Windows Analysis Report
PlasmaSetup@LR_2.exe

Overview

General Information

Sample name: PlasmaSetup@LR_2.exe
Analysis ID: 1579303
MD5: 3443898e0b0bd2a27c1bcebfe41b702e
SHA1: 3d83edc844cb4c011e9a5a554fe99a6f128e21ca
SHA256: de4c90695da23b3ed3a399bf5cdc2e5f85f3c074180480b19fb54dcb0ece007f
Infos:

Detection

Score: 25
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Signatures

Machine Learning detection for dropped file
Checks if the current process is being debugged
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
One or more processes crash
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

AV Detection

barindex
Source: C:\Plasma\Switcher.exe Joe Sandbox ML: detected
Source: C:\Plasma\pmarquee.exe Joe Sandbox ML: detected
Source: C:\Plasma\Switcher.exe Joe Sandbox ML: detected
Source: C:\Plasma\pmarquee.exe Joe Sandbox ML: detected
Source: C:\Plasma\Switcher.exe Joe Sandbox ML: detected
Source: C:\Plasma\pmarquee.exe Joe Sandbox ML: detected
Source: C:\Plasma\Switcher.exe Joe Sandbox ML: detected
Source: C:\Plasma\pmarquee.exe Joe Sandbox ML: detected
Source: PlasmaSetup@LR_2.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\LangDLL.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Plasma\pmanager.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 4856 -s 648
Source: PlasmaSetup@LR_2.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: sus25.winEXE@9/46@0/11
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma
Source: C:\Plasma\pmanager.exe Mutant created: \Sessions\1\BaseNamedObjects\IB.SQL.MONITOR.Mutex4_1
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess5076
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess4856
Source: C:\Plasma\pbrowser.exe Mutant created: \Sessions\1\BaseNamedObjects\LDV_BROWSER
Source: C:\Windows\SysWOW64\WerFault.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\WERReportingForProcess3916
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Local\Temp\nsn7F2F.tmp
Source: Yara match File source: 0000000A.00000002.1448474464.0000000000401000.00000040.00000001.01000000.0000000C.sdmp, type: MEMORY
Source: Yara match File source: 00000010.00000002.1655947520.0000000000401000.00000040.00000001.01000000.0000000D.sdmp, type: MEMORY
Source: PlasmaSetup@LR_2.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Plasma\pbrowser.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Plasma\pmanager.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Plasma\pmanager.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Plasma\pbrowser.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Plasma\pmanager.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File read: C:\Users\desktop.ini
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File read: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe
Source: unknown Process created: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe "C:\Users\user\Desktop\PlasmaSetup@LR_2.exe"
Source: unknown Process created: C:\Plasma\pbrowser.exe "C:\Plasma\pbrowser.exe"
Source: unknown Process created: C:\Plasma\pmanager.exe "C:\Plasma\pmanager.exe"
Source: C:\Plasma\pmanager.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 4856 -s 648
Source: unknown Process created: C:\Plasma\pmanager.exe "C:\Plasma\pmanager.exe"
Source: C:\Plasma\pmanager.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 5076 -s 624
Source: unknown Process created: C:\Plasma\pbrowser.exe "C:\Plasma\pbrowser.exe"
Source: unknown Process created: C:\Plasma\pmanager.exe "C:\Plasma\pmanager.exe"
Source: C:\Plasma\pmanager.exe Process created: C:\Windows\SysWOW64\WerFault.exe C:\Windows\SysWOW64\WerFault.exe -u -p 3916 -s 620
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: apphelp.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: acgenral.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: uxtheme.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: winmm.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: samcli.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: msacm32.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: userenv.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: dwmapi.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: urlmon.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: mpr.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: sspicli.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: winmmbase.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: srvcli.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: netutils.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: aclayers.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: sfc.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: sfc_os.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: shfolder.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: propsys.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: textinputframework.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: coremessaging.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: ntmarta.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: textshaping.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: riched20.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: usp10.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: msls31.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: linkinfo.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: ntshrui.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Section loaded: cscapi.dll
Source: C:\Plasma\pbrowser.exe Section loaded: apphelp.dll
Source: C:\Plasma\pbrowser.exe Section loaded: urlmon.dll
Source: C:\Plasma\pbrowser.exe Section loaded: version.dll
Source: C:\Plasma\pbrowser.exe Section loaded: winmm.dll
Source: C:\Plasma\pbrowser.exe Section loaded: iertutil.dll
Source: C:\Plasma\pbrowser.exe Section loaded: srvcli.dll
Source: C:\Plasma\pbrowser.exe Section loaded: netutils.dll
Source: C:\Plasma\pbrowser.exe Section loaded: uxtheme.dll
Source: C:\Plasma\pbrowser.exe Section loaded: olepro32.dll
Source: C:\Plasma\pbrowser.exe Section loaded: kernel.appcore.dll
Source: C:\Plasma\pbrowser.exe Section loaded: textshaping.dll
Source: C:\Plasma\pbrowser.exe Section loaded: textinputframework.dll
Source: C:\Plasma\pbrowser.exe Section loaded: coreuicomponents.dll
Source: C:\Plasma\pbrowser.exe Section loaded: coremessaging.dll
Source: C:\Plasma\pbrowser.exe Section loaded: ntmarta.dll
Source: C:\Plasma\pbrowser.exe Section loaded: wintypes.dll
Source: C:\Plasma\pbrowser.exe Section loaded: wintypes.dll
Source: C:\Plasma\pbrowser.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: apphelp.dll
Source: C:\Plasma\pmanager.exe Section loaded: version.dll
Source: C:\Plasma\pmanager.exe Section loaded: winmm.dll
Source: C:\Plasma\pmanager.exe Section loaded: uxtheme.dll
Source: C:\Plasma\pmanager.exe Section loaded: olepro32.dll
Source: C:\Plasma\pmanager.exe Section loaded: kernel.appcore.dll
Source: C:\Plasma\pmanager.exe Section loaded: gds32.dll
Source: C:\Plasma\pmanager.exe Section loaded: textshaping.dll
Source: C:\Plasma\pmanager.exe Section loaded: textinputframework.dll
Source: C:\Plasma\pmanager.exe Section loaded: coreuicomponents.dll
Source: C:\Plasma\pmanager.exe Section loaded: coremessaging.dll
Source: C:\Plasma\pmanager.exe Section loaded: ntmarta.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: version.dll
Source: C:\Plasma\pmanager.exe Section loaded: winmm.dll
Source: C:\Plasma\pmanager.exe Section loaded: uxtheme.dll
Source: C:\Plasma\pmanager.exe Section loaded: olepro32.dll
Source: C:\Plasma\pmanager.exe Section loaded: kernel.appcore.dll
Source: C:\Plasma\pmanager.exe Section loaded: gds32.dll
Source: C:\Plasma\pmanager.exe Section loaded: textshaping.dll
Source: C:\Plasma\pmanager.exe Section loaded: textinputframework.dll
Source: C:\Plasma\pmanager.exe Section loaded: coreuicomponents.dll
Source: C:\Plasma\pmanager.exe Section loaded: coremessaging.dll
Source: C:\Plasma\pmanager.exe Section loaded: ntmarta.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pbrowser.exe Section loaded: urlmon.dll
Source: C:\Plasma\pbrowser.exe Section loaded: version.dll
Source: C:\Plasma\pbrowser.exe Section loaded: winmm.dll
Source: C:\Plasma\pbrowser.exe Section loaded: iertutil.dll
Source: C:\Plasma\pbrowser.exe Section loaded: srvcli.dll
Source: C:\Plasma\pbrowser.exe Section loaded: netutils.dll
Source: C:\Plasma\pbrowser.exe Section loaded: uxtheme.dll
Source: C:\Plasma\pbrowser.exe Section loaded: olepro32.dll
Source: C:\Plasma\pbrowser.exe Section loaded: kernel.appcore.dll
Source: C:\Plasma\pbrowser.exe Section loaded: textshaping.dll
Source: C:\Plasma\pbrowser.exe Section loaded: textinputframework.dll
Source: C:\Plasma\pbrowser.exe Section loaded: coreuicomponents.dll
Source: C:\Plasma\pbrowser.exe Section loaded: coremessaging.dll
Source: C:\Plasma\pbrowser.exe Section loaded: ntmarta.dll
Source: C:\Plasma\pbrowser.exe Section loaded: wintypes.dll
Source: C:\Plasma\pbrowser.exe Section loaded: wintypes.dll
Source: C:\Plasma\pbrowser.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: version.dll
Source: C:\Plasma\pmanager.exe Section loaded: winmm.dll
Source: C:\Plasma\pmanager.exe Section loaded: uxtheme.dll
Source: C:\Plasma\pmanager.exe Section loaded: olepro32.dll
Source: C:\Plasma\pmanager.exe Section loaded: kernel.appcore.dll
Source: C:\Plasma\pmanager.exe Section loaded: gds32.dll
Source: C:\Plasma\pmanager.exe Section loaded: textshaping.dll
Source: C:\Plasma\pmanager.exe Section loaded: textinputframework.dll
Source: C:\Plasma\pmanager.exe Section loaded: coreuicomponents.dll
Source: C:\Plasma\pmanager.exe Section loaded: coremessaging.dll
Source: C:\Plasma\pmanager.exe Section loaded: ntmarta.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Plasma\pmanager.exe Section loaded: wintypes.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File written: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\ioSpecial.ini
Source: C:\Plasma\pbrowser.exe Window found: window name: TEdit
Source: Window Recorder Window detected: More than 3 window changes detected
Source: PlasmaSetup@LR_2.exe Static file information: File size 2046487 > 1048576
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Plasma\pmarquee.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Plasma\pbrowser.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Plasma\Switcher.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Plasma\pmanager.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Plasma\uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Manager.lnk
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Browser.lnk
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Website.lnk
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Plasma\Uninstall.lnk
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Plasma\pbrowser.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Plasma\pmanager.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Plasma\pmanager.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Plasma\pbrowser.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Plasma\pmanager.exe Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: FAILCRITICALERRORS | NOGPFAULTERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\WerFault.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Plasma\pmanager.exe Window / User API: threadDelayed 2268
Source: C:\Plasma\pmanager.exe Window / User API: threadDelayed 4093
Source: C:\Plasma\pmanager.exe Window / User API: threadDelayed 824
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Dropped PE file which has not been started: C:\Plasma\pmarquee.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Dropped PE file which has not been started: C:\Plasma\Switcher.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Dropped PE file which has not been started: C:\Plasma\pmanager.exe Jump to dropped file
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Dropped PE file which has not been started: C:\Plasma\uninst.exe Jump to dropped file
Source: C:\Plasma\pmanager.exe TID: 6408 Thread sleep count: 58 > 30
Source: C:\Plasma\pmanager.exe TID: 1488 Thread sleep count: 31 > 30
Source: C:\Plasma\pmanager.exe TID: 1488 Thread sleep count: 4093 > 30
Source: C:\Plasma\pmanager.exe TID: 1344 Thread sleep count: 42 > 30
Source: C:\Plasma\pmanager.exe TID: 1344 Thread sleep count: 89 > 30
Source: C:\Plasma\pmanager.exe TID: 4008 Thread sleep count: 824 > 30
Source: C:\Plasma\pbrowser.exe File opened: PHYSICALDRIVE0
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\Temp\nsc7F3F.tmp\LangDLL.dll
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe File opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Plasma\pmanager.exe Process queried: DebugPort
Source: C:\Plasma\pmanager.exe Process queried: DebugPort
Source: C:\Plasma\pmanager.exe Process queried: DebugPort
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\PlasmaSetup@LR_2.exe Queries volume information: C:\ VolumeInformation
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs