..3..3..3..3..3..3..3..3..3.................f..f..f..f..f..3..............3....................f..f..f..f..3..3...........3....................f..f..f..f..3..3..3........3....................f..f..f..f..f..f..f..f..f..3....................f..f..3..............f..f..3....................f..f..3..3...........f..f..3....................f..f..3..3..3........f..f..3....................f..f..f..f..f..f..f..f..f..3....................3..............f..f..f..f..3....................3..3...........f..f..f..f..3....................3..3..3........f..f..f..f..f............................................f..f.........................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.5099827180334706
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffnEMNQEMN/EmgRREmgRkEUymyVEb4iEAwfqf8EAwfTflEAmpl7mpl0EAhEAE:Ef1Mlg1g4my7boM1MA
                                                                                                                            MD5:F95C9623EB5109FAEF551AF6F0056BAF
                                                                                                                            SHA1:DF8D81F366FA91EBF6ECB3D9A645C6FF76A4E151
                                                                                                                            SHA-256:D2C1AB34760E7F424330CFBF0F74EC08DE09AF24ACE55044ACC1FA262AA24BCB
                                                                                                                            SHA-512:C274A890A458EE30930576306C701C88464DA20A5AF7EB56ED37A4CBB31BE35FEA4BE2AD90A4E6DDC8CDB3C5771DFD86E08C76F2D0C626D1594D8155360E9B5A
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(..........................................................................................................................................................................................................................................................3f.3f..........3f.3f.........................3f....3f.......3f....3f......................3f.......3f....3f.......3f...................3f..........3f.3f..........3f................3f.............3f.............3f...................3f..........3f.3f..........3f......................3f.......3f....3f.......3f.........................3f....3f.......3f....3f............................3f.3f..........3f.3f.........................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.0837920083552524
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffBEMNKEmgRjEUy4ETZEAwfbEAwfIEAmplzEAtEMNH:EfLggxglZH
                                                                                                                            MD5:B269D6CBD494764EF046DC574DFA1269
                                                                                                                            SHA1:DEF15E3638CA21E2B0414E1E0D956ABCAEF6C7C4
                                                                                                                            SHA-256:433444A5738A028C64204156428050A0175700085CCDDDDC559372578D77290E
                                                                                                                            SHA-512:FD13677181323501765C6ED5DD6284AB3F01098DF5289EFC1000C019014A2025FBD25263F803B496788A6796171B253006558C5D9B707EE6C1C0D6CBE49A6023
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(................................................................................................................................................................................................................................................................3f.3f........................................3f....3f.....................................3f.......3f..................................3f..........3f...............................3f.............3f..................................3f..........3f.....................................3f.......3f........................................3f....3f...........................................3f.3f..................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.515437111715756
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffqEMNQEMNWEmgRREmgR/EUymykEb4VEAmplT1pl7iEAwfTfyEAwBwXEAhEAS:EfCM0g1gqtNj/bR2/MH
                                                                                                                            MD5:689CEEF22F64E24BB30B3859C0F63E99
                                                                                                                            SHA1:FF239EA06AB2FA42E338F744FD73181658EE827A
                                                                                                                            SHA-256:8027E3D587C6FE821D0172C7605FEB515D9E44D9CEE1D1533AB6D9B0D0F4E3B6
                                                                                                                            SHA-512:5DD3FC42AB5B6ADDC2519DB8C7EE1E81F6ADA464B2463618145354F6BCA0991C48271AF22339EFB10BC31AC1CB4D989E8864F2937F60440CF89A6419E4D48BB7
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(.................................................................................................................................................................................................................................................3f.3f..........3f.3f............................3f....3f.......3f....3f.........................3f.......3f....3f.......3f......................3f..........3f.3f..........3f...................3f.............3f.............3f................3f..........3f.3f..........3f...................3f.......3f....3f.......3f......................3f....3f.......3f....3f.........................3f.3f..........3f.3f..................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.0865192051963952
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffsEMNdEmgRKEUyjET4EAmpl7ZEAwfpEAwCEAaEMNi:EfIzgwU+Zi
                                                                                                                            MD5:3A29CAD4EB3E670BDDF59C852F13073F
                                                                                                                            SHA1:F43E2201B51B39E1E3690C8FB953153291D1503D
                                                                                                                            SHA-256:F535EB1349FA5B8B8E03B4BAC1E6A5BE54CC527CC60C6D06E5C29F7690F2E815
                                                                                                                            SHA-512:63D77802CD26885BA3723C631EE7C764A6008AEBC36E15548A0D561DB516B24D7DCB5766F773B96F80660B0C62D9E28BEF1CD58B2E6318DD67BA7302126C95D5
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(.......................................................................................................................................................................................................................................................3f.3f...........................................3f....3f........................................3f.......3f.....................................3f..........3f..................................3f.............3f...............................3f..........3f..................................3f.......3f.....................................3f....3f........................................3f.3f...........................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):2.0203789743314697
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12:EfvMojj3uHglf2NOtNK19oTTbroxNEoH2SWCF:Ejjj3uHglf2N4NhmfF
                                                                                                                            MD5:87390EE313845A2C8E33C62F192EDA20
                                                                                                                            SHA1:4E6EFE337211A9AF19C160F3427F98B76FD0E45A
                                                                                                                            SHA-256:60A3EA5724E2AEF1766C93A536950ECE7FE30F815B66C3C7A8104DA5660EA0CD
                                                                                                                            SHA-512:8F2436467B8274CB882356007A28E95EEADFD41F2747819E20FCA32F886EBB683F2DD75412BFCC07CDB8CF1B1DD73BA8C694B22285879DC0BCE82DF1DE5F1B28
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(........................................................................................................................................................................................................................................3f.3f.....................................3f.3f.3f....3f...........f..3..3.............3f....3f.3f.......3f........f..f..3..........3f.......3f.3f..........3f.....f..f..3.......3f..........3f.3f.............3f..f..f..f....3f.............3f.3f..........3f.....f..f..f.......3f..........3f.3f.......3f...........f..f..........3f.......3f.3f....3f..............f..f.............3f....3f.3f.3f....................f................3f.3f................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PC bitmap, Windows 3.x format, 16 x 16 x 24, resolution 2835 x 2835 px/m, cbSize 822, bits offset 54
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):822
                                                                                                                            Entropy (8bit):1.983130860986226
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6:bAlffuXxSzbStOI5StL7Spo27MrDgAL7DX67DMxnSDMqXvVDMmn4qMzpDuMPFud9:EfW8wOIiL8oZlbTxfKv2G6zHPbs
                                                                                                                            MD5:8D92A2FD68161E3054847D31EBBF004F
                                                                                                                            SHA1:83C197DAF353D21AD4ED640F3EA051385FC4A749
                                                                                                                            SHA-256:60A8DB371550D616BEBE903157890498E44E8E171764719E380BFA10D71AF033
                                                                                                                            SHA-512:5929F850B3CD700B86F0D9538EEC5DB4E269B288CC0D5C605431F1AF393D8FF4EF5EF6A2617567EE628A0A61A21A5190BEA08971DFDAB016B164744B0E9E56BF
                                                                                                                            Malicious:false
                                                                                                                            Preview:BM6.......6...(..............................................................................................................................................................................................................f..f..3..3..3..3................................f..f..f........3...................................f..f..f..f..3...............ffffffffffffffffffffffff.....f..3....................................fff..f..f..3....................................fff..f..f..f....................................fff.....f..f....................................fff.............................................fff.............................................fff.............................................fff.............................................fff..................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):506008
                                                                                                                            Entropy (8bit):6.4284173495366845
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:6144:yY8mmN3YWYGAj9JwXScp39ioIKzKVEKfr01//bbh3S62Wt3A3ksFqXqjh6AusDyn:yY8XiWYGAkXh3Qqia/zAot3A6AhezSpK
                                                                                                                            MD5:98CCD44353F7BC5BAD1BC6BA9AE0CD68
                                                                                                                            SHA1:76A4E5BF8D298800C886D29F85EE629E7726052D
                                                                                                                            SHA-256:E51021F6CB20EFBD2169F2A2DA10CE1ABCA58B4F5F30FBF4BAE931E4ECAAC99B
                                                                                                                            SHA-512:D6E8146A1055A59CBA5E2AAF47F6CB184ACDBE28E42EC3DAEBF1961A91CEC5904554D9D433EBF943DD3639C239EF11560FA49F00E1CFF02E11CD8D3506C4125F
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........g.}............|.&.....|.$.J...|.%.....H}*.....H}./....H}./.....~P.....H}./.....~D.........z...F}./....F}(.....F}./....Rich............PE..d.....@f.........."....!.b.....................@.....................................'....`.................................................|...........H........4.......(......8...0I..T....................J..(....G..@............................................text....a.......b.................. ..`.rdata...3.......4...f..............@..@.data...............................@....pdata...4.......6..................@..@_RDATA..\...........................@..@.rsrc...H...........................@..@.reloc..8...........................@..B................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):11200
                                                                                                                            Entropy (8bit):6.7627840671368835
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:clIHyZ36WYhWulWWFYg7VWQ4yWqeQDbLtsQlmqnajlDC:clIHyZKWYhWKhlbp6l9C
                                                                                                                            MD5:0233F97324AAAA048F705D999244BC71
                                                                                                                            SHA1:5427D57D0354A103D4BB8B655C31E3189192FC6A
                                                                                                                            SHA-256:42F4E84073CF876BBAB9DD42FD87124A4BA10BB0B59D2C3031CB2B2DA7140594
                                                                                                                            SHA-512:8339F3C0D824204B541AECBD5AD0D72B35EAF6717C3F547E0FD945656BCB2D52E9BD645E14893B3F599ED8F2DE6D3BCBEBF3B23ED43203599AF7AFA5A4000311
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d....f............" .........................................................0.......>....`.........................................`................ ...................!..............T............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12224
                                                                                                                            Entropy (8bit):6.590253878523919
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:4GeVvXK9WYhW1WWFYg7VWQ4yWj6k50IsQlmqnajlDl:4GeVy9WYhWzVk6l9l
                                                                                                                            MD5:E1BA66696901CF9B456559861F92786E
                                                                                                                            SHA1:D28266C7EDE971DC875360EB1F5EA8571693603E
                                                                                                                            SHA-256:02D987EBA4A65509A2DF8ED5DD0B1A0578966E624FCF5806614ECE88A817499F
                                                                                                                            SHA-512:08638A0DD0FB6125F4AB56E35D707655F48AE1AA609004329A0E25C13D2E71CB3EDB319726F10B8F6D70A99F1E0848B229A37A9AB5427BFEE69CD890EDFB89D2
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...._............" .........................................................0.......S....`.........................................`................ ...................!..............T............................................................................rdata..<...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):11720
                                                                                                                            Entropy (8bit):6.672720452347989
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:byMvQWYhW5fWWFYg7VWQ4eWio3gDwcunYqnajv9JS:byMvQWYhW/BXwulhw
                                                                                                                            MD5:7A15B909B6B11A3BE6458604B2FF6F5E
                                                                                                                            SHA1:0FEB824D22B6BEEB97BCE58225688CB84AC809C7
                                                                                                                            SHA-256:9447218CC4AB1A2C012629AAAE8D1C8A428A99184B011BCC766792AF5891E234
                                                                                                                            SHA-512:D01DD566FF906AAD2379A46516E6D060855558C3027CE3B991056244A8EDD09CE29EACEC5EE70CEEA326DED7FC2683AE04C87F0E189EBA0E1D38C06685B743C9
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d.....<.........." .........................................................0.......g....`.........................................`................ ...................!..............T............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):13760
                                                                                                                            Entropy (8bit):6.575688560984027
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:L1dv3V0dfpkXc2MAvVaoKKDWYhWTJWWFYg7VWQ4uWoSUtpwBqnajrmaaGWpmJ:Zdv3V0dfpkXc0vVaeWYhWj/qlQGWpmJ
                                                                                                                            MD5:6C3FCD71A6A1A39EAB3E5C2FD72172CD
                                                                                                                            SHA1:15B55097E54028D1466E46FEBCA1DBB8DBEFEA4F
                                                                                                                            SHA-256:A31A15BED26232A178BA7ECB8C8AA9487C3287BB7909952FC06ED0D2C795DB26
                                                                                                                            SHA-512:EF1C14965E5974754CC6A9B94A4FA5107E89966CB2E584CE71BBBDD2D9DC0C0536CCC9D488C06FA828D3627206E7D9CC8065C45C6FB0C9121962CCBECB063D4F
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d......c.........." .........................................................0............`.........................................`...X............ ...................!..............T............................................................................rdata..|...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12232
                                                                                                                            Entropy (8bit):6.70261983917014
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:ztZ3XWYhW3WWFYg7VWQ4eWNnpit7ZqnajgnLSl:ztZ3XWYhWVg+llk2
                                                                                                                            MD5:D175430EFF058838CEE2E334951F6C9C
                                                                                                                            SHA1:7F17FBDCEF12042D215828C1D6675E483A4C62B1
                                                                                                                            SHA-256:1C72AC404781A9986D8EDEB0EE5DD39D2C27CE505683CA3324C0ECCD6193610A
                                                                                                                            SHA-512:6076086082E3E824309BA2C178E95570A34ECE6F2339BE500B8B0A51F0F316B39A4C8D70898C4D50F89F3F43D65C5EBBEC3094A47D91677399802F327287D43B
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d................." .........................................................0......G.....`.........................................`...x............ ...................!..............T............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12744
                                                                                                                            Entropy (8bit):6.599515320379107
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:fKIMFFyWYhW6WWFYg7VWQ4eWoVjxceXqnajLJ4:fcyWYhWKRjmAlnJ4
                                                                                                                            MD5:9D43B5E3C7C529425EDF1183511C29E4
                                                                                                                            SHA1:07CE4B878C25B2D9D1C48C462F1623AE3821FCEF
                                                                                                                            SHA-256:19C78EF5BA470C5B295DDDEE9244CBD07D0368C5743B02A16D375BFB494D3328
                                                                                                                            SHA-512:C8A1C581C3E465EFBC3FF06F4636A749B99358CA899E362EA04B3706EAD021C69AE9EA0EFC1115EAE6BBD9CF6723E22518E9BEC21F27DDAAFA3CF18B3A0034A7
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...r............" .........................................................0............`.........................................`...H............ ...................!..............T............................................................................rdata..l...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12232
                                                                                                                            Entropy (8bit):6.690164913578267
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:4EWYhWdWWFYg7VWQ4eWvvJ6jxceXqnajLJn:4EWYhWbwYjmAlnJ
                                                                                                                            MD5:43E1AE2E432EB99AA4427BB68F8826BB
                                                                                                                            SHA1:EEE1747B3ADE5A9B985467512215CAF7E0D4CB9B
                                                                                                                            SHA-256:3D798B9C345A507E142E8DACD7FB6C17528CC1453ABFEF2FFA9710D2FA9E032C
                                                                                                                            SHA-512:40EC0482F668BDE71AEB4520A0709D3E84F093062BFBD05285E2CC09B19B7492CB96CDD6056281C213AB0560F87BD485EE4D2AEEFA0B285D2D005634C1F3AF0B
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d....Y$..........." .........................................................0.......d....`.........................................`...H............ ...................!..............T............................................................................rdata..l...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):11720
                                                                                                                            Entropy (8bit):6.615761482304143
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:dZ89WYhWFWWFYg7VWQ4eW5QLyFqnajziMOci:dZ89WYhWDnolniMOP
                                                                                                                            MD5:735636096B86B761DA49EF26A1C7F779
                                                                                                                            SHA1:E51FFBDDBF63DDE1B216DCCC753AD810E91ABC58
                                                                                                                            SHA-256:5EB724C51EECBA9AC7B8A53861A1D029BF2E6C62251D00F61AC7E2A5F813AAA3
                                                                                                                            SHA-512:3D5110F0E5244A58F426FBB72E17444D571141515611E65330ECFEABDCC57AD3A89A1A8B2DC573DA6192212FB65C478D335A86678A883A1A1B68FF88ED624659
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d................" .........................................................0......Xc....`.........................................`...<............ ...................!..............T............................................................................rdata..\...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12744
                                                                                                                            Entropy (8bit):6.627282858694643
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:R0WYhWRWWFYg7VWQ4eWLeNxUUtpwBqnajrmaaG:R0WYhWPzjqlQG
                                                                                                                            MD5:031DC390780AC08F498E82A5604EF1EB
                                                                                                                            SHA1:CF23D59674286D3DC7A3B10CD8689490F583F15F
                                                                                                                            SHA-256:B119ADAD588EBCA7F9C88628010D47D68BF6E7DC6050B7E4B787559F131F5EDE
                                                                                                                            SHA-512:1468AD9E313E184B5C88FFD79A17C7D458D5603722620B500DBA06E5B831037CD1DD198C8CE2721C3260AB376582F5791958763910E77AA718449B6622D023C7
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d..../}..........." .........................................................0......a.....`.........................................0................ ...................!..............T............................................................................rdata.. ...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):15816
                                                                                                                            Entropy (8bit):6.435326465651674
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:JM0wd8dc9cydWYhWyWWFYg7VWQ4eW9jTXfH098uXqnajH/VCf:G0wd8xydWYhWi2bXuXlTV2
                                                                                                                            MD5:285DCD72D73559678CFD3ED39F81DDAD
                                                                                                                            SHA1:DF22928E43EA6A9A41C1B2B5BFCAB5BA58D2A83A
                                                                                                                            SHA-256:6C008BE766C44BF968C9E91CDDC5B472110BEFFEE3106A99532E68C605C78D44
                                                                                                                            SHA-512:84EF0A843798FD6BD6246E1D40924BE42550D3EF239DAB6DB4D423B142FA8F691C6F0603687901F1C52898554BF4F48D18D3AEBD47DE935560CDE4906798C39A
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...x............." .........................................................@.......5....`.........................................0................0...................!..............T............................................................................rdata..............................@..@.rsrc........0......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12232
                                                                                                                            Entropy (8bit):6.5874576656353145
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:6KNMWYhW6WWFYg7VWQ4eWSA5lJSdqnajeMh3:6KNMWYhWKiKdlaW
                                                                                                                            MD5:5CCE7A5ED4C2EBAF9243B324F6618C0E
                                                                                                                            SHA1:FDB5954EE91583A5A4CBB0054FB8B3BF6235EED3
                                                                                                                            SHA-256:AA3E3E99964D7F9B89F288DBE30FF18CBC960EE5ADD533EC1B8326FE63787AA3
                                                                                                                            SHA-512:FC85A3BE23621145B8DC067290BD66416B6B1566001A799975BF99F0F526935E41A2C8861625E7CFB8539CA0621ED9F46343C04B6C41DB812F58412BE9C8A0DE
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...g P..........." .........................................................0............`.........................................0..."............ ...................!..............T............................................................................rdata..R...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):13768
                                                                                                                            Entropy (8bit):6.645869978118917
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:CGnWlC0i5ClWYhWwWWFYg7VWQ4eWtOUtpwBqnajrmaaGN4P:9nWm5ClWYhWQ8qlQGN6
                                                                                                                            MD5:41FBBB054AF69F0141E8FC7480D7F122
                                                                                                                            SHA1:3613A572B462845D6478A92A94769885DA0843AF
                                                                                                                            SHA-256:974AF1F1A38C02869073B4E7EC4B2A47A6CE8339FA62C549DA6B20668DE6798C
                                                                                                                            SHA-512:97FB0A19227887D55905C2D622FBF5451921567F145BE7855F72909EB3027F48A57D8C4D76E98305121B1B0CC1F5F2667EF6109C59A83EA1B3E266934B2EB33C
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...r..x.........." .........................................................0.......(....`.........................................0................ ...................!..............T............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12744
                                                                                                                            Entropy (8bit):6.564006501134889
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:8a9aY17aFBRAWYhWYWWFYg7VWQ4eWbr0tJSUtpwBqnajrmaaG:8ad9WYhW4F/qlQG
                                                                                                                            MD5:212D58CEFB2347BD694B214A27828C83
                                                                                                                            SHA1:F0E98E2D594054E8A836BD9C6F68C3FE5048F870
                                                                                                                            SHA-256:8166321F14D5804CE76F172F290A6F39CE81373257887D9897A6CF3925D47989
                                                                                                                            SHA-512:637C215ED3E781F824AE93A0E04A7B6C0A6B1694D489E9058203630DCFC0B8152F2EB452177EA9FD2872A8A1F29C539F85A2F2824CF50B1D7496FA3FEBE27DFE
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...h{............" .........................................................0......J(....`.........................................0................ ...................!..............T............................................................................rdata..F...........................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12232
                                                                                                                            Entropy (8bit):6.678162783983714
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:+WYhWoWWFYg7VWQ4eWSoV7jjT6iBTqnajbQwr1:+WYhWIiVTTXZl3QC
                                                                                                                            MD5:242829C7BE4190564BECEE51C7A43A7E
                                                                                                                            SHA1:663154C1437ACF66480518068FBC756F5CABB72F
                                                                                                                            SHA-256:EDC1699E9995F98826DF06D2C45BEB9E02AA7817BAE3E61373096AE7F6FA06E0
                                                                                                                            SHA-512:3529FDE428AFFC3663C5C69BAEE60367A083841B49583080F0C4C7E72EAA63CABBF8B9DA8CCFC473B3C552A0453405A4A68FCD7888D143529D53E5EEC9A91A34
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...+P............" .........................................................0......@.....`.........................................0...e............ ...................!..............T............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20928
                                                                                                                            Entropy (8bit):6.2047011292890195
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:8JIDSM4Oe59rmkUALQe1hgmL44WYhWWWWFYg7VWQ4yWARgKZRqnajl6umA:8JI2M4Oe59Ckb1hgmLhWYhW2v2yRlwQ
                                                                                                                            MD5:FB79420EC05AA715FE76D9B89111F3E2
                                                                                                                            SHA1:15C6D65837C9979AF7EC143E034923884C3B0DBD
                                                                                                                            SHA-256:F6A93FE6B57A54AAC46229F2ED14A0A979BF60416ADB2B2CFC672386CCB2B42E
                                                                                                                            SHA-512:C40884C80F7921ADDCED37B1BF282BB5CB47608E53D4F4127EF1C6CE7E6BB9A4ADC7401389BC8504BF24751C402342693B11CEF8D06862677A63159A04DA544E
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...IV............" .........,...............................................P.......e....`.........................................0....%...........@...............0...!..............T............................................................................rdata...&.......(..................@..@.rsrc........@.......,..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):19904
                                                                                                                            Entropy (8bit):6.189411151090302
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:4SrxLPmIHJI6/CpG3t2G3t4odXLhWYhWfgy6l9ne:4iPmIHJI6vZO
                                                                                                                            MD5:A5B920F24AEA5C2528FE539CD7D20105
                                                                                                                            SHA1:3FAE25B81DC65923C1911649ED19F193ADC7BDDE
                                                                                                                            SHA-256:5B3E29116383BA48A2F46594402246264B4CB001023237EBBF28E7E9292CDB92
                                                                                                                            SHA-512:F77F83C7FAD442A9A915ABCBC2AF36198A56A1BC93D1423FC22E6016D5CC53E47DE712E07C118DD85E72D4750CA450D90FDB6F9544D097AFC170AEECC5863158
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d.../..N.........." .........(...............................................P......C.....`.........................................0.... ...........@...............,...!..............T............................................................................rdata..$".......$..................@..@.rsrc........@.......(..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):64456
                                                                                                                            Entropy (8bit):5.53593950821058
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:1536:Se6De5c4bFe2JyhcvxXWpD7d3334BkZn+PI5c:Se6De5c4bFe2JyhcvxXWpD7d3334BkZU
                                                                                                                            MD5:5C2004DAF398620211F0AD9781FF4EC2
                                                                                                                            SHA1:E43DD814E90330880EE75259809EEE7B91B4FFA6
                                                                                                                            SHA-256:55BC91A549D22B160AE4704485E19DEE955C7C2534E7447AFB84801EE629639B
                                                                                                                            SHA-512:11EDBBC662584BB1DEA37D1B23C56426B970D127F290F3BE21CD1BA0A80D1F202047ABB80D8460D17A7CACF095DE90B78A54F7C7EC395043D54B49FFE688DF51
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d......F.........." ......................................................................`.........................................0...T................................!..............T............................................................................rdata..............................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12736
                                                                                                                            Entropy (8bit):6.592404054572702
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:+nqjd7dWYhWDWWFYg7VWQ4yWMJ5HKZRqnajl6b:+nsWYhWxp5HyRlwb
                                                                                                                            MD5:DD899C6FFECCE1DCA3E1C3B9BA2C8DA2
                                                                                                                            SHA1:2914B84226F5996161EB3646E62973B1E6C9E596
                                                                                                                            SHA-256:191F53988C7F02DD888C4FBF7C1D3351570F3B641146FAE6D60ACDAE544771AE
                                                                                                                            SHA-512:2DB47FAA025C797D8B9B82DE4254EE80E499203DE8C6738BD17DDF6A77149020857F95D0B145128681A3084B95C7D14EB678C0A607C58B76137403C80FE8F856
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...P..D.........." .........................................................0......N.....`.........................................0...x............ ...................!..............T............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):16328
                                                                                                                            Entropy (8bit):6.449442433945565
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:maajPrpJhhf4AN5/KixWYhW4XWWFYg7VWQ4eWvppXjxceXqnajLJhrdCq:mlbr7nWYhW41MXjmAlnJhUq
                                                                                                                            MD5:883120F9C25633B6C688577D024EFD12
                                                                                                                            SHA1:E4FA6254623A2B4CDEA61712CDFA9C91AA905F18
                                                                                                                            SHA-256:4390C389BBBF9EC7215D12D22723EFD77BEB4CD83311C75FFE215725ECFD55DC
                                                                                                                            SHA-512:F17D3B667CC8002F4B6E6B96B630913FA1CB4083D855DB5B7269518F6FF6EEBF835544FA3B737F4FC0EB46CCB368778C4AE8B11EBCF9274CE1E5A0BA331A0E2F
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d...9..b.........." .........................................................@......^%....`.........................................0...4............0...................!..............T............................................................................rdata..d...........................@..@.rsrc........0......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):17864
                                                                                                                            Entropy (8bit):6.393000322519701
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:WpPLNPjFuWYFxEpahTWYhWHWWFYg7VWQ4eW9M3u57ZqnajgnLSuRCz:W19OFVhTWYhWlBu5llk2
                                                                                                                            MD5:29680D7B1105171116A137450C8BB452
                                                                                                                            SHA1:492BB8C231AAE9D5F5AF565ABB208A706FB2B130
                                                                                                                            SHA-256:6F6F6E857B347F70ECC669B4DF73C32E42199B834FE009641D7B41A0B1C210AF
                                                                                                                            SHA-512:87DCF131E21041B06ED84C3A510FE360048DE46F1975155B4B12E4BBF120F2DD0CB74CCD2E8691A39EEE0DA7F82AD39BC65C81F530FC0572A726F0A6661524F5
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d.....v..........." ......... ...............................................@............`.........................................0...a............0...............$...!..............T............................................................................rdata..............................@..@.rsrc........0....... ..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):18368
                                                                                                                            Entropy (8bit):6.28071959876622
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:384:NFvU4x0C5yguNvZ5VQgx3SbwA7yMVIkFGl/WYhW49PBolniMcx:T5yguNvZ5VQgx3SbwA71IkFwNJT
                                                                                                                            MD5:F816666E3FC087CD24828943CB15F260
                                                                                                                            SHA1:EAE814C9C41E3D333F43890ED7DAFA3575E4C50E
                                                                                                                            SHA-256:45E0835B1D3B446FE2C347BD87922C53CFB6DD826499E19A1D977BF4C11B0E4A
                                                                                                                            SHA-512:6860ABE8AB5220EFB88F68B80E6C6E95FE35B4029F46B59BC467E3850FE671BDA1C7C1C7B035B287BDFED5DAEAC879EE481D35330B153EA7EF2532970F62C581
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d......e.........." ........."...............................................@......:y....`.........................................0................0...............&...!..............T............................................................................rdata..............................@..@.rsrc........0......."..............@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):14280
                                                                                                                            Entropy (8bit):6.540126514657828
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:192:qy5NDSWYhWcQWWFYg7VWQ4eWAcSJR/BVrqnajcm2:qU0WYhWcwASJRLlA
                                                                                                                            MD5:143A735134CD8C889EC7D7B85298705B
                                                                                                                            SHA1:906AC1F3A933DD57798AE826BBEFA3096C20D424
                                                                                                                            SHA-256:B48310B0837027F756D62C37EA91AF988BAA403CBCBD01CB26B6FDAE21EA96A2
                                                                                                                            SHA-512:C9ABE209508AFAE2D1776391F73B658C9A25628876724344023E0FC8A790ECB7DBCE75FDDAE267158D08A8237F83336B1D2BD5B5CE0A8EED7DD41CBE0C031D48
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........&...Ge..Ge..Ge../e..Ge../a..Ge../...Ge../g..Ge.Rich.Ge.........................PE..d................." .........................................................0.......>....`.........................................0................ ...................!..............T............................................................................rdata..............................@..@.rsrc........ ......................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1328520
                                                                                                                            Entropy (8bit):6.328591477003584
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:24576:ajUzTjBcyjY4qH3sSH7VhPrnFXgSVfqSVMXLrYvgraB9Z:QUzpc4qHHnvfqSVl
                                                                                                                            MD5:9C82A1B100FF7197B773FCE092D0E443
                                                                                                                            SHA1:8EC4C5689512825986E2AF16B78EC9E10F3D7488
                                                                                                                            SHA-256:340489A1108E112C199049E867F1066A51FFC38ADB4BB78000AA2E55191D1838
                                                                                                                            SHA-512:DF0C470CF62016904A0C5855B2962D68268318AD6C44E826D1ACDD85027DFFDE69361D7673459BA8F3E143D804B708F4B9C97E858FC652468DD68D844A75FAFF
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=.=...........!....."...................@.....k.........................p............@... .................................P....0..................p[................................... ......................p................................text....!......."..................`.P`.data...h....@.......&..............@.`..rdata...N...`...P...8..............@.`@.buildid5...........................@.0@.bss..................................`..edata..............................@.0@.idata..P........0..................@.0..CRT....,...........................@.0..tls.... .... ......................@.0..rsrc........0......................@.0..reloc...............`..............@.0B/4...........`......................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1024760
                                                                                                                            Entropy (8bit):6.139996300511799
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:12288:/RghONOevw0cNh/FmSZA7wVVSG7A0RaSTjFeR5+n+oSduMd:ZghOBvwRh/I6LSCALSqYMd
                                                                                                                            MD5:0A4362FEACEDA366CC0B036BEEA0357C
                                                                                                                            SHA1:CC2629B2BE361714A0E3718B89FAC70B598763BA
                                                                                                                            SHA-256:E012EB68C70282D4D2A02440D32AD6C975B07B75A31C2A068E65FD6F16BC3E96
                                                                                                                            SHA-512:3B005F76D1850775DFF2DE3F0E3C984691EA10D9F7C5775F430D91519360171017EFDB43DB25B8F3AADA28FA7980D8A140DBE4892D9CB778A1445BD9552895A8
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...Q.'`.........." .................3.......................................p......].....`A........................................e...........(....@.......p..8m...........P..............................X...(....................................................text............................... ..`.rdata..L`.......b..................@..@.data...L....P.......0..............@....pdata..8m...p...n..................@..@.00cfg...............X..............@..@.crthunk@............Z..............@..@.gehcont.............\..............@..@.oldntma.............^..............@....tls....!.... .......`..............@...CPADinfo8....0.......b..............@....rsrc........@.......d..............@..@.reloc.......P.......l..............@..B........................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:ASCII text, with very long lines (65536), with no line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):93000000
                                                                                                                            Entropy (8bit):0.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:3:tj1:n
                                                                                                                            MD5:6C6159FD202E6B355C216817A5821093
                                                                                                                            SHA1:1A08F2DA47642695485235F0CD06C499A6B40BD2
                                                                                                                            SHA-256:76241296846A92767493A3BDA4B80D615371FD39EDDEC7A03BE1F034D608BAD9
                                                                                                                            SHA-512:FD13A4D910689B89E653C0D3C97F098ADFAE1FC245B72667CADE1675E9027F4A8B145D1B5FA0C3E9D20E5CD0E18E0F96FF8CDE73DBBF6FAC3E9E3ECD5B219F6E
                                                                                                                            Malicious:false
                                                                                                                            Preview:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):137224
                                                                                                                            Entropy (8bit):7.538421711983135
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:16C9E7021C2A0B4C7F2C9DF843E6F5EB
                                                                                                                            SHA1:348B4D4A45C24D91C081F73471D677B55518761E
                                                                                                                            SHA-256:624155444368D5159736E9CCA825850E278D4C0FFA3BBFCB8099ACC318A05B3D
                                                                                                                            SHA-512:0B5A35F0C7C587B41C3C522F28BB0025B8380EE43459DF019DAC58B651FDB6AB92454A70E84F191158903045D223BD4FC64D615D19E95914066244AC16B28714
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...oR.d..........&....(.:.....................@....................................P.....`... .........................................5................r..............h-...p..x............................j..(...................P................................text....9.......:..................`..`.data........P.......@..............@....rdata..0....`.......B..............@..@.pdata...............X..............@..@.xdata..@............\..............@..@.bss.....................................edata..5............`..............@..@.idata...............b..............@....CRT....`............p..............@....tls.................r..............@....rsrc....r.......r...t..............@....reloc..x....p......................@..B.debug..............................@.../19.....D...........................@..B/31...... ...`..."..................@..B/45.....
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):136696
                                                                                                                            Entropy (8bit):7.5475559987825935
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:8E48E14F5F139D256047726E1A85BD1B
                                                                                                                            SHA1:C59D3646A335CD961C6385C65C75D7A03FE1143E
                                                                                                                            SHA-256:ABC826E4BA8F6ECDD5C0D41DD82265850C8869ACBA14D5D7812E2DB04873A51E
                                                                                                                            SHA-512:7354B421C21662A388C9B78C5FA6ACF82A703EAE6FB4A3BCA99A0CEB16437555D4E8ED1D7F9AF8C2BCD5AD62ABAE13E2DD39E883D15D1091556A4E0AD724F4C6
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...oR.d..........&....(.:.....................@..........................................`... .........................................4................p..............h-...p..x...p........................j..(...................P................................text....9.......:..................`..`.data........P.......@..............@....rdata..0....`.......B..............@..@.pdata...............X..............@..@.xdata..@............\..............@..@.bss.....................................edata..4............`..............@..@.idata...............b..............@....CRT....`............p..............@....tls.................r..............@....rsrc....p.......p...t..............@....reloc..x....p......................@..B.debug..............................@.../19.....D...........................@..B/31...... ...`..."..................@..B/45.....
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:RAR archive data, v5
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):410510
                                                                                                                            Entropy (8bit):7.999530017955874
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B94C8A920D967447D96FF82AA0CE1E43
                                                                                                                            SHA1:DFA79FB8339E8E2E640D4F3FB19B202BE54EC361
                                                                                                                            SHA-256:226660D300611B00EE23692E740FCF829A1333D1CD8CECCC6D4777518D4D10F3
                                                                                                                            SHA-512:E75CD6F63236ABCEA899422BAB178E1EFAAF171EF4EAC70E90E7AF6C95BCD1C99F03D13D85AF9795213A29D4F54988679FAF0F8D81EAE97653B62478535B3F03
                                                                                                                            Malicious:false
                                                                                                                            Preview:Rar!.....^4.!.....,j.R.....Q.P........*z........]$.y.&..b..Z....93.4.......I.(...8.....:.*P8.z.=..:...kw?^..Qg.^..o).$.b6.Y..%Xtp.K[~..%.r.h...c........v.!....+..G.4...Xs. ..sR*.!..........f.......T@w....hg.....\..L......8.t...g0..:h........;n....$..7s.@+.J.x.T.t..Q.....6..T..em.U..-.Kh.`........c.......t1z>X9\.../...l2...%.<.......==LRv..;.r..Z.H.... .%.....F..#.D...g......7VX{`.P..J.z'.h..J.....O...........f...s.1...#[IM.Q.<k..>];.......A...~.......y.@jT.wv...0.....p...l?w.....1..z."f$@0h.4u9g .g..p.k9q.(.F....8(..*...'.>d..3.......B..".E`M.....p..x3.$3.M'.[..x........[.Q..U.f...L..M~.Y...|.\.|...G5..6.....7.V.<.Ox.'.'+..(bz...n.........u".......l....4...*z...Ro..D..,.<{Y.Y{Mj.-w..)F..F=.V.#.H?^.|r.P.o..y....=#.Fs..?..W..Kd.8.'...."g...T.*%.s...HxEz..^..#..g.....$.<.e.]n.&.t>/.W6+......[.{D.&Z!<.q...1..Q..Tphf........Q...a...?.I..b....<iL#.x.....KQ.....t.i~...q...O3...Fz6.....p...q..u.HX.(..S,Lpa.,.5...u.j.S....F.]a.S...m&c.$..{..
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12133334
                                                                                                                            Entropy (8bit):7.944474086295981
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:E3705B15388EC3BDFE799AD5DB80B172
                                                                                                                            SHA1:0B9B77F028727C73265393A68F37FC69C30205BD
                                                                                                                            SHA-256:BE59AC0E673827B731CF5616B41DA11581A5863285FEA1A0696AA4F93796BCC3
                                                                                                                            SHA-512:CA44B3E7658232FCC19C9AD223455F326D34B17384E566B8CAF0F7409D71B2B86F4089BF4A35128EC6CFFE080DF84C69C72C22B230FB0F2F8CB345442318F737
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class.X...e../.l.!..!.#..M..."..g..#.B.........0;{.AAD.EE..QQQ.aG....{.]....7......~.{....k...{....<HD...4.......x%?G.4_St.Z...\..].+c..t.t........iC./...gZ..].8C..D'M...\3.+~5......z.<.f1..2.v./.As.Lv.....`2.M%...d.h..S`....YC.....D.u0-l.V#.5.,.e..)[..[.v..*............d.I...A........A+&."..8g.)"..E..1!.Z.]....Ak..5.......<'..L8bC..V4.U2.~$...i....)."I...O...d:......@..S...w0m...-....2..x....z.....O....k.8.}....P.....=..I/...<../.d..k....43VL.i...........C.S|`..!b.8....3.Ey..S..e..+.../T..j...g..B.@q9.."..>.LU..2-i....-.!....Z....g.BGl.j..R...Z.D.YJ.Kd...9 l.FN4.Rk.22..b..Rn...u..x.,...j.I.aZ.....X[{L.e..Z#..`.Z...*8..[.p..0.(...j..W..-M...V..H7.c.KN...5e.."...t[um..R...UF.c..1.....z|z.EeO..j..k.V..\x.8.....et;.9.^.Pa..+......U....Iu.q.t....HY.g...q.......omK...FKr1.F..F?.i.d../.]....68..L.........W..s.CU.|y.....zE..Q\...82..W.i[.#Q..xm......P..u.<.#...yC...,........~B..|sF.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):41127
                                                                                                                            Entropy (8bit):7.961466748192397
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:D039093C051B1D555C8F9B245B3D7FA0
                                                                                                                            SHA1:C81B0DAEDAB28354DEA0634B9AE9E10EE72C4313
                                                                                                                            SHA-256:4A495FC5D119724F7D40699BB5D2B298B0B87199D09129AEC88BBBDBC279A68D
                                                                                                                            SHA-512:334FD85ACE22C90F8D4F82886EEF1E6583184369A031DCEE6E0B6624291F231D406A2CEC86397C1B94D535B36A5CF7CB632BB9149B8518B794CBFA1D18A2478F
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classU.M..0..../..........LL...*A.$.t.\x..e,U.N.N..7o.....=B+..,.@..:.`.....`....L.,.".B.M......:...._..uBGf.5.M..g..."..8K\..B.".z..|=6.=1.KB..v,.yJ0/......[.r..OU`....Q}...kP.94oh...b..K{...].'PK........#...PK.........n/Q............2...classes/java/lang/instrument/ClassDefinition.class.SMo.@.}.8q.4M.@.h..b;... ..d.RP$.c...#g...#@.....@.G..........7o.......@.-..J.T.eT..'.......tt.=.P9.C_t.J.5... ...Y...z|*.(..TE...e.....(.......v?pg....<...I.1.:....H.U...1.)..p...P.......|...04..Q..2...%..8~.......#..p"...n..<.Uq..=..:.c..1.2...x.o.w..#....^?q.I..:..Y...6...N..c..>2.k.U...L..&V.H...%....y...[.~GJ...B/M......%...t....+.I.E....H..}....m..j_..8C...:.n...(*..z..Z.Q...$....a.}..T.xW.$....52...T.o..mSL_~.L.FM....W.z.I.]....)..e.....A..$..xH...Td...0i..."...0X....PK..X..~........PK.........n/Q............7...classes/java/lang/instrument/ClassFileTransformer.class.S.n.@.=.8.M.n..b^-/..G..
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):113725
                                                                                                                            Entropy (8bit):7.928841651831531
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:3A03EF8F05A2D0472AE865D9457DAB32
                                                                                                                            SHA1:7204170A08115A16A50D5A06C3DE7B0ADB6113B1
                                                                                                                            SHA-256:584D15427F5B0AC0CE4BE4CAA2B3FC25030A0CF292F890C6D3F35836BC97FA6D
                                                                                                                            SHA-512:1702C6231DAAB27700160B271C3D6171387F89DA0A97A3725B4B9D404C94713CB09BA175DE8E78A8F0CBD8DD0DD73836A38C59CE8D1BD38B4F57771CF9536E77
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classuQ.N.1.=W......n\1.D.5$&....T...2%....\..~..3(......9.6...o....%..:L...x.=..p..L.......".Gm......*..Z9.R+...}x..$.Y,,..-..z..{.v.K..:9m[.dl....Q#t..F$:5c..h.*.^x".8 \N..A!....O....@.0.Z....p]......0_(.mB...=.J..<.k"4....g<......M$,....:Kz|..^.........8q..{...}.*G....p.S.W...l.M.....PK..R...).......PK.........n/Q................classes/java/util/logging/ConsoleHandler.class}S[o.A...KW..jk.....jy...K.b.R.mH|.......2.K....h...G..,..K...s..r......7....d.u....C...y3..j*..2...1..!wx..2T:.T...b.^..`.D[...0....n.cXy#C..e...=.E.....]..%L..<x.....W........z..u.s..a.e..Zq..-.E@n.!..)....F...\.E...<...[.;W..t.i%.mT".w.x..(.m,...r.....tZ..vPepFI_...D..b..0.U...S;....XP.@..C.#Cq..}aNy_..ZG...q#m<;..g2b.]"..Y.....[7."+..#"wOtb..-..."..@..(.>Y0......C.h...?.~..8A.Mp.....N....Z$ .E...."o.E.uz3;..m.P.z.....7...?.'.q>...2mN.gLv...q1..[}..@~..M.....K..sS.....PK....0w........PK.........n/Q............,...classes/ja
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):896846
                                                                                                                            Entropy (8bit):7.923431656723031
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:C6FBB7D49CAA027010C2A817D80CA77C
                                                                                                                            SHA1:4191E275E1154271ABF1E54E85A4FF94F59E7223
                                                                                                                            SHA-256:1C8D9EFAEB087AA474AD8416C3C2E0E415B311D43BCCA3B67CBF729065065F09
                                                                                                                            SHA-512:FDDC31FA97AF16470EA2F93E3EF206FFB217E4ED8A5C379D69C512652987E345CB977DB84EDA233B190181C6E6E65C173062A93DB3E6BB9EE7E71472C9BBFE34
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class.S.N.A.=-.............^PQP4F..|..]{.........S|...(cu/..i.d.z...[....'.M|`.M.GrI.).1.4...8...V.b.EE.Rg...zV.K......Os.W.S?.e.GY.Q`.od..d..Zf....2>.B.29.D.3L7...M&....8.;..2...}..n..n.g...S. ?..._V..Q..9mBo0L..~dD.t.c.ric..2r5qLvr..V....Sm..I}.}.a..Od$2e..M.v.m..w....L..s.C.;...#.f..Ln.......5..9.2....5......P......M.$V.|;...'mw.Vl.2....D..1%.l.a..o...O....!.......h...9V.L.x..?..n]/.6......iVe..{.4.K..s.[....y..|2....3,`.a.....H69.a.;09.5K.C....a_.G.`Jm...ER......9I.D.n...Wp........%..WI...tf..pg5..SN.8y..Y'.:9....U.pq.....}.]X..aE....^t..x.l...^....m.#.......a."r.l.2..Lf).y.^.h..u....PK....N.i.......PK.........n/Q............0...classes/com/sun/jmx/defaults/JmxProperties.class.UMS#U.=.aH.4.4.....J2...h..6v.L2q.......tS.)F........\.....Y..h2...*...{.......w..8Ha.....p.C.c..C;..^+S...F.0..xNt....J5.$.b.og..9l.g....Q..k......"..I....b....-..^.n..<x..4.$pY.(..,\~.F..0...Z<`X[...(p...u^.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):92135
                                                                                                                            Entropy (8bit):7.945919597257173
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:22F603FFB69D73089DDE462D567E88C9
                                                                                                                            SHA1:7ACF3CADC41F208280B8F115C2EE58FE16FDB538
                                                                                                                            SHA-256:27047E3D872637D62DD251A1E7CBE0AE5F1DD1F0F275A06405E6C673421681C6
                                                                                                                            SHA-512:AA7ACDB5DD69CE5C8C62E4A89F65F94DD9316F9364E30EBEB66A542FC418FC586EC41B0D13D41548EB05B4B96E22113B879D20B9F146B935D8B6CB3826E78A51
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class.Q.N.0.}C..............J..*U..W...%....G.....G!.......g.o..=.o./...qH(I...~,..... .>#.Y.$S..%Wi`..1M....'A...i.v{*..ah..)..J.Q,.-....'.S..OR...i../.1..J..3s.....I..>*..7.>.....m.P....9.-..~S.n.5.R<J.i...17y...?..6.a...Y#..G.>........-B.F.L.D...5....GE.E..B.P....yJ.....A.........xMc..9.]..1c.E.n.q.]..b.e...&..\^v..Vm..M...g...=.-c...>.PK......a.......PK.........n/Q............6...classes/com/sun/jmx/remote/internal/rmi/ProxyRef.class.UmS.U.~n.YI......j.$@.VZ...k.64%.4V@.\aqs7nv).........?8~.G9.{.$1....{..y.9.9.....O.E<O#.!.I..H1.90.M.6.Q.=.u.!u...w.a(....5.hH..@g......q.<2\.t<nX..0m.mZ...}..&mW./V..y...!w.u.E"....pF.Y.c...d.]n6..:....:...x].-.+.k...L2..p-...........c....%..o8..\..%...KRi.a.O.#T..%"l2g<...(nW.9/...{....+.d..\n...M\c..q..).f..P....u.s-..P....r.../d0.[q...l...-..b...h.....9.,...o}.&.g....oI..:...0..|d..KN...,K..:..bW`....p>..=.;..L...69......P.....L..L...?........?.k...?.%..
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):460349
                                                                                                                            Entropy (8bit):7.928980735357845
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B396D42998F877CBDE5B93A1B238B5C5
                                                                                                                            SHA1:ED864130A63A807EFC16CE9F97F8C24750A14C35
                                                                                                                            SHA-256:734130C3E9D7A12A75BBB194C9FD29DFC85FD802B42B3CCD2C617C86FC905473
                                                                                                                            SHA-512:8E44D12F37DE7A1F7453299FA0A3ACC566C2959A1C482DA936108BFB6514650AA3E2400AC090B65F2FE3FA53BCFF4F676D129695B10334B4160B45EF3B440043
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class.Sio.1.}..KO.f{p.Hi8J.-..DU.T...3..5.9...........G!f...$..J...g...........3L............ ..CA{2.h.R.V.(...V..l0...M[..oF"..1...\v..q..a*...s9#.q..K}..#.eyh;>.^.F*.Q..m...8(..<..AA=..XdX.q.p..L........ur....u......[.s}.<..ju...wU.%.C07..B.......42l....$..U$S...&...#.g.w....,.a.+....^...0S...u."m...ciK...J.B..H.A.|.&........U.OZY%..c*j...W+.O.V.M...dG.j......y.r.....$.s....P...ab?n...UMI...{#.uwR.aC...w....e.>R:..LE.......z.(..l=....2.1Z?:...n...t~..;..-;{..Y...|./.:..<.&...N.%....8.)..9..%\..,S...e<.[...?PK..._./....$...PK.........n/Q............=...classes/com/sun/jndi/ldap/AbstractLdapNamingEnumeration.class.Y.x..u........S.,a....JF..."#.h.$.X...v....5.1....PB...Ml -N...%...i.;.>..WhC.I...G..A....h..d.M.o.....s.....]..W^..........A.)..a.[bv|{...N.U(j..n.BaC......B.F..BK81.J.[v.#.X..j..O.I;.v.e.=..o.....F.q.+.s..QP[E.,...f..w.Q'.0...v..... .l..s5.a.B0...R-.Nz+5.Jo`(..KG..".pX...K..
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):718964
                                                                                                                            Entropy (8bit):7.932673218886782
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:5A11C4A6D94E1C67F84D2D22B7012B11
                                                                                                                            SHA1:273C3A253F6845441C6B4D0AA000BD0860574EA8
                                                                                                                            SHA-256:AF1946B6683575D724430220DB7C948AF2598E69091F74459CCA1F97A15C2A54
                                                                                                                            SHA-512:841460A10900517CEB80F734F1492AEEE83287ECB521BB5107BECA3684189521D56F9CD2B17A136C521884124CD1F307CE51F63DABCAC60247960BBBFAC046BA
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classu.MN.0...@..K!...8A.*......n2m.$v....b..8..IAt.F..x.gKo>..?.<..It..y...n........I...Ul.1+.5B}r.....Y..L.A.......T.x....J..:I........T&,..W.XI?.8&.T.r.f.....Z.....Ch..u..S....\n...5/.g9.....d:gc...t..e.<.m...F.C..C..:.=. .mA.M....M......(__~.PK............PK.........n/Q................classes/java/net/http/HttpClient$Builder.class.T[O.A...(..r..Q...^X....E....%D..vw..e...b.Y....?..e<;.(......w.7...?....(c....Z.+ .~..]..s#..........b...sN.._..!.=...@.8..T/......|..P`(...h}..P.....D.........F.....n....F..z.7...%.a.rO.U/..Tk.#.J'.p.L..C.."....\&.....i.]N.....i..8..H...,..L..n.Qm....)..)o.k.b..K...l.6oq?1'^i.h....~..9........e....<..v....t.;u.m.R]...+Whn.8e..@...>b.v.2......g.;5.iz..).{f.;.:.lr.fj2L8...z..PDB/0.:3[.}..p:....z...j.k.4.o.D.|E.?.."..zzcy.We.-..K.mI...]'U..8...V;e...&.....i..Uo..ioXm.^7....1....B......:n...[.oc.....,b..]L.......dp...>..)..cZ...%..../...~......s.^....)..|.Y.q...v.....
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):54624
                                                                                                                            Entropy (8bit):7.943156238505704
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:224D8C26B9454FFE244D354BC030CAB9
                                                                                                                            SHA1:E531A7BAF213D72964CE4DD83A11AEEAE5713F00
                                                                                                                            SHA-256:43622935A7EF06E30D1BDA7E77CB76488DA9E721728AE0B8ACDB1F9C7B91C943
                                                                                                                            SHA-512:E0754FFF5801CEB2B1512AD0DDDF0D74C4C2AE97EE70A467E7D83E3AE5870A6ECC6F250B849108923AA8CA94EA3505C4CC7C9BEEBFC192B2DFF1E99A943DCBB4
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class]N.N.@.=W..K....--$.=;.......J.!3....r...Q.;.&.Y.;.qs....'.9..N..:.qV.u."....zS.......h...h.M.}g.u..w...-.~Q.C.....<D.p.o#^...2a.PI..{..T>..$..r...?.ps..T.U....YxVf......T..X.....\..5......J.).}tn.g...T...=......PK..t?u.....9...PK.........n/Q............3...classes/java/util/prefs/AbstractPreferences$1.class.S]O.A.=.nYZ.(....Rd[.._/%D$..R.h.x..C.\w..,..H_1A%>...Q..M.iL7...;.;g...?~...q..dmX.r.c.;...k.W."....-.#...4...<.J+.}.@..2..=0j..#o..`..C.p|....C.i.\...k.Y...c..6..F.M.......P.p.c6..L.*......X.....f..%#..\.u.S.n.&....a...0.....>...... ..f...mr..D.w..l.2L...^.I..."../.bo..2$...t..&..F.'...2...CKDoy..h=....L.i.J..a....J.apGs...?J.....\0..;..p.G.y~.P.......F...0.<.)..].........C%.......x@t..Q.4..Q..RU4../BEU....m.\)...2T..w.......R.@..s4Z#D..Be.+X.;./4.......k..4.....Q...8R.W.a..r.v..3.~.m}..=...}..dt..#.P.!3...Ix!...D.T.......R.......L_.2.....<4.!<2...E..PK..]5\.H...`...PK.........n/Q.........
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):385108
                                                                                                                            Entropy (8bit):7.9135425794114935
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:C4BF3C85D5A2B5A2482D29682F937339
                                                                                                                            SHA1:2ACCDEEAD4904C6EC919771CE49943C9D6E8A9E9
                                                                                                                            SHA-256:25FDC4D19B9F9BFF599212307C35ADE3C5B14D8FA326352837E2AC1919A27679
                                                                                                                            SHA-512:51908DB9F980EAABB144C3BBD38563DF0DE3AD9AD286FD4D4F5C41B4F2D70CF278395E123D8C26A64742858A4B629902532C0AF097D020EDA92A7031AF586B66
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classeR.N.1..*......E....ogX.n.411.../Pg..L.i....\^..>..Lwg.b'=?...z.........8eX.M6*dO.K..cX.......J.T.....'.Q...).7..E..q...+.c.!..D.^..WFs,3.4.,O9V.....\9o.pt.....K..Z..'.+8"j...09.&.....g.......q<...H{UJ......Kx../6K.......z.].....C.g.Ka........\.<.!..dWq)..e)..Ik...t...T.+.J..F;S.m.a..4..g.>...Fd..U..C.<..Q....,..4...E.Wt.#..p!l.=....v=Qf..7...k.}T..........n..p.M_.V......F.<.E.............b...U..;.;.R^..;.AL.(...({....8Tw..PK..{;\l........PK.........n/Q............R...classes/com/sun/rmi/rmid/ExecOptionPermission$ExecOptionPermissionCollection.class.V.S.W..]..aY.....hQI".UAJ.V....*..k.\..f7f7......K_./}.C....L.38..8...C..7.........#.:.>d.....;...9y......|!....n...2.^R...g3.=.>.3).4..6u..mZ1.vh.fw1...#.....kY[....5i..:.!A.j.....H.*P)a..*ld....5.dB....i..J...v...W.)O/.-..X.$.ay......K?.2O0.1.[.v........U#........$.)n..q...Qh..lG=..:.M#..g4{.V...6Amn....H .le..hF2"c+v.p............e40.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):44965
                                                                                                                            Entropy (8bit):7.9310029341229376
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:A64194B2F7AD00E12C9E5AE260B57B3E
                                                                                                                            SHA1:2617AE8B733B5E7B31180A3EED1DDFFD1B5CF631
                                                                                                                            SHA-256:BC08974AF0D13B1B362A651329036C24CC54028F1D0B3EB327350B51E2270FA5
                                                                                                                            SHA-512:68FE47540C844FE28B92C0AE4E8FF5C77F60A4AD0C5F1F3857412DF36E11A6053697B823E7C3D653E012F1923502DBBAAA9B03803A24344DC5C384853A3D44F8
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classMNAN.@....PJK!9q@|.Y*Q......|`.,a!.E......x.....>x.....o.7H...eM.g.>..D....|..I..W.y...c....".L.3.J..+j../:...(.D..v.c.'......:.p.+....67V/..]..aL8\..Rzi...w.G..+.z.........uM.......d.]_m.....c........<._.S6....I..p..i...PK..=..+....F...PK.........n/Q............*...classes/com/sun/tools/script/shell/init.js.<.s....@47.]+.......K.......];i&CK.."u$e[.......AYI{.6.....]...<....^=.V.:.Z.*..G...>....0Q.u6-....AU..mT6..E...I..P..Z7.....}....z.............W'/^.~w..4U.4Z.j....Um..|.Kx..z. .?....{....>.....U?g.....\.E. /.|]N.*.\..h64....X.`.U..Z5.... .R..j...QU.p9-.]h5......^UI...k]vx....e....^.f.U....'.Z?./.j...s...V.c.O.<...ROTV_5{.|p..i.~....-........v..v..+.).a......<T2....H.,t....6..l..9>X/u.64..n.O...s......Q.R.Z...j.g.r..G.....^O.&V.%.e."X.=\F..u].e>.e+........n?~T..,...,]..].-.:.0..................L.K..^...$..B..:........p...~.H.l:.M....5.u1k./-.7B.^.%.f.. ...w?....8...\g.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2207
                                                                                                                            Entropy (8bit):7.650310282866788
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:3B4DCB7D28ED3DA5F09ADE9FDE137D3B
                                                                                                                            SHA1:0EEDA129FA837E4D5E54F678249C7265C96BE4FA
                                                                                                                            SHA-256:4BD4726EB7772FD1A202DF3EEF6367ED66688E0603C4B970D22AC8EB560F2A04
                                                                                                                            SHA-512:BBC8165555B54BCE7E2342CEE798F93245B0F5A4B6E9CD9CCBB28F7EF42E8B4E3DD729DB95E7B027CE955DB27FA3B8555D8015B568CF8672A4BEC9DC6028EC1E
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classe..V.1....2.!.xC.&...A7.....=.68.4IF`..gr...P..k.9...K.OU.........p"0_..hh...|.B..@P....h5..FbJ`..A....,..t....9,|U........:.....F..X..&.H..X.Xf...2.I,./K.J.NN.....I....Be%...o8]q...Bg....].D`..:.A.x&0.1..B`i...N|.K...^..`.:/#U..O.:.%v...."..e4..uv.-.E..+-q.k.*.}.k)RE...../~...zN_s._G../..P.D./...}]].?.....c.Gh.I.......X..M.;.-..s..f.0W.....S.s.&s....e.3..o...G._...PK..U.FO........PK.........n/Q................legal/COPYRIGHT.VMs.6...W..L.I{ir.$n....N...J.A..@).I..}...e.i{.@......C?F..f.....KC?.}.kCwQ*gHz.S.ds"..Y.MZ.K.X%.&..3z%..M.B..2.S|t0...:..6x.}.;..i..D..Ye|..&..wI..Xo....h.['..!..B.\HC.W.g.8.z$.q.....Kob...=.p.].>.Ld.....H.........H/a.(.sa?E...oR'G.!3......j...A..'.....V2..m..5H.....ex.z...m..........a.l.6..7{........v.3]..(..g.|E.fg"^d..zc".-.dJ.[..M.6*t.uS.BKy...Ys`./.k.......yaZ..........U'.....&.n.&...P....F9..J.1bo.6..I.]%....x..../.1...[.u....ey...-.Ag$H@.BD....xHL.>..V...>
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):698330
                                                                                                                            Entropy (8bit):7.957481640793777
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:372B6F9949895C86164FDF3A1E99CAC6
                                                                                                                            SHA1:B9D3ECAFAE368E7ACDADCC347DE6FFC08D031CE8
                                                                                                                            SHA-256:934114BA650D81262CFE3CFBA0D5A190520C05CDDDCD9A7A875E3E1D951AD71D
                                                                                                                            SHA-512:2DB6F0FEAAD1DD724447CE6E1E1CE92C5293AAB8A661031BB4B343564703BA033410EB0BE56B223F2F8901CDF158530503C0F5B6459D7918253C3AC7CF99F029
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class.R[O.A..."."..........P..w.LH..d.;l...lfgYy.w....G.g/.i.L2sn.d.......>.#aq..t$.At.j ..?.g(..a%.N".T.....I...a....;....._".H..R..V.C......iNy..@.I.G..,.x..Q...11O.H..a...Q....K..)7.u..p..:.K.IX._..."lLG3-.Xj...Q.v...)7."#u$F.......u.;...o..........a......3...}...]u5.jW...R#....;.&...P../...K...8...^._.z.$...`-p.<...Vg.'u...[..<I.+.[B.D......t.R0..(.c....^..*./.%s.D....{G...-\.9...qd.7........S..B..a/..r!..^.v..\.v.B.+.7....;h.zu.m..+`X.5...#.........S}..PK..CU\.........PK.........n/Q............?...classes/javax/security/auth/kerberos/DelegationPermission.class.V[s.......,.....".f-a!..+.Ip.M.q....0...x..h...,s..Il..vl.v..0.I..B.L.-....C^...<'...T.....8..;.}.w...............`...$L$...}.Z...Y.|;\.>f.v.9.W. .=W .....a...qm.X...T.........l c.].=.L..pV....?+}/.>..9g..m..P.TV.*.-..ZDj..@.@.^.B...{...K?......[.r....B.Qeub....W`.+.C.*.up.~..vb...&.......$Q^.,'XG...+......xD...0.(....\T.nxb.(...,;.ob/..
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):81698
                                                                                                                            Entropy (8bit):7.940663737798511
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BDD7FCA80A0E7436DC46FADE0C8CD511
                                                                                                                            SHA1:C491F4A649B8DB593F26D25133DD104D8985AE60
                                                                                                                            SHA-256:F783A14F1FD9E804553F54E8B97E38A5BEB8C25ADF096FD380FC1BEE391153AA
                                                                                                                            SHA-512:6DD0A97BC791E78C28E1D1D949911B94DB3E2B08E5055283AD0195E0897E7984FACB517FF8E6C7B6E78E310819AFCBEAC9876B0FF35370AD96539C3E8B28C134
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classuP.N.@.=..r.h...-$........,..t[.7...?..2N....Mf.\....O...&4...C9V.kR..:...\,..W.....*{w...2.2.u&......y.n9n..Q%...\_.Rg6j..~F......<S<.E..uo.G..jF....B..4a........;............{o.&K...S.h....P.J...*..G..;..3..B..g.x.i 3Bk.b?Y....5P...q.">..q.C.+...E.6..:..l....gl.\...#.........PK..... *.......PK.........n/Q............5...classes/com/sun/security/sasl/ClientFactoryImpl.class.W.w.......,lc.hB.b._.@.C...&26.6.nH..X.UV+.$i..6....> }.m }..b....9.9.I=).7...-.9m.W3........[.n.h.....G.7..*....HJ5."..Gu....0L..).ij....U..AT#(.f.#....Z.6..HV."....N..9.=.....d...g.....$..0....A... V..6/...B.9.....).......5A..:.`...Y)C3t*T.u.....l..O`Ky.s....z...R.Z......o..o......`.@cy{.'..6.T....GX......4...?vpW..=..... ..a.1.;.Y..6G-..2.wX91.s.#..J...D$V..U..n.7.-EUA..Cw`.V.t2...V......U..M`}.'.v. .....wu.W.C.....R.a........W...GR.d.O.i.7j.HE!..n*..CK.-#..../..u7.G..M.8.e...."...<.a....p.+.".G2j6{.G.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):58645
                                                                                                                            Entropy (8bit):7.913344050895434
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:4C54BF6DD5C142E6C8C1A360C985167C
                                                                                                                            SHA1:7449C89D087ADC871E26218F6AD82FD1FF5BC01D
                                                                                                                            SHA-256:0AF33A68F7B71F12FA3B7F27BC69B80A86633F25EB82830076ACFC3170538EC0
                                                                                                                            SHA-512:2C5050F04B4F7AD373CDD33B3874A38AA317C996DF27630D4AFCD6F2ACCEC6A5ACEE3ABADFCF8D0182104651BA68239FA13E4658398F9F92D0E1C6D4B4F4568A
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classu..N.1.E.Cd.D.A..gF.t...$...i%Ef..S...........6i_.=..........B;W..H..*...GB.b..$_".3]fLs.B....}t...=._.#.G@..[.FdV.../m..U....M....h..\......Aqj.d...\.Z..:..r-...O.....e/l)... .^..........?Lv@....|..+Woq...\..S...].f.a.9.B.:{..PK..F......k...PK.........n/Q............#...classes/javax/smartcardio/ATR.class.Vko.e.~.t......R,....V.j..m.ta.e......v;....%..5.D.D..1A0.....\B..o..'..A.wf...J.0...y.s.s......2.."...P.a4...jOY5&z.....#.G7tg.@.+..".F............e....t%sK.3.X.f...V!*....{...r..U.....V.+J..1..<...5.6.uX/.l;...m...Z..Yy..C.<o2..\.Ql.s.:c.......h3...e..E.2+..Z.=[g+..P..1l....f.im.4..sZw&9#M..iWv..#.....(..T..!..5RUG/..I..k...eN.......t....D&U.AJT;..d6...`g..d=Z]<..........lc.J..{R....WY....f.jY....D...2.Y.n....(.a.....j......[..b.>..@.#....hu..Y..`K.dQ.*Q..7C..,...vD...0aa...M.............YG#J.+);..;.]....M..+....."....16.Y...,;d.3.Y...D...;..G.W...*.3..g.....VqX.[....5......
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):76011
                                                                                                                            Entropy (8bit):7.806124696487568
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:E910C6B0413AB8D4CD0A5EBCCDA387EF
                                                                                                                            SHA1:6782B1D03ED398C4AA558C219294C6367F7C8479
                                                                                                                            SHA-256:2A24C132034F0894A0AA38A2DFA546F6D20113783B791EDCC9831DFC144256FA
                                                                                                                            SHA-512:A729C0449FD21D633E5F70B8FE98876E96FE7559DE0E4E137A55B329403B624D6F298B2D4BBA061AD4049DE224CC2A2C3B6FA2BDCB13430BE78E84992D537B2B
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classM.MN.0...../....@]*A7l.;$$..I.eHb..m.=........Hx..........p.K.05.&......D....]l.._.n?........|...s..A......_...C....(.3.0&0O.\dVD.6./..M+S.vD..!..\oe....g..#.....y...&..ID.BI.Bk."r%..x.....B...f.t..NP.........}.........~/l..s.g~..8.S..PK...p......k...PK.........n/Q................classes/java/sql/Array.class...N.0.."2............FH.h..Dg...,#s.3.j^..>..[1@....dY{.''_...O.0.P.....Q#|u.. .....*Bs.g.....p.e..........#P..9g...l.@..}.|.P....,...<...@.+z.C ..h!.O[`..>U#.F.....Y..Q...|+.h%K/(.....i.l....MGi...j...\."....-..~.T<......\o.q.y...d....d....a.......5....v\......2....)._....k.K.7.J...R...R..\.2.RP..z..P...T.&.U.+.-.4...Ag...Y|..w..PK...?mb...&...PK.........n/Q............+...classes/java/sql/BatchUpdateException.class.W.s.W...+.k..8vl)..$N#._q.I.7qS.i.(vR...).F..JdI.V.(.|5..|.xf.....q2..2.e.7...x.7.x...sw..m..0c.....w..s..OO....$~.C.....-.=...X.......K..f...s.-.er..@,.R&Y#.26o.3....3..
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):190817
                                                                                                                            Entropy (8bit):7.967262446791647
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:435A6696E8BABB8D66B3D838FAED2BF9
                                                                                                                            SHA1:4EB408C7D7E6A347CC6F331CAEC10DE7F55FBC57
                                                                                                                            SHA-256:3F55459BE1A9E300D872F712039F975A3C5BCCFDC498CD0A603A465DE8633300
                                                                                                                            SHA-512:D3D8D34400230FDDBBCDF469786869FCDF50491CDDF70B58ADCB33E959A5ED8649E374E714FFFFA7AA2D4884042F09B0FCB7963402B65BD48E1634D099E2B2BA
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classeP.N.0.......hy.......{CB..0...I\...[.....G!6.E.Z...v......W8e.F.../.GU.ch.!.'>...,8.K.h5KDj!.P.\8g....M&...m....9W..1.m..:+.X...NlTi~6..i..u2\e.Dh..6..uq,ml1....x",X.5S.*.d.X...&.!...._-.1t...l$.!.R..8`...D{b(CA[.1..,.[.=.@$4{A.s....>..O.}....s`.....:...kl.......a.......ep....n..K..FY...q?..PK....:.:.......PK.........n/Q............/...classes/com/sun/rowset/CachedRowSetImpl$1.class...N.1.....K..RN=.(.$.e.R.....AE.....Wt.X.h.....V.D..E...UuvI..Ua%....o<...??..X.4....B/a.....RN..ja.....vpZ.f....-.z..y.W...3.C.B.F?lB..=q..UMgs.@x.aKRI.L....i.`.B..}..............jiwk{...Z.&.U.=.L(U..2.Q.c6..!a"..9...G.G..+o..L......Fi.*O...o3...R...D6D.~.xl...r.aK...w.g.9a&v.....9w.By"}....'........|..(...R..`.+R.j.pO.;./.......PF.1..4a..:..H.\.I[.!..e.JO.i..fmp....k..}.&..5..........t.{X.B.....k2J.hg.s..sZV..h...a.....*.y.h.s{])..|Wk.1.5...3P6.=<~.=..1....-.".}.8..T........./k@./x<v...r@<J......E.............
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4035
                                                                                                                            Entropy (8bit):7.63515724105447
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:FF54FAF2ABD3B1BD2B868FEC043BB19D
                                                                                                                            SHA1:C6EBE8364D84B85478C164A6A6A09FEB4394F6A6
                                                                                                                            SHA-256:D73340591C1D956650175CDF0B12F5523EE5D5644ECDAF663DD7F44EBC28290E
                                                                                                                            SHA-512:F6225B4F0FD673226F20D8BFC9A99851FE230C7DF59472FE07269B83A52F52E5878A39B9B2C55D8435E98C140F16BC383AEA01D4AEDED5BC4531084D491A3B37
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classMMI..@..v..x......7A....(.L.....>.G....:tuWWQ....`.....z.C..u.Dp..q...<K".84..J."a..Bm2.c1!..#..YF..Q'4....$.6...r..2...*B.X... ..S.[..2&8w...n.|....(...w.....f...(._B.?8..j.<...PK..Z...........PK.........n/Q................classes/javax/transaction/xa/XAException.class..MS.P.....R.a@.?...(U....&..4a...7L(...:iq...p.q..?.?.7........>....;..r......J.....o.t=p+5.\....^S.....c......$..Q?.O...I...9.....E&&K.#....L...b=.+...81:..n.a.....d.[.#.3.y......U].^By.Z...J....{....}..ZG...ag2JQ..X[....#.d.C.Z.BN..^.R.....\.`.-.n:..;..n3J.k9y..f'4+..X.....8zA.V..v.4.V....d.).f..&.*......ym..+..l....X......:Z%.}....[4..g.6/I.LC..h.....nf#...G....ms.G4....p.;,..bp.+4.......#...GX....*7...apUE]...(.....x...M/p..=.>.Z.<...pSF.;~.......x.?c...}..(..,..'......|..^)e.w...6....a..>P..c.Y.z..... ..)>/..>..../H|.|I...Q....._._.....).!..xR..xJ..[.O........xF.{...?.?......O.....J<.^...X.8..J.R.k.m.[....
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):670979
                                                                                                                            Entropy (8bit):7.887042011821685
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:895377EEDFDE160D01971E53C5657F7C
                                                                                                                            SHA1:8A3E4A11683A7F406DF57277921A9B5E49DCA185
                                                                                                                            SHA-256:026D61591C17B3ACBF900F3EA676452CC668062116C5B823709AEABBF77AC7B6
                                                                                                                            SHA-512:D73AB337D179B07DB5F01D58243578687A9E4323BCF6ADE8137E31D882099966EBC8C132CC3A5391A4C77D532B54C5354C6C0279CC24AC0970375B0EEA0EBEF4
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class.UYW.P..F...6.....K..-.&(.((.*...6......7~.......[.....9'..............9..:].Prx...~.D.`..Y..z.^q...'A..Bh...q=K.3}..K....`.3..!....q.1...Y.vt.!E.lt....?.n............"..'.:.....l...M.%........KXH....z.........$......'..A..v/.p....4V..)q...0..I%?>..6a&.^..C.).5L.h.^.r...f...Y\..a.)h}......bJ..<&L4..m.cQIH.(a>9N..r..8..$.>.........I....~.2I.......'b....v$F^...0Fm.N....W.'.]$..b..G...q;.(.j?.0C.......0G....@...UE.../w.-.w'..e.....njX..."..@.P.Z-.2.?..$....}c!Oc..T.,..xOh;k.il..b.6.../...R.H..o4c.kse.v6R.D..U.q.v..[.+.z.?..<..>..T.{LX<"t..^.?.3.-L.N.+8{Z..X..=...5)[....J.......J.W.KJ.Qr..-..|V.....].A.n@..na.wpW.>.#<.....t.c.9L.4/#,I....-......PK..v.G........PK.........n/Q............K...classes/com/sun/org/apache/xml/internal/security/algorithms/Algorithm.class...O.P..w.+t...(...0.I%&j2...@.F.._..M.v-io..+}....}..2.{W+HM4.Y.=..|...s.o.?.........*....F.'IC'.=..qwW8....C)..N".4..J?H...\..X..@.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4554630
                                                                                                                            Entropy (8bit):7.924266858160998
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:3EE11567D8AB959D277D58D7392FBFD2
                                                                                                                            SHA1:59599F0D878C7D959FB392A3996D730EB083818F
                                                                                                                            SHA-256:F1C275641604A2BE56E559772AA55CBB1CD8EDAE9EC1B51D5B568F9656A157CB
                                                                                                                            SHA-512:0A7FC2CACD203211BFD2760B2043F485D53B41A3088F7FC8800113A795F40A3806AFEA7F6B29D141AD322B13891E0CD9FF9D3A70DF572C5B2CF036A72A12AD14
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class.Xw..T..."Go....I.6..X.... .b.w..^.l.&.=l....;******vTTTT......s....%\.~{..{..|3o.d7..~......{.Lfu.F3..*0.>..D3o..].K"....s...D-.p.L.v...J6#k..Z..e+k8ZZ.P.0,.3...3\iR..E..h.]..w.....v......v.O..ji.....:Dg......*..q...{.2L..&.9G5l.4l...6.i.Z......J..`..1.Q...;..N.c:Vp. ..X...;D....b.e.e(.....S+..C5<..j.LK.. .U(..(.i.*.f..d..cbe...X<'a\......F.i....E.A@.CM<.....C) G.@..F.&.6""!`9.$%.1L.@A....95.\..H.!....GD.D.x....R.|.._4S.....S.fT@r..$w.dI.._r..4I..PW..U..Jy.@.$....A4..l.6..3.V..O...$....G.. ..E(Q.hQ-.>....y^.....<..pXD......i.P5<"^...`.../.....t<W<...o......x.'....M..<^....r%^..+.,.Ns.Y5.Fs.<.$.b:.1..-..(W s.......)..F.)...V.3..l...C..."L.....d....%..<.l..E...0.# .H.._N......p..1./.]..$....#...pjDJ..v{..N......M....&....U..y.]...K....R.o........2...F.Q.5..U....h......1....w..<"..x..+.....X*..p5..m.....@...i......FlK%.q..xa..y5...~.C.Z.#N.[.....9.&.v.....B.L7.;.......]...q..U....{J.
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):517331
                                                                                                                            Entropy (8bit):7.932914811977659
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:1BF162783EC1B1DE6BF846275CB30304
                                                                                                                            SHA1:DAED3EAFA8D19CA690F8A46B55DEFB0FD5F55387
                                                                                                                            SHA-256:BE8A7293DEADFF4410281D93A0B6E8CAF2ABD08486000F933E2B7794998B0AAA
                                                                                                                            SHA-512:71000CFDE3B33D7E1DE2BE8F34D1A4451CA37DB7C7CA28B59A6F6C00A730E974EE9F0AE4868659B9BD47970FE70CD83A4F523AD0D03F70362C5C7BD7FD99AC95
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class...N.@....HA>....M............}..].B.%....sy..|(..S=.....g~3.;...o..qL...O..S..@.V!.L.\..........T.b.D(....3 .y:tM....~.].%2.D.E8..L..P....*.......6..z.}i.....!.g...}n.j...el.M.../......l...NcO.@.\.....+g(...K.[..E<....P....'B..b.l`.J.C.7..g.[l...,..)[...'.......WU8W.a....PK..a.-.........PK.........n/Q............@...classes/com/sun/java/accessibility/internal/AccessBridge$1.class.SMo.@.}..q..............RU....i..rA ......v......~.?.1v".R.QK..}.7..3......}..QC.C#.....1?.a.U...c.8..T..2..Q.-...c;.R}.>|.x.........:1aX.5O#..n.....B.3Re...G.k.:..`..q.'.-TX..$...X..MC..0......fb...3.b.t{..FZ.}...6*..0e..F..\d".$Nj"6.t*.V#..~1..y..N.......}.6...O..+.3...9.../.e..+..x~: .w.;...K)...L"^.R....e4..B%..Qfo.;..;.....Ck_X.J[..R....Za.I....O.V....n....g%r.+.g:.p.l....*.`..k.N...1'?............g...>...f)..Jq.T./X=...K.YEm.V.7q.|.[d.+d.w+..#.z~.PK...G.'....h...PK.........n/Q............A...classes/com/sun/java/acces
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):286933
                                                                                                                            Entropy (8bit):7.911348853312728
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:CB1CFBA8201EE222C2D69845FC055F84
                                                                                                                            SHA1:8C448B58260790B6B10231F0153FC7438B41F4D8
                                                                                                                            SHA-256:DE900FCC734F2CE46175DFBAA4C26368452C6049EA96A35F1E27F5CD988C9D3A
                                                                                                                            SHA-512:2B69DD8B25F2549C4BCD4F2F3E3FB21F0EB66FD8BCAD4CEC0F7B731317041BC01B8329644109C0823839F3BA78BE48CEB227C5CB958CA3101E24035C24FD15C2
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.class}..N.0.E.c*...1.(.y..H..=;$$...b..IA..],..>..BB.`..G..~..|{.p..P.&.*..)...?...9....}nR.#...3..?!L95H.QI.q.`(...s+..O....S..U!,.....)C..Rh.R.........0....')L.....0JI.R.#....P<Ib.%C..,....}eX$4......B...a.w.J.V....O..u.lV.(N..../".......HI.a.P.\.c~/...7.%L.....A.O\..8........a./.r{/SB.%.C.....!|...#.....{.u.S7z...3;.......eT1..L..i.a..Xrz.k8...PK....h.x.......PK.........n/Q............>...classes/jdk/tools/jaotc/aarch64/AArch64ELFMacroAssembler.class.U]W.E.~...tm....b-.MBe...HK..l0..4j..a...M6.nPZ..z..^z.7............n.ml)x<........;......FPH...q....U`.S+..]/..W,;..L..M)..:t......i)o.....=.Z.8%'...If...M..0C.6..Z....o)..8^i$.oG...H.8.C._..........m2;..x.(e...R!..)...X:.... ...a.E..8.......j`...k..W.?..H..=j..:..e..l..-...W...T>..p"...^.).s...E...,e.......6Wr7......}..%.b.4^%.n...&3......6t.xMs.V,k....8+.V.|'..d*.M).i...H.Y.>..D9.4......|.c.N..x......:.tc+-...Li.SE......_...:]).s.....
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):38562
                                                                                                                            Entropy (8bit):7.938691448340528
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B1ECA358F4D3525178F96244F11344FD
                                                                                                                            SHA1:EA84D813907BA33FB66E54FC0A8272230F7F6FCB
                                                                                                                            SHA-256:178B1246FA90169F75CC8DED648A88276DD252A28A85F26676777D75D290BB64
                                                                                                                            SHA-512:985D19030C00EAF12E088184745739ACA59797D6E354FD41B1483A231E66479DAC0260E1BA9A3A5FFE4954CD69EC8FF49ECAF7D14DF0C4333BC77B2790EAE410
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classuP.J.@.=..&M.V..>v.\5..".r#.....c2.I.d&........TA....9.........1....L.(...".~4..U..$..gJ...E..._.g....".d..J.T.+...0....<.....3.B.V...zzy....9K...b......$."........N.Q../,...5.o.]6O-...DY..6N.>......J&,..).....)W..".#..#.E..K`...}.u.C....}K..e......D...6.....@.a:.qhv.}.PK...4..........PK.........n/Q............?...classes/com/sun/tools/attach/AgentInitializationException.class..KO.A..O..y........1.c\..b...6.. .qU...LSm....7.!...p..v.....TO.H....7.~...>.s..@..u.P...D....W.]z.4#..~..Y....6..(.-.k..Z..&.h.<..=/I.g.(L<i..v..#e.."-C} .....+..f(.T....1.&h.....f..6...P`&Q1aC.'dl..,|'0.Lb.......k....(../........?...;.( G..8O..N.....M.s$.zcj.../.3.{...[Q...v.,...S.."o..g+..fp..Em~|..K.....2Zg^p.wO!...T.2}..4.\WX....p.Qs.&.>wGj..r...'....zEy.....3..(wz.9..t>.n._..:?....nf.........9......1....J..|.p...L../PK..............PK.........n/Q............5...classes/com/sun/tools/attach/AgentLoadException.cl
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Java jmod module version 1.0
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1500675
                                                                                                                            Entropy (8bit):7.994343436992055
                                                                                                                            Encrypted:true
                                                                                                                            SSDEEP:
                                                                                                                            MD5:50B98B6BFCDE8F8D339803B5B6C49CCF
                                                                                                                            SHA1:9122BC89BD2BFC3AE39DBEA6793519781D0391FD
                                                                                                                            SHA-256:FAE4A04FB4D9129A524B9230BFD050ACF4B755B5A6E3511877FADE2569EFB478
                                                                                                                            SHA-512:2DA5BA7C3238CFA9E9E1DCD8225EF9B5A09F4B67FE73725D17B74D5B375E83BADD3BAC88EF1D4DCB164AD8711B2523E0200D663435ECD487BEE030255FCBA5B6
                                                                                                                            Malicious:false
                                                                                                                            Preview:JM..PK.........n/Q................classes/module-info.classUN.N.1....#.A.R"...&..P".E..?`.Kp.gd.%).].|......J.....||......^Y].yh.g....?.1WkE...Bd/.y.|...9...bD..2...2.....U...E..`.....y..k..%h.......s.....t.G..t.....Im6...Te.5c.<..r3.......Z.....h....G?.3...Dx........I.'..._PK..Y~......K...PK.........n/Q............6...classes/sun/nio/cs/ext/AbstractCharsetProvider$1.class.T.R.A.=C.6..D...7..B`...D#.P....J.e........+......w...(.g.h$."U..;.}N.I.|...3...[.........~.5\.3,._.#...nZb.hr.......<5..,........r.+...1..4K........4..pJF.s.e..E...q.m:.`H.....K.OmK....:b.!..\....5$ut...x.H..#ln..3t..kh.uU...'.....d..V..3:...CG}..V4.E.BU.Df...C.U...jz.i....e..w=.4.5dt.!.0p4.I...mT..#..a.\..p..F.@U.0\.....+....T..:.;....a....6&..g.M....e.YwMQ..z.&.K....G....4.B.O{kD.^p\{..l.......t.<.,.....bX.7C..1*2d.....!.,Lkc.,+x...fT.=,r.y.....Mr....j...-..U.e.:......H..f.J.O.....G).....E..s.<J....|.d.......:..!.T......&L$...d.~...=.L{W.{ o..=....Lv.Zf....6.]..A
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):2680200
                                                                                                                            Entropy (8bit):6.905929223312974
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:C2B035714796B7100C0A2C578519B8CC
                                                                                                                            SHA1:FD9CDBB1EF7C559C41A3D6E1E336655B9B67BBF7
                                                                                                                            SHA-256:D55B519477FF7BE1BE5B1B7C6870D6313E3E3BEBB7C9ECE0ECE5992322A33107
                                                                                                                            SHA-512:E68FDD8128DD62A57DFC428AA9824DF3AF140B15677E6551CFAFE8AF40DCCE330505553C104FD446928FFD7A55BD61D51A0A10517976B2BD6939B70E9B5A9A52
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:.:..(........!..........(..8........... ....tj.........................@).......(...@... .......................'.xU....(.. ...`(.H.............(.p[...p(.....`'......................P(.....................`.(..............................text...............................`.P`.data........ ......................@.`..rdata.......@......................@.`@.buildid5....`'......F'.............@.0@.bss.... 7...p'.......................`..edata..xU....'..V...H'.............@.0@.idata... ....(.."....'.............@.0..CRT....,....@(.......'.............@.0..tls.... ....P(.......'.............@.0..rsrc...H....`(.......'.............@.0..reloc......p(.......'.............@.0B/4...........0).......(.............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):566704
                                                                                                                            Entropy (8bit):6.494428734965787
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:6DA7F4530EDB350CF9D967D969CCECF8
                                                                                                                            SHA1:3E2681EA91F60A7A9EF2407399D13C1CA6AA71E9
                                                                                                                            SHA-256:9FEE6F36547D6F6EA7CA0338655555DBA6BB0F798BC60334D29B94D1547DA4DA
                                                                                                                            SHA-512:1F77F900215A4966F7F4E5D23B4AAAD203136CB8561F4E36F03F13659FE1FF4B81CAA75FEF557C890E108F28F0484AD2BAA825559114C0DAA588CF1DE6C1AFAB
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Y...................Z.........O.....O.....O.....O.....O.....O.6....O.....Rich...........................PE..d...%|.a.........." .....<...\.......)...................................................`A.........................................5..h...(...,............p...9...~...'......0.......T...............................8............P...............................text....;.......<.................. ..`.rdata..j....P.......@..............@..@.data...`:...0......................@....pdata...9...p...:...6..............@..@.rsrc................p..............@..@.reloc..0............t..............@..B................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1141640
                                                                                                                            Entropy (8bit):6.314705497413316
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:1E2FF5EA2A27D355FB21A46322FAB0D6
                                                                                                                            SHA1:A303CA421D099A1DC7F7D99516ACE399E885873A
                                                                                                                            SHA-256:9B08A1C7822A1710C01D38DE6DE74878C20EEAFB1B2C8417B8472EC84AE92E7B
                                                                                                                            SHA-512:55D35B7F835692B3F9C81619731B8E8A88E72E643DBF498CF7FE501D7EB926A318BBED65FC3836FC9E69092A3C6AC67DBFD461EE0A5DDFAA93636E4389B2C563
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....?.?...........!...............................j......................................@... ...................... ..|....0...$......................p[... ..\x...........................p.......................4..d............................text...,...........................`.P`.data....%.......&..................@.`..rdata..............................@.`@.buildid5...........................@.0@.bss..................................`..edata..|.... ......................@.0@.idata...$...0...&..................@.0..CRT....,....`......................@.0..tls.... ....p......................@.0..rsrc...............................@.0..reloc..\x... ...z..................@.0B/4..................................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):148856
                                                                                                                            Entropy (8bit):4.180002572542603
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:7F557BAFF029D4B724BA74DBA9564647
                                                                                                                            SHA1:1D441CF1D331D49DAA4805C178EEF67C72BE7753
                                                                                                                            SHA-256:6708FA90D5C1543D3C42E2EFB274BECD2E97C450FA9669FD3780EF293A9F1E1A
                                                                                                                            SHA-512:FD1932228864281CE60343508F798887183D599D31CEA6C1247A2BB1645A62B864BB08513161F9EEB7D678433BB01840593477B4D5DA3BE28E26E24A642B61EC
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......c...............#............. ........@.....................................A......... ..............................................................P......."..x#..........................................................l................................text............................... .P`.data...0....0......................@.P..rdata.......@......................@.P@.pdata.......P......."..............@.0@.xdata.......`.......$..............@.0@.bss....@....p........................`..idata...............&..............@.0..rsrc................,..............@.0..reloc............... ..............@.0B........................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):460144
                                                                                                                            Entropy (8bit):5.918754254337758
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:846CCE051E8E1EECBF7AF5FBB6D254A7
                                                                                                                            SHA1:CDF4675FD842FFDDC2564A9139B7A9A6E0BC75E5
                                                                                                                            SHA-256:DEF3EBA3D76A81DA41DFFE07B2359D420D83D535B39B71755CF622DFAE82FE3F
                                                                                                                            SHA-512:E5F150696E75C5C41EE874D38F9EF1DEE3417AC70844731E61442A0601C8F6BB0BB212A342FEA81DAFA9AD64DEB4352AFE72240D6DC7C4840B83246A5A5245B2
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........,v..B%..B%..B%C..%..B%...%.B%...%T.B%.y,%..B%.y9%..B%..C%;.B%...%..B%...%..B%...%..B%...%..B%Rich..B%................PE..d......a.........."......z...H.................@.....................................J....@.........................................p........o..d................)......p%...........................................................................................text....y.......z.................. ..`.rdata...............~..............@..@.data............(...t..............@....pdata...).......*..................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):460144
                                                                                                                            Entropy (8bit):5.918880572622775
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B15D67987E131B813C35BE5719AA4C20
                                                                                                                            SHA1:07F51B1A56AD583972B3E700D50DA2247564455A
                                                                                                                            SHA-256:477480D485177A62AEDDC5FC15DDA4F77C32C4FA8D281AC3A6E8348D38761603
                                                                                                                            SHA-512:453486235A5C38BBB0301BBDBDDB2C101AB4346BFCE94523BBB8C5482D67C09AA0B10E5E9E2CC7502557F73651537C0AAC9DB68214E37F716704C5438479BC2D
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........,v..B%..B%..B%C..%..B%...%.B%...%T.B%.y,%..B%.y9%..B%..C%;.B%...%..B%...%..B%...%..B%...%..B%Rich..B%................PE..d......a.........."......z...H.................@....................................F.....@.........................................p........o..d................)......p%...........................................................................................text....y.......z.................. ..`.rdata...............~..............@..@.data............(...t..............@....pdata...).......*..................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):12432416
                                                                                                                            Entropy (8bit):6.2324332935821865
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:65AFA181C69CC2D53EE8629A6AC5D2C8
                                                                                                                            SHA1:FBC9E6EED40AF682091E9E49D3F746ADC9852BF0
                                                                                                                            SHA-256:A041E91306596DD024F77CE2890AEDC9CAAEF6409B930755A06DAA9697550EC0
                                                                                                                            SHA-512:B8EEF993382977A6BB6C81F01F027A1168752BB5AAEE645B69ED1D341E7740EC96F1D44FFEC0E672706382B5E89470C44DBDCBBCA3C26AEA6A96B336723E400C
                                                                                                                            Malicious:false
                                                                                                                            Preview:...'........CmnD........ Copyright (C) 2016 and later: Unicode, Inc. and others. License & terms of use: http://www.unicode.org/copyright.html .n...tK..."...K...D...K..`E...K...E...K...F...K..PF...K...n...K...o...L..po...L.. ...$L..p...7L..`...JL......]L.. ...pL.......L.. ....L.......L......L..p....L......L.......L.......M.......M..`....M.. ...AM......TM......gM......zM..@....M.......M.......M.......M..P....M.......M.......M..P....N......%N..P...6N......JN......ZN..`...mN.......N.......N..P....N.......N.......N..."...N..."...N.. #...O..p#...O..pU..2O...U..IO...x..YO......lO.......O..`....O.......O.......O.......O..`....O...Q'..P...\'.&P..P]'.=P..@d'.WP...d'.nP...m'..P...q'..P..pt'..P...u'..P....(..P..P.)..Q..`.*.'Q...n*.IQ.. .*.iQ...-+..Q..p.+..Q..`.+..Q..0.+..Q....+..Q...+..R....+.&R.. 0,.DR......]R...s..tR...t...R...v...R..0....R.......R.......R.......R..P....S.......S......0S..`...CS......VS......iS..P...zS.......S.......S.......S.. ./..S..@%/..S..0'/..S...y/..T...y/.$T..../.9T..
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):11394704
                                                                                                                            Entropy (8bit):6.390661514563496
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B97B7AAB1F877A7B3A426A434ED5562D
                                                                                                                            SHA1:12D88F7C2FE3D3908BFEDD415CF3C6590CEB42CB
                                                                                                                            SHA-256:B30ACCB880B398FC9743A51831A741CE22364FE091AFF9846CF457A772BBE2A2
                                                                                                                            SHA-512:23489E913523444FE24462E36A70EC5B8E6C1CFC4C7AC1DD8290DAA778362789B484E43B4A35930EAFC6B29C2322597B38F7AEA19E029A09FAAC9A5ED42D1D77
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.............~...~...~.....~......~.i....~...z...~...}...~...{..~......~......~.3.{.I.~.3.~...~.3....~......~.3.|...~.Rich..~.................PE..d...6.`_.........." ......}...8.....$.}............................................KU....`............................................................8.......P....................T......................(...P..0.............}..............................text.....}.......}................. ..`.rdata..D.!...}...!...}.............@..@.data........@......................@....pdata..P...........................@..@.rsrc...8.........................@..@.reloc............................@..B................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):4737864
                                                                                                                            Entropy (8bit):6.3457915614302225
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:8BBF34C55E0F517E1C2D29A4D49807B0
                                                                                                                            SHA1:2544A43D6AE1A635C204ACB941A5579A5D6B44B3
                                                                                                                            SHA-256:7E074778EA6335C9769E66057BB87B36B5B783FFE6B056058B6C0DA31EDF00D2
                                                                                                                            SHA-512:02D4FC973E03D6536C0FA883102A90540C6C1DA3179D3072662946700337BC55C29E026A3A7A8955993E9281264DAD5E9ADA839ED7EE7C7AABA39C2B9633EB53
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...k%e`.........." ......-...........+.......................................H......PH...`A..........................................;.(...-.=.P.....G.......E.......H.HG....G......5;......................4;.(.......0...........H.=.....(.;.@....................text...E.-.......-................. ..`.rdata..4f.......h....-.............@..@.data...@6...pA......PA.............@....pdata........E.......E.............@..@.00cfg..(.....G.......G.............@..@.tls....1.....G.......G.............@..._RDATA........G.......G.............@..@.rsrc.........G.......G.............@..@.reloc........G.......G.............@..B................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):40840
                                                                                                                            Entropy (8bit):6.874181188691215
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:36F2852E6B61EDC165C1F52680E81A4D
                                                                                                                            SHA1:ED69D74A64CF5266D7C591C822E02C3DF5DBC093
                                                                                                                            SHA-256:34BFBCC03EE7507575373273BAE51BE42977B9FBC9F6BF362333E1BBAAE47E71
                                                                                                                            SHA-512:F9081D1EBE267B5CA8B2FF8DC89C692D42516F5420DB266CFF8C5BA0B3EE507C24D1790702CC54D43336FD2D8DE88FD9011EE894065A66F8D7436C2D7B4C3074
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....L..D.........!.........>...............0....xg................................W.....@... ......................p...............................D..p[......X....P..............................................8................................text...h...........................`.P`.data........0......."..............@.0..rdata.......@.......$..............@.0@.buildid5....P.......*..............@.0@.bss.........`........................`..edata.......p.......,..............@.0@.idata..............................@.0..CRT....,............6..............@.0..tls.... ............8..............@.0..rsrc................:..............@.0..reloc..X............>..............@.0B/4......,............B..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):71048
                                                                                                                            Entropy (8bit):6.866903825468998
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:0554771D7993D701C40FE58766FF8C9C
                                                                                                                            SHA1:BFADCF29AFDA1B39ED8B2F2F0FD7A2296037D945
                                                                                                                            SHA-256:5D6C79492645356C0BAFC2FCA2AAFC21D17F7A5BB9DB8209F3E8FFEDEAC27F15
                                                                                                                            SHA-512:594CCF41D44D1FFE8A7898D73F16D302CC8AD8F462F0FE88D9D20432B7AAC5C4E8A44A1C815CEE2E0D26D82FE5F6BFD8192D5574ACE91A0DB7F9F542A4204B48
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=W=...........!..............................$j.........................`.......n....@... ......................................0..................p[...@..0............................ .......................... ............................text..............................`.P`.data...H...........................@.0..rdata..............................@.`@.buildid5...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....,...........................@.0..tls.... .... ......................@.0..rsrc........0......................@.0..reloc..0....@......................@.0B/4......(....P......................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1213320
                                                                                                                            Entropy (8bit):6.44604470467315
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:9370C98E0666EB9A37895412C420CF98
                                                                                                                            SHA1:74DBA565481C74313B2DBC8740613429AC5114FF
                                                                                                                            SHA-256:0B2EC3613E032655D4E2D43EAD38535A659D046420E0ECAA874F1EE5A10F10F0
                                                                                                                            SHA-512:95EDF0197AF3DE8912DE89CCD17964013847D33088B67996275110F440FE24716101933F517884262EF6E34A56BC6EE46090F324FB82B43CEBC8592E6855A959
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:4:.(.........!........."...$.................c.................................W....@... .................................D....0...............(..p[...@............................... .......................................................text...H...........................`.P`.data...h...........................@.`..rdata..H...........................@.`@.buildid5...........................@.0@.bss.....#............................`..edata..............................@.0@.idata..D...........................@.0..CRT....0...........................@.0..tls.... .... ......................@.0..rsrc........0......................@.0..reloc.......@......................@.0B/4......0............&..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1130888
                                                                                                                            Entropy (8bit):6.436582805427262
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:1E01FBE2BA7943BC942D3D3381DC0C44
                                                                                                                            SHA1:A0CDCDDCD3265B24C684E8B401CECD3E5879BABC
                                                                                                                            SHA-256:2A2C1B568B95E803C96D3A63000EEE0BE9FF2C7160CD118768176BF539121AEA
                                                                                                                            SHA-512:2B7091B2F9BF8EEE12F1E34B1CDC980C9D4AE2465671A4E2A17BAF3A32D8EE0C6C82AEA9558FB38C1CF51F313795F1B91C59906A73CE504CC0B0272587ECBF44
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L... 9*9...........!.....*...................@.....g......................................@... .........................................................p[...........`..............................................P................................text...|).......*..................`.P`.data...H....@......................@.`..rdata.......`.......@..............@.`@.buildid5....`.......:..............@.0@.bss....@....p........................`..edata...............<..............@.0@.idata...............>..............@.0..CRT....,............T..............@.0..tls.... ............V..............@.0..rsrc................X..............@.0..reloc...............\..............@.0B/4......,...........................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):42888
                                                                                                                            Entropy (8bit):6.923257394882841
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:08C8AAE1881011F7A45C8E4320310AFF
                                                                                                                            SHA1:34FFE1D7C6C5F8C42D3BC2AFCD8537D77EFEE1A7
                                                                                                                            SHA-256:F46CB49D7B177C49B6D01C7B699810E1686CBC922890ACE9F4389DC0B792127A
                                                                                                                            SHA-512:040B01FDD963479223FF05CDAB264C8E36E16719962540A24FDCEF3B13B7D8CAAD5D998C3BE0F2AD65CF2FB60E050683519B27E0B23E0C030389175E398666DA
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...X...L.........!.....&...F...............@.....f................................+c....@... .................................l....................L..p[...........`..............................................D................................text....%.......&..................`.P`.data........@.......*..............@.0..rdata.......P.......,..............@.0@.buildid5....`.......2..............@.0@.bss.........p........................`..edata...............4..............@.0@.idata..l............6..............@.0..CRT....,............>..............@.0..tls.... ............@..............@.0..rsrc................B..............@.0..reloc...............F..............@.0B/4......(............J..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):40328
                                                                                                                            Entropy (8bit):6.943602605708255
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:8C3823536F6DB0FBDF42FFC2ED77FED0
                                                                                                                            SHA1:6D1DE0CC3990E17485C9297C5D4224F2D66A1108
                                                                                                                            SHA-256:120D24770AAFC7D846779D59CAB83B9D6942AEAEFA2BF7C4DD502EBC77F498F3
                                                                                                                            SHA-512:448D9299C867B142CC51773D50350EEDEA15D7A0043D26224C93F999D7D8A90085BFB8A685C570793AB3AB658280D16FDC17E6F4CFDDC4949B9860EFA31F40EF
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L........B.........!.........<...............0....Lm......................................@... ......................p...............................B..p[......l....P..............................................,................................text...............................`.P`.data...(....0......."..............@.0..rdata..x....@.......$..............@.0@.buildid5....P.......*..............@.0@.bss.........`........................`..edata.......p.......,..............@.0@.idata..............................@.0..CRT....,............4..............@.0..tls.... ............6..............@.0..rsrc................8..............@.0..reloc..l............<..............@.0B/4......(............@..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):40328
                                                                                                                            Entropy (8bit):6.892834355982993
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:1A384C4AB28FB5F9EA140B2E756281BC
                                                                                                                            SHA1:FE8916179A7CD7167F66F522241CB5D9B42F295F
                                                                                                                            SHA-256:2BD8AE09147FB871884AFD760F2E249562DC398B59D13CDA98997BFCF3656112
                                                                                                                            SHA-512:5D18EDE5B0B42FD0133C514CB5923C345E81A9741B5A7222591CD76B06AA73413BA7F7019F9AB35EAA4100EF4E2801EE4EFC3C98F3A09774DA54B5D865231581
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L........B.........!.........<...............0.....e......................................@... ......................p...............................B..p[......l....P..............................................8................................text...x...........................`.P`.data........0....... ..............@.0..rdata..$....@......."..............@.0@.buildid5....P.......(..............@.0@.bss.........`........................`..edata.......p.......*..............@.0@.idata...............,..............@.0..CRT....,............4..............@.0..tls.... ............6..............@.0..rsrc................8..............@.0..reloc..l............<..............@.0B/4......0............@..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):40840
                                                                                                                            Entropy (8bit):6.9416821953334145
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BA359DD80C09291D412F56577B419FA9
                                                                                                                            SHA1:09DFDF638D3C96C4ACD02919C26D5D4CBAE7A2A2
                                                                                                                            SHA-256:BC6E4AC08EF1F972B605D1215F2DC44436AAC5E892825C86A1684153261976DA
                                                                                                                            SHA-512:2BC49FEFA7944EE58DDC21578836B7AB3FEA2F80539BB96D8BC719090C3CFA239EE8459416B4B8BA29A4A271F1961EADEEAEA545E66EA183BDEDD669306D45D0
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...X.6..D.........!.........>...............0.....h................................J.....@... ......................p...............................D..p[......|....P..............................................D................................text...............................`.P`.data........0......."..............@.0..rdata.......@.......$..............@.0@.buildid5....P.......*..............@.0@.bss.........`........................`..edata.......p.......,..............@.0@.idata..............................@.0..CRT....,............6..............@.0..tls.... ............8..............@.0..rsrc................:..............@.0..reloc..|............>..............@.0B/4......,............B..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):38280
                                                                                                                            Entropy (8bit):6.996888861325459
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:B29272E41F4D1FBF1F65FC5FF9F29539
                                                                                                                            SHA1:37F6E7EDB6E8D69CF170B92CE024407D08ABF1E9
                                                                                                                            SHA-256:7413968053AB16EBF123A1AF97DC9EC7AAC825D7071B1369325A637AF06437A4
                                                                                                                            SHA-512:4D69918F8ACE963B84D659E709486A0B7C2D045F0EF0729C215F356C6B5445DEC65CC00363CB4CDDBAB4103101913C3CBDD9496FD7101AACE8F2C654E649CE26
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....L..:.........!.........4...............0.....k......................................@... ......................p..........D....................:..p[......8....P...............................................................................text...............................`.P`.data........0......................@.0..rdata.......@......................@.0@.buildid5....P......."..............@.0@.bss.........`........................`..edata.......p.......$..............@.0@.idata..D............&..............@.0..CRT....,............,..............@.0..tls.... ...........................@.0..rsrc................0..............@.0..reloc..8............4..............@.0B/4......(............8..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):96648
                                                                                                                            Entropy (8bit):6.761888616133481
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:62C756810AC218EDFDF8F8D4870B6215
                                                                                                                            SHA1:1A0A10BC468FB8FA025C4F8DA585B206058C7E0E
                                                                                                                            SHA-256:944D7A18DEFC54115E0273EE5D8E77E2CD6D28183AE3AC85FA251E5AC25FFBCB
                                                                                                                            SHA-512:025833126CF3A5773193558C42A0C989A9D92CB6AE555A719E454B112B108C478B621D9311E791A55B63EAFCD97EB23CCFD07F2576049C5093E35F347A9BD18D
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....:.:...........!..............................Lf......................................@... ......................@.......P..L.......................p[........... .......................p.......................Q..0............................text...............................`.P`.data...............................@.0..rdata..............................@.`@.buildid5.... ......................@.0@.bss.........0........................`..edata.......@......................@.0@.idata..L....P......................@.0..CRT....,....`......................@.0..tls.... ....p......................@.0..rsrc...............................@.0..reloc..............................@.0B/4......,...........................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):44424
                                                                                                                            Entropy (8bit):6.957805692366972
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:CEE2F2EB515E146853490134E4EE23F3
                                                                                                                            SHA1:3F1EDF11F2ACCE67652ACE09D42E61C8DE8FB610
                                                                                                                            SHA-256:29BBFA9B5242C0F0C35910A9970CA853E2F412E978294CDE88E8B45F014D0C19
                                                                                                                            SHA-512:DA7F2775AAF3155DD7A4E9425895CA841DD1723355BF8719EFC11B1DA6BD58660337E24599D7EC4848D6062CBAE3B216D6BD8BB5767919C55E22B257F49A6DFD
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Z6b6.R.........!.....(...L...............@....Lf.................................{....@... ......................................................R..p[...........`..............................................h................................text....'.......(..................`.P`.data........@.......,..............@.0..rdata..H....P......................@.`@.buildid5....`.......8..............@.0@.bss.........p........................`..edata...............:..............@.0@.idata...............<..............@.0..CRT....,............D..............@.0..tls.... ............F..............@.0..rsrc................H..............@.0..reloc...............L..............@.0B/4......$............P..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):41352
                                                                                                                            Entropy (8bit):6.942456203627978
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:66FD00AD1B9E792C68227E46100041B2
                                                                                                                            SHA1:66EA49E100281596FC8AA95C9D5776D3B2170013
                                                                                                                            SHA-256:48AD0D37BDF70E9CD6B7F93709E23E81AAD85609B49E94B017F78FDDEA7DC17D
                                                                                                                            SHA-512:48609EB2FB04952B2C9D80DA57D1A96BCB873E9EB4097037FA0C60F5CCDC41044DF9296DB93BD75F290346BF3CC88E034A0FEF566800C5DE72B5D2EAE6A2B2F3
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....L..F.........!....."...@...............@....Hh......................................@... ......................................................F..p[......\....`..............................................4................................text.... ......."..................`.P`.data........@.......&..............@.0..rdata.......P.......(..............@.0@.buildid5....`......................@.0@.bss.........p........................`..edata...............0..............@.0@.idata...............2..............@.0..CRT....,............8..............@.0..tls.... ............:..............@.0..rsrc................<..............@.0..reloc..\............@..............@.0B/4......(............D..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):48520
                                                                                                                            Entropy (8bit):6.887380923537153
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:E62C9E055CD508266AD68BAA99A2A762
                                                                                                                            SHA1:3C7AFB1F518FB3682D3D2A98702359173B9C4442
                                                                                                                            SHA-256:100E59FDB371942695496A785B94741B5C8D65E7582B3387612000D71B114015
                                                                                                                            SHA-512:4892694355EBE0D8658D0608B73B92C4A9A9B673516345A6B1DC3608D219DBE37DF08C68CCC844712469D2548AD8220A5DDF7149BB69D63547FD2F5C3B6ACF9B
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....=.=.b.........!.....6...\...............P.... n.................................-....@... .................................L....................b..p[...........p..................................................<............................text....4.......6..................`.P`.data........P.......:..............@.0..rdata..\....`.......<..............@.`@.buildid5....p.......F..............@.0@.bss..................................`..edata...............H..............@.0@.idata..L............J..............@.0..CRT....,............T..............@.0..tls.... ............V..............@.0..rsrc................X..............@.0..reloc...............\..............@.0B/4......0............`..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):75656
                                                                                                                            Entropy (8bit):6.458876926478972
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:774D9A724374084E14C2839CAAF52B0D
                                                                                                                            SHA1:10B014822DBCABCDEDFEC1F40C67985271B2494F
                                                                                                                            SHA-256:7D50284A7479E00063F7D1834E95669888502BFC9002FCCF70CD66AD6C3E09C1
                                                                                                                            SHA-512:8FBC8EFA8C377CD207BF2EE52785AED658D0769601FF1C0ECB0B3C92259F2DF780A0BB0FD56116060A779C1ABA3A17A6E31FD6EDF3DDE11BE73B01DC0AFDA467
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....8.=...........!...............................p.........................`............@... ......................................0..................p[...@............................... ..........................0............................text....~..........................`.P`.data...H...........................@.0..rdata..x&.......(..................@.`@.buildid5...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....,...........................@.0..tls.... .... ......................@.0..rsrc........0......................@.0..reloc.......@......................@.0B/4......(....P......................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):698248
                                                                                                                            Entropy (8bit):6.576745864221562
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:F7DD4A50064596DCF305200E21727322
                                                                                                                            SHA1:D261DAC7F23D05E67235FB464A9C58F643B00039
                                                                                                                            SHA-256:50F391A5FAF2148EE68D178AC5BEFFF4F3C44D0063E25019FCB204FC5E996C96
                                                                                                                            SHA-512:9C443F977457A3422CCE077D0C5A732C9C1C91988BAB161436409F8EC3EC05B4ABDD2B584D9C524C44A29A55E36857E5EAC7AA67F0593E133D6BA3447D5CF893
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....0.0.L.........!.....h...F....................,l.................................'....@... ......................0.......@.......................L..p[......`?...........................p.......................D.. ............................text....g.......h..................`.P`.data...p............l..............@.`..rdata...X.......Z..................@.`@.buildid5...........................@.0@.bss.... .............................`..edata.......0......................@.0@.idata.......@......................@.0..CRT....,....`......................@.0..tls.... ....p......................@.0..rsrc...............................@.0..reloc..`?.......@..................@.0B/4......(............J..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):41864
                                                                                                                            Entropy (8bit):6.930537760928011
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BFA8D8B8F71043ABA51C9773A537095E
                                                                                                                            SHA1:DA6A9ABACEF7DBB6598F081048B76E9B48ABC41A
                                                                                                                            SHA-256:3DA008490594B35245578FF3A1809C1A7E3440F88E10E7A6B42C3A4409EFEDAA
                                                                                                                            SHA-512:87A91F2ED4777125954EB0F55D05F80A03DDE764885E0046493CBA241CB347ABDC6FABF3AD802C97A02D848F96019353152794C41000AF07FE9DD9199A619CEB
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....P...H.........!....."...B...............@.....n......................................@... ......................................................H..p[...........`..............................................,................................text.... ......."..................`.P`.data...4....@.......&..............@.0..rdata.......P.......(..............@.0@.buildid5....`.......0..............@.0@.bss.........p........................`..edata...............2..............@.0@.idata...............4..............@.0..CRT....,............:..............@.0..tls.... ............<..............@.0..rsrc................>..............@.0..reloc...............B..............@.0B/4......(............F..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):43912
                                                                                                                            Entropy (8bit):6.941381697221795
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:AEE60AB73C8CD0C5368A69BC628F8664
                                                                                                                            SHA1:11E36C6CBC30B9184A08A117CFE431D685373028
                                                                                                                            SHA-256:0FC0C28AA99AD09D2FD56934836DAA18EDDCD72BFC00F7D556584E2A99AD076A
                                                                                                                            SHA-512:E22D76B2D36654C3EAE079F1D83AEAD1E3DCFFB07A1851F64D758DC8DBB8B85B23EA048FFE176BBA7F04483B76155C7D2E2BD6C1D4A8ACE396D74CCFD3E845BA
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...!5:5.P.........!.....&...J...............@.....f......................................@... .................................D....................P..p[...........`..............................................<................................text...x%.......&..................`.P`.data........@.......*..............@.0..rdata.......P.......,..............@.`@.buildid5....`.......6..............@.0@.bss.........p........................`..edata...............8..............@.0@.idata..D............:..............@.0..CRT....,............B..............@.0..tls.... ............D..............@.0..rsrc................F..............@.0..reloc...............J..............@.0B/4......(............N..............@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):72072
                                                                                                                            Entropy (8bit):6.874140212149791
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:41C3FD3D498B224C1F0B6D96BE6A74FB
                                                                                                                            SHA1:C51F689EA8A8CC36576992ABA9F0498709534158
                                                                                                                            SHA-256:1D34A7FA41E6FE3228B53554C94DAC7470AADBFC6B14C633B46122496D213939
                                                                                                                            SHA-512:38F5C6BA1048D927308850611532F5BFF86591840DD1811539DFF0F98232ED29A2FB7A787229DFF7B53B96ADE31FFC8C3855719B5564FC6F9FC458EF0414C279
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....5.5...........!.............................. b.........................`............@... ......................................0..................p[...@............................... ..........................X............................text...............................`.P`.data...............................@.`..rdata..D...........................@.`@.buildid5...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....,...........................@.0..tls.... .... ......................@.0..rsrc........0......................@.0..reloc.......@......................@.0B/4......,....P......................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):66440
                                                                                                                            Entropy (8bit):6.872060765663202
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:6AC0CD031A6D9639F854B19C5C869C4C
                                                                                                                            SHA1:93B389E820A3A910EA1A44F2769F47A7C691C83D
                                                                                                                            SHA-256:69F3560C12FABCB0C0A2A372EFBFDBDF894559B95DE71A331BBE5FE9EB2EB4A8
                                                                                                                            SHA-512:6621CF316DDA057E58CD526630B9B6AC20221080D5D570ECC33A8D7A6DB184D41891125EB3357209E90A33C54BEB29EA7A9D19EEC545D45AA7BF236C5F556489
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....0m5...........!.....x.........................e.........................@.......E....@... .........................................................p[... ......................................................|................................text...Xv.......x..................`.P`.data...\............|..............@.0..rdata...............~..............@.`@.buildid5...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....,...........................@.0..tls.... ...........................@.0..rsrc...............................@.0..reloc....... ......................@.0B/4......(....0......................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):72072
                                                                                                                            Entropy (8bit):6.693408201051494
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:FE095FF0E2A38D178808AFEC2E7EE653
                                                                                                                            SHA1:7A5E70D89BB8E396DB8DC36EB6973DFDA9EE6430
                                                                                                                            SHA-256:BFF1D90C8238887E0273E6966EE0348C4B316AD0E797C22F2840C00C0CEF952A
                                                                                                                            SHA-512:EA0FAC1757ED3DC9638867339418D9C47B25B20B110D664F63A2453B1BF39F906EF3EA0ECF88DA67028F52CB7754BB8D70C1DFED760C21006181FEB63830C11B
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....2.2...........!.....t........................Xd.........................P.......}....@... ...................................... ..................p[...0......................................................@................................text...8s.......t..................`.P`.data................x..............@.0..rdata...............z..............@.`@.buildid5...........................@.0@.bss..................................`..edata..............................@.0@.idata..............................@.0..CRT....,...........................@.0..tls.... ...........................@.0..rsrc........ ......................@.0..reloc.......0......................@.0B/4......,....@......................@.0B................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):3298192
                                                                                                                            Entropy (8bit):6.51555441715493
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:92F1DAA643720C895BAB5DB0D5F7A48C
                                                                                                                            SHA1:A5E0F7E6666E3794077E34EF24CF3890C7DB6521
                                                                                                                            SHA-256:D75B152D14D9815C92E9D7A226797632E205947DD610314763CFC5F693DAFC8D
                                                                                                                            SHA-512:FD569A4B88237105FECE598B7E4A2041E6E9E135B5E695110227D8E7BD7BD3A43C840EEC3CC4CCDA81966DAFF15FFD757DEC1003D9BDDB024406803E244EE039
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZx.....................@...................................x...........!..L.!This program cannot be run in DOS mode.$..PE..d...k%e`.........." ......$..........c!.......................................2......U2...`A........................................@.,.Yy...:-.(.....2.......0.`q...02..#....2.L=....,.....................@.,.(... .$.0............?-.......,.`....................text...(.$.......$................. ..`.rdata..47....$..8....$.............@..@.data........./......./.............@....pdata..`q....0..r...r0.............@..@.00cfg..(....`2.......1.............@..@.retplne0....p2.......1..................tls..........2.......1.............@..._RDATA........2.......1.............@..@.rsrc.........2.......1.............@..@.reloc..L=....2..>....1.............@..B........................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):98224
                                                                                                                            Entropy (8bit):6.452201564717313
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:F34EB034AA4A9735218686590CBA2E8B
                                                                                                                            SHA1:2BC20ACDCB201676B77A66FA7EC6B53FA2644713
                                                                                                                            SHA-256:9D2B40F0395CC5D1B4D5EA17B84970C29971D448C37104676DB577586D4AD1B1
                                                                                                                            SHA-512:D27D5E65E8206BD7923CF2A3C4384FEC0FC59E8BC29E25F8C03D039F3741C01D1A8C82979D7B88C10B209DB31FBBEC23909E976B3EE593DC33481F0050A445AF
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......*..qn.."n.."n.."...#l.."g.."e.."n.."B.."<..#c.."<..#~.."<..#q.."<..#o.."<.g"o.."<..#o.."Richn.."................PE..d...%|.a.........." .........`......p................................................{....`A.........................................B..4....J...............p..X....X...'..........h,..T............................,..8............................................text............................... ..`.rdata...@.......B..................@..@.data...@....`.......@..............@....pdata..X....p.......D..............@..@_RDATA...............P..............@..@.rsrc................R..............@..@.reloc...............V..............@..B........................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):37256
                                                                                                                            Entropy (8bit):6.297533243519742
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:135359D350F72AD4BF716B764D39E749
                                                                                                                            SHA1:2E59D9BBCCE356F0FECE56C9C4917A5CACEC63D7
                                                                                                                            SHA-256:34048ABAA070ECC13B318CEA31425F4CA3EDD133D350318AC65259E6058C8B32
                                                                                                                            SHA-512:CF23513D63AB2192C78CAE98BD3FEA67D933212B630BE111FA7E03BE3E92AF38E247EB2D3804437FD0FDA70FDC87916CD24CF1D3911E9F3BFB2CC4AB72B459BA
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......D_.O.>...>...>...N...>..RK...>...F^..>...>..1>..RK...>..RK...>..RK...>..RK...>..RK2..>..RK...>..Rich.>..........................PE..d...)|.a.........." .....:...6......`A....................................................`A.........................................l.......m..x....................n...#......<...(b..T............................b..8............P..X............................text...e9.......:.................. ..`.rdata.. "...P...$...>..............@..@.data... ............b..............@....pdata...............d..............@..@.rsrc................h..............@..@.reloc..<............l..............@..B................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {FF6FBE99-0B7D-4FE7-A5BF-AA69254A8889}, Number of Words: 10, Subject: Niwp App, Author: Tioao Wesah, Name of Creating Application: Niwp App, Template: ;1033, Comments: This installer database contains the logic and data required to install Niwp App., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Sun Dec 8 16:02:39 2024, Last Saved Time/Date: Sun Dec 8 16:02:39 2024, Last Printed: Sun Dec 8 16:02:39 2024, Number of Pages: 450
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):51524608
                                                                                                                            Entropy (8bit):7.975870328557857
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:69E06E5438DBF3A22FB6EF3315FFA43D
                                                                                                                            SHA1:78DBC3E5E0A5E3DF39011948755EF02429768EF1
                                                                                                                            SHA-256:27ADF3443BA52E71223895BF961F7116BC0CE95FB639F970DDE4DF392ED0ADFB
                                                                                                                            SHA-512:59BCEF295AB60CE1E5CF695C44AB4880A80BB9702B95B4F0C004D0198D6F136525416769458422554379F0C9935DB2F32C44FF7F639257BF1ADDE7D1D6FCEB78
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>.......................................................S.......m....................... ...!..."...#...$...%...&...'...(...)...*...............................................................................................l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...{...|...}...~...........................................................................................................................................................................................................L...........................8...:............................................................................... ...!..."...#...$...%...&...'...(...2...*...+...,...-......./...0...1.......3...4...5...6...7...;...9...A...D...<...=...>...?...@...2...B...C...J...E...F...G...H...I...1...K...M.......N...O...P...Q...R...........U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {FF6FBE99-0B7D-4FE7-A5BF-AA69254A8889}, Number of Words: 10, Subject: Niwp App, Author: Tioao Wesah, Name of Creating Application: Niwp App, Template: ;1033, Comments: This installer database contains the logic and data required to install Niwp App., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Sun Dec 8 16:02:39 2024, Last Saved Time/Date: Sun Dec 8 16:02:39 2024, Last Printed: Sun Dec 8 16:02:39 2024, Number of Pages: 450
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):51524608
                                                                                                                            Entropy (8bit):7.975870328557857
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:69E06E5438DBF3A22FB6EF3315FFA43D
                                                                                                                            SHA1:78DBC3E5E0A5E3DF39011948755EF02429768EF1
                                                                                                                            SHA-256:27ADF3443BA52E71223895BF961F7116BC0CE95FB639F970DDE4DF392ED0ADFB
                                                                                                                            SHA-512:59BCEF295AB60CE1E5CF695C44AB4880A80BB9702B95B4F0C004D0198D6F136525416769458422554379F0C9935DB2F32C44FF7F639257BF1ADDE7D1D6FCEB78
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>.......................................................S.......m....................... ...!..."...#...$...%...&...'...(...)...*...............................................................................................l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...{...|...}...~...........................................................................................................................................................................................................L...........................8...:............................................................................... ...!..."...#...$...%...&...'...(...2...*...+...,...-......./...0...1.......3...4...5...6...7...;...9...A...D...<...=...>...?...@...2...B...C...J...E...F...G...H...I...1...K...M.......N...O...P...Q...R...........U...V...W...X...Y...Z...[...\...]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):215596
                                                                                                                            Entropy (8bit):6.312631116144444
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:90B5841062A081CCE08A398387344CAE
                                                                                                                            SHA1:356F38478D335FE510EFA2F4538AF87623EA1181
                                                                                                                            SHA-256:60396AD814E18E50FD333256102549ACA565D418895DF014923BFAA76584C4BB
                                                                                                                            SHA-512:79FA31196518020F26159DC7220EB127F938E615A3EB2DF7D72373835F721E88880E275B1BE8A7FCD0F90F304373FD0EE2BB6E01436B25E6CDA322E5F686505B
                                                                                                                            Malicious:false
                                                                                                                            Preview:...@IXOS.@.....@CB.Y.@.....@.....@.....@.....@.....@......&.{0CF3B4A2-1F02-44A2-B594-48889D7BF089}..Niwp App..build.msi.@.....@.....@.....@......icon_15.exe..&.{FF6FBE99-0B7D-4FE7-A5BF-AA69254A8889}.....@.....@.....@.....@.......@.....@.....@.......@......Niwp App......Rollback..Rolling back action:....RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@B....@.....@.]....&.{89BA0234-ECD1-4530-8410-DE14A82C9A6A}4.C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\.@.......@.....@.....@......&.{095BE648-CEBF-4E68-A76A-76A3ED057C9C}).01:\Software\Tioao Wesah\Niwp App\Version.@.......@.....@.....@......&.{8CFDFB52-4805-4BC0-83B1-0AE6F0BF8F4B}B.C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\chrome_elf.dll.@.......@.....@.....@......&.{7D965C96-6AC9-4D41-A354-03670BE7C96D}E.C:\Users\user\AppData\Roaming\Tioao Wesah\Niwp App\CEPHtmlEngine.exe.@.......@.....@.....@......&.{4C833F3A-2BFC-4D04-B58A-F771BA32881A}=.C:\Us
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):787808
                                                                                                                            Entropy (8bit):6.693392695195763
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:8CF47242B5DF6A7F6D2D7AF9CC3A7921
                                                                                                                            SHA1:B51595A8A113CF889B0D1DD4B04DF16B3E18F318
                                                                                                                            SHA-256:CCB57BDBB19E1AEB2C8DD3845CDC53880C1979284E7B26A1D8AE73BBEAF25474
                                                                                                                            SHA-512:748C4767D258BFA6AD2664AA05EF7DC16F2D204FAE40530430EF5D1F38C8F61F074C6EC6501489053195B6B6F6E02D29FDE970D74C6AE97649D8FE1FD342A288
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............m..m..m.'n..m.'h.q.m.'i..m.."i..m.."n..m.."h..m.'l..m..l..m.#d..m.#m..m.#...m.....m.#o..m.Rich.m.........PE..L.....$g.........."!...).....4............................................... ............@A........................@J.......J..........................`=......4`...~..p........................... ~..@............................................text............................... ..`.rdata..Z...........................@..@.data...D-...`.......B..............@....fptable.............^..............@....rsrc................`..............@..@.reloc..4`.......b...f..............@..B........................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1021792
                                                                                                                            Entropy (8bit):6.608727172078022
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:EE09D6A1BB908B42C05FD0BEEB67DFD2
                                                                                                                            SHA1:1EB7C1304B7BCA649C2A5902B18A1EA57CEAA532
                                                                                                                            SHA-256:7BBF611F5E2A16439DC8CD11936F6364F6D5CC0044545C92775DA5646AFC7752
                                                                                                                            SHA-512:2DD2E4E66D2F2277F031C5F3C829A31C3B29196AB27262C6A8F1896A2113A1BE1687C9E8CD9667B89157F099DFB969EF14AE3EA602D4C772E960BC41D39C3D05
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......ia.p-..#-..#-..#].."!..#].."...#=..":..#=.."<..#=.."b..#].."7..#]..",..#].."...#-..#...#e.."T..#e..",..#e..#,..#-.g#,..#e..",..#Rich-..#........................PE..L.....$g.........."!...).....`...... ........ ...........................................@A............................L...,...@....................Z..`=......\....K..p....................L...... K..@............ ...............................text............................... ..`.rdata....... ......................@..@.data....(..........................@....fptable............................@....rsrc...............................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1021792
                                                                                                                            Entropy (8bit):6.608727172078022
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:EE09D6A1BB908B42C05FD0BEEB67DFD2
                                                                                                                            SHA1:1EB7C1304B7BCA649C2A5902B18A1EA57CEAA532
                                                                                                                            SHA-256:7BBF611F5E2A16439DC8CD11936F6364F6D5CC0044545C92775DA5646AFC7752
                                                                                                                            SHA-512:2DD2E4E66D2F2277F031C5F3C829A31C3B29196AB27262C6A8F1896A2113A1BE1687C9E8CD9667B89157F099DFB969EF14AE3EA602D4C772E960BC41D39C3D05
                                                                                                                            Malicious:false
                                                                                                                            Antivirus:
                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......ia.p-..#-..#-..#].."!..#].."...#=..":..#=.."<..#=.."b..#].."7..#]..",..#].."...#-..#...#e.."T..#e..",..#e..#,..#-.g#,..#e..",..#Rich-..#........................PE..L.....$g.........."!...).....`...... ........ ...........................................@A............................L...,...@....................Z..`=......\....K..p....................L...... K..@............ ...............................text............................... ..`.rdata....... ......................@..@.data....(..........................@....fptable............................@....rsrc...............................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1021792
                                                                                                                            Entropy (8bit):6.608727172078022
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:EE09D6A1BB908B42C05FD0BEEB67DFD2
                                                                                                                            SHA1:1EB7C1304B7BCA649C2A5902B18A1EA57CEAA532
                                                                                                                            SHA-256:7BBF611F5E2A16439DC8CD11936F6364F6D5CC0044545C92775DA5646AFC7752
                                                                                                                            SHA-512:2DD2E4E66D2F2277F031C5F3C829A31C3B29196AB27262C6A8F1896A2113A1BE1687C9E8CD9667B89157F099DFB969EF14AE3EA602D4C772E960BC41D39C3D05
                                                                                                                            Malicious:false
                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......ia.p-..#-..#-..#].."!..#].."...#=..":..#=.."<..#=.."b..#].."7..#]..",..#].."...#-..#...#e.."T..#e..",..#e..#,..#-.g#,..#e..",..#Rich-..#........................PE..L.....$g.........."!...).....`...... ........ ...........................................@A............................L...,...@....................Z..`=......\....K..p....................L...... K..@............ ...............................text............................... ..`.rdata....... ......................@..@.data....(..........................@....fptable............................@....rsrc...............................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1021792
                                                                                                                            Entropy (8bit):6.608727172078022
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:EE09D6A1BB908B42C05FD0BEEB67DFD2
                                                                                                                            SHA1:1EB7C1304B7BCA649C2A5902B18A1EA57CEAA532
                                                                                                                            SHA-256:7BBF611F5E2A16439DC8CD11936F6364F6D5CC0044545C92775DA5646AFC7752
                                                                                                                            SHA-512:2DD2E4E66D2F2277F031C5F3C829A31C3B29196AB27262C6A8F1896A2113A1BE1687C9E8CD9667B89157F099DFB969EF14AE3EA602D4C772E960BC41D39C3D05
                                                                                                                            Malicious:false
                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......ia.p-..#-..#-..#].."!..#].."...#=..":..#=.."<..#=.."b..#].."7..#]..",..#].."...#-..#...#e.."T..#e..",..#e..#,..#-.g#,..#e..",..#Rich-..#........................PE..L.....$g.........."!...).....`...... ........ ...........................................@A............................L...,...@....................Z..`=......\....K..p....................L...... K..@............ ...............................text............................... ..`.rdata....... ......................@..@.data....(..........................@....fptable............................@....rsrc...............................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1021792
                                                                                                                            Entropy (8bit):6.608727172078022
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:EE09D6A1BB908B42C05FD0BEEB67DFD2
                                                                                                                            SHA1:1EB7C1304B7BCA649C2A5902B18A1EA57CEAA532
                                                                                                                            SHA-256:7BBF611F5E2A16439DC8CD11936F6364F6D5CC0044545C92775DA5646AFC7752
                                                                                                                            SHA-512:2DD2E4E66D2F2277F031C5F3C829A31C3B29196AB27262C6A8F1896A2113A1BE1687C9E8CD9667B89157F099DFB969EF14AE3EA602D4C772E960BC41D39C3D05
                                                                                                                            Malicious:false
                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......ia.p-..#-..#-..#].."!..#].."...#=..":..#=.."<..#=.."b..#].."7..#]..",..#].."...#-..#...#e.."T..#e..",..#e..#,..#-.g#,..#e..",..#Rich-..#........................PE..L.....$g.........."!...).....`...... ........ ...........................................@A............................L...,...@....................Z..`=......\....K..p....................L...... K..@............ ...............................text............................... ..`.rdata....... ......................@..@.data....(..........................@....fptable............................@....rsrc...............................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):1021792
                                                                                                                            Entropy (8bit):6.608727172078022
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:EE09D6A1BB908B42C05FD0BEEB67DFD2
                                                                                                                            SHA1:1EB7C1304B7BCA649C2A5902B18A1EA57CEAA532
                                                                                                                            SHA-256:7BBF611F5E2A16439DC8CD11936F6364F6D5CC0044545C92775DA5646AFC7752
                                                                                                                            SHA-512:2DD2E4E66D2F2277F031C5F3C829A31C3B29196AB27262C6A8F1896A2113A1BE1687C9E8CD9667B89157F099DFB969EF14AE3EA602D4C772E960BC41D39C3D05
                                                                                                                            Malicious:false
                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......ia.p-..#-..#-..#].."!..#].."...#=..":..#=.."<..#=.."b..#].."7..#]..",..#].."...#-..#...#e.."T..#e..",..#e..#,..#-.g#,..#e..",..#Rich-..#........................PE..L.....$g.........."!...).....`...... ........ ...........................................@A............................L...,...@....................Z..`=......\....K..p....................L...... K..@............ ...............................text............................... ..`.rdata....... ......................@..@.data....(..........................@....fptable............................@....rsrc...............................@..@.reloc..\...........................@..B................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):380520
                                                                                                                            Entropy (8bit):6.512348002260683
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:FFDAACB43C074A8CB9A608C612D7540B
                                                                                                                            SHA1:8F054A7F77853DE365A7763D93933660E6E1A890
                                                                                                                            SHA-256:7484797EA4480BC71509FA28B16E607F82323E05C44F59FFA65DB3826ED1B388
                                                                                                                            SHA-512:A9BD31377F7A6ECF75B1D90648847CB83D8BD65AD0B408C4F8DE6EB50764EEF1402E7ACDFF375B7C3B07AC9F94184BD399A10A22418DB474908B5E7A1ADFE263
                                                                                                                            Malicious:false
                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........^..?{..?{..?{..x..?{..~..?{...x..?{......?{...~..?{.....?{..z..?{..?z..>{..r..?{..{..?{....?{..?.?{..y..?{.Rich.?{.........PE..L...>.$g.........."!...)..................... .......................................'....@A........................@3..X....3.......... ...............h:.......6..@...p...............................@............ ..(............................text...J........................... ..`.rdata...$... ...&..................@..@.data....!...P......................@....fptable.............@..............@....rsrc... ............B..............@..@.reloc...6.......8...\..............@..B........................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20480
                                                                                                                            Entropy (8bit):1.1619545331470458
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:57A7694FA6BFA1281CADF80D6910ACE7
                                                                                                                            SHA1:4C6E797D4873E150CD0892AAA23940ECD19D721C
                                                                                                                            SHA-256:87B9C3B05E276C1703E4163704293F814FFB26389372FF0F4337C5EAFEE6B0CE
                                                                                                                            SHA-512:E3AF65F1585E9B8BFF336558705196EB5C9246026732081128D16BC4646132D0FA2EA0A3604131BE865FCF7B25BC901AA7E9589239D22075E69168E71B5D7070
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20480
                                                                                                                            Entropy (8bit):1.5381539320919624
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:9042B46F34063D6CA81F0936442F7907
                                                                                                                            SHA1:6F38847BB23BC594B29F9F88983E8384F82DC1BC
                                                                                                                            SHA-256:24669F11A6F5F67668EEC58195B68C411B93DA4E541282B920A9932FE1AEB1BA
                                                                                                                            SHA-512:153C44DEB3FFAD355772CD2F267278C9DBA58C8E2E001955ED6B2711680B5BCC2E37745593882982E1860AA3E08B25C1AF6BD541AB61E66E5AE1D0119A75D91F
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):436892
                                                                                                                            Entropy (8bit):5.36583141132504
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:ABCFCA0F468852059C4FCB12F43A5A7B
                                                                                                                            SHA1:ADB96830D14FCBEACF0E53D8DC9FA5CEE6B7E438
                                                                                                                            SHA-256:273861A3853CE2497E3443E597A5FEBF809B337225EE3871A136C5EDC7AD2D69
                                                                                                                            SHA-512:2D459C188DB49CC6270CFCFC13F0EDDA1A230E8E782A24D5EDBD8334F84E0A72D4F4F02D44D0D1B0BAE82D4D083AD009B24EDB82171A327108C01B59D708D90A
                                                                                                                            Malicious:false
                                                                                                                            Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20480
                                                                                                                            Entropy (8bit):1.5381539320919624
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:9042B46F34063D6CA81F0936442F7907
                                                                                                                            SHA1:6F38847BB23BC594B29F9F88983E8384F82DC1BC
                                                                                                                            SHA-256:24669F11A6F5F67668EEC58195B68C411B93DA4E541282B920A9932FE1AEB1BA
                                                                                                                            SHA-512:153C44DEB3FFAD355772CD2F267278C9DBA58C8E2E001955ED6B2711680B5BCC2E37745593882982E1860AA3E08B25C1AF6BD541AB61E66E5AE1D0119A75D91F
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):512
                                                                                                                            Entropy (8bit):0.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                                                                                            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                                                                                            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                                                                                            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                                                                                            Malicious:false
                                                                                                                            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):32768
                                                                                                                            Entropy (8bit):1.235288389566707
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:64D640F15F67EC95BC83BD9B5C79B580
                                                                                                                            SHA1:4F8465593221AFB64308C2B2BFFC6802F64A36FF
                                                                                                                            SHA-256:87C73CCE2B6EAD2BF64ED5523CC0236121A0ED0FD48E1CAD841E289F3695102A
                                                                                                                            SHA-512:E3CB83E4D435733A2120BCB31A1C8B24C8ABA37459BDA427F966B9E4D4355A95CD4678A9DF971025BE352D85E2FDC36529819FD31255728843ADD7C69980CED2
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):73728
                                                                                                                            Entropy (8bit):0.12763299849269313
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:F3117A8274014699015E68B930F64C5F
                                                                                                                            SHA1:6A346991E5B6C4A5EFBF65E51E9DB80072AB76E7
                                                                                                                            SHA-256:869D6FD921060981F809CD0A3D898EC4D0DC278A6F89D9CA2FFEB9E07EAD5281
                                                                                                                            SHA-512:5705144DB68A252D53DAAA98652CDE947D168963A32503F986A33EE5BB29790CE8AA9F3E36D1333A4E2DEE8C41357B33137F393DDEED2426A02116B3D39FC249
                                                                                                                            Malicious:false
                                                                                                                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):32768
                                                                                                                            Entropy (8bit):1.235288389566707
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:64D640F15F67EC95BC83BD9B5C79B580
                                                                                                                            SHA1:4F8465593221AFB64308C2B2BFFC6802F64A36FF
                                                                                                                            SHA-256:87C73CCE2B6EAD2BF64ED5523CC0236121A0ED0FD48E1CAD841E289F3695102A
                                                                                                                            SHA-512:E3CB83E4D435733A2120BCB31A1C8B24C8ABA37459BDA427F966B9E4D4355A95CD4678A9DF971025BE352D85E2FDC36529819FD31255728843ADD7C69980CED2
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):32768
                                                                                                                            Entropy (8bit):0.06905371372694025
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:E1AE08167A0C913F1D7B65B4243A5722
                                                                                                                            SHA1:DB64212471FC6CBB428ECF65A67B6B37C5A7D046
                                                                                                                            SHA-256:A667AF6041B9849389E9688F84B03CFF75A3814338A6E6F5EA7EFCAFFE8CD12D
                                                                                                                            SHA-512:3CC34B799F41F7DB35E3BD2E108098A8233F32EBB205667EA10F873AA5675359A8166AAB34EDB02A56A2483E5CD17E4EC92BFA74CAA47CCD1C949DDA34DFFF9B
                                                                                                                            Malicious:false
                                                                                                                            Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):20480
                                                                                                                            Entropy (8bit):1.5381539320919624
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:9042B46F34063D6CA81F0936442F7907
                                                                                                                            SHA1:6F38847BB23BC594B29F9F88983E8384F82DC1BC
                                                                                                                            SHA-256:24669F11A6F5F67668EEC58195B68C411B93DA4E541282B920A9932FE1AEB1BA
                                                                                                                            SHA-512:153C44DEB3FFAD355772CD2F267278C9DBA58C8E2E001955ED6B2711680B5BCC2E37745593882982E1860AA3E08B25C1AF6BD541AB61E66E5AE1D0119A75D91F
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):512
                                                                                                                            Entropy (8bit):0.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                                                                                            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                                                                                            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                                                                                            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                                                                                            Malicious:false
                                                                                                                            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):512
                                                                                                                            Entropy (8bit):0.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                                                                                            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                                                                                            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                                                                                            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                                                                                            Malicious:false
                                                                                                                            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:Composite Document File V2 Document, Cannot read section info
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):32768
                                                                                                                            Entropy (8bit):1.235288389566707
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:64D640F15F67EC95BC83BD9B5C79B580
                                                                                                                            SHA1:4F8465593221AFB64308C2B2BFFC6802F64A36FF
                                                                                                                            SHA-256:87C73CCE2B6EAD2BF64ED5523CC0236121A0ED0FD48E1CAD841E289F3695102A
                                                                                                                            SHA-512:E3CB83E4D435733A2120BCB31A1C8B24C8ABA37459BDA427F966B9E4D4355A95CD4678A9DF971025BE352D85E2FDC36529819FD31255728843ADD7C69980CED2
                                                                                                                            Malicious:false
                                                                                                                            Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):512
                                                                                                                            Entropy (8bit):0.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                                                                                            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                                                                                            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                                                                                            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                                                                                            Malicious:false
                                                                                                                            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            Process:C:\Windows\System32\msiexec.exe
                                                                                                                            File Type:data
                                                                                                                            Category:dropped
                                                                                                                            Size (bytes):512
                                                                                                                            Entropy (8bit):0.0
                                                                                                                            Encrypted:false
                                                                                                                            SSDEEP:
                                                                                                                            MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                                                                                            SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                                                                                            SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                                                                                            SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                                                                                            Malicious:false
                                                                                                                            Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                            File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Security: 0, Code page: 1252, Revision Number: {FF6FBE99-0B7D-4FE7-A5BF-AA69254A8889}, Number of Words: 10, Subject: Niwp App, Author: Tioao Wesah, Name of Creating Application: Niwp App, Template: ;1033, Comments: This installer database contains the logic and data required to install Niwp App., Title: Installation Database, Keywords: Installer, MSI, Database, Create Time/Date: Sun Dec 8 16:02:39 2024, Last Saved Time/Date: Sun Dec 8 16:02:39 2024, Last Printed: Sun Dec 8 16:02:39 2024, Number of Pages: 450
                                                                                                                            Entropy (8bit):7.975870328557857
                                                                                                                            TrID:
                                                                                                                            • Windows SDK Setup Transform Script (63028/2) 88.73%
                                                                                                                            • Generic OLE2 / Multistream Compound File (8008/1) 11.27%
                                                                                                                            File name:build.msi
                                                                                                                            File size:51'524'608 bytes
                                                                                                                            MD5:69e06e5438dbf3a22fb6ef3315ffa43d
                                                                                                                            SHA1:78dbc3e5e0a5e3df39011948755ef02429768ef1
                                                                                                                            SHA256:27adf3443ba52e71223895bf961f7116bc0ce95fb639f970dde4df392ed0adfb
                                                                                                                            SHA512:59bcef295ab60ce1e5cf695c44ab4880a80bb9702b95b4f0c004d0198d6f136525416769458422554379f0c9935db2f32c44ff7f639257bf1adde7d1d6fceb78
                                                                                                                            SSDEEP:1572864:DfdQN5+iFUj3dn1U0PymWU6L7NXDW6TpyDGau:hg5+r3dn/y/VflDW7f
                                                                                                                            TLSH:10B7332175A6C93EEA7E23B2257CAF59417D7D780B3209E363E47B6A5A70CC15231B03
                                                                                                                            File Content Preview:........................>.......................................................S.......m....................... ...!..."...#...$...%...&...'...(...)...*...............................................................................................l...m..
                                                                                                                            Icon Hash:2d2e3797b32b2b99
                                                                                                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                            2024-12-14T14:18:05.275559+01002822521ETPRO MALWARE Malicious SSL Certificate Detected (Linux.Rex Scanner)1104.131.68.180443192.168.2.1249711TCP
                                                                                                                            2024-12-14T14:18:05.281226+01002829202ETPRO MALWARE MSIL/Zbrain PUP/Stealer Installer UA1192.168.2.1249711104.131.68.180443TCP
                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                            Dec 14, 2024 14:18:03.965672016 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:03.965720892 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:03.965836048 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:03.970346928 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:03.970361948 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.209945917 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.210031033 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.275501013 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.275558949 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.276550055 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.276635885 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.280836105 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.281143904 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.281188011 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.627635956 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.627856016 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.627955914 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.628011942 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.628027916 CET44349711104.131.68.180192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:05.628040075 CET49711443192.168.2.12104.131.68.180
                                                                                                                            Dec 14, 2024 14:18:05.628077030 CET49711443192.168.2.12104.131.68.180
                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                            Dec 14, 2024 14:18:02.527544022 CET4987453192.168.2.121.1.1.1
                                                                                                                            Dec 14, 2024 14:18:03.515531063 CET4987453192.168.2.121.1.1.1
                                                                                                                            Dec 14, 2024 14:18:03.959393024 CET53498741.1.1.1192.168.2.12
                                                                                                                            Dec 14, 2024 14:18:03.959419966 CET53498741.1.1.1192.168.2.12
                                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                            Dec 14, 2024 14:18:02.527544022 CET192.168.2.121.1.1.10x31fStandard query (0)puta-key.comA (IP address)IN (0x0001)false
                                                                                                                            Dec 14, 2024 14:18:03.515531063 CET192.168.2.121.1.1.10x31fStandard query (0)puta-key.comA (IP address)IN (0x0001)false
                                                                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                            Dec 14, 2024 14:18:03.959393024 CET1.1.1.1192.168.2.120x31fNo error (0)puta-key.com104.131.68.180A (IP address)IN (0x0001)false
                                                                                                                            Dec 14, 2024 14:18:03.959393024 CET1.1.1.1192.168.2.120x31fNo error (0)puta-key.com45.77.249.79A (IP address)IN (0x0001)false
                                                                                                                            Dec 14, 2024 14:18:03.959393024 CET1.1.1.1192.168.2.120x31fNo error (0)puta-key.com178.62.201.34A (IP address)IN (0x0001)false
                                                                                                                            Dec 14, 2024 14:18:03.959419966 CET1.1.1.1192.168.2.120x31fNo error (0)puta-key.com104.131.68.180A (IP address)IN (0x0001)false
                                                                                                                            Dec 14, 2024 14:18:03.959419966 CET1.1.1.1192.168.2.120x31fNo error (0)puta-key.com45.77.249.79A (IP address)IN (0x0001)false
                                                                                                                            Dec 14, 2024 14:18:03.959419966 CET1.1.1.1192.168.2.120x31fNo error (0)puta-key.com178.62.201.34A (IP address)IN (0x0001)false
                                                                                                                            • puta-key.com
                                                                                                                            Session IDSource IPSource PortDestination IPDestination PortPIDProcess
                                                                                                                            0192.168.2.1249711104.131.68.1804436936C:\Windows\SysWOW64\msiexec.exe
                                                                                                                            TimestampBytes transferredDirectionData
                                                                                                                            2024-12-14 13:18:05 UTC194OUTPOST /licenseUser.php HTTP/1.1
                                                                                                                            Content-Type: application/x-www-form-urlencoded; charset=utf-8
                                                                                                                            User-Agent: AdvancedInstaller
                                                                                                                            Host: puta-key.com
                                                                                                                            Content-Length: 37
                                                                                                                            Cache-Control: no-cache
                                                                                                                            2024-12-14 13:18:05 UTC37OUTData Raw: 44 61 74 65 3d 31 34 25 32 46 31 32 25 32 46 32 30 32 34 26 54 69 6d 65 3d 30 38 25 33 41 31 38 25 33 41 30 31
                                                                                                                            Data Ascii: Date=14%2F12%2F2024&Time=08%3A18%3A01
                                                                                                                            2024-12-14 13:18:05 UTC94INHTTP/1.1 200 OK
                                                                                                                            Date: Sat, 14 Dec 2024 13:18:05 GMT
                                                                                                                            Content-Length: 0
                                                                                                                            Connection: close


                                                                                                                            Click to jump to process

                                                                                                                            Click to jump to process

                                                                                                                            Click to dive into process behavior distribution

                                                                                                                            Click to jump to process

                                                                                                                            Target ID:0
                                                                                                                            Start time:08:17:50
                                                                                                                            Start date:14/12/2024
                                                                                                                            Path:C:\Windows\System32\msiexec.exe
                                                                                                                            Wow64 process (32bit):false
                                                                                                                            Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\build.msi"
                                                                                                                            Imagebase:0x7ff70ce70000
                                                                                                                            File size:69'632 bytes
                                                                                                                            MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                                                                                            Has elevated privileges:true
                                                                                                                            Has administrator privileges:true
                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                            Reputation:high
                                                                                                                            Has exited:true

                                                                                                                            Target ID:2
                                                                                                                            Start time:08:17:51
                                                                                                                            Start date:14/12/2024
                                                                                                                            Path:C:\Windows\System32\msiexec.exe
                                                                                                                            Wow64 process (32bit):false
                                                                                                                            Commandline:C:\Windows\system32\msiexec.exe /V
                                                                                                                            Imagebase:0x7ff70ce70000
                                                                                                                            File size:69'632 bytes
                                                                                                                            MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                                                                                            Has elevated privileges:true
                                                                                                                            Has administrator privileges:true
                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                            Reputation:high
                                                                                                                            Has exited:false

                                                                                                                            Target ID:3
                                                                                                                            Start time:08:17:53
                                                                                                                            Start date:14/12/2024
                                                                                                                            Path:C:\Windows\SysWOW64\msiexec.exe
                                                                                                                            Wow64 process (32bit):true
                                                                                                                            Commandline:C:\Windows\syswow64\MsiExec.exe -Embedding 59296BC936D923419909214161EEAC82
                                                                                                                            Imagebase:0xe20000
                                                                                                                            File size:59'904 bytes
                                                                                                                            MD5 hash:9D09DC1EDA745A5F87553048E57620CF
                                                                                                                            Has elevated privileges:true
                                                                                                                            Has administrator privileges:true
                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                            Reputation:high
                                                                                                                            Has exited:true

                                                                                                                            Target ID:7
                                                                                                                            Start time:08:18:06
                                                                                                                            Start date:14/12/2024
                                                                                                                            Path:C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
                                                                                                                            Wow64 process (32bit):true
                                                                                                                            Commandline: -NoProfile -Noninteractive -ExecutionPolicy Bypass -File "C:\Users\user\AppData\Local\Temp\pssD9B.ps1" -propFile "C:\Users\user\AppData\Local\Temp\msiD88.txt" -scriptFile "C:\Users\user\AppData\Local\Temp\scrD89.ps1" -scriptArgsFile "C:\Users\user\AppData\Local\Temp\scrD8A.txt" -propSep " :<->: " -lineSep " <<:>> " -testPrefix "_testValue."
                                                                                                                            Imagebase:0xa90000
                                                                                                                            File size:433'152 bytes
                                                                                                                            MD5 hash:C32CA4ACFCC635EC1EA6ED8A34DF5FAC
                                                                                                                            Has elevated privileges:true
                                                                                                                            Has administrator privileges:true
                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                            Reputation:high
                                                                                                                            Has exited:true

                                                                                                                            Target ID:8
                                                                                                                            Start time:08:18:06
                                                                                                                            Start date:14/12/2024
                                                                                                                            Path:C:\Windows\System32\conhost.exe
                                                                                                                            Wow64 process (32bit):false
                                                                                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                            Imagebase:0x7ff704000000
                                                                                                                            File size:862'208 bytes
                                                                                                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                            Has elevated privileges:true
                                                                                                                            Has administrator privileges:true
                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                            Reputation:high
                                                                                                                            Has exited:true

                                                                                                                            Reset < >
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503645600.0000000002C20000.00000040.00000800.00020000.00000000.sdmp, Offset: 02C20000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2c20000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 4f4bd838ee10c0542b6345626ca74f73b626e7e411f0fa9f8f588d6b0b95b656
                                                                                                                              • Instruction ID: fee3f02dfc9ee4c92bbe26de47e6c89a59def44db14ddbddafea6440bb4420b8
                                                                                                                              • Opcode Fuzzy Hash: 4f4bd838ee10c0542b6345626ca74f73b626e7e411f0fa9f8f588d6b0b95b656
                                                                                                                              • Instruction Fuzzy Hash: FDA17F35E002188FDB14DFA5C584A6DBBF2FF84710F158659E506AB368DB34AD8DCB50
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2513011410.00000000072E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 072E0000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_72e0000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 62260116a62597c92ddf8a2028b12fdd0ef31ce63570ce57164b45380aaa9122
                                                                                                                              • Instruction ID: a6397ecf59970fdc457d71b3a0c0502667a4353d21bc41c7ec83e85abb04de32
                                                                                                                              • Opcode Fuzzy Hash: 62260116a62597c92ddf8a2028b12fdd0ef31ce63570ce57164b45380aaa9122
                                                                                                                              • Instruction Fuzzy Hash: 966105B072021EDFDB259F69D4406AA7BFABF85210F54C07AE449CB251DB31CCA1C7A1
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503645600.0000000002C20000.00000040.00000800.00020000.00000000.sdmp, Offset: 02C20000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2c20000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 95e7e1243e9becbad40d5db0807d32439652cde29d7d72a1ce24b9e9a26fc212
                                                                                                                              • Instruction ID: f1ec83310fc51bff9b8df61bdaca80e54e50c4ad2743a68c0d1eacb3841790af
                                                                                                                              • Opcode Fuzzy Hash: 95e7e1243e9becbad40d5db0807d32439652cde29d7d72a1ce24b9e9a26fc212
                                                                                                                              • Instruction Fuzzy Hash: 3671E230A00219CFDB14DF68D890B9EBBF6FF89354F14866AD415DB251DB31AD4ACB90
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503645600.0000000002C20000.00000040.00000800.00020000.00000000.sdmp, Offset: 02C20000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2c20000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 4f6f60acb7754c06e0499b49e22f2e92c24cabffbb53e5eaa00f4f4eeb8ee430
                                                                                                                              • Instruction ID: 98bd58b6b7609ff02fabe8ef9241e9fdb08830e217079fc4583ae705b9f75501
                                                                                                                              • Opcode Fuzzy Hash: 4f6f60acb7754c06e0499b49e22f2e92c24cabffbb53e5eaa00f4f4eeb8ee430
                                                                                                                              • Instruction Fuzzy Hash: B7717E34E01258DFDB14EFA5D894BADBBF2BF88344F148569D402AB290DF35AD4ACB50
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503645600.0000000002C20000.00000040.00000800.00020000.00000000.sdmp, Offset: 02C20000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2c20000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: f6b72b43cfe1f28629f6a4f2897a6d145edb9782911de5309fd9e506deb0d0a6
                                                                                                                              • Instruction ID: b7413b50986ec109a73510316acddf7bb917d0bf741dac603a6874650c922944
                                                                                                                              • Opcode Fuzzy Hash: f6b72b43cfe1f28629f6a4f2897a6d145edb9782911de5309fd9e506deb0d0a6
                                                                                                                              • Instruction Fuzzy Hash: 1B41A175A402109FEB18DF64C895AAE77F2FF89790F184569E506EB3A0CF349D41CB90
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503645600.0000000002C20000.00000040.00000800.00020000.00000000.sdmp, Offset: 02C20000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2c20000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 46d0479e418e48795dedccd2d0d05a3e8c5b6cee1b5aef691e06c5cd08f60e10
                                                                                                                              • Instruction ID: 494d6b50ca608f3f0d736611a21c08014b2b89380923b869a07185245bce7e2d
                                                                                                                              • Opcode Fuzzy Hash: 46d0479e418e48795dedccd2d0d05a3e8c5b6cee1b5aef691e06c5cd08f60e10
                                                                                                                              • Instruction Fuzzy Hash: 83419070E00219CFDB18DFA5C89479DBBF2BF85340F188969D105AB290DF74A949CF90
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2513011410.00000000072E0000.00000040.00000800.00020000.00000000.sdmp, Offset: 072E0000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_72e0000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 2fbd236c385168acf1d9effa70920ce821de1e80d8fcdcd062d106b81b7216d3
                                                                                                                              • Instruction ID: 4569e99e0b55e0ea218a83c2698ba6cb68e3fb7bd94fbcd477c8d084e0146936
                                                                                                                              • Opcode Fuzzy Hash: 2fbd236c385168acf1d9effa70920ce821de1e80d8fcdcd062d106b81b7216d3
                                                                                                                              • Instruction Fuzzy Hash: B0317CF0A2420FDFCB258F15C5846A977F9BF45210F9881BAD845CB266D374D9E0CB92
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503210742.0000000002B1D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B1D000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2b1d000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 41d53536aa729d7ef917dee381005ffeebf3a9f19d8e46b9642f9d31f0d76714
                                                                                                                              • Instruction ID: 6ad6d8ca1f601341f0e63f47974e07df9d9266870d2ba546dd4491fdcbadf7c4
                                                                                                                              • Opcode Fuzzy Hash: 41d53536aa729d7ef917dee381005ffeebf3a9f19d8e46b9642f9d31f0d76714
                                                                                                                              • Instruction Fuzzy Hash: 6C015E7240D3C49FE7124B258DA8752BFB8EF53224F1981DBE9848F1A3D2689C45CB72
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503210742.0000000002B1D000.00000040.00000800.00020000.00000000.sdmp, Offset: 02B1D000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2b1d000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: 2a0c4b5dd2f5336b41d36f0d0650dbda690075f7f0df2a08e9b4749f8c492f1d
                                                                                                                              • Instruction ID: e2ae595d78f503a4696e7c41579ff29e9737d2dc13f696500c9e8ea5332d6af2
                                                                                                                              • Opcode Fuzzy Hash: 2a0c4b5dd2f5336b41d36f0d0650dbda690075f7f0df2a08e9b4749f8c492f1d
                                                                                                                              • Instruction Fuzzy Hash: DA012B31504301EBE7204F19CD98B67BF98DF81324F5CC099DE440F142C3789442C6B1
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503645600.0000000002C20000.00000040.00000800.00020000.00000000.sdmp, Offset: 02C20000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2c20000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: dc665e9f58d8cc65a354c2605671e5c8213955e79db2502a33539bcb56cfb95e
                                                                                                                              • Instruction ID: cb67dc60f6f07aa9343a597f35e784069aaa648dfca3df1e549d70ce8e124cfe
                                                                                                                              • Opcode Fuzzy Hash: dc665e9f58d8cc65a354c2605671e5c8213955e79db2502a33539bcb56cfb95e
                                                                                                                              • Instruction Fuzzy Hash: 4BF01235A000189FCB05CF9CD890AEEF7B1FF88324F208199E515A72A0C732AC52CB60
                                                                                                                              Memory Dump Source
                                                                                                                              • Source File: 00000007.00000002.2503645600.0000000002C20000.00000040.00000800.00020000.00000000.sdmp, Offset: 02C20000, based on PE: false
                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                              • Snapshot File: hcaresult_7_2_2c20000_powershell.jbxd
                                                                                                                              Similarity
                                                                                                                              • API ID:
                                                                                                                              • String ID:
                                                                                                                              • API String ID:
                                                                                                                              • Opcode ID: ccd5bf2842b6b7e14bc338572e5b85da31f32db7a19ae3596689fac73e0c0b35
                                                                                                                              • Instruction ID: 8c97df26658ca5e0084fc8563328dd3449975062a5f3ad6bf4d0aab95e87c7ca
                                                                                                                              • Opcode Fuzzy Hash: ccd5bf2842b6b7e14bc338572e5b85da31f32db7a19ae3596689fac73e0c0b35
                                                                                                                              • Instruction Fuzzy Hash: 23F0373464020ADFEB04DBA4C555B6E77F2DB41300F144558D202AF294DF789D89CBC0