Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
AudioCodesAppSuite.exe

Overview

General Information

Sample name:AudioCodesAppSuite.exe
Analysis ID:1587822
MD5:e8b8f253038fa8d6b0fc92e5e13bc185
SHA1:2b453e43890063bfa80cbeafaf21128f17d43213
SHA256:940a36dc38446f4a878b29474138bdf1c8e8faa59a680301456726f937eada80
Infos:

Detection

Score:56
Range:0 - 100
Whitelisted:false
Confidence:100%

Compliance

Score:50
Range:0 - 100

Signatures

Changes security center settings (notifications, updates, antivirus, firewall)
Creates multiple autostart registry keys
Modifies the windows firewall
Uses netsh to modify the Windows network and firewall settings
Allocates memory with a write watch (potentially for evading sandboxes)
Checks for available system drives (often done to infect USB drives)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains capabilities to detect virtual machines
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Creates files inside the driver directory
Creates files inside the system directory
Creates or modifies windows services
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Enables driver privileges
Enables security privileges
Found dropped PE file which has not been started or loaded
Launches processes in debugging mode, may be used to hinder debugging
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains sections with non-standard names
Queries disk information (often used to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sigma detected: CurrentVersion Autorun Keys Modification
Sigma detected: Suspicious MsiExec Embedding Parent
Sigma detected: Use Short Name Path in Command Line
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • svchost.exe (PID: 6900 cmdline: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • AudioCodesAppSuite.exe (PID: 7088 cmdline: "C:\Users\user\Desktop\AudioCodesAppSuite.exe" MD5: E8B8F253038FA8D6B0FC92E5E13BC185)
    • AudioCodesAppSuite.exe (PID: 7112 cmdline: "C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe" -burn.clean.room="C:\Users\user\Desktop\AudioCodesAppSuite.exe" -burn.filehandle.attached=644 -burn.filehandle.self=652 MD5: 713FBE0DFE40D0F29D8EA60D5839AEC5)
      • AudioCodes App Suite_1.2.0.10.exe (PID: 2232 cmdline: "C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe" -q -burn.elevated BurnPipe.{1E7B6431-AA5E-4AB2-B188-5A5F27990A8C} {872B8E36-896D-4DA8-9A49-0AA90E513431} 7112 MD5: 713FBE0DFE40D0F29D8EA60D5839AEC5)
        • cmd.exe (PID: 2956 cmdline: C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\custom_act.cmd" MsiExec.exe /quiet /X {1ED60F87-9DD1-4A3A-9A7F-BAA708F6FFA5} MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 2104 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • msiexec.exe (PID: 7136 cmdline: MsiExec.exe /quiet /X {1ED60F87-9DD1-4A3A-9A7F-BAA708F6FFA5} MD5: 9D09DC1EDA745A5F87553048E57620CF)
        • cmd.exe (PID: 6704 cmdline: C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\cleaning_up_1.cmd" rd /s /q c:\PROGRA~2\AudioCodes\MTR MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 3392 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • svchost.exe (PID: 6200 cmdline: C:\Windows\System32\svchost.exe -k NetworkService -p MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • SgrmBroker.exe (PID: 6440 cmdline: C:\Windows\system32\SgrmBroker.exe MD5: 3BA1A18A0DC30A0545E7765CB97D8E63)
  • svchost.exe (PID: 6496 cmdline: C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • svchost.exe (PID: 6532 cmdline: C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • MpCmdRun.exe (PID: 4280 cmdline: "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable MD5: B3676839B2EE96983F9ED735CD044159)
      • conhost.exe (PID: 3764 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • svchost.exe (PID: 6740 cmdline: C:\Windows\system32\svchost.exe -k UnistackSvcGroup MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • VSSVC.exe (PID: 4004 cmdline: C:\Windows\system32\vssvc.exe MD5: 875046AD4755396636A68F4A9EDB22A4)
  • svchost.exe (PID: 5192 cmdline: C:\Windows\System32\svchost.exe -k swprv MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
  • SrTasks.exe (PID: 3060 cmdline: C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1 MD5: 2694D2D28C368B921686FE567BD319EB)
    • conhost.exe (PID: 4360 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • msiexec.exe (PID: 6612 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 4284 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 858F3915C070FC9440284D95BC84A9C8 MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 7076 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding FD2693E6E89D476E86CC362884034874 E Global\MSI0000 MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • system_ui.exe (PID: 4276 cmdline: "C:\Program Files\AudioCodes\DM Client\system_ui.exe" MD5: F8BEA85FE40413FE0E57F11551CBFA4D)
    • msiexec.exe (PID: 7128 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 54E9FE486362F533840C69F5DAA10592 MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 1256 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 43B54B8776100830EC531CBAA63FEE6F E Global\MSI0000 MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 5864 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding E548DB2F1D63A1C6E354125D869B28C1 MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • ISBEW64.exe (PID: 5156 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6BDEB247-9D01-48AA-ABCD-D87B5061EFBD} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 4928 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{51D50112-ED8F-4781-BDCA-DB3DB9A2908F} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 3744 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{19C0EDDD-2DE5-4E07-A4C2-F5F77C78BC0D} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 2124 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{90BC320F-060E-42A7-886E-D73D1B212003} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 3780 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{1AEA6D95-DB36-4158-B832-24FAEA19FC8C} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 6332 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{DC96E7AD-7558-4DE6-B328-D7BE884EBB80} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 2116 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{F07E5476-CA61-4057-8CFC-0691175DB699} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 1420 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{7BC0D5A7-F5BF-407C-9C58-6BECD74CE13D} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 644 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8B31811A-1B04-4DE5-8863-2A7DAB70B909} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 5836 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{A6B428F2-4071-4724-9233-C0B7B7431B5B} MD5: 0F316043BFD136A509347148D203D541)
      • ISBEW64.exe (PID: 1544 cmdline: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{00529697-12CC-4FCF-B6DD-B652855A2BA0} MD5: 0F316043BFD136A509347148D203D541)
      • cmd.exe (PID: 6100 cmdline: cmd.exe /C netsh advfirewall firewall delete rule name="AudioCodes Device Duo" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
        • conhost.exe (PID: 2824 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
        • netsh.exe (PID: 4204 cmdline: netsh advfirewall firewall delete rule name="AudioCodes Device Duo" MD5: 4E89A1A088BE715D6C946E55AB07C7DF)
    • msiexec.exe (PID: 1444 cmdline: C:\Windows\System32\MsiExec.exe -Embedding EF35E424742556F3A46DACF60A0CE384 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
    • sc.exe (PID: 1392 cmdline: sc.exe failure "AcDeviceDuo" reset= 0 actions= restart/60000 MD5: 3FB5CF71F7E7EB49790CB0E663434D80)
      • conhost.exe (PID: 1752 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • emsc.exe (PID: 1600 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • emsc.exe (PID: 5564 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • AudioCodes Camera Service.exe (PID: 4104 cmdline: "C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe" MD5: 53A7E7279304B5052571870208ADDD54)
  • emsc.exe (PID: 848 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • emsc.exe (PID: 2476 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • emsc.exe (PID: 3788 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • emsc.exe (PID: 3736 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • svchost.exe (PID: 5060 cmdline: C:\Windows\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall MD5: B7F884C1B74A263F746EE12A5F7C9F6A)
    • drvinst.exe (PID: 1520 cmdline: DrvInst.exe "4" "1" "c:\program files (x86)\audiocodes\device duo\audiocodesb2goe_usb.inf" "9" "4a60a61bb" "00000000000000F4" "WinSta0\Default" "0000000000000170" "208" "c:\program files (x86)\audiocodes\device duo" MD5: 294990C88B9D1FE0A54A1FA8BF4324D9)
    • drvinst.exe (PID: 5812 cmdline: DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem4.inf" "oem4.inf:741f41b506a957ba:B2G_VirtualBusDriver_Device:1.3.6.5:root\b2g_virtualbusdriver," "4a60a61bb" "00000000000000F4" MD5: 294990C88B9D1FE0A54A1FA8BF4324D9)
  • emsc.exe (PID: 5892 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • emsc.exe (PID: 6208 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • emsc.exe (PID: 400 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • emsc.exe (PID: 4412 cmdline: "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service MD5: 21A984BC0631FC7D70C6C606495E9C3D)
  • DeviceDuoService.exe (PID: 3824 cmdline: "C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe" MD5: A9DA4077A7050C3A2745F547E4BD0FC2)
  • DeviceDuoService.exe (PID: 1160 cmdline: "C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe" MD5: A9DA4077A7050C3A2745F547E4BD0FC2)
  • cleanup
No yara matches
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\Program Files\AudioCodes\DM Client\system_ui.exe", EventID: 13, EventType: SetValue, Image: C:\Windows\System32\msiexec.exe, ProcessId: 6612, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AudioCodes DM Client UI
Source: Process startedAuthor: frack113: Data: Command: cmd.exe /C netsh advfirewall firewall delete rule name="AudioCodes Device Duo", CommandLine: cmd.exe /C netsh advfirewall firewall delete rule name="AudioCodes Device Duo", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: C:\Windows\syswow64\MsiExec.exe -Embedding E548DB2F1D63A1C6E354125D869B28C1, ParentImage: C:\Windows\SysWOW64\msiexec.exe, ParentProcessId: 5864, ParentProcessName: msiexec.exe, ProcessCommandLine: cmd.exe /C netsh advfirewall firewall delete rule name="AudioCodes Device Duo", ProcessId: 6100, ProcessName: cmd.exe
Source: Process startedAuthor: frack113, Nasreddine Bencherchali: Data: Command: C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\cleaning_up_1.cmd" rd /s /q c:\PROGRA~2\AudioCodes\MTR, CommandLine: C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\cleaning_up_1.cmd" rd /s /q c:\PROGRA~2\AudioCodes\MTR, CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\cmd.exe, NewProcessName: C:\Windows\SysWOW64\cmd.exe, OriginalFileName: C:\Windows\SysWOW64\cmd.exe, ParentCommandLine: "C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe" -q -burn.elevated BurnPipe.{1E7B6431-AA5E-4AB2-B188-5A5F27990A8C} {872B8E36-896D-4DA8-9A49-0AA90E513431} 7112, ParentImage: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe, ParentProcessId: 2232, ParentProcessName: AudioCodes App Suite_1.2.0.10.exe, ProcessCommandLine: C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\cleaning_up_1.cmd" rd /s /q c:\PROGRA~2\AudioCodes\MTR, ProcessId: 6704, ProcessName: cmd.exe
Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: "C:\ProgramData\Package Cache\{be54e699-bb8b-43bf-8829-09565d7525fb}\AudioCodes App Suite_1.2.0.10.exe" /burn.runonce, EventID: 13, EventType: SetValue, Image: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe, ProcessId: 2232, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce\{be54e699-bb8b-43bf-8829-09565d7525fb}
Source: Process startedAuthor: vburov: Data: Command: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, CommandLine|base64offset|contains: , Image: C:\Windows\System32\svchost.exe, NewProcessName: C:\Windows\System32\svchost.exe, OriginalFileName: C:\Windows\System32\svchost.exe, ParentCommandLine: , ParentImage: , ParentProcessId: 660, ProcessCommandLine: C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS, ProcessId: 6900, ProcessName: svchost.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

Compliance

barindex
Source: AudioCodesAppSuite.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gtest_main.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_cfg_gtest.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\acl_env_params.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\winport.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\scep.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\emsc.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libcrypto-1_1-x64.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\uv_app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ExportTrustedRootCAs.ps1
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_common.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\c_rehash.pl
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\httpc.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\openssl.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\HAL.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gmock_main.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libssl-1_1-x64.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libuv_app_gtest.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\emsc_gtest.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libexpat.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\param_tool.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\device_upgrade.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\system_ui.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libcurl.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_des3.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gmock.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\text.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\device_management.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\inifile.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\uv.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gtest.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_curl_tftp.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\test.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\curl.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\cares.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\uriparser.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\syslog_msg.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\winport.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\libcrypto-1_1-x64.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\libusb-1.0.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\uv_app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\ExportTrustedRootCAs.ps1
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\ac_common.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe.metagen
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\AudioFwUpgrade
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\AudioFwUpgrade\UsbDevCfg.ini
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\USBCameraTool.map
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\UsbUtil.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x64.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtGui4.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\config.ini
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x86.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\HAL.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\hidapi.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcp100.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcr100.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\libexpat.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\objectfactory.json
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtCore4.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\device_upgrade.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\WebCamLib.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\ac_des3.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\audio_analysis.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\text.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\device_management.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\tmp
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\tmp\.gitignore
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\logs
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\logs\.gitignore
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\snapshots
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\snapshots\.gitignore
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\inifile.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\uv.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\AudioFwUpgrade\MicArrayFwUpdTool.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\USBCameraConsoleTool.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\UsbUtild.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\cares.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\readme.txt
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\syslog_msg.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore SRInitDone
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9C73A861-DF15-4EB8-A20B-6696D7E153F9}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\readme.txt
Source: AudioCodesAppSuite.exeStatic PE information: certificate valid
Source: AudioCodesAppSuite.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Windows\System32\msiexec.exeFile opened: z:
Source: C:\Windows\System32\msiexec.exeFile opened: x:
Source: C:\Windows\System32\msiexec.exeFile opened: v:
Source: C:\Windows\System32\msiexec.exeFile opened: t:
Source: C:\Windows\System32\msiexec.exeFile opened: r:
Source: C:\Windows\System32\msiexec.exeFile opened: p:
Source: C:\Windows\System32\msiexec.exeFile opened: n:
Source: C:\Windows\System32\msiexec.exeFile opened: l:
Source: C:\Windows\System32\msiexec.exeFile opened: j:
Source: C:\Windows\System32\msiexec.exeFile opened: h:
Source: C:\Windows\System32\msiexec.exeFile opened: f:
Source: C:\Windows\System32\svchost.exeFile opened: d:
Source: C:\Windows\System32\msiexec.exeFile opened: b:
Source: C:\Windows\System32\msiexec.exeFile opened: y:
Source: C:\Windows\System32\msiexec.exeFile opened: w:
Source: C:\Windows\System32\msiexec.exeFile opened: u:
Source: C:\Windows\System32\msiexec.exeFile opened: s:
Source: C:\Windows\System32\msiexec.exeFile opened: q:
Source: C:\Windows\System32\msiexec.exeFile opened: o:
Source: C:\Windows\System32\msiexec.exeFile opened: m:
Source: C:\Windows\System32\msiexec.exeFile opened: k:
Source: C:\Windows\System32\msiexec.exeFile opened: i:
Source: C:\Windows\System32\msiexec.exeFile opened: g:
Source: C:\Windows\System32\msiexec.exeFile opened: e:
Source: C:\Windows\System32\msiexec.exeFile opened: c:
Source: C:\Windows\System32\msiexec.exeFile opened: a:
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\NULL
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: office.com
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\AudioCodesB2GoE_USB.sys
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\DriverStore\FileRepository\audiocodesb2goe_usb.inf_amd64_0c42b9736d668426\audiocodesb2goe_usb.PNF
Source: C:\Windows\System32\svchost.exeFile created: C:\Windows\ServiceProfiles\LocalService\AppData\Local\FontCache\Fonts\Download-1.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48c1cb.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC3AF.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{9C73A861-DF15-4EB8-A20B-6696D7E153F9}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC47B.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC49B.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC4EB.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC52A.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC9A0.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSICA2D.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48c1ce.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48c1ce.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48c1cf.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{74CFF291-6D94-478F-890D-CECD25AAEB01}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID606.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSID645.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIDE35.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48c1d2.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48c1d2.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\48c1d3.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIEBF2.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIEC51.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{DE04E53C-AE5B-4630-AD95-5C63C3333027}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIECCF.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIECDF.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF84A.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF8B9.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIFE96.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{DE04E53C-AE5B-4630-AD95-5C63C3333027}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{DE04E53C-AE5B-4630-AD95-5C63C3333027}\ARPPRODUCTICON.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{DE04E53C-AE5B-4630-AD95-5C63C3333027}\DeviceDuoControlle_69E583703C3349219962B37352964441.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\DriverStore\FileRepository\audiocodesb2goe_usb.inf_amd64_0c42b9736d668426\audiocodesb2goe_usb.PNF
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSIC3AF.tmp
Source: C:\Windows\System32\msiexec.exeProcess token adjusted: Load Driver
Source: C:\Windows\System32\svchost.exeProcess token adjusted: Security
Source: AudioCodesAppSuite.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: classification engineClassification label: mal56.evad.winEXE@89/132@1/10
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4360:120:WilError_03
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeMutant created: NULL
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeFile created: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\
Source: AudioCodesAppSuite.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeFile read: C:\Users\user\Desktop\desktop.ini
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeFile read: C:\Users\user\Desktop\AudioCodesAppSuite.exe
Source: unknownProcess created: C:\Users\user\Desktop\AudioCodesAppSuite.exe "C:\Users\user\Desktop\AudioCodesAppSuite.exe"
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeProcess created: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe "C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe" -burn.clean.room="C:\Users\user\Desktop\AudioCodesAppSuite.exe" -burn.filehandle.attached=644 -burn.filehandle.self=652
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeProcess created: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe "C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe" -burn.clean.room="C:\Users\user\Desktop\AudioCodesAppSuite.exe" -burn.filehandle.attached=644 -burn.filehandle.self=652
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeProcess created: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe "C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe" -q -burn.elevated BurnPipe.{1E7B6431-AA5E-4AB2-B188-5A5F27990A8C} {872B8E36-896D-4DA8-9A49-0AA90E513431} 7112
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeProcess created: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe "C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe" -q -burn.elevated BurnPipe.{1E7B6431-AA5E-4AB2-B188-5A5F27990A8C} {872B8E36-896D-4DA8-9A49-0AA90E513431} 7112
Source: unknownProcess created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
Source: C:\Windows\System32\SrTasks.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\custom_act.cmd" MsiExec.exe /quiet /X {1ED60F87-9DD1-4A3A-9A7F-BAA708F6FFA5}
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\msiexec.exe MsiExec.exe /quiet /X {1ED60F87-9DD1-4A3A-9A7F-BAA708F6FFA5}
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\cleaning_up_1.cmd" rd /s /q c:\PROGRA~2\AudioCodes\MTR
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 858F3915C070FC9440284D95BC84A9C8
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding FD2693E6E89D476E86CC362884034874 E Global\MSI0000
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files\AudioCodes\DM Client\system_ui.exe "C:\Program Files\AudioCodes\DM Client\system_ui.exe"
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 54E9FE486362F533840C69F5DAA10592
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k netsvcs -p -s BITS
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k NetworkService -p
Source: unknownProcess created: C:\Windows\System32\SgrmBroker.exe C:\Windows\system32\SgrmBroker.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted -p -s StorSvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted -p -s wscsvc
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k UnistackSvcGroup
Source: unknownProcess created: C:\Windows\System32\VSSVC.exe C:\Windows\system32\vssvc.exe
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe -k swprv
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 43B54B8776100830EC531CBAA63FEE6F E Global\MSI0000
Source: unknownProcess created: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe "C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe"
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding E548DB2F1D63A1C6E354125D869B28C1
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6BDEB247-9D01-48AA-ABCD-D87B5061EFBD}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{51D50112-ED8F-4781-BDCA-DB3DB9A2908F}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{19C0EDDD-2DE5-4E07-A4C2-F5F77C78BC0D}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{90BC320F-060E-42A7-886E-D73D1B212003}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{1AEA6D95-DB36-4158-B832-24FAEA19FC8C}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{DC96E7AD-7558-4DE6-B328-D7BE884EBB80}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{F07E5476-CA61-4057-8CFC-0691175DB699}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{7BC0D5A7-F5BF-407C-9C58-6BECD74CE13D}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8B31811A-1B04-4DE5-8863-2A7DAB70B909}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{A6B428F2-4071-4724-9233-C0B7B7431B5B}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{00529697-12CC-4FCF-B6DD-B652855A2BA0}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C netsh advfirewall firewall delete rule name="AudioCodes Device Duo"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh advfirewall firewall delete rule name="AudioCodes Device Duo"
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\custom_act.cmd" MsiExec.exe /quiet /X {1ED60F87-9DD1-4A3A-9A7F-BAA708F6FFA5}
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding EF35E424742556F3A46DACF60A0CE384 E Global\MSI0000
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\cleaning_up_1.cmd" rd /s /q c:\PROGRA~2\AudioCodes\MTR
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: unknownProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "1" "c:\program files (x86)\audiocodes\device duo\audiocodesb2goe_usb.inf" "9" "4a60a61bb" "00000000000000F4" "WinSta0\Default" "0000000000000170" "208" "c:\program files (x86)\audiocodes\device duo"
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: unknownProcess created: C:\Program Files\AudioCodes\DM Client\emsc.exe "C:\Program Files\AudioCodes\DM Client\emsc.exe" --service
Source: unknownProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem4.inf" "oem4.inf:741f41b506a957ba:B2G_VirtualBusDriver_Device:1.3.6.5:root\b2g_virtualbusdriver," "4a60a61bb" "00000000000000F4"
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\sc.exe sc.exe failure "AcDeviceDuo" reset= 0 actions= restart/60000
Source: C:\Windows\System32\sc.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknownProcess created: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe "C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe"
Source: unknownProcess created: C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe -k DcomLaunch -p -s DeviceInstall
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Program Files\Windows Defender\MpCmdRun.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\svchost.exeProcess created: C:\Program Files\Windows Defender\MpCmdRun.exe "C:\Program Files\Windows Defender\mpcmdrun.exe" -wdenable
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 858F3915C070FC9440284D95BC84A9C8
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding FD2693E6E89D476E86CC362884034874 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files\AudioCodes\DM Client\system_ui.exe "C:\Program Files\AudioCodes\DM Client\system_ui.exe"
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 54E9FE486362F533840C69F5DAA10592
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 43B54B8776100830EC531CBAA63FEE6F E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding E548DB2F1D63A1C6E354125D869B28C1
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding EF35E424742556F3A46DACF60A0CE384 E Global\MSI0000
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\sc.exe sc.exe failure "AcDeviceDuo" reset= 0 actions= restart/60000
Source: unknownProcess created: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe "C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe"
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{6BDEB247-9D01-48AA-ABCD-D87B5061EFBD}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{51D50112-ED8F-4781-BDCA-DB3DB9A2908F}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{19C0EDDD-2DE5-4E07-A4C2-F5F77C78BC0D}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{90BC320F-060E-42A7-886E-D73D1B212003}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{1AEA6D95-DB36-4158-B832-24FAEA19FC8C}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{DC96E7AD-7558-4DE6-B328-D7BE884EBB80}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{F07E5476-CA61-4057-8CFC-0691175DB699}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{7BC0D5A7-F5BF-407C-9C58-6BECD74CE13D}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{8B31811A-1B04-4DE5-8863-2A7DAB70B909}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{A6B428F2-4071-4724-9233-C0B7B7431B5B}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{00529697-12CC-4FCF-B6DD-B652855A2BA0}
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C netsh advfirewall firewall delete rule name="AudioCodes Device Duo"
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "1" "c:\program files (x86)\audiocodes\device duo\audiocodesb2goe_usb.inf" "9" "4a60a61bb" "00000000000000F4" "WinSta0\Default" "0000000000000170" "208" "c:\program files (x86)\audiocodes\device duo"
Source: C:\Windows\System32\svchost.exeProcess created: C:\Windows\System32\drvinst.exe DrvInst.exe "2" "211" "ROOT\SYSTEM\0001" "C:\Windows\INF\oem4.inf" "oem4.inf:741f41b506a957ba:B2G_VirtualBusDriver_Device:1.3.6.5:root\b2g_virtualbusdriver," "4a60a61bb" "00000000000000F4"
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: cryptbase.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: msi.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: cabinet.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: msxml3.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: wldp.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: profapi.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: feclient.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: iertutil.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeSection loaded: apphelp.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: cryptbase.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: msi.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: version.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: cabinet.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: msxml3.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: windows.storage.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: wldp.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: profapi.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: feclient.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: iertutil.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: uxtheme.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: textinputframework.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: coreuicomponents.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: coremessaging.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: ntmarta.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: wintypes.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: wintypes.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: wintypes.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: msimg32.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: windowscodecs.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: explorerframe.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: textshaping.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: propsys.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: edputil.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: urlmon.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: srvcli.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: netutils.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: sspicli.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: appresolver.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: bcp47langs.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: slc.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: userenv.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: sppc.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeSection loaded: apphelp.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: cryptbase.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: msi.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: version.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: cabinet.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: msxml3.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: windows.storage.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: wldp.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: profapi.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: uxtheme.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: textinputframework.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: coreuicomponents.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: coremessaging.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: ntmarta.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: wintypes.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: wintypes.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: wintypes.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: srclient.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: spp.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: powrprof.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: vssapi.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: vsstrace.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: umpdc.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: usoapi.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: sxproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: qmgr.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bitsperf.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dll
Source: C:\Windows\System32\svchost.exeSection loaded: firewallapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: esent.dll
Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dnsapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: iphlpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fwbase.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dll
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
Source: C:\Windows\System32\svchost.exeSection loaded: netprofm.dll
Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bitsigd.dll
Source: C:\Windows\System32\svchost.exeSection loaded: upnp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ssdpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: urlmon.dll
Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wsmauto.dll
Source: C:\Windows\System32\svchost.exeSection loaded: miutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wsmsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dsrole.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pcwum.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
Source: C:\Windows\System32\svchost.exeSection loaded: gpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: netutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dll
Source: C:\Windows\System32\svchost.exeSection loaded: webio.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mswsock.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winnsi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rasadhlp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fwpuclnt.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: usermgrcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: execmodelclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dll
Source: C:\Windows\System32\svchost.exeSection loaded: coremessaging.dll
Source: C:\Windows\System32\svchost.exeSection loaded: twinapi.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: resourcepolicyclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\svchost.exeSection loaded: samcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: samlib.dll
Source: C:\Windows\System32\svchost.exeSection loaded: es.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bitsproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ondemandconnroutehelper.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc6.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dhcpcsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: schannel.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mskeyprotect.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ncrypt.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ncryptsslp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mpr.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: moshost.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mapsbtsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mosstorage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ztrace_maps.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ztrace_maps.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ztrace_maps.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bcp47langs.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mapconfiguration.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: storsvc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: devobj.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fltlib.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: bcd.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wer.dll
Source: C:\Windows\System32\svchost.exeSection loaded: winhttp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: appxdeploymentclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: storageusage.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: propsys.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: aphostservice.dll
Source: C:\Windows\System32\svchost.exeSection loaded: networkhelper.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdataplatformhelperutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mccspal.dll
Source: C:\Windows\System32\svchost.exeSection loaded: syncutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\svchost.exeSection loaded: syncutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vaultcli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmcfgutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wintypes.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msvcp110_win.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmcmnutils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dmxmlhelputils.dll
Source: C:\Windows\System32\svchost.exeSection loaded: policymanager.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: xmllite.dll
Source: C:\Windows\System32\svchost.exeSection loaded: inproclogger.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\svchost.exeSection loaded: flightsettings.dll
Source: C:\Windows\System32\svchost.exeSection loaded: windows.networking.connectivity.dll
Source: C:\Windows\System32\svchost.exeSection loaded: npmproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: iertutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: msv1_0.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntlmshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cryptdll.dll
Source: C:\Windows\System32\svchost.exeSection loaded: synccontroller.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pimstore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: aphostclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: accountaccessor.dll
Source: C:\Windows\System32\svchost.exeSection loaded: dsclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\svchost.exeSection loaded: systemeventsbrokerclient.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdatalanguageutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: mccsengineshared.dll
Source: C:\Windows\System32\svchost.exeSection loaded: pimstore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: cemapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userdatatypehelperutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: phoneutil.dll
Source: C:\Windows\System32\svchost.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\svchost.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Windows\System32\svchost.exeSection loaded: execmodelproxy.dll
Source: C:\Windows\System32\svchost.exeSection loaded: rmclient.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: cryptsp.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: rsaenh.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: feclient.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: iertutil.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: srpapi.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: tsappcmp.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: netapi32.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: wkscli.dll
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeSection loaded: netutils.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: devobj.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: authz.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: virtdisk.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: bcd.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: fltlib.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: es.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: amsi.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: userenv.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: profapi.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: vss_ps.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: samcli.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: netutils.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: samlib.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: propsys.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: catsrvut.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: mfcsubs.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: sxs.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: msxml3.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: clusapi.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: dnsapi.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: iphlpapi.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\VSSVC.exeSection loaded: cscapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: swprv.dll
Source: C:\Windows\System32\svchost.exeSection loaded: devobj.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\svchost.exeSection loaded: virtdisk.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fltlib.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\svchost.exeSection loaded: amsi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: userenv.dll
Source: C:\Windows\System32\svchost.exeSection loaded: profapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: es.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vss_ps.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: fveapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: spp.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: srclient.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: srcore.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: ktmw32.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: wer.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: bcd.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: dsrole.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: msxml3.dll
Source: C:\Windows\System32\SrTasks.exeSection loaded: vss_ps.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: apphelp.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: uv_app.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: httpc.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: device_management.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: app.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: text.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: ac_common.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: msvcp140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: uv.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: app.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: ac_common.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: msvcp140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: text.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: ac_common.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: msvcp140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: cares.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: device_management.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: libcurl.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: ac_common.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: msvcp140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: ac_common.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: libexpat.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: winport.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: msvcp140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: hal.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: inifile.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: dbghelp.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: winport.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: userenv.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: libssl-1_1-x64.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: libcrypto-1_1-x64.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: libcrypto-1_1-x64.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: ac_des3.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: winport.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: libcrypto-1_1-x64.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: dbgcore.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: cryptbase.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: powrprof.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: umpdc.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: uxtheme.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: mswsock.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: msxml6.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: wpnapps.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: wintypes.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: rmclient.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: xmllite.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: twinapi.appcore.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: usermgrcli.dll
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: mscoree.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: apphelp.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: uv.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: app.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: ac_common.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: msvcp140.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: vcruntime140.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: vcruntime140_1.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: text.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: iphlpapi.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: userenv.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: libexpat.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: winport.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: cryptbase.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: hal.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: inifile.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: dbghelp.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: dbgcore.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: version.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: powrprof.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: umpdc.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: mswsock.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: mf.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: mfplat.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: mfcore.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: ksuser.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: rtworkq.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: devenum.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: winmm.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: ntmarta.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: devobj.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: msasn1.dll
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeSection loaded: msdmo.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: winmm.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: riched32.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: riched20.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: usp10.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msls31.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sxs.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: devobj.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: devrtl.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: spinf.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: drvstore.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: devobj.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: newdev.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dll
Source: C:\Windows\System32\svchost.exeSection loaded: umpnpmgr.dll
Source: C:\Windows\System32\svchost.exeSection loaded: wldp.dll
Source: C:\Windows\System32\svchost.exeSection loaded: devrtl.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: mscoree.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: version.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: cryptsp.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: rsaenh.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: cryptbase.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: profapi.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: mswsock.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: napinsp.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: pnrpnsp.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: wshbth.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: nlaapi.dll
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeSection loaded: iphlpapi.dll
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32
Source: C:\Windows\System32\msiexec.exeFile written: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\AudioFwUpgrade\UsbDevCfg.ini
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: C:\Windows\SysWOW64\RICHED32.DLL
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gtest_main.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_cfg_gtest.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\acl_env_params.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\winport.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\scep.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\emsc.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libcrypto-1_1-x64.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\uv_app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ExportTrustedRootCAs.ps1
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_common.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\c_rehash.pl
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\httpc.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\openssl.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\HAL.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gmock_main.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libssl-1_1-x64.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libuv_app_gtest.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\emsc_gtest.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libexpat.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\param_tool.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\device_upgrade.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\system_ui.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\libcurl.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_des3.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gmock.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\text.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\device_management.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\inifile.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\uv.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\gtest.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\ac_curl_tftp.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\test.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\curl.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\cares.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\uriparser.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\DM Client\syslog_msg.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\winport.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\libcrypto-1_1-x64.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\libusb-1.0.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\uv_app.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\ExportTrustedRootCAs.ps1
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\ac_common.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe.metagen
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\AudioFwUpgrade
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\AudioFwUpgrade\UsbDevCfg.ini
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\USBCameraTool.map
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\UsbUtil.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x64.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtGui4.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\config.ini
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x86.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\HAL.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\hidapi.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcp100.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcr100.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\libexpat.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\objectfactory.json
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtCore4.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\device_upgrade.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\WebCamLib.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\ac_des3.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\audio_analysis.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\text.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\device_management.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\tmp
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\tmp\.gitignore
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\logs
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\logs\.gitignore
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\snapshots
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\snapshots\.gitignore
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\inifile.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\uv.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\AudioFwUpgrade\MicArrayFwUpdTool.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\USBCameraConsoleTool.exe
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\UsbUtild.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\cares.dll
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\readme.txt
Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\AudioCodes\Camera Service\syslog_msg.dll
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{9C73A861-DF15-4EB8-A20B-6696D7E153F9}
Source: AudioCodesAppSuite.exeStatic PE information: certificate valid
Source: AudioCodesAppSuite.exeStatic file information: File size 25993192 > 1048576
Source: AudioCodesAppSuite.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: AudioCodesAppSuite.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: AudioCodesAppSuite.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: AudioCodesAppSuite.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: AudioCodesAppSuite.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: AudioCodesAppSuite.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: AudioCodesAppSuite.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: AudioCodesAppSuite.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: AudioCodesAppSuite.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: AudioCodesAppSuite.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: AudioCodesAppSuite.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: AudioCodesAppSuite.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: AudioCodesAppSuite.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: AudioCodesAppSuite.exeStatic PE information: section name: .wixburn
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeFile created: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoController.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\system_ui.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC9A0.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\hidapi.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\UsbUtil.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\_isres_0x0409.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIEC51.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\Telerik.WinControls.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\httpc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\ac_cfg_gtest.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\ac_common.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\gmock_main.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x86.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\libusb-1.0.dllJump to dropped file
Source: C:\Windows\System32\drvinst.exeFile created: C:\Windows\System32\SET7954.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\gtest_main.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\AudioCodesB2GoE_USB.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\VdiStates.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIECDF.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\winport.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcp100.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcr100.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\libcrypto-1_1-x64.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\text.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\gmock.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\libexpat.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\Telerik.WinControls.RichTextBox.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISRT.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Practices.ServiceLocation.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC3AF.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\BusControlLibrary.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\libcurl.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\libuv_app_gtest.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\HAL.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\ac_curl_tftp.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\param_tool.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\acl_env_params.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\libssl-1_1-x64.dllJump to dropped file
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeFile created: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\openssl.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\Newtonsoft.Json.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\scep.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtGui4.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\uriparser.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\uv_app.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Lync.Model.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF8B9.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\PairCodeGenerator.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\cares.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\test.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x64.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\emsc_gtest.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\app.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\syslog_msg.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{DE04E53C-AE5B-4630-AD95-5C63C3333027}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Practices.Unity.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISBEW64.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\gtest.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\curl.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\DM Client\emsc.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Office.Uc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\log4net.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\AudioCodes\Device Duo\LyncPcAudio.dllJump to dropped file
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeFile created: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIF8B9.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC3AF.tmpJump to dropped file
Source: C:\Windows\System32\drvinst.exeFile created: C:\Windows\System32\SET7954.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIC9A0.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{DE04E53C-AE5B-4630-AD95-5C63C3333027}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIECDF.tmpJump to dropped file
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeFile created: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIEC51.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\readme.txt

Boot Survival

barindex
Source: C:\Windows\System32\msiexec.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AudioCodes DM Client UI
Source: C:\Windows\System32\msiexec.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AC.Device.Duo
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeRegistry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Source: C:\Windows\System32\SrTasks.exeRegistry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioCodes
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioCodes\DeviceDuo
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioCodes\DeviceDuo\AudioCodes Device Duo.lnk
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioCodes\DeviceDuo\Uninstall AudioCodes Device Duo.lnk
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioCodes\DeviceDuo\~ninstall AudioCodes Device Duo.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AudioCodes\DeviceDuo\Uninstall AudioCodes Device Duo.lnk~RF498cdb.TMP
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {be54e699-bb8b-43bf-8829-09565d7525fb}
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {be54e699-bb8b-43bf-8829-09565d7525fb}
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {be54e699-bb8b-43bf-8829-09565d7525fb}
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeRegistry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {be54e699-bb8b-43bf-8829-09565d7525fb}
Source: C:\Windows\System32\msiexec.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AudioCodes DM Client UI
Source: C:\Windows\System32\msiexec.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AudioCodes DM Client UI
Source: C:\Windows\System32\msiexec.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AC.Device.Duo
Source: C:\Windows\System32\msiexec.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AC.Device.Duo
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\sc.exe sc.exe failure "AcDeviceDuo" reset= 0 actions= restart/60000
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\VSSVC.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\svchost.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Program Files\AudioCodes\DM Client\system_ui.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeMemory allocated: 1DE3F830000 memory reserve | memory write watch
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeMemory allocated: 1DE57AE0000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeMemory allocated: 1070000 memory reserve | memory write watch
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeMemory allocated: 192E0000 memory reserve | memory write watch
Source: C:\Windows\System32\svchost.exeFile opened / queried: scsi#disk&ven_vmware&prod_virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Windows\System32\svchost.exeFile opened / queried: SCSI#Disk&Ven_VMware&Prod_Virtual_disk#4&1656f219&0&000000#{53f56307-b6bf-11d0-94f2-00a0c91efb8b}
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeThread delayed: delay time: 922337203685477
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoController.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC9A0.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\hidapi.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\UsbUtil.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\_isres_0x0409.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIEC51.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\Telerik.WinControls.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\httpc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\ac_cfg_gtest.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\gmock_main.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\ac_common.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x86.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\libusb-1.0.dllJump to dropped file
Source: C:\Windows\System32\drvinst.exeDropped PE file which has not been started: C:\Windows\System32\SET7954.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\gtest_main.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\AudioCodesB2GoE_USB.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\VdiStates.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIECDF.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\winport.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcr100.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcp100.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\libcrypto-1_1-x64.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\text.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\gmock.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\libexpat.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\Telerik.WinControls.RichTextBox.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{7E5FA71A-0657-4B39-8CA7-4C2F2802F98E}\ISRT.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Practices.ServiceLocation.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIC3AF.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\BusControlLibrary.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\libcurl.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\libuv_app_gtest.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\ac_curl_tftp.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\HAL.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\param_tool.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\acl_env_params.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\libssl-1_1-x64.dllJump to dropped file
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeDropped PE file which has not been started: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\openssl.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\Newtonsoft.Json.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\scep.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtGui4.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\uriparser.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\uv_app.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Lync.Model.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSIF8B9.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\PairCodeGenerator.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\test.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x64.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\app.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\emsc_gtest.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\syslog_msg.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{DE04E53C-AE5B-4630-AD95-5C63C3333027}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Practices.Unity.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\gtest.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\AudioCodes\DM Client\curl.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Office.Uc.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\log4net.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\AudioCodes\Device Duo\LyncPcAudio.dllJump to dropped file
Source: C:\Windows\System32\svchost.exe TID: 7000Thread sleep time: -30000s >= -30000s
Source: C:\Windows\System32\SrTasks.exe TID: 1340Thread sleep time: -290000s >= -30000s
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe TID: 1584Thread sleep count: 326 > 30
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe TID: 5884Thread sleep time: -922337203685477s >= -30000s
Source: C:\Windows\System32\svchost.exeFile opened: PhysicalDrive0
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile Volume queried: C:\Windows FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\Windows\System32 FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\svchost.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeThread delayed: delay time: 922337203685477
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\NULL
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeFile opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files\AudioCodes\DM Client\system_ui.exe "C:\Program Files\AudioCodes\DM Client\system_ui.exe"
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeMemory allocated: page read and write | page guard
Source: C:\Users\user\Desktop\AudioCodesAppSuite.exeProcess created: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe "C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe" -burn.clean.room="C:\Users\user\Desktop\AudioCodesAppSuite.exe" -burn.filehandle.attached=644 -burn.filehandle.self=652
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeProcess created: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe "C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe" -q -burn.elevated BurnPipe.{1E7B6431-AA5E-4AB2-B188-5A5F27990A8C} {872B8E36-896D-4DA8-9A49-0AA90E513431} 7112
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\custom_act.cmd" MsiExec.exe /quiet /X {1ED60F87-9DD1-4A3A-9A7F-BAA708F6FFA5}
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c "C:\ProgramData\Package Cache\1608BB75347CD8C40187E5F3C0A969ED73A98D51\cleaning_up_1.cmd" rd /s /q c:\PROGRA~2\AudioCodes\MTR
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\sc.exe sc.exe failure "AcDeviceDuo" reset= 0 actions= restart/60000
Source: C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exeQueries volume information: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.ba\logo.png VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.log VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\edb.chk VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.jfm VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ProgramData\Microsoft\Network\Downloader\qmgr.db VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\svchost.exeQueries volume information: C: VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeQueries volume information: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe VolumeInformation
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeQueries volume information: C:\Program Files\AudioCodes\Camera Service\WebCamLib.dll VolumeInformation
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeQueries volume information: C:\Program Files\AudioCodes\Camera Service\WebCamLib.dll VolumeInformation
Source: C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exeQueries volume information: C:\Program Files\AudioCodes\Camera Service\WebCamLib.dll VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\Program Files (x86)\AudioCodes\Device Duo\audiocodesb2goe_usb.cat VolumeInformation
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeQueries volume information: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe VolumeInformation
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeQueries volume information: C:\Program Files (x86)\AudioCodes\Device Duo\log4net.dll VolumeInformation
Source: C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exeQueries volume information: C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Practices.Unity.dll VolumeInformation
Source: C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Windows\System32\svchost.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center cval
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\cmd.exe cmd.exe /C netsh advfirewall firewall delete rule name="AudioCodes Device Duo"
Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\netsh.exe netsh advfirewall firewall delete rule name="AudioCodes Device Duo"
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
Source: C:\Windows\System32\svchost.exeWMI Queries: IWbemServices::ExecNotificationQuery - ROOT\SecurityCenter : SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
1
Windows Management Instrumentation
32
Windows Service
32
Windows Service
32
Masquerading
OS Credential Dumping3
Security Software Discovery
Remote ServicesData from Local System1
Non-Application Layer Protocol
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts1
Service Execution
111
Registry Run Keys / Startup Folder
11
Process Injection
311
Disable or Modify Tools
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable Media1
Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
LSASS Driver
111
Registry Run Keys / Startup Folder
51
Virtualization/Sandbox Evasion
Security Account Manager51
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCron1
DLL Side-Loading
1
LSASS Driver
11
Process Injection
NTDS11
Peripheral Device Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
DLL Side-Loading
1
DLL Side-Loading
LSA Secrets3
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
File Deletion
Cached Domain Credentials23
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
AudioCodesAppSuite.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe0%ReversingLabs
C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.ba\wixstdba.dll0%ReversingLabs
C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.ba\wixstdba.dll0%VirustotalBrowse
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtGui4.dll0%ReversingLabs
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\UsbUtil.dll0%ReversingLabs
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x64.exe0%ReversingLabs
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\devcon-x86.exe0%ReversingLabs
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\hidapi.dll0%ReversingLabs
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\libusb-1.0.dll2%ReversingLabs
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcp100.dll0%ReversingLabs
C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\msvcr100.dll2%ReversingLabs
C:\Program Files\AudioCodes\DM Client\emsc.exe0%ReversingLabs
C:\Program Files\AudioCodes\DM Client\system_ui.exe0%ReversingLabs
C:\Windows\Installer\MSIC3AF.tmp0%ReversingLabs
C:\Windows\Installer\MSIC9A0.tmp0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\AudioCodesB2GoE_USB.sys0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\BusControlLibrary.dll0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoController.exe0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\LyncPcAudio.dll2%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Lync.Model.dll0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Office.Uc.dll0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Practices.ServiceLocation.dll0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\Microsoft.Practices.Unity.dll0%ReversingLabs
C:\Program Files (x86)\AudioCodes\Device Duo\Newtonsoft.Json.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
NameIPActiveMaliciousAntivirus DetectionReputation
office.com
13.107.6.156
truefalse
    high
    fp2e7a.wpc.phicdn.net
    192.229.221.95
    truefalse
      high
      • No. of IPs < 25%
      • 25% < No. of IPs < 50%
      • 50% < No. of IPs < 75%
      • 75% < No. of IPs
      IPDomainCountryFlagASNASN NameMalicious
      2.23.242.162
      unknownEuropean Union
      8781QA-ISPQAfalse
      IP
      127.0.0.1
      Joe Sandbox version:42.0.0 Malachite
      Analysis ID:1587822
      Start date and time:2025-01-10 17:33:45 +01:00
      Joe Sandbox product:CloudBasic
      Overall analysis duration:
      Hypervisor based Inspection enabled:false
      Report type:full
      Cookbook file name:defaultwindowsinteractivecookbook.jbs
      Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
      Number of analysed new started processes analysed:75
      Number of new started drivers analysed:0
      Number of existing processes analysed:0
      Number of existing drivers analysed:0
      Number of injected processes analysed:0
      Technologies:
      • EGA enabled
      Analysis Mode:stream
      Analysis stop reason:Timeout
      Sample name:AudioCodesAppSuite.exe
      Detection:MAL
      Classification:mal56.evad.winEXE@89/132@1/10
      Cookbook Comments:
      • Found application associated with file extension: .exe
      • Exclude process from analysis (whitelisted): dllhost.exe, svchost.exe
      • Excluded IPs from analysis (whitelisted): 2.23.242.162, 4.245.163.56
      • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, e16604.g.akamaiedge.net, sls.update.microsoft.com, prod.fs.microsoft.com.akadns.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, glb.sls.prod.dcat.dsp.trafficmanager.net
      • Not all processes where analyzed, report is missing behavior information
      • Report size getting too big, too many NtAllocateVirtualMemory calls found.
      • Report size getting too big, too many NtOpenFile calls found.
      • Report size getting too big, too many NtOpenKeyEx calls found.
      • Report size getting too big, too many NtQueryValueKey calls found.
      • Report size getting too big, too many NtSetInformationFile calls found.
      • Timeout during stream target processing, analysis might miss dynamic analysis data
      • VT rate limit hit for: C:\Program Files\AudioCodes\Camera Service\RXV90UpgradeTool\USBCameraConsoleTool\QtGui4.dll
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):363876
      Entropy (8bit):6.679904855815163
      Encrypted:false
      SSDEEP:
      MD5:0A4CA5E3EED196887F3B33918E9FD76F
      SHA1:E455121150490C38C97C2DA6C0A6D9F19F7C804E
      SHA-256:257FEA328BA19F30AF623A77C4BEEDB1AD40DBCF1B62B2C7EFC5DA69C943B067
      SHA-512:ACBB2361DA36D628A9E16A4CFBC6F7E6FC55B57DFB377B8FD8A25DB3EDDDF4DD6D8742118C7B1DB216DBB2875198F2ADA5544AAD237C929FA35CB7BB46892DF6
      Malicious:false
      Reputation:unknown
      Preview:...@IXOS.@.....@X\*Z.@.....@.....@.....@.....@.....@......&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}..AudioCodes DM Client!.AudioCodes DM Client_1.2.0.10.msi.@.....@.....@.....@........&.{4A16C067-3D3A-48E9-90AF-DF5E841F98BF}.....@.....@.....@.....@.......@.....@.....@.......@......AudioCodes DM Client......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{B23D3133-6A90-5F78-B046-85A553389C3A}&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}.@......&.{47C03B18-8A62-58FB-B943-6B18ACFA9CDD}&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}.@......&.{601E4BF1-19F0-5333-94FF-0EFDDE0BC483}&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}.@......&.{34B3CFF6-2C43-549A-AB66-6A940A095F20}&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}.@......&.{A0AFD448-AF43-5B3E-B592-398E2B2A5538}&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}.@......&.{EB011603-F846-5B2A-8982-9473B5A3C282}&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}.@......&.{F79A7195-CD40-551C-8
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):233761
      Entropy (8bit):6.671041767620564
      Encrypted:false
      SSDEEP:
      MD5:A604ED0C21D860A1C7126066B7E1335B
      SHA1:C009116A4CE590E2D67A973004D07B3ECFE196AA
      SHA-256:1838AA10A8F7CFB1AC7D74989AC07A25CA14DED1B93BE9D729D323D7B3AB9657
      SHA-512:78C087577745AD580D49D706FEB032F3CB413F5CDEA163A4DACF92D82A8BC40EBA636EB1D49D6F42ADC849E951C22F5CB8085869C1B9F7093F10C333CF3C71A9
      Malicious:false
      Reputation:unknown
      Preview:...@IXOS.@.....@Z\*Z.@.....@.....@.....@.....@.....@......&.{74CFF291-6D94-478F-890D-CECD25AAEB01}..AudioCodes Camera Service&.AudioCodes Camera Service_1.2.0.10.msi.@.....@.....@.....@........&.{DA9B471C-955A-4B43-95F2-CC82DB5476BA}.....@.....@.....@.....@.......@.....@.....@.......@......AudioCodes Camera Service......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{DCA2AAFE-BC34-57DE-8714-378F47919BBD}&.{74CFF291-6D94-478F-890D-CECD25AAEB01}.@......&.{A68D6528-11E7-5E15-B592-077BD4DB8AC3}&.{74CFF291-6D94-478F-890D-CECD25AAEB01}.@......&.{C81436EB-6BB1-5C94-97FA-AC9C980A2271}&.{74CFF291-6D94-478F-890D-CECD25AAEB01}.@......&.{75F3B301-1E4F-555D-822D-706823339A34}&.{74CFF291-6D94-478F-890D-CECD25AAEB01}.@......&.{00469C62-DF22-5342-9EB0-1F63D25880E2}&.{74CFF291-6D94-478F-890D-CECD25AAEB01}.@......&.{36960B57-2AE8-5DEC-951A-5A840902AAB1}&.{74CFF291-6D94-478F-890D-CECD25AAEB01}.@......&.{4346D
      Process:C:\Windows\System32\msiexec.exe
      File Type:Windows setup INFormation
      Category:dropped
      Size (bytes):3485
      Entropy (8bit):5.400006115472206
      Encrypted:false
      SSDEEP:
      MD5:DC04A345534AB9D5BC8ED9D8D629CCF2
      SHA1:DF4A5057DCDD9C3BC84DE1AA82EAD9EED98880EF
      SHA-256:5C15B54E93BC308F4C677827D1E4E5CC2E00B9647DB1E43A2F44F145CFC13679
      SHA-512:152F494B62E4A32037C34B7944EA4A012AA4B9A2D1947F6FB1EB718E03C4C48C321D5C6E8A0A3C6AE6518D5CDB7AA93786EEA444C4B824D621DB7BE10409B899
      Malicious:false
      Reputation:unknown
      Preview:;/*++..;..;Copyright (c) 1990-1999 Microsoft Corporation All rights Reserved..;..;Module Name:..;..; AudioCodesB2GoE_USB.INF..;..;Abstract:..; INF file for installing B2G_VirtualBusDriver bus enumerator driver..;..;Installation Notes:..; Using Devcon: Type "devcon install B2G_VirtualBusDriver.inf root\B2G_VirtualBusDriver" to install..;..;--*/..[Version]..Signature="$WINDOWS NT$"..Class=System..ClassGuid={4D36E97D-E325-11CE-BFC1-08002BE10318}..Provider=%AUDIOCODES%..DriverVer=03/30/2021,1.3.6.5..CatalogFile=AudioCodesB2GoE_USB.cat......;*****************************************..; B2G_VirtualBusDriver Install Section..;*****************************************....[Manufacturer]..%StdMfg%=Standard,NTamd64,NTIA64....; For Win2K because it cannot parse decorated sections...[Standard]..;..; These are the toaster bus pnp ids..;..%B2G_VirtualBusDriver.DeviceDesc%=B2G_VirtualBusDriver_Device, root\B2G_VirtualBusDriver....; For XP and later..[Standard.NTamd64]..%B2G_VirtualBusDriver.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (native) x86-64, for MS Windows
      Category:dropped
      Size (bytes):90392
      Entropy (8bit):6.544094349819553
      Encrypted:false
      SSDEEP:
      MD5:8C80ADF257C0C2ECB3276DE2189AE1C1
      SHA1:2CC2D13ED8C7B8D22AB1EEA6C78151353BA1729D
      SHA-256:1479AED9C00A5F3D593E1507DF4EFC06471EFD0BC42AB5C81803D01BF1002C00
      SHA-512:498CEE0CE4114DFAE768A2F753AC928F79DFFA3D1495E95CE71C26E5EF076172E88287C8467D915F999DC735391F6DF2EE83C6B6F60D4EF1FB2378BC9DA39F75
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........H...)q.)q.)q..At.)q..Aw.)q.Q..)q.Q..)q..Ap.)q.)p.)q..Ar.)q..Au.)q..[u.)q..[..)q..[s.)q.Rich.)q.................PE..d....b`.........."..........2.................@....................................m.....`A................................................4R..<....`...................C...p..0...<...8............................................................................text............................... ..h.rdata..............................@..H.data...D...........................@....pdata..............................@..HPAGE..... ... ...".................. ..`INIT.........P...................... ..b.rsrc........`......................@..B.reloc..0....p......................@..B................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):154112
      Entropy (8bit):6.195598491405035
      Encrypted:false
      SSDEEP:
      MD5:E93BA08B805A04CA8BB4DD5E5E5DD729
      SHA1:F38867593991BCE0616D0E0A19DCE0C23E9CF2B0
      SHA-256:574F1A933E7376DF945049C8915E6D32B966D7233A7FFBCA98868AABCDDC4954
      SHA-512:AC1DB0DB7F09E3F0D6FB7D46F6A603428342497643E653331F678BCB984DADF4356BE514104662C0DFAC566419E650782B95A46BABF713C07967A15571B3B97E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......]....s...s...s......s.....as......s.."-...s.."-...s.."-...s......s...s..s..-...s..-...s..-...s...so..s..-...s..Rich.s..................PE..d....`.........." .....d...........{....................................................`..........................................5.......6..x.......(....p..........................p............................................................................text...pb.......d.................. ..`.rdata...............h..............@..@.data........P.......,..............@....pdata.......p.......6..............@..@.gfids...............J..............@..@.rsrc...(............L..............@..@.reloc...............R..............@..B........................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):133120
      Entropy (8bit):6.722992072213855
      Encrypted:false
      SSDEEP:
      MD5:7D6422BE7E20D37754DACC358570E8D9
      SHA1:2C04D35099843D0D9EC75FECD2F101989889B679
      SHA-256:66DE8C1C8F6A6538352A6A5FAD1E4B37E34AAA4180AA0BAF4B09857736A2E1CE
      SHA-512:8F102EDF0606B3F5B42DBCE4B02023B668238D35F1488F934ECCF8D744613C47DB6585C19764F6F7C15CDB2B038A3AF48A83F33221282661163F8D95131F90A2
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....`.........."...0.................. ... ....@.. .......................`............@.....................................O.... .......................@....................................................... ............... ..H............text... .... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H.......Tx..L............2................................................(....*~r...p.....r%..p.....rK..p.....*r.(.....(....~....r...po....*..(....*.*z.,..{....,..{....o......(....*...0..K............(....s......s ...}.....s!...}.....("....{.....o#....{.... <....Os$...o%....{.........s&...o'....{....r...po(....{.....K..s)...o*....{.....o+....{....r...po,....{.....o-....{...........s....o/....{....(0...o1....{....(2...o3....{......o4....{......s$...o%....{.... .....Js)...o5..
      Process:C:\Windows\System32\msiexec.exe
      File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):4813
      Entropy (8bit):5.04855847236651
      Encrypted:false
      SSDEEP:
      MD5:84C47FA26D4813E7160757277B8E9013
      SHA1:82672B4EAE8A1D5AD777D3DAFA117E2D154E0ABB
      SHA-256:1518FE2EA326AAB1082065AFE5B6E483AE4B438E025E12E8B549BEB04A1C01ED
      SHA-512:3E0ACF4D3029057BE006C20B70519EF57BF8952DE1EE5ED853E91B121733B90FC3ECADB2ADF8A61848ADFFF04343CDC5497DC8F6A88597DF35DD2C465056AAC5
      Malicious:false
      Reputation:unknown
      Preview:.<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <configSections>.. <section name="log4net" type="log4net.Config.Log4NetConfigurationSectionHandler, log4net" />.. <sectionGroup name="applicationSettings" type="System.Configuration.ApplicationSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089">.. <section name="Better2Gether.BToE.View.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" requirePermission="false" />.. </sectionGroup>.. </configSections>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.0" />.. </startup>.... <system.serviceModel>.. <client>.. <endpoint address="net.pipe://localhost/BToEService" binding="netNamedPipeBinding" contract="Better2Gether.BToE.Service.IBToEService" name="b2gClient" />.. </client>.. </system.serviceModel>.... <log4net>.. <appender name="Outpu
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):123904
      Entropy (8bit):5.739337322409304
      Encrypted:false
      SSDEEP:
      MD5:A9DA4077A7050C3A2745F547E4BD0FC2
      SHA1:2B88562916A917C1DCCA9F16C42C78405B71494C
      SHA-256:534D70EF41922C15C2EFEF6DF94E22848F1C1986320D67B71F86E75BD058497F
      SHA-512:9A84E2916FD04353D65B94C8C6E272D8A949FDD04A952DFF18E38A5C5558F0ABD29AB5304E48D65FCE2673CA4E02192B811370F3650D6ECFBB4F2901EC76C2EE
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....`.........."...0.................. ........@.. .......................@............@.....................................O............................ ......x................................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc....... ......................@..B........................H...........H............................................................{....*..{ ...*V.(!.....}......} ...*...0..;........u......,/("....{.....{....o#...,.($....{ ....{ ...o%...*.*. G... )UU.Z("....{....o&...X )UU.Z($....{ ...o'...X*.0...........r...p......%..{.....................-.q.............-.&.+.......o(....%..{ ....................-.q.............-.&.+.......o(....()...*..(!...*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*.ra
      Process:C:\Windows\System32\msiexec.exe
      File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):6757
      Entropy (8bit):4.900818193846518
      Encrypted:false
      SSDEEP:
      MD5:89C73C6526C8141F29359FC163464605
      SHA1:14D1D2532F525DFA823BA5244695991BDA075D6D
      SHA-256:FBA16AC45A2444BDD29B42FE60E1F75C2A37811054DAC863BC0C8F255603F590
      SHA-512:0D5505CFA7565AE65D89EABF911A5CFB74BFCCE7623CBEB94DE11416D69EDA8767C8B61C8D4D6ADBECF2E7E93AE264106D958E7D75EB15BDCA0C84B48C3EBDF8
      Malicious:false
      Reputation:unknown
      Preview:.<?xml version="1.0"?>..<configuration>.. <configSections>.. <section name="log4net" type="log4net.Config.Log4NetConfigurationSectionHandler, log4net"/>.. <sectionGroup name="applicationSettings" type="System.Configuration.ApplicationSettingsGroup, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" >.. <section name="Better2Gether.BToE.Service.Properties.Settings" type="System.Configuration.ClientSettingsSection, System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089" requirePermission="false" />.. </sectionGroup>.. </configSections>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.0"/>.. </startup>.. <system.serviceModel>.. <bindings>.. <netNamedPipeBinding>.. <binding name="bindingConfiguration" receiveTimeout="infinite"/>.. </netNamedPipeBinding>.. </bindings>.. <services>.. <service name="Better2Gether.BToE.Service.BToEService">.. <endpoint address=
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):61440
      Entropy (8bit):5.490393296382429
      Encrypted:false
      SSDEEP:
      MD5:EB3F9AECDD5EBB4380B1AB038A4F9D4E
      SHA1:B9877876403581FA92A4281679D300CB9E63E97A
      SHA-256:AC3F269059E3C8199770A22A15D6493A9C865E08FF42674C0062FEDFA7C8EEAF
      SHA-512:F911702CB055DF615CA82D5F5571AA58747C306E73AFAF1DF2AF7ECB35C81B21BBBCE57E4F1172A622D1973B7D5FE9B3FA34CC1B1E6475DB248FCBDFB0AF65E0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 2%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....`.........." ..0.................. ... ....... .......................`............@.....................................O.... .......................@......`................................................ ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H........`..H.............................................................(....*.0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0...........{......,....o....*..0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0...........{......,....s ...o!...*..s....}......s"...}.......}.....(......o#...(....*..0..C........s....}......s"...}.......}.....(.....,..o$.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):413888
      Entropy (8bit):5.886368185341827
      Encrypted:false
      SSDEEP:
      MD5:0DB348A2A4AF1CD673382FD559F5E81A
      SHA1:72A2616D92937BC1DFE68E3C17F66A40E8F52582
      SHA-256:F66DD879C87D5EE7157D0A2E87B7BC9BA3E565F64B5ACE2F0BC932287BBFE453
      SHA-512:62A60DD93DC132175EE4B150B7CDE3F871BD681CDDEAF15C02BD0E4B20A1906C790D2A4053FB7BE15227BCA2280853A0D4F16DC0209FF5E8321C6D2FB37AE788
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......S...........!.....,..........NK... ...`....@.. ....................................@..................................J..W....`...............6...............I............................................... ............... ..H............text...T+... ...,.................. ..`.rsrc........`......................@..@.reloc...............4..............@..B................0K......H.......tD..H...................P ......................................w}........SWepYM....l........T.f3...V...r.....,O...:.A~.n.6..h!.o...I"i..ieL...{^..7t5....W.]..zW....|..J..=](..Uv.......2.."..}....*....0..T..........%...(......}....~\...oH....2'~\...oG...._,.....o....(.....o....(|......,..(.....*........GI.......0..|........{....-.*...%...(.....{....-..s....}.....{......o....~\...oH....2-~\...oG...._,.....o....(.....o.....o....(.......,..(.....*........fq.......0..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):479400
      Entropy (8bit):5.862387708313177
      Encrypted:false
      SSDEEP:
      MD5:8050F72F4B2A01F0EF1D6D010C3ECA01
      SHA1:4AAE3AED85062A2B162EA9DDFA96B4F57E1B042C
      SHA-256:98D00737A61FE674B8C2488125D168818FFC652F85D2FC0D04CAAA398148E2E5
      SHA-512:CA39B593ABEBBAF533E5274FCE6B3BD8AEE825E1BE5C1B7C25FC260DBD65D685ABE067F3AD4C67B2EC034DB0BD42D05A71AE6C780BEE4C3413625483DED500C4
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......S...........!.................L... ...`....@.. ..............................ZW....@.................................DL..W....`...............6............................................................... ............... ..H............text....,... ...................... ..`.rsrc........`.......0..............@..@.reloc...............4..............@..B.................L......H........^..D....................].......................................0..&...........{....9........{............o....**...0..&...........{....9........{............o....**...0..&...........{....9........{............o....**...0..6...........(........ ....}.........}.........}.........}....*...0............ ....."..... .... ...... .... n..... .... ...... .... P..... .... ...... .... (..... .... ...... .... D..... .... ...... .... D..... .... i..... .... ...... .... ...... .
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):29760
      Entropy (8bit):4.841427370418328
      Encrypted:false
      SSDEEP:
      MD5:6DF78BB163D443D95B21F58808320AF7
      SHA1:A0263EC61435D1EE4C18A92A06AC3EA2C42EB730
      SHA-256:79E7BE6BE7509A1A5263F0292F1462A57744A7C52C4DA6475C70A5054D08C327
      SHA-512:D10510EC52C57061AB8C516B30B6FDC1A4602DEF69482EE0E230E1A161D7A08CA98280BA71478668C36C541D4EF944B17132DB46A8D7298DD1F4749ADD61D372
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......H...........!..... ... .......?... ...@....@.. ..............................."....@.................................`?..K....@...............P..@$...`.......>............................................... ............... ..H............text........ ... .................. ..`.rsrc........@.......0..............@..@.reloc.......`.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):124216
      Entropy (8bit):6.003994465819638
      Encrypted:false
      SSDEEP:
      MD5:8BB973283D503C9DEE003476810018C1
      SHA1:3816A03528E003F25746C03AC565EDED9EAE74EC
      SHA-256:CFF20CF01155DEE730337A5684285B7A39C59B8321BDC242170AE189C3841A19
      SHA-512:0912F81553DB5121F860FDE3F418BC4665C1F5DB84EC679239D7CF9BF41C059BED7E23EF45680207790445B73E93F85D1C2CB90CF7B1E91E0F6A5F1AFB02957E
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......M...........!..................... ........@.. ....................... .......<....@.................................h...S.......................8............................................................ ............... ..H............text....... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H.......0...................u...P .......................................m.=4.....*...N......R..A..... ....k..*x.>F`....X.Z..I.......&H.8N....C.3.v....GE.....>.j..7].v...,..2n.Z....0.D...J.}..(....*..(....*..(....*"..(....*:.(......}....*..{....*6..{....s....*"..(....*:.(......}....*..{....*6..{....s|...*..s....*"..s....*..(....*6.{.....o....*6.{.....o....*..(....*F.{....o.........*..0..3........{....(...+.Y.+..{.....o .....o......,..*..Y.../..*J.s!...}.....(....*..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):574376
      Entropy (8bit):5.8881470355864725
      Encrypted:false
      SSDEEP:
      MD5:8F81C9520104B730C25D90A9DD511148
      SHA1:7CF46CB81C3B51965C1F78762840EB5797594778
      SHA-256:F1F01B3474B92D6E1C3D6ADFAE74EE0EA0EBA6E9935565FE2317686D80A2E886
      SHA-512:B4A66389BF06A6611DF47E81B818CC2FCD0A854324A2564A4438866953F148950F59CD4C07C9D40CC3A9043B5CE12B150C8A56CCCDF98D5E3F0225EDF8C516F3
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Ot............" ..0.............6.... ........... ....................................@....................................O.......................................T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........f...P............................................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X.+....b...aX...X...2.....cY.....cY....cY...{...._..{........+,..{E....3...{D......(....,...{D...*..{F.......-..*...0...........-.r...ps....z.o......-.~....*.~....X...+....b..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):88576
      Entropy (8bit):5.854572431585149
      Encrypted:false
      SSDEEP:
      MD5:39BA887C4A5B3F2C57A23AD332AD0D03
      SHA1:EC2B55789852A90A33B943591F936C5CB3C83C56
      SHA-256:38ACF4AA30900A5096DA7230AE8E663D5F36F8280829C21D0E1884698A0A8E72
      SHA-512:9DAD25B5A273FC087661E57CE533B61D601D236E49C92B7808599E628054E55295B645118F46561F56AE6C1B5400EA1710FC4DF6DA5B1F182E84847C68A50A93
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......o..e+..6+..6+..6..Y6/..6..[6^..6..Z6&..6..7,..6..7>..6..7;..6".;6(..6+..6~..6..7*..6..7*..6..W6*..6+.?6*..6..7*..6Rich+..6........................PE..d....`.........." ......................................................................`.........................................0@......$A..(.......(....p......................@1..p............................1...............................................text............................... ..`.rdata..J...........................@..@.data........P.......2..............@....pdata.......p.......<..............@..@.gfids...............J..............@..@.rsrc...(............L..............@..@.reloc...............R..............@..B................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):1060
      Entropy (8bit):5.328832830810776
      Encrypted:false
      SSDEEP:
      MD5:C79DDB86DD95CA60317A9B3216B21162
      SHA1:20F53885E17B72910EEF895B162851801179F724
      SHA-256:041A6769EA6A8510E5BBC01E6F7A905D04AE9A59BCFA0A96CCCB4B90725A0E9D
      SHA-512:204806984426DC1DA62E1022B01A389B224F92667C50BBD95384BC6673E5E273C3A4B484C7BA2AE933828F445ABAF311B3FC8CC53F2D58DA084508F2B3567BAD
      Malicious:false
      Reputation:unknown
      Preview:.[.... {.. "AppName": "Zoom",.. "ProcessName" : "zoom",.. "ID": 2,.. "DiscoveryMethod": "Registry",.. "DiscoveryPathList": [ "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\ZoomUMX","HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\Zoom"].. },.. {.. "AppName": "Teams",.. "ProcessName" : "Teams",.. "ID": 3,.. "DiscoveryMethod": "Registry",.. "DiscoveryPathList": [ "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\Teams", "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\IM Providers\\Teams" ],.. "CallStartCommand": "%LocalAppData%\\Microsoft\\Teams\\current\\Teams.exe",.. "CallStartArgs" : "callto:{0}".. },.. {.. "AppName": "SfB",.. "ProcessName" : "lync",.. "ID" : 4,... "DiscoveryMethod": "Registry",.. "DiscoveryPathList": [ "HKEY_LOCAL_MACHINE\\SOFTWARE\\IM Providers\\Lync", "HKEY_LOCAL_MACHINE\\SOFTWARE\\WOW6432Node\\IM Providers\\Lync", "HKEY_CURRENT_USER\\Software\\Microsoft\\Of
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):11019776
      Entropy (8bit):5.2535509414137955
      Encrypted:false
      SSDEEP:
      MD5:994DF8CA4B5AD0923915F3A3F587EE80
      SHA1:8A19399DA235F501717E5840B1E3965FA9CD828D
      SHA-256:5131AD073D470E5C499CEECBC3B46A9873C4CA593073E266D4AEF48A85064627
      SHA-512:0C8F87B28D93B45B3E817DC73769D840D47BB1DA653963E50C72855B6EF7D90F2843CB9C05CA0FBC9919F8E512A059B08B12E2AA0A2BF35D75C641CD64614A5E
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[D.S...........!.................;... ...@....... ...............................+....@.................................h;..S....@..(....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...(....@......................@..@.reloc.......`.......$..............@..B.................;......H.............................P .......................................4lh.r........])..K.....C.A;..\S...n..b...>_.1HT....YN..K.&...[...^#d_.1.Tsb...;.m.<..r..&.s.c...?....{.DYzY...e.].z).H.E..v.mt>..(D.....}....*..**^.(E....{....oF...(G...*6.{.....oH...*..*..oI...*....0..........s.......{....oI$..o....*.0..,.......s.......o.......{....o`$..o.....{.....oJ$..*.0..]..........(2.....,O.o....,Gs......o......o~...sJ.......o......j.oK...&.sL.......oM.......,..o).....*.........-.
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):2559488
      Entropy (8bit):6.292010993717748
      Encrypted:false
      SSDEEP:
      MD5:9FFCBF8448C481F1B87678A754BE08E7
      SHA1:EA88BD2462EA739D8F0C4D5D8E4C716F2F9BAE60
      SHA-256:374F8A96A78EBA271721B3A7191D00827190AFB487F2AFA299903C852C21B4A6
      SHA-512:B7F5ABDA529432C5229D8C444336EB852B27CF369EB0732BA345CF59EF4B7268B492E28364D5FFF68C75A8A622B4AB954DE8546D8F9FA03B0C1197EC95195384
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...AD.S...........!......'.........n%'.. ...@'...... ........................'......1'...@..................................%'.S....@'......................`'...................................................... ............... ..H............text...t.'.. ....'................. ..`.rsrc........@'.......'.............@..@.reloc.......`'.......'.............@..B................P%'.....H............|..............c...P ...........................................D..o,.m.6.P.=...8.{.u.d..{w.E...:....EBP..%.K..0.....@.6J..zkG...{e.....3.....{.....99..~w............g'.D.aW.m.T...~5...*...5...*..0..F.......(....-.*r...p..(z.....,-.,..({...+....(|...-.r...p..(z....(.....o....*...0..G.........(......,;.,..({...+....(|...,.r...p.(}....+.r...p..(z....(.....o....*..0..2........,..o....,&.o....o....,..o....o....u>.......(....*...0..1........,-.o....,%.o....o..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):7680
      Entropy (8bit):4.576398261787889
      Encrypted:false
      SSDEEP:
      MD5:8578DBB9802F1D423A0ECFC5301D0848
      SHA1:6CAB64B374E18E4B22885A9A85E42C877FBBDE25
      SHA-256:175CFA0D2FFC9664D003FE6BE012099A0DE1B187715F6BD4BAFF4B7470EF72B9
      SHA-512:3C40520D2180D847CE4840C84792A474CD503275DC7554BF704F35685164CB95C01D919023D7D225EB2DCD1E2A477D389460CE5FFD3AB496FFC4FB0F78512478
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....`.........."...0..............2... ...@....@.. ....................................`.................................x2..O....@.......................`......@1............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................2......H........!..\.............................................................(....*.0..[.........i...r...p(......(.......r9..p(....,.(....*...rI..p(....,.(....*r_..p...(....(......(....*.~....(....*.~....(....*..0..".......(......~....(....,.. ......(....&*.s....%~....}....%(....}....%......s.....(....&{....*..0..".......r...p(.......-..*..i.1..*...o....*V ......... .........*.0..W..........(....&.n.{....j3A.{....~....(....,/.ds........o....(....&.o....r...po....,...}.....*.BSJB
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):11384
      Entropy (8bit):7.165241389129084
      Encrypted:false
      SSDEEP:
      MD5:A325F08A065FAF19072387FEE57897D4
      SHA1:1F1E6C9676077D2C290D30AB8171E4F4596744F7
      SHA-256:A787D1BA9142F891D2F081454A36D2B50170A1F34D2A5541E2BBB908B434355F
      SHA-512:122C37636B27684E0345E803B0DD57B6C0DF07AB7EF6EBD617328D8E7368AFBDE9BBC3F975FB32EC80F95FE5031C12EE88C398B31280701E7B91005387BDC5F2
      Malicious:false
      Reputation:unknown
      Preview:0.,t..*.H........,e0.,a...1.0...`.H.e......0.....+.....7......0...0...+.....7......J.>..oO...RV.r..210330082216Z0...+.....7.....0...0.....c.....I..x.....c...1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0R..+.....7...1D0B...F.i.l.e.......0w.d.f.c.o.i.n.s.t.a.l.l.e.r.0.1.0.0.9...d.l.l...0.. . ....K..q(?.Q)2T4.,.j<.N..I.=,.1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0R..+.....7...1D0B...F.i.l.e.......0a.u.d.i.o.c.o.d.e.s.b.2.g.o.e._.u.s.b...s.y.s...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... ....K..q(?.Q)2T4.,.j<.N..I.=,.0.. . . q&H.Hv4;.s....N....uB^...@_.%1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........2.:.1.0...0...0R..+.....7...1D0B...F.i.l.e.......0w.d.f.c.o.i.n.s.t.a.l.l.e.r.0.1.0.0.9...d.l.l...0]..+.....7...1O0M0...+.....7...0...........010...`.H.e....... . q&H.Hv4;.s....N....uB^...@_.%0.... \..N..0.Lgx'.......d}..:/D.E..6y1..0...+.....7...1...04..+.....7...1&0$...O.S.A.t.t.r........
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
      Category:dropped
      Size (bytes):298496
      Entropy (8bit):5.663662007449741
      Encrypted:false
      SSDEEP:
      MD5:2FE9A2C6A74969827AFA760F3C66180D
      SHA1:D28E326871148553596CE50E57F48096CACC192A
      SHA-256:09C9F905902634049ACD27A9C9844775B7A2C68CA5ACD60A9B35AC626B971BC0
      SHA-512:50B3200919106C7ECF4B97C7E4DAB5BF0430D76542C4960E7B75AFD7462026250E13A38FC8AB2175C860A4EFCFEEFFFF2F967DAA5F3ACD450BE62A94ABDDC546
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....-R...........!..................... ........@.. ...............................b....@.................................p...K.......(............................................................................ ............... ..H............text....... ...................... ..`.rsrc...(...........................@..@.reloc..............................@..B........................H.......h3...o..........H... -..P ..........................................g.0..lQ,l...I..s...q.rw.D0.X...S..yY....!...(y..........G......B7.......E..K.anX8+37...x/...W..U....)l.3..... .7...}......}......}.....(/.......(0...o1...so...}.....*...0..A.........{......-).~....r...p.{....r9..p(2...(D.....(..........(3......*...........77.......0............{.....+..*&...}....*...0............{.....+..*.0..L...........%...(4..............-..~....r?..p(G.....+....}......
      Process:C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2959
      Entropy (8bit):5.365691264063275
      Encrypted:false
      SSDEEP:
      MD5:72A65C44275458E8DA06A81EDC649CB0
      SHA1:E1D0D93798A7A7688DEB6DD76178243F062B7B6B
      SHA-256:5AE2C2C97925CF4237F7FC936292C8E0A083D0625A315806D60AB9A6427953D5
      SHA-512:EC2DD610B7BA2F4A4088F4C4F474569AB556F3A26313F06B3BC541DEEF2BA8329C876878FA4B427F7C6669F6B82C7E229E3B9BB5628384E7045DB8E98BF0FDC7
      Malicious:false
      Reputation:unknown
      Preview:BToE [] 2025-01-10 11:35:38,133 [1] FATAL Better2Gether.BToE.Service.BToEWindowsService Welcome to BToEWindowsService,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,180 [1] DEBUG Better2Gether.BToE.Service.BToEWindowsService Welcome to BToEService..BToE [] 2025-01-10 11:35:38,243 [4] INFO Better2Gether.BToE.Service.BToEWindowsService OnStart..BToE [] 2025-01-10 11:35:38,290 [4] FATAL serviceLog Welcome to serviceLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,305 [4] DEBUG serviceLog Service call - GetVersion..BToE [] 2025-01-10 11:35:38,305 [4] INFO serviceLog ==============================Build version : ============================================..BToE [] 2025-01-10 11:35:38,305 [4] FATAL dispatcherlog Welcome to dispatcherlog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,321 [4] INFO dispatcherlog Welcome..BToE [] 2025-01-10 11:35:38,337 [4] FATAL phoneLog Welcome to phoneLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,367 [4] FATAL tc
      Process:C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2486
      Entropy (8bit):5.3607146647829635
      Encrypted:false
      SSDEEP:
      MD5:71FDE4F49CC3D0DF7DA9E7C95DD8AE71
      SHA1:ABE00332ADD7F1CD09A3C875FDA87B6FF34FED7A
      SHA-256:7653018758F62CBA88D4FC6060A6D10FCAB9AD2CF6E0088CDCDE4D38FE4A9DD4
      SHA-512:25EB6F9824D10397F31ADFC5246058CCBF4EF4CF85469694120E1F63E6987C009D6DDF2C00C4AFF505478A3C1A2B762338B36DB5DF36375177A0B9530D5444F8
      Malicious:false
      Reputation:unknown
      Preview:BToE [] 2025-01-10 11:35:38,133 [1] FATAL Better2Gether.BToE.Service.BToEWindowsService Welcome to BToEWindowsService,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,243 [4] INFO Better2Gether.BToE.Service.BToEWindowsService OnStart..BToE [] 2025-01-10 11:35:38,290 [4] FATAL serviceLog Welcome to serviceLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,305 [4] INFO serviceLog ==============================Build version : ============================================..BToE [] 2025-01-10 11:35:38,305 [4] FATAL dispatcherlog Welcome to dispatcherlog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,321 [4] INFO dispatcherlog Welcome..BToE [] 2025-01-10 11:35:38,337 [4] FATAL phoneLog Welcome to phoneLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,367 [4] FATAL tcpLog Welcome to tcpLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,367 [4] INFO tcpLog Welcome to TCP Log..BToE [] 2025-01-10 11:35:38,383 [6] INFO tcpLog ConnectionWorker Start.
      Process:C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe
      File Type:ASCII text, with CRLF line terminators
      Category:modified
      Size (bytes):113
      Entropy (8bit):5.003486066643253
      Encrypted:false
      SSDEEP:
      MD5:91A4CAF8CCB8B6720614DFF918011AB9
      SHA1:596D060855861C96BF4A0609D1865CCCF7E7C3EE
      SHA-256:3E5DB3A7F4682F84F8B26E680BBCD78A4197BBE4EC6B9EAD24D9DB43C69F9C32
      SHA-512:7757C0DCB8E535520DB56D6B81C8B208EE7C7F8BB1817E4648D6D921DDF97BCFD043BE8DA7E61A2C2DF128213CCE33CA5F30FB6228997F242A5D08A9159FF99E
      Malicious:false
      Reputation:unknown
      Preview:BToE [] 2025-01-10 11:35:38,538 [4] FATAL driverDLLIsolog Welcome to driverDLLIsolog,Assembly Version 2.3.101.0..
      Process:C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoService.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):1533
      Entropy (8bit):5.273723259271203
      Encrypted:false
      SSDEEP:
      MD5:3EB555AC9068773383DF43F59A0948E3
      SHA1:68979EF037DAFC805148892F8112D4E7511C7A76
      SHA-256:6A4C7732C3D5AD61992002195D6F41FF37675B0355D5CBEAEBFBFCEB20E1335D
      SHA-512:028B339031B9848DED1796E1DC42B8A789DF2D12AED7407A81CFB40C6694A0E8C9809AA2D3B20F69A9E2278194B01364943D6395DFC957BD49997C7B74BB6754
      Malicious:false
      Reputation:unknown
      Preview:BToE [] 2025-01-10 11:35:38,133 [1] FATAL Better2Gether.BToE.Service.BToEWindowsService Welcome to BToEWindowsService,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,290 [4] FATAL serviceLog Welcome to serviceLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,305 [4] FATAL dispatcherlog Welcome to dispatcherlog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,337 [4] FATAL phoneLog Welcome to phoneLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,367 [4] FATAL tcpLog Welcome to tcpLog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,538 [4] FATAL driverlog Welcome to driverlog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,538 [4] FATAL driverDLLlog Welcome to driverDLLlog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,538 [4] FATAL driverDLLIsolog Welcome to driverDLLIsolog,Assembly Version 2.3.101.0..BToE [] 2025-01-10 11:35:38,554 [4] ERROR driverDLLlog Error:Interface GUID_DEVINTERFACE_B2G_BUS is not registered..BToE [] 202
      Process:C:\Windows\System32\msiexec.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):384
      Entropy (8bit):5.174316400763902
      Encrypted:false
      SSDEEP:
      MD5:ABD4E6538FB0D3562BF2FD34C9AD48C7
      SHA1:2451B7C4080859E37C57FF7A6E177EB1D151B67F
      SHA-256:30247B3CA838F0870888D29DE22957118B06DC4E4ED413F474B198580D8AD817
      SHA-512:36B59E9610CABE30C95ADE2312D070898E2A7B3ECEC92A610E4031762BCFE3259AA79BAD7EE61E8B189146A48F0AD138F3326BAD059DFC86195EBDDE79DB2C27
      Malicious:false
      Reputation:unknown
      Preview:ImageRuntimeVersion: v4.0.30319..Assembly AudioCodes Camera Service, Version=0.0.*, Culture=Invariant Language (Invariant Country): ...hash=SHA1, flags=PublicKey..Assembly mscorlib, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089: ...hash=None, flags=None..Assembly WebCamLib, Version=0.0.*, Culture=Invariant Language (Invariant Country): ...hash=None, flags=None..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):10752
      Entropy (8bit):4.88990988878134
      Encrypted:false
      SSDEEP:
      MD5:C65CF88FFB1EDAD9A3C690F8D55AEC25
      SHA1:307038C0887D43853C6A65F3754B41574291EA99
      SHA-256:AFFE8CDBB212A457C1C513F21A6E00F4402C1FC1FFDAA8B6FEA9B192E856FE5D
      SHA-512:A0B72AB273F722DF4B39156C4A1FD4E420D360C58BEF41B7F4DDF2700E1FD0D59FDA6C97E7C19B48F2F88CA398CAA810483BC045B77D3918AC667B7391287B31
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......].e....S...S...S...S...SK..R...SK..R...SK..R...SK..R...S...R...S...S=..S...R...S...R...S...S...S...R...SRich...S........................PE..d....zFd.........." ................0........................................p............`..........................................(.......)..d....P.......@...............`..$....!..T........................... "..8............ ...............................text...h........................... ..`.rdata....... ......................@..@.data........0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..$....`.......(..............@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):64
      Entropy (8bit):3.7239882355820617
      Encrypted:false
      SSDEEP:
      MD5:A40FFDAA9729C5FC32B60DF194F63681
      SHA1:7F29939C36CB88309394FA69A605C71E12E76ACB
      SHA-256:F7425FB6F1A8EA969BD4EABACEB923E77B53CFA05A9CA310925FB442A9143328
      SHA-512:80912DAC6A07B5C9F7EF14ED9994B3AAE0A08BFB6243E15DB282F5496B91A0E36EEEC0EF510F762332320188F71AE51D14D7BECA134A8689EA56767A18B49FB1
      Malicious:false
      Reputation:unknown
      Preview:VID0=3430..PID0=1202..VID1=1FF7..PID1=0408..VID2=3430..PID2=1101
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
      Category:dropped
      Size (bytes):3939840
      Entropy (8bit):7.742028611643238
      Encrypted:false
      SSDEEP:
      MD5:A9C2F2677D599967E306D17731D41582
      SHA1:68E58E2E311804D0BFD06D6AE7642CEA0FD616DB
      SHA-256:3E32AE99E23E29323EDBB32E399E353667819DD54C5790BC4BC82D94970A6D6F
      SHA-512:DA1ECF7979F95C1539495DBD29FCE976435DBEDB857AFC3FCA20DA6448844B6ACA73F9CCEA73F1115790C4E0F612C8B82021C5C484AA5AA4222FDDF1C162DF78
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......0...t...t...t......p.....u...oq.|...}...q...oq.r...}..c...t.~.....oq.i...oq.....oq.u...oq.u...oq.u...Richt...........PE..L......Q...........!.........p....X.0.....X........e..............U.......................@..............................c..........................................................................$...H...........................................UPX0......X.............................UPX1..........X.....................@....rsrc....p.......l..................@..............................................................................................................................................................................................................................................................................................................................................................................3.95.UPX!....
      Process:C:\Windows\System32\msiexec.exe
      File Type:ASCII text, with very long lines (1248), with CRLF line terminators
      Category:dropped
      Size (bytes):405114
      Entropy (8bit):5.265794986331144
      Encrypted:false
      SSDEEP:
      MD5:F7C0F4983FF4D8D3A1CBF9CEC80498DD
      SHA1:E5CAC289874105BC4582D08417A4771451E5CFA4
      SHA-256:896C3170FEFE4C8D19866C9A46CB361045541022D69713BEC69F4C1B98DAD4BB
      SHA-512:920961C245ADECE45E3072EAFC5398D07D60E3B77517B3A142DE48D3BE01EC5BBCC1C04793C999782B1BABA1F527EFE3F5A5E13E583A22FFEF233347A3898B15
      Malicious:false
      Reputation:unknown
      Preview: USBCameraTool.... Timestamp is 618bb6e6 (Wed Nov 10 20:11:18 2021).... Preferred load address is 00400000.... Start Length Name Class.. 0001:00000000 0001c4dcH .text CODE.. 0001:0001c4e0 0000371bH .text$x CODE.. 0001:0001fc00 0000011bH .text$yc CODE.. 0001:0001fd20 0000001bH .text$yd CODE.. 0002:00000000 00000dc0H .idata$5 DATA.. 0002:00000dc0 00000004H .CRT$XCA DATA.. 0002:00000dc4 00000004H .CRT$XCAA DATA.. 0002:00000dc8 00000040H .CRT$XCU DATA.. 0002:00000e08 00000004H .CRT$XCZ DATA.. 0002:00000e0c 00000004H .CRT$XIA DATA.. 0002:00000e10 00000004H .CRT$XIAA DATA.. 0002:00000e14 00000004H .CRT$XIY DATA.. 0002:00000e18 00000004H .CRT$XIZ DATA.. 0002:00000e20 0000aae0H .rdata DATA.. 0002:0000b900 000014c4H .rdata$r DATA.. 0002:000
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):438272
      Entropy (8bit):6.692870292751396
      Encrypted:false
      SSDEEP:
      MD5:A25F0FDDDBF1E3C107D0507913B2FDAF
      SHA1:6C56082EACD0693E053DA570FD2D23B67C05C808
      SHA-256:5C9A4F37C933032181F1B65677CBCEC2E27994CFE8739BC26870A6311AF618B8
      SHA-512:E81DBA017DCFE1A3FCC9224EC3D3F3ED0C06A405DADF91ECACA5F58522D29DB67076FA478F4D1F1F11CA7D62E2837565EC8FD7E2C2A1A6337A961B5E1FD3EF20
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........h....K...K...K/..K...K..K...K..K...K...K...K..K...K..K...K.q.K...K...K...K...K...K..K...K..K...K.*zK...K..K...KRich...K........PE..L....G.a...........!......................................................................@.........................P.......`........p..........................@C...................................G..@............................................text............................... ..`.rdata...?.......@..................@..@.data...t&...@...$..................@....rsrc........p.......R..............@..@.reloc..hW.......X...X..............@..B................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):102
      Entropy (8bit):4.989820901722083
      Encrypted:false
      SSDEEP:
      MD5:9697F77357DA35B86F1F75F60AFFBE41
      SHA1:52CE7FD83DB6CBE0954EFE9209C762A8128D3EF2
      SHA-256:88FD7C94979D29532C418F39B0B243D72F508A3BF1E7A413026D111FE8CF9187
      SHA-512:BB15FD41E9959B1F0D9024B6C44A2EDBEFEEA3C576FB30B98F73C051B2A18FB0B227D39A09470C00A7EFF88E37E7D8BF5886DB2CDFC3B16C4EF3A6A5FA7C70A5
      Malicious:false
      Reputation:unknown
      Preview:.[Hid]..;Vendor id(10..)..Vid=7531...;1d6b....;Product id(10..)..Pid=258....;0102....[Uvc]..
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):81920
      Entropy (8bit):4.977706172799676
      Encrypted:false
      SSDEEP:
      MD5:3904D0698962E09DA946046020CBCB17
      SHA1:EDAE098E7E8452CA6C125CF6362DDA3F4D78F0AE
      SHA-256:A51E25ACC489948B31B1384E1DC29518D19B421D6BC0CED90587128899275289
      SHA-512:C24AB680981D8D6DB042B52B7B5C5E92078DF83650CAD798874FC09CE8C8A25462E1B69340083F4BCAD20D67068668ABCFA8097E549CFA5AD4F1EE6A235D6EEA
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........X...9...9...9...AF..9...AW..9...A@..9...9..f9...AP.9...AY..9.......9...AG..9...AB..9..Rich.9..........................PE..d.....pK.........."......~...........s.......................................p......|.....@.......... ......................................X}..........p.......T............`......0................................................................................text....|.......~.................. ..`.data...x...........................@....pdata..T...........................@..@.rsrc...p...........................@..@.reloc..p....`.......>..............@..B................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (console) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):77824
      Entropy (8bit):4.995224286140262
      Encrypted:false
      SSDEEP:
      MD5:B40FE65431B18A52E6452279B88954AF
      SHA1:C25DE80F00014E129FF290BF84DDF25A23FDFC30
      SHA-256:800E396BE60133B5AB7881872A73936E24CBEBD7A7953CEE1479F077FFCF745E
      SHA-512:E58CF187FD71E6F1F5CF7EAC347A2682E77BC9A88A64E79A59E1A480CAC20B46AD8D0F947DD2CB2840A2E0BB6D3C754F8F26FCF2D55B550EEA4F5D7E57A4D91D
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........L..."..."..."....."......"......"...#.S."....."..`\..."......"......".Rich..".................PE..L...#.pK.................l..........Td.......................................P............@...... ..........................lm..........p....................@...... ...............................0...@............................................text... j.......l.................. ..`.data...4............p..............@....rsrc...p............v..............@..@.reloc.......@.......&..............@..B........................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):13312
      Entropy (8bit):5.665343625655401
      Encrypted:false
      SSDEEP:
      MD5:8C740EE5F6408C65D341A87533C552B0
      SHA1:1D2C1E539E58878FEE143583136DD8990657F485
      SHA-256:FCD897F07BE5320C9AEF52F1A1249BAF6444A8E1FBB80FBECE9D43051329277C
      SHA-512:D29DC98BB3E57F7B9EB30FB4E76443E44B462FAF044C7DC8B56B02D0A420E20965288DEDDC0970E5B1A2301C575529CC6663A0E3A37D29A3FC21874C6087ABA0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........>.;.PL;.PL;.PLT..L9.PLT..L:.PLT..L7.PLT..L9.PL2..L>.PL;.QL..PLT..L:.PLT..L:.PLT..L:.PLRich;.PL................PE..L....W._...........!.................#.......0...............................p......:.....@..........................9..~....4..P....P.......................`..H....1...............................2..@............0...............................text............................... ..`.rdata..>....0......................@..@.data........@.......,..............@....rsrc........P......................@..@.reloc.......`.......0..............@..B........................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):117248
      Entropy (8bit):6.668935022626029
      Encrypted:false
      SSDEEP:
      MD5:7EEA0694ED9D25F1B2FB9738C7E49927
      SHA1:8CA175338CEDA1DE5392E68BEC06092A346FB9CC
      SHA-256:31C660FF9448835EC0755FFED922E4A44C167E2F7206606FDA412D22612AC26B
      SHA-512:DD1402DE3ABA83FA1DF1AB2222F786CBA10A133075C10491B982CBAB9B9B4FA1A55E94CA421E371AAD8ED17744FC728FC7E8B0076C6A696078BD97F570D1A812
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 2%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.................................8.....9................<......................Rich...........................PE..L....&._...........!................O........0............................................@......................... .......,...P....... .......................D...................................`...@............0..|............................text...U........................... ..`.rdata.......0......................@..@.data...h...........................@....rsrc... ...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
      Category:dropped
      Size (bytes):215888
      Entropy (8bit):6.857623419590538
      Encrypted:false
      SSDEEP:
      MD5:33E500602D099B859F05ACA348F0E782
      SHA1:1AFEF539276BB42F7566ACA3365C8D054CDB36E0
      SHA-256:30021FDA4E6BB6CFD9B8A0B1DA922B6B7478F6258D620CEC1BDA0163B1ECD089
      SHA-512:35F0C2FB888222A7E4359380E5A57C5AD88C2BFD955A4901C4BA3AB0AF5DC7A554CA17262D5F9A6D04331CB8D3C01E63BEBD41F0F183E70C8BFD8743C8DEE680
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........e..d...d...d.......d.......d...d..Cd..K*...d.......d.......d.......d.......d.......d.......d.......d..Rich.d..........................PE..L...A..M.........."!.....@..........@..............x......................................@.........................t.......................................<.......................................,...H...........................................UPX0....................................UPX1.....@.......:..................@....rsrc................>..............@......................................................................................................................................................................................................................................................................................................................................................................3.95.UPX!....
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
      Category:dropped
      Size (bytes):399184
      Entropy (8bit):7.8544247742387805
      Encrypted:false
      SSDEEP:
      MD5:0AC53BD7A0B6E35FEACEB8DAA4866957
      SHA1:61378D5B8DA6A4ABB3FFFDCBCACB84686E9194DC
      SHA-256:6A6276649795A6A4F8A849FF57A52F0A756B5270C06141E21BFA62EC404F0510
      SHA-512:DA958EA7DF1EF3FCBB13B74782D0568D664C5EAC7C5D9E07A8335FB67C58FB1D7730EB0FFA8DBCB916AC9B0AFEFA33A15D0206591979BAE087090D1F4D73E22F
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 2%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:.y.~...~...~...w...}...~.......eD.....eD..+...eD..J...eD......eD......eD......eD......Rich~...................PE..L......M.........."!.....P...........7.......@.....x......................................@.........................hD.......C..x....@...............................................................9..H...........................................UPX0....................................UPX1.....P.......L..................@....rsrc........@.......P..............@..............................................................................................................................................................................................................................................................................................................................................................................................3.95.UPX!....
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):695808
      Entropy (8bit):5.696634986442527
      Encrypted:false
      SSDEEP:
      MD5:8FEE317E438434DFD4A87735B7A073FF
      SHA1:D7FD2F8E89F8423C607E8CB9A6BE879045080A61
      SHA-256:1B437DA885D57DE067F66A9B6601C9337C78FDE11C37F78A33884CC2764840AA
      SHA-512:84C70831DD6E59F0F36B859C95C495C4E7B11BBFBE370B2C60CC482D1CF984372E22A71F309DA1E7327DA89CB3E23D6F82E04980B3DBA583CC499EB5884F92BE
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........V...8...8...8......8...9...8......8...=...8...<...8...;...8..9...8.j.9...8...9...8.j.=...8.j.<...8.j.8...8.j....8.j.:...8.Rich..8.................PE..d....{Fd.........." ......................................................................`.........................................0........................`...2.................. s..T....................u..(....s..8............................................text............................... ..`.rdata..............................@..@.data....o.......\..................@....pdata...2...`...4...8..............@..@.rsrc................l..............@..@.reloc...........0...n..............@..B........................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):2569728
      Entropy (8bit):5.860650151364542
      Encrypted:false
      SSDEEP:
      MD5:5D71C12B94D0E6F77BAC93BF15CF0FEB
      SHA1:E1CA856A0E482CC1D7B2A7AF219224998EFC76A7
      SHA-256:794B281AF8999E690EF065492CE1FCAB0FE3CC2F797C36E6072F0279D18857FC
      SHA-512:9627EA57BB69601DCFBBF7633E97A7E3EB99F743FA07D3CA7185BC3278B0670792B1A0CDCE02587CCF227ED6A1C5201B8ABD95A94BBA6CBE8306C1A332C27832
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......-_6.i>X.i>X.i>X.`F..{>X.;KY.k>X.;K].b>X.;K\.a>X.;K[.m>X.}UY.b>X.i>Y..>X..K[.h>X..K\.*<X..KX.h>X..K..h>X..KZ.h>X.Richi>X.................PE..d...,xFd.........." ................r.........................................'...........`.........................................P."..Q..`*'.@....`'.|.....%..p...........p'.LK...a .8...........................`a .8............ '.`............................text...D........................... ..`.rdata....... ......................@..@.data....~....%..(....$.............@....pdata........%.......%.............@..@.idata..<!... '.."....&.............@..@.00cfg..Q....P'.......&.............@..@.rsrc...|....`'.......&.............@..@.reloc..Vk...p'..l....&.............@..B........................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):37888
      Entropy (8bit):5.7431740697295375
      Encrypted:false
      SSDEEP:
      MD5:6DCD5E0805DF2E61ED5286BF9C3B91EC
      SHA1:BEF2DEA1FAABB424483CB2A0F2304CFFE50F0635
      SHA-256:5BEAB446F9AE4B598C0655D3A6B7B63016003C08D4117DD35598FA65BFB72FB6
      SHA-512:8E58C60FBAF8D4828DECF6DD5AD63C2F7AC2799E52BC9F1640F3045DC61A113D751AD35BB7F26439F2F7FF08AEDF547ECFA28F79579D7A1ED04F7EC1F8ECA513
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......V..1..b..b..b...b..b@..c..bt.ab..b@..c..b@..c..b@..c..b...c..b..bg.b...c..b...c..b...c..b..cb..b...c..bRich..b........PE..d....zFd.........." .....B...T.......C....................................................`..........................................y..............................................g..T............................g..8............`...............................text...kA.......B.................. ..`.rdata...>...`...@...F..............@..@.data...h...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):2633
      Entropy (8bit):5.111096379547324
      Encrypted:false
      SSDEEP:
      MD5:02BE433BD7A11662698DCB7E16650598
      SHA1:E5D5830CD42717B7E9A5C7D6DC9F670898B38B29
      SHA-256:A868426890DF945EC7CAB082FFF9BF164D63EB1D77885A1A5C6AF6246581A0C9
      SHA-512:EE9D3F6654E954F337102F65BC2F4595780DBEF2D1BE304B9EEC094D1DB1C5B921ABFA8F121F911AE1A578C749701F2AC20CCF5C440C3E46897586723086E5FC
      Malicious:false
      Reputation:unknown
      Preview:# This script can be used to generate a ca-cert.crt file that can be used by..# Unix-based utilities like curl, git, .....#..# It allows you to synchronize the root certificates (CA) based on the..# certificates installed in your Windows certification stores. You can also..# get a list from Mozilla, but I think it's convenient to have the same CA..# certificates in all tools...#..# Some examples on how to use this script:..#..# CreateCaCert.ps1 -StoreLocation CurrentUser..# CreateCaCert.ps1 -StoreLocation LocalMachine | Out-File -Encoding utf8 ca-cert.crt..#..# Written by Ramon de Klein <mail@ramondeklein.nl>..#..# Got source script from https://gist.github.com/ramondeklein/ebf0764fd9341c0850f308f86e31adcc..#..# Modified by Audio Codes:..# 1.Change System.Security.Cryptography.X509Certificates.StoreName from "AuthRoot" to "Root" to export all certs from "Trusted Root Certificate Authorities"...# Detail about StoreName - https://docs.microsoft.com/en-us/dotnet/api/system.security.cr
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):90624
      Entropy (8bit):5.547708062020467
      Encrypted:false
      SSDEEP:
      MD5:3451372A5D1A8413432A87BEEB289C5A
      SHA1:793ED47070B427A37807EDE3D27CCBC3021BF1DA
      SHA-256:A7260995670CEE22645D28B84520740431667683FC7FC639215488BB4D59E048
      SHA-512:B8E1489E03341E84B807791E7D8B8831384C1ACC699DDC9A43D2BB9125108E821FFB54BD72D7EAC9FEBDBABA52BBF1854935864BC76C0EC82D4A4543D8AD9314
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........e[(..5{..5{..5{.|.{..5{.q1z..5{.q6z..5{.q0z..5{.q4z..5{.o4z..5{.q4z..5{..4{..5{.q0z..5{.q.{..5{.q7z..5{Rich..5{........................PE..d...!|Fd.........."............................@..........................................`.................................................d,..@...............................0.......T...........................0...8............................................text..._........................... ..`.rdata..0z.......|..................@..@.data....$...P.......2..............@....pdata...............P..............@..@.rsrc................Z..............@..@.reloc..0............\..............@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):13312
      Entropy (8bit):4.877721927738491
      Encrypted:false
      SSDEEP:
      MD5:595831C97F4083A02534E1C1B6104363
      SHA1:D6DE7E77A7709F275C6B9678F402AD9B750EC7EE
      SHA-256:264CBE11FF2AFA5B36430DC27D670519954E7E6294EAE872448514E37D0BE4FF
      SHA-512:56DB4CBB056BED82685200EC885157160ABF7554B72DA50F7A36DA62A772093564BEB356B856448F36A3BB110432E3DD281F1541B79A4875AC36C312A24956EA
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........%..D..D..D..<C..D..1..D..+-..D..1..D..1..D..1..D../..D..1..D..D..D..1..D..1/..D..1..D.Rich.D.................PE..d....{Fd.........."..........".................@..........................................`..................................................9.......p.......`..................,....3..T............................4..8............0..@............................text...L........................... ..`.rdata.......0......................@..@.data........P.......,..............@....pdata.......`......................@..@.rsrc........p.......0..............@..@.reloc..,............2..............@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):16384
      Entropy (8bit):4.979823981264845
      Encrypted:false
      SSDEEP:
      MD5:FC375AF63A466A3791578AA5776F1B23
      SHA1:632D457AF98EA19C04DBC72BF2F8E88D0D4F7160
      SHA-256:DFF493E1ED35329DD9EC73F4335FBAF4C73BD5B5236C60E106259A7D26ED6624
      SHA-512:4873CFCD9F35EAD04351083725505FA548215984E0D4968C340159DDA0A18786AFEB517EBC9474DE431434B1EA83D225D6981CFDF0A312959A645EBB29087B74
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................".....................................D............D......D.N....D......Rich...................PE..d....{Fd.........."..........*.................@..........................................`..................................................>.......p.......`..X...............T...p4..T............................4..8............0..8............................text............................... ..`.rdata..6....0......................@..@.data........P.......6..............@....pdata..X....`.......8..............@..@.rsrc........p.......<..............@..@.reloc..T............>..............@..B................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):134144
      Entropy (8bit):6.034005823272754
      Encrypted:false
      SSDEEP:
      MD5:126FD7CE37919FD5E57BAB7C37155535
      SHA1:EA4D5472610C1A537C1B88AB9B30C3E1B5826EAF
      SHA-256:67AE87A9E5D4CA3CDDE53EF153C1D50E88E72CA85DC5B92697D1B336C1658B6A
      SHA-512:9E74DE3B2911984156A2DCE79741EA80D94CD772DBEC7A1032A683443209AD4F6CA9F56552C691D0BFA34D9A20D406A1B6EEDFF3386716A3F0EC89F697E92131
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........3wV.R...R...R...*...R...=...R...'...R...'...R...'...R...'...R...9...R...'...R...R...R...'...R...'...R...'...R...'...R..Rich.R..................PE..d....{Fd.........." .........<......`........................................`............`..........................................^..8............@....... ..l............P..0.......T.......................(...P...8............................................text............................... ..`.rdata..N...........................@..@.data...(...........................@....pdata..l.... ......................@..@.rsrc........@......................@..@.reloc..0....P......................@..B................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Perl script text executable
      Category:dropped
      Size (bytes):6512
      Entropy (8bit):5.181482222762947
      Encrypted:false
      SSDEEP:
      MD5:B24F16E362C0FAC91E9B1FF82BAB101B
      SHA1:574D643A6D2D1FFBEBDEBDEFF09FF4B5E767D17C
      SHA-256:DC3CF2D9EA0C1B01FA61EA09D6783095F4723B42DC1D1A43A8CDB212F3491078
      SHA-512:D86E42DD2FD1428A3CF2994EC39D7332EFC5B8AE6A97C2E4CD687518BC4EB5614746DBD12D2BB294BD82F2E44A4F0D956EBCD3E627D717CFB48793ED11B44E7A
      Malicious:false
      Reputation:unknown
      Preview:#!/usr/bin/env perl....# WARNING: do not edit!..# Generated by makefile from tools\c_rehash.in..# Copyright 1999-2021 The OpenSSL Project Authors. All Rights Reserved...#..# Licensed under the OpenSSL license (the "License"). You may not use..# this file except in compliance with the License. You can obtain a copy..# in the file LICENSE in the source distribution or at..# https://www.openssl.org/source/license.html....# Perl c_rehash script, scan all files in a directory..# and add symbolic links to their hash values.....my $dir = "C:/jenkins/workspace/ipp-dwc/DWC/.prebuild/openssl/ssl";..my $prefix = "C:/jenkins/workspace/ipp-dwc/DWC/.prebuild/openssl";....my $errorcount = 0;..my $openssl = $ENV{OPENSSL} || "openssl";..my $pwd;..my $x509hash = "-subject_hash";..my $crlhash = "-hash";..my $verbose = 0;..my $symlink_exists=eval {symlink("",""); 1};..my $removelinks = 1;....## Parse flags...while ( $ARGV[0] =~ /^-/ ) {.. my $flag = shift @ARGV;.. last if ( $flag eq '--');.. i
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):88064
      Entropy (8bit):6.16795402274318
      Encrypted:false
      SSDEEP:
      MD5:1807808290068D689EF4CCF50C4DD852
      SHA1:82B566CDD38F01B438B32909171D73F882D41369
      SHA-256:21077645B5112B7A5D2B0A2FB31F024FF30BC1D56661F831CF6974DB1EA08212
      SHA-512:4A948F9341AEC5AAA47C36B450180D808B1A41AAF297BADDBB160FDE3704381DC25DBC05F94DA0870F159CF870FC730BD0A11EA3CA66B3D0933C3855C77FED1A
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........;...U.U.U....U...T.U....U...P.U...Q.U...V.U..T.U.T...U...Q.U...U.U.....U...W.U.Rich..U.................PE..d....vFd.........." .........\......|................................................@....`..........................................7.......>...............`..X...............8...0...............................P...8............................................text............................... ..`.rdata...8.......:..................@..@.data........P.......<..............@....pdata..X....`.......>..............@..@.rsrc................P..............@..@.reloc..8............V..............@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):167424
      Entropy (8bit):6.07000963132479
      Encrypted:false
      SSDEEP:
      MD5:BAFCAF1BB87F46FE3E2DABDD62F46814
      SHA1:B36C2543DDD406B92809D837AE6BD60DF0306BFA
      SHA-256:C1A01BD0AFDF8CE401834148AEC4AE0AF617FD897DB6C9F094CD7E9B9FABD70F
      SHA-512:E6507010DB30F039F492FDACB11EFEB34CB328CF63F4EC370D7132E659FA4C868E32F9B0BAD142DCBF3C2DAA3A77A58C6B817D8EA1978F66B36D5D51B61ECF49
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........q...............h!......e........O......e.......e.......e.......{.......e...............e.......eM......e......Rich............PE..d....{Fd.........."......X...:......``.........@..........................................`..................................................g..T.......P.......L....................P...............................Q..8............p...............................text....W.......X.................. ..`.rdata..6....p.......\..............@..@.data...8............h..............@....pdata..L............j..............@..@.rsrc...P............z..............@..@.reloc..............................@..B................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1034752
      Entropy (8bit):6.343030128697968
      Encrypted:false
      SSDEEP:
      MD5:21A984BC0631FC7D70C6C606495E9C3D
      SHA1:3D4730B61309416CC0812428921CDC0154BCF421
      SHA-256:C366BA181AACD67E27E7659CACAF04ECA7F71BC28F5D329F03C03249283B2442
      SHA-512:060E0F827DFC58975BE1EA8D465B071DC5D31F0725A2BE9BDD635AA66182510C634E2787822460206EF7F0427D995F6A62CAA131DB3EEDCAC5D80A98D30DA428
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......Z.....|...|...|.L.x...|.L.....|.L.y.7.|.L.}...|.x.....|......|...z...|...x...|...}...|...}...|...}.`.|...y.+.|...|...|.....|...~...|.Rich..|.................PE..d...!|Fd.........."......h.....................@.............................0............`.............................................L...<...\............p...u..............,"...&..T....................(..(....&..8............................................text....f.......h.................. ..`.rdata..R%.......&...l..............@..@.data...@...........................@....pdata...u...p...v..................@..@.rsrc...............................@..@.reloc..,".......$..................@..B................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):981504
      Entropy (8bit):6.323119374651462
      Encrypted:false
      SSDEEP:
      MD5:C1F241031DAF55E3CB2D54221C6D5A54
      SHA1:28272E9F30C1980A898156FB5164581C190165B1
      SHA-256:EEC5EFF9885C63DE13D4758B44338B746B76AD3F13030B68EB46551A6456DA2D
      SHA-512:0750900264A51C067E0BBAE7D8EDFA4E9FCDA64AAABF365D70D934B91131AD5609B37FB4A7A100A16C7C9208369C6BA557FA8CC519E1DB822074EA28E843D72A
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........VL...L...L.......F.......H.......e.......J...*...D...E.m.R...X...N......J...X...Z......W...L..........s......M......M......M...RichL...........PE..d...Z|Fd.........."..........`.......^.........@.............................`............`.........................................p=..T....=..4.... ..........8g...........0..."..Xt..T....................v..(....t..8............................................text.............................. ..`.rdata..............................@..@.data...............................@....pdata..8g.......h...l..............@..@.rsrc........ ......................@..@.reloc..."...0...$..................@..B........................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):472064
      Entropy (8bit):6.431849452082854
      Encrypted:false
      SSDEEP:
      MD5:53E879A12ACB11EB7703CC3A0BD42A6B
      SHA1:3984E2D3AAC25EFD846CA2F7B82AB361DF82FB0A
      SHA-256:F805B22C38EC35736E7D5B1B09D8C19A0B02D23DF722BAC2959BF7684456CF1E
      SHA-512:19C17A92023860D8F2F4D1EF2BC98B62CF823B9AC0475FDF6BADCEEAB5CF05A98F0767FBD362F15E2E54428A5DFC21203295FAE23AEA86DC2E69DEA77DC4D386
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........n....{...{...{..w...{..`....{..z....{..zx...{..z~...{..zz...{..dz...{...z...{.}z~...{.}z{...{.}z....{.}zy...{.Rich..{.........................PE..d....|Fd.........." ................|.....................................................`.............................................\...L...@....`....... ...8...........p.......$.......................%..(...0$..8............................................text............................... ..`.rdata.., ......."..................@..@.data...P#..........................@....pdata...8... ...:..................@..@.rsrc........`.......,..............@..@.reloc.......p......................@..B................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):472064
      Entropy (8bit):6.431543921866444
      Encrypted:false
      SSDEEP:
      MD5:C0624E2EC256D2AF6CAB7ECC106816B7
      SHA1:C7D8AA92AC844D25658405BF6E0C168566E88454
      SHA-256:CB4E76585A98380A506F7D83FFEF27D75446A170A64A973A3EDB105EE883F3BB
      SHA-512:F6EF8ABC74D20ECE39E3CC6493AD64BD7C6DCDF9CB42443B891DCC7AD26F5A326A8F8498C27F03CCFA13D40F82A9AFF5BF73F0A99497AC50B1586C40AD06B839
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$......................m...................................r...............o.........Rich..................PE..d..."|Fd.........." ......................................................................`.........................................p...p......@....`....... ...8...........p......0$.......................&..(...P$..8............................................text...C........................... ..`.rdata... ......."..................@..@.data...P#..........................@....pdata...8... ...:..................@..@.rsrc........`.......,..............@..@.reloc.......p......................@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):402944
      Entropy (8bit):6.423603583155346
      Encrypted:false
      SSDEEP:
      MD5:0A8C56D3DBEAA7308CFD535AB27C0009
      SHA1:E6DC03747D6065E5F6786C352128802C68911DEB
      SHA-256:9A450ED4D0F7BA7FD31385C4918603867D5410E4668411B4C0AFB3DEA55E9C6A
      SHA-512:8B41BB23EAF78DE43F6E567893871A9ECBBAB0CC4164D1F97171A66C472A5C8B19A6ADC00AE37A5DF047C4A4F931D52487CA62540AFFB6385CC97E0604098EF3
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......ki.g/..4/..4/..4&pS4;..4Ig=4(..4}}.5'..4}}.5+..4}}.55..4}}.5)..4;c.5,..4/..4...4.}.5...4.}.5...4.}?4...4.}.5...4Rich/..4................PE..d....{Fd.........." ........."......L........................................`............`.........................................0...t.......,....@.......................P.......s.......................u..(....s..8............ ...............................text............................... ..`.rdata....... ......................@..@.data...............................@....pdata...........0..................@..@.rsrc........@....... ..............@..@.reloc.......P......."..............@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):61952
      Entropy (8bit):5.851644321610057
      Encrypted:false
      SSDEEP:
      MD5:8574C5716A45351E1F3E88D2C95D820E
      SHA1:3E7FD93C9B0E39D78349E037507F8759CC2A32B1
      SHA-256:8E06B0E2BDC7AFE956265F9314025EE83DA4D0548B62B6548FA9CD1605F36440
      SHA-512:12D9A439CE68925CFAF3F59E0D2142FED45C074429FF45D0769B92BBEB98E5F0729EDA8128C6F4B5E63BCA931F25E2D59916FE0F0DA90EBC4EFE198B514AB3ED
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........xd...7...7...7..7...7...6...7...6...7...6...7...6...7...6...7...6...7...7..7...6...7...6...7...7...7...6...7Rich...7................PE..d...)|Fd.........." .....Z...........Z.......................................0............`..............................................A................................... ......Py..............................py..8............p..P............................text....X.......Z.................. ..`.rdata.."}...p...~...^..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc....... ......................@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):290816
      Entropy (8bit):6.389710523640788
      Encrypted:false
      SSDEEP:
      MD5:64DF8F37234D426588FE565E15202C32
      SHA1:1C6CDF344C7B865697B218D585D018779F02AF68
      SHA-256:96D9953DB041B23B01C3DD9D53EB82E33D8A4105193A48F1C4F2ABCBB96F78AE
      SHA-512:DA8269C0E5B3A58B9B5C3E193FB475FA5006B9C3A6BA8D73176C27A24E472710094C87894675E9C8C4600737724103124FB40BDD5C43942BE16DACA396D1ACCB
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........q_.......................................................................................................................Rich....................PE..d...I{Fd.........." .................s....................................................`..........................................e.........h............p..................D...p...T.......................(.......8...............H............................text............................... ..`.rdata.............................@..@.data...(....P.......:..............@....pdata.......p.......N..............@..@.rsrc................h..............@..@.reloc..D............j..............@..B........................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):350208
      Entropy (8bit):6.321943322347708
      Encrypted:false
      SSDEEP:
      MD5:FE7F8896D9895BF3C546E5F7D0DFCE7A
      SHA1:02506E6EF82099194E639C528A218322BE33C172
      SHA-256:25125CA3D5C2F766F4BB817DE5E40E9AB68DB97C09A46E37264FFFB9DEC54C18
      SHA-512:40DC75ACF6F1E9506195B81D830DC6093955EFB24B40B4B7FF7DD15027DD8D4A727D4CFF99CDC21A7A1E40E6EBB70D9C726DC6A4376F987A7A895197C7AD1661
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............r..r..r......r...s..r....r...w...r...v..r...q..r.u.s..r...s..r..s.r.u.v.W.r.u.r..r.u....r.....r.u.p..r.Rich.r.........PE..d....zFd.........." .........z............................................................`.............................................0.......T............P..................X...`...................................8...............h............................text............................... ..`.rdata..P...........................@..@.data....&... ... ..................@....pdata.......P...0..................@..@.rsrc................L..............@..@.reloc..X............R..............@..B................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):143872
      Entropy (8bit):6.237230609732789
      Encrypted:false
      SSDEEP:
      MD5:D20AA18555F94FCCFB1E992B0B8BB4EE
      SHA1:4BBCD8DA6EF626251A2BA1F5E8E09BBDCBF54635
      SHA-256:2F92E5A7E9B7B9B95E761F3B40ABF507A8559F702D74B34CBF1B9E7840186841
      SHA-512:938F01DFDECB5BBF36927BF0A532DD7404DFF045BDB5F6E095FF4F4DEA6EC919FEBB72821542FC09EA87356F901F24EFD825526EEAE5A35FDC383B0F20C6147B
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............~.}.~.}.~.}..|}.~.}...|.~.}...|.~.}...|.~.}...|.~.}...|.~.}.~.}.~.}{..|.~.}{..|.~.}{..}.~.}{..|.~.}Rich.~.}........................PE..d....zFd.........." .........r......p.....................................................`.........................................@"..@....+.......p.......P..................t...................................@...8...............p............................text...(........................... ..`.rdata..pQ.......R..................@..@.data...H....@......................@....pdata.......P......................@..@.rsrc........p......................@..@.reloc..t............0..............@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):650240
      Entropy (8bit):5.484406746574827
      Encrypted:false
      SSDEEP:
      MD5:54A019E656CAF0B36B3E14EC3AFDD1B3
      SHA1:B793E4952D46A73A4F02B2CC9D048806109B6C72
      SHA-256:7EB7F941AE53654571BE1A66C174A0DDC5F67347727742BA6F97FC0E4D267397
      SHA-512:F567A1D56A4CCA0F37ED82A259C85CB8D1C3E0731813B1A1D95320D1A10908EF47430AEB5CD4FC479C3060F582DF655F12EF690C9AC42364640733DA79FC54E2
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......O....m.].m.].m.]..3].m.]Y..\.m.]...\.m.]Y..\.m.]Y..\.m.]Y..\.m.]...\.m.].m.].l.]...\'m.]...\.m.].._].m.]...\.m.]Rich.m.]................PE..d...QxFd.........." ................<........................................P............`.............................................I........... ..s....P...H...........0......d4..8............................4..8............................................text...t........................... ..`.rdata..z...........................@..@.data...q?.......6..................@....pdata...P...P...R..."..............@..@.idata..{Q.......R...t..............@..@.00cfg..Q...........................@..@.rsrc...s.... ......................@..@.reloc..H....0......................@..B........................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):50176
      Entropy (8bit):5.696117107727629
      Encrypted:false
      SSDEEP:
      MD5:DE49EE03487D3374D13852DEF83B972F
      SHA1:B904AA8E5626E3E94986966E17B88A183B914202
      SHA-256:80CDAE2F55BFCD9C6E105405FF67657CE4DA2D53D1C168F09B42658ED4A61745
      SHA-512:774CF58934C107A6041A1B6707FDEDEB7C66776A42A248CA013F6F0B4B00CF1FED5299F29B37CA68796FD85B4780CA123A51A1A155E5C7A5049CD113CDA80CF9
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......O1..P...P...P...("..P..Y%...P..Y%...P..Y%...P..Y%...P...;...P..%...P...P..P..%...P..%N..P..%...P..Rich.P..................PE..d...)|Fd.........."......d...b......`d.........@..........................................`.................................................|...,.......................................T...........................P...8............................................text....c.......d.................. ..`.rdata...H.......J...h..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):522752
      Entropy (8bit):6.357367061522949
      Encrypted:false
      SSDEEP:
      MD5:7AA98DD0A988D77B77FBBC60ED400B60
      SHA1:CE47C9DBC0A0850D329077EC9E6BA35E60FBF966
      SHA-256:0D1B727A4790F2ECCE92AA675B81932611B06A5782290C7440FC239CFDF2F8D9
      SHA-512:32234F7C9E81C8E6FBE21EF7D0CE2D04CD427879FC2D9AA813D80D2A9730A6046E6BAD0A3020F57EB9BC3E05B4B2239FFFC7F92A4B27FBD3EBB4D1639B11F440
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........^..C?..C?..C?..JGo.U?...J..A?...J..I?...J..G?..WT..G?...J..F?..C?...:...J..u?...J..P?...J..B?...J..B?...J..B?..RichC?..........................PE..d...{xFd.........."......P..........<U.........@.............................@............`.............................................P...P...T...............D............ ..h.......T........................... ...8............`...*...........................text...,N.......P.................. ..`.rdata.......`.......T..............@..@.data........`...p...J..............@....pdata..D...........................@..@.rsrc...............................@..@.reloc..h.... ......................@..B................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):16896
      Entropy (8bit):5.2173505020285615
      Encrypted:false
      SSDEEP:
      MD5:0287BF3410B0C5B02A682E983951ED15
      SHA1:948C74C819A9478E5BDA493495C74DAAB2E6054E
      SHA-256:CA4240E9920D099E39E90894131326BEB7848DF04D970901E52CC76BBDBCC159
      SHA-512:D2A28B7582554A9B0E088F93D27D25A8F99C03F8748FBC19429C2A9F610EDEB6F1E4E6530F8F782FB3D72904F478815CC6A85D0363EC4EC26BA93CF7BF3CB722
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........;e..;e..;e..2...7e..i...9e..i...)e..i...1e..i...?e../...?e.....>e..;e..~e.....:e...c.:e.....:e..Rich;e..................PE..d....|Fd.........."..........*.................@..........................................`..................................................@.......p.......`..................L...0:..T............................:..8............0..X............................text............................... ..`.rdata.......0......................@..@.data........P.......8..............@....pdata.......`.......:..............@..@.rsrc........p.......>..............@..@.reloc..L............@..............@..B................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):70656
      Entropy (8bit):5.871157245535179
      Encrypted:false
      SSDEEP:
      MD5:DFD45960F2531C79979D80CEE91D7887
      SHA1:CC30D71ACF8276F37BE3C2635F8A505667E62981
      SHA-256:2185B3F9821BCA848BC5441880BD5641D52C5BB3A7078A190F349237F76EA49C
      SHA-512:1C6B649424E87781A53E74197C0A3E6E3A2A79D818B64B2C9FA8EC70B35BAE0ADE4FA78254523AA8B5E5C967E4CEEE0A0311E05C85385CD644C1FE2D3217E458
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.........8..rV..rV..rV......rV..W..rV.....rV..S..rV..R..rV..U..rV...W..rV.p.S..rV.p.W..rV..rW.-rV.p.R..rV.p.V..rV.p....rV.p.T..rV.Rich.rV.........................PE..d....{Fd.........." ................`g.......................................P............`.........................................0...P............0....... ...............@..................................(.......8............................................text............................... ..`.rdata..<m.......n..................@..@.data...............................@....pdata....... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1536
      Entropy (8bit):1.9051535919491287
      Encrypted:false
      SSDEEP:
      MD5:A55AF1DAF8E7DEF69421DD9C7CB68FAE
      SHA1:B94542F248931BB48E2B5ABE3038F6250952CF91
      SHA-256:9B5D62DD642CAC4C1AF9DDD4DF93BBCAF5EA6592E46CCC8CE04B0D00300BBE8C
      SHA-512:B7B19DDB154D08E623150EFB7A82E1BF726E056E48A9B39A57C643C16EE42F545778271FAE3064501B7B2824962BE27A1A8A707EEFEB31ADA0A6108DB3B9669F
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......Ej=...S...S...S..~....S..~Q...S.Rich..S.PE..d....zFd.........." .........................................................0............`.......................................................... ...............................................................................................................rdata..............................@..@.rsrc........ ......................@..@.....zFd........l...4...4........................................rdata...........rdata$voltmd...4...l....rdata$zzzdbg.... ..`....rsrc$01....` .......rsrc$02............................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):92160
      Entropy (8bit):5.714171118418633
      Encrypted:false
      SSDEEP:
      MD5:F8BEA85FE40413FE0E57F11551CBFA4D
      SHA1:DCC923B94ED326DE065B982178D59E9560CECEE3
      SHA-256:FE8D8372E70C5A109A36E2BDA72731236FAC630146E8E009FC9C7668F7574450
      SHA-512:6F8C8889AA55A513ABC1FBE95B4DA9A55CCD58DC9B66EA1C5D7E9D41C10093E709B6923A3214997513A027D73CC8BECE3070A2A228F99FF0440CEA8351BC8957
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......r--.6LC.6LC.6LC.d9G.<LC.d9@.5LC.d9F..LC.d9B.0LC..9B.:LC.?4."LC."'B.=LC.6LB..LC..9F.2LC..9..7LC..9A.7LC.Rich6LC.........PE..d...+|Fd.........."............................@..........................................`.................................................T,...............p.. ...................x...T.......................(.......8............................................text.............................. ..`.rdata..Fw.......x..................@..@.data........P.......<..............@....pdata.. ....p.......T..............@..@.rsrc................b..............@..@.reloc...............d..............@..B........................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):20992
      Entropy (8bit):5.127020324431615
      Encrypted:false
      SSDEEP:
      MD5:9D57D995C84505E36F131FC4D45FA865
      SHA1:BEFECB82702D80F4AD8F63B46095EA673EEB171B
      SHA-256:5224F29FFEC91F02F32D172B19377F2158C939898FBD18F875C39D3FEB3BAECA
      SHA-512:589D50C51A5CB2D97EE627E569A8D85BAE3FA329D26E476AEB261F5F7B548C9F2DAFB11F04717FC1A807FCCE65E835DD3A5EC5E6617D3101B072874FF28CE7A6
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........h....................................................V.............V......V......V......Rich...................PE..d..."|Fd.........."..........8......l..........@..........................................`..................................................G..,............p......................p6..T............................6..8............0...............................text............................... ..`.rdata..&%...0...&... ..............@..@.data........`.......F..............@....pdata.......p.......J..............@..@.rsrc................N..............@..@.reloc...............P..............@..B................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):103424
      Entropy (8bit):6.152275726289569
      Encrypted:false
      SSDEEP:
      MD5:2ED02752EE74403C46C3309EAAC31A23
      SHA1:386513CE78EB9A1949509F7A5CFF3921649F9C68
      SHA-256:85C5EC0A01556C0EE63094FBFE56C55D13A349EC43FBA2640911656B60E0BFCB
      SHA-512:060D38C7C54DD1E0275D9E8D7526B6A526E4D0F22A5BFA9FF2372B7BE2D9AFFD8833A559AE4261C914F7C135A97BF47CCF9430092157E9EAD9B63DE542975BD5
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......,.#Nh.M.h.M.h.M.a...d.M.:.H.p.M.:.I.`.M.:.N.l.M.:.L.n.M.|.L.j.M..L.o.M.h.L...M..H.c.M..M.i.M....i.M..O.i.M.Richh.M.................PE..d....{Fd.........." .....................................................................`..........................................*..,J...u..................................P.......T.......................(.......8...............8............................text............................... ..`.rdata..N...........................@..@.data................t..............@....pdata...............~..............@..@.rsrc...............................@..@.reloc..P...........................@..B........................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):61440
      Entropy (8bit):6.065759571883634
      Encrypted:false
      SSDEEP:
      MD5:B6E735540752CD648D5DE7BFC78051E5
      SHA1:4FE5832A5891F1A76FCF251E1B21BF0BF56CF564
      SHA-256:D89F8CB25645311D1C9458DA28ECAD903B2219D2702AAA8186ACAC8066FFB794
      SHA-512:44546528FB9F55A8C693A1EEE1021990D7E569A6B373ECE03E618E17B2B545178807FE8F70AE8B5E751CD6EC818F4A68C9FC46560FD369532EFC8EEEC6037598
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........4g..Z4..Z4..Z4...4..Z4..[5..Z4.._5..Z4..^5..Z4..Y5..Z4..[5..Z4..[4..Z4..^5..Z4..Z5..Z4...4..Z4..X5..Z4Rich..Z4........PE..d....zFd.........." .........6......p........................................0............`......................................... .......$...x...............8............ ..@... ...............................@...8...............0............................text............................... ..`.rdata..............................@..@.data...x...........................@....pdata..8...........................@..@.rsrc...............................@..@.reloc..@.... ......................@..B........................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):74752
      Entropy (8bit):5.883149851401643
      Encrypted:false
      SSDEEP:
      MD5:1F78D4FAF3F20319DD68345381489B47
      SHA1:490445E11E222554DEAE6AC687C3B1E84263FC06
      SHA-256:747B2B72AA96EC0B33532D08ADD7780CB185A261BA5260B89180E0C4993F5FCB
      SHA-512:B17543873D3F3DAC6BB14628FCE65A4AD407A82A9AB10ED6614E73677CA4D5708CD700FDA0EB9703090AF8E07CC9BFE2B8ECBA5650A39932794BF6C4B1541B3D
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9yh.}...}...}...t`..u.../m..j.../m..u.../m..~.../m..{...is..y....m..z...}........m..u....m..|....m..|....m..|...Rich}...........PE..d.../{Fd.........." ................._.......................................`............`.............................................<)...........@.......0...............P..4...T...T.......................(.......8...............h............................text............................... ..`.rdata...{.......|..................@..@.data........ ......................@....pdata.......0......................@..@.rsrc........@......................@..@.reloc..4....P....... ..............@..B................................................................................................................................................................................................................................................
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):78
      Entropy (8bit):4.688998297131205
      Encrypted:false
      SSDEEP:
      MD5:795F361400820BAB07EFC36BF1F7A53C
      SHA1:CA0526FFC11E1A10DCDCAB6A47D18E9931AAB9C1
      SHA-256:DCE153A50E73A11B7EA8ED6034AC306106FB1A65175F02FD4983142BD7C14DA6
      SHA-512:187752B46EEE9FFF26A7685E238A28201AD8492925C309C88A3E6875BE6E322D805FEFD5365948D7F777FE890364B5F665A6C1FA5E4FC63746BE74C774F8FCF3
      Malicious:false
      Reputation:unknown
      Preview:;sw_version=1.2.0.10..;version_id=1..system/cfg/version_id=1..;checksum=5137..
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):47020
      Entropy (8bit):4.750832672745247
      Encrypted:false
      SSDEEP:
      MD5:D35D2EEE91E84078D486F39CEDEB02D7
      SHA1:AEA607903C1EC1B258496813D52B233FBEB5E029
      SHA-256:BEB5E6EBFD0C1F4CD05B1CD5B8C12892E8AB36BE7A7CADE6C9404C7F9B36725F
      SHA-512:50F7FC13FF24096DE9FEF94F1AEFD9696BD6FC47F077E6BBEDFCA55CD560B3D8CB5F51CD73AA7DEC1558F58D2505659BD800C585A760B53357974237E2A11F6F
      Malicious:false
      Reputation:unknown
      Preview:bundle/device/0/name=..bundle/device/1/name=..bundle/device/2/name=..bundle/device/3/name=..bundle/device/4/name=..bundle/device/5/name=..camera_settings/control_audiocodes_cameras_only=0..camera_settings/property/0/BacklightCompensation=-1..camera_settings/property/0/DS/Device_Id=..camera_settings/property/0/MF/Device_Id=..camera_settings/property/0/brightness=-1..camera_settings/property/0/contrast=-1..camera_settings/property/0/enable=0..camera_settings/property/0/exposure=-1..camera_settings/property/0/flash=-1..camera_settings/property/0/focallength=-1..camera_settings/property/0/gamma=-1..camera_settings/property/0/hue=-1..camera_settings/property/0/iris=-1..camera_settings/property/0/isReset=0..camera_settings/property/0/only_read=0..camera_settings/property/0/pan=-1..camera_settings/property/0/powerlinefrequency=DISABLED..camera_settings/property/0/roll=-1..camera_settings/property/0/saturation=-1..camera_settings/property/0/sharpness=-1..camera_settings/property/0/tilt=-1..cam
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:data
      Category:dropped
      Size (bytes):12
      Entropy (8bit):0.41381685030363374
      Encrypted:false
      SSDEEP:
      MD5:E4A1661C2C886EBB688DEC494532431C
      SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
      SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
      SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
      Malicious:false
      Reputation:unknown
      Preview:............
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:34:53 2025, 0x200001 type
      Category:dropped
      Size (bytes):3846011
      Entropy (8bit):0.8923403051286228
      Encrypted:false
      SSDEEP:
      MD5:F73AA5C5FC07C9F735A1F6287534BD2D
      SHA1:C3D744E6D1BA7F1F8FE2FA552ABAFA729CF5A071
      SHA-256:D50115BCF0042B805F5D990EA5A5031460BF8BA673C65A78F8A21BFEE47F16CF
      SHA-512:02A3576F7E77AF523D6CC3183ED97FD0B1DEF132A37FFB633BE73F10ED5E5C61D8FA4C653EDF1230DB68CA09AF00A8359469B3CBB5022760B24AA1836E6DEDB0
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......-L.g.. .........d...........0"..T...........0I..........<.......8...........T................,..........p...................................................................eJ......./......Lw......................T...........,L.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:34:58 2025, 0x200001 type
      Category:dropped
      Size (bytes):3845380
      Entropy (8bit):0.891249871705803
      Encrypted:false
      SSDEEP:
      MD5:1B312BB5C60F530C714AFF254458D6D7
      SHA1:59C67CDD19F86C87BBD5EEB9D490B614500C1B40
      SHA-256:6B1D8C1A6EE6977B226BD126A025CC3C1144B24DA93B610E6ABFCBD6836259CC
      SHA-512:E4FD8D6EE870C74139E2B72FA60D8C8EBC8D42A3479EEBC8D44426DCF30F777B4AD5FC6EAAA1FB7B678823385C5F05C7752426CE9A698579507C6B71071AF2CB
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......2L.g.. .........4...........0"..$...........A<..........<.......8...........T...............T,..........@...................................................................eJ..............Lw......................T.......P.../L.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:35:01 2025, 0x200001 type
      Category:dropped
      Size (bytes):3839572
      Entropy (8bit):0.893175760103826
      Encrypted:false
      SSDEEP:
      MD5:A49104A87AB249336368D471E81E53FB
      SHA1:68BAB84206EAB0076368D8E68FBEB4DAB5399C64
      SHA-256:ABA02304F7DB60FCB15EDC4563228302957FF1BBB9212BD9A813CE656ACB06B8
      SHA-512:1A6457938506494097B4759765C899CA248B57E304F8E4865F2703DFAD1EF0264BA81AF96260EDC958BFE6FE5BCEF4CBB0FA5545D85CFDC5AFF6F321B3BB1F88
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......5L.g.. .........4...........0"..$...........A<..........<.......8...........T...............T,..........@...................................................................eJ..............Lw......................T...........4L.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:35:05 2025, 0x200001 type
      Category:dropped
      Size (bytes):3846523
      Entropy (8bit):0.8915721698163886
      Encrypted:false
      SSDEEP:
      MD5:CA8F5AC739DD9905EBD2A01D02B68FCA
      SHA1:DAE3FA56C5436EA96C3672C14A9E7072AE821425
      SHA-256:FE2B4A97F83468740F700D7BD196B1422ABBF2E0B01ADF522CF209901685B032
      SHA-512:8739F801E0B53B93CEEA2293B955A71F37A9031CD5CC1296915712F8ABCBBFCBAA228BD872BA1A6A9B8AB2D81A2718453019F6D43411C7EEE140855EFC2A4FC9
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......9L.g.. .........d...........0"..T...........0I..........<.......8...........T................,..........p...................................................................eJ......./......Lw......................T...........7L.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:35:08 2025, 0x200001 type
      Category:dropped
      Size (bytes):3846219
      Entropy (8bit):0.8926916770211043
      Encrypted:false
      SSDEEP:
      MD5:0CC4D72048CEE818E158781662AC7521
      SHA1:C18DC85664F18E58ED4CF6DB427B33137C50B7FD
      SHA-256:32D0FC1C7980B10C605366DC5718137181290501A0E4D9F1DB9E41ECEF25F349
      SHA-512:0165EB3D6263568895BDD9EC9FC0C077CEE169698E8D8A1ED28DFF2585031B393D717688B718026A12591108C013ACBE7FD3F0FE0065719232E90D7B1FFEC0FC
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......<L.g.. .........d...........0"..T...........0I..........<.......8...........T................,..........p...................................................................eJ......./......Lw......................T...........;L.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:35:12 2025, 0x200001 type
      Category:dropped
      Size (bytes):3843947
      Entropy (8bit):0.8920001381431581
      Encrypted:false
      SSDEEP:
      MD5:BDAFF5D626FCDF60E797E9EC058D8C28
      SHA1:B86407B5924D56CD55543278A7C3745D6E9C68D7
      SHA-256:860B7F618FCDBC496FE82BF4D3268ACE4BF3CF33DC36B8CD7B5A67BBECAF3860
      SHA-512:D36935B9E40C52AF644B6261A3BDF3E8BB9DE18FC04F14C8E2AB8A3E65B98C652C63790A13DF812CD6723815AF769AFF3FC8309180C12CD3E59D4CF9BCDFB2AB
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......@L.g.. .........d...........0"..T...........0I..........<.......8...........T................,..........p...................................................................eJ......./......Lw......................T...........>L.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:35:15 2025, 0x200001 type
      Category:dropped
      Size (bytes):3846475
      Entropy (8bit):0.891906205064448
      Encrypted:false
      SSDEEP:
      MD5:FC92B12C6A29CD8994454F286376951F
      SHA1:90FA64B4357EF75C321B6D59503893B8922A55D2
      SHA-256:E78A80654ACEB8937F277657D3531A327EF5BC03C740D9D63C1C9F32344378A4
      SHA-512:77837491C975AFC6B6FF47AB880C3672BCD4F921004E1D0990D4FC7C6B9ADF609587A6EC107FD6916D36A937B6E9304E4FE5F98E9352213D47E78B5342ABB555
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......CL.g.. .........d...........0"..T...........0I..........<.......8...........T................,..........p...................................................................eJ......./......Lw......................T.......@...AL.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Program Files\AudioCodes\DM Client\emsc.exe
      File Type:Mini DuMP crash report, 12 streams, Fri Jan 10 16:35:19 2025, 0x200001 type
      Category:dropped
      Size (bytes):3845083
      Entropy (8bit):0.8929005287425188
      Encrypted:false
      SSDEEP:
      MD5:9190178EBE5015ACD036891A23D0E511
      SHA1:E867F740F29B5597C8C4126CB95DAEE217436CFC
      SHA-256:F9C0F9CCF10CBD55DD43EFF014964DAC70D9C1E90C0CB275660A34F3B19C70A0
      SHA-512:B33705AEDAA54EAC0CA5690EE19717EDC0809973956BA3ACB763AD83C28670EC957E3FC5A16F26E77AD8FA042F1043FC90692629AA15D455DD36D9B6B1A21C2C
      Malicious:false
      Reputation:unknown
      Preview:MDMP..a..... .......GL.g.. .........d...........0"..T...........0I..........<.......8...........T................,..........p...................................................................eJ......./......Lw......................T...........EL.g.............................@..............,...E.a.s.t.e.r.n. .S.t.a.n.d.a.r.d. .T.i.m.e...........................................E.a.s.t.e.r.n. .S.u.m.m.e.r. .T.i.m.e...............................................1.9.0.4.1...1...a.m.d.6.4.f.r.e...v.b._.r.e.l.e.a.s.e...1.9.1.2.0.6.-.1.4.0.6...........................................................................................................................................................................................................................................................................................................................................................................................................................................................d.b.g.c.o.r.e...
      Process:C:\Windows\System32\msiexec.exe
      File Type:JSON data
      Category:dropped
      Size (bytes):7111
      Entropy (8bit):3.819230866420275
      Encrypted:false
      SSDEEP:
      MD5:2632FDC97AA303DEA60F9865270E116D
      SHA1:6B3B0432EAD27A350352B7C26C084788B5AE4E30
      SHA-256:28ADE39B4A8C2BEA6E15FFB963D0035999A381993AB23B08500A158CA3378BBC
      SHA-512:C59C0B98C0F62118E2BB5F1888447F4C7997D2CDD28C92F732A5C1DF2E376206095F1945937344B33390D5850FD20030A64D472D9E315692CF73A875DFF3839A
      Malicious:false
      Reputation:unknown
      Preview:{.. "name": "DefaultperipheralFilters",.. "filters": [.. {.. "in": {.. "name": "RX15",.. "vid": 13360,.. "pid": 4353,.. "type": "",.. "hw_type": "".. },.. "out": {.. "name": "AudioCodes Speaker RX15",.. "vid": -1,.. "pid": -1,.. "type": "",.. "hw_type": "",.. "additional_info": "".. }.. },.. {.. "in": {.. "name": "RX15 Stereo",.. "vid": -1,.. "pid": -1,.. "type": "",.. "hw_type": "".. },.. "out": {.. "name": "AudioCodes Speaker RX15",.. "vid": -1,.. "pid": -1,.. "type": "",.. "hw_type": "",.. "additional_info": "".. }.. },.. {.. "in": {.. "name": "",.. "vid": 4310,.. "pid": 56576,.. "type": "",.. "hw_type": "".. },.. "out": {.. "name": "AudioCodes Speaker RX15",.. "vid": -1,.. "pid": -1,.. "type": "",.
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:25:52 1600, mtime=Sun Dec 31 23:25:52 1600, atime=Sun Dec 31 23:25:52 1600, length=0, window=hide
      Category:dropped
      Size (bytes):2813
      Entropy (8bit):2.84188989768658
      Encrypted:false
      SSDEEP:
      MD5:F1E281678A6240B009504B8E748061FB
      SHA1:68A49D876D5923501ECB34283CB5BD2510039C1E
      SHA-256:E7F29CE05D66CDD27CB15B6C80C9362EC0D2F245FA385167853B07818788A0EC
      SHA-512:B9BAE715E9AE58FD68450E4422373DF1EA91732B34239FE87ACB404A20AB3A95CC4048C52EE36EF84CB773A2F95EB9BBC60BF94419439CBCC8F0975F57C63F7C
      Malicious:false
      Reputation:unknown
      Preview:L..................F.P......................................................3....P.O. .:i.....+00.../C:\...................V.1.....*ZJ...Windows.@......OwH*ZP.....3.......................'.W.i.n.d.o.w.s.....\.1.....*Zs...Installer.D......O.I*Zs.............................t.I.n.s.t.a.l.l.e.r.......1.....*Zs...{DE04E~1..~......*Zs.*Zs.............................t.{.D.E.0.4.E.5.3.C.-.A.E.5.B.-.4.6.3.0.-.A.D.9.5.-.5.C.6.3.C.3.3.3.3.0.2.7.}.......2.....*Zs.!.DEVICE~1.EXE.........*Zs.*Zs.............................r.D.e.v.i.c.e.D.u.o.C.o.n.t.r.o.l.l.e._.6.9.E.5.8.3.7.0.3.C.3.3.4.9.2.1.9.9.6.2.B.3.7.3.5.2.9.6.4.4.4.1...e.x.e.............\.....\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.D.E.0.4.E.5.3.C.-.A.E.5.B.-.4.6.3.0.-.A.D.9.5.-.5.C.6.3.C.3.3.3.3.0.2.7.}.\.D.e.v.i.c.e.D.u.o.C.o.n.t.r.o.l.l.e._.6.9.E.5.8.3.7.0.3.C.3.3.4.9.2.1.9.9.6.2.B.3.7.3.5.2.9.6.4.4.4.1...e.x.e.-.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.A.u.d.i.o.C.o.d.e.s.\.D.e.v.i.c.e. .D.u.o.\
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Archive, ctime=Sat Dec 7 08:10:02 2019, mtime=Fri Jan 10 15:34:56 2025, atime=Sat Dec 7 08:10:02 2019, length=59904, window=hide
      Category:dropped
      Size (bytes):939
      Entropy (8bit):4.670555246866224
      Encrypted:false
      SSDEEP:
      MD5:79872F544D957E0714CFE5BCA246B4BC
      SHA1:75414D3A1B6BDB70B034D23351781BB4E666EC62
      SHA-256:62CD9BE4B2287AD3AB35871F3142420A7654D073474B6035AD32367C4127A88B
      SHA-512:F78D79CFEE710B12F17415AEEBFA17F017C76B0C1B77BA9CF36605B76EBC23B66BA675E11053E3F5A8D02492057808960AD5B4507236912DC36B0CB23017ECAC
      Malicious:false
      Reputation:unknown
      Preview:L..................F.... ...25.......$.}c..25.............................A....P.O. .:i.....+00.../C:\...................V.1.....*ZJ...Windows.@......OwH*ZP.....3.......................'.W.i.n.d.o.w.s.....Z.1.....*ZI...SysWOW64..B......O.I*ZJ.....Y..................... ..S.y.s.W.O.W.6.4.....b.2......OBI .msiexec.exe.H......OBI*ZW...............................m.s.i.e.x.e.c...e.x.e.......N...............-.......M............vz.....C:\Windows\SysWOW64\msiexec.exe..1.....\.....\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.S.y.s.W.O.W.6.4.\.m.s.i.e.x.e.c...e.x.e.)./.x. .{.D.E.0.4.E.5.3.C.-.A.E.5.B.-.4.6.3.0.-.A.D.9.5.-.5.C.6.3.C.3.3.3.3.0.2.7.}.........)................1R..WH.....}'....`.......X.......287400...........hT..CrF.f4... .g:..p..../....%..hT..CrF.f4... .g:..p..../....%.........A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Archive, ctime=Sat Dec 7 08:10:02 2019, mtime=Fri Jan 10 15:34:56 2025, atime=Sat Dec 7 08:10:02 2019, length=59904, window=hide
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:79872F544D957E0714CFE5BCA246B4BC
      SHA1:75414D3A1B6BDB70B034D23351781BB4E666EC62
      SHA-256:62CD9BE4B2287AD3AB35871F3142420A7654D073474B6035AD32367C4127A88B
      SHA-512:F78D79CFEE710B12F17415AEEBFA17F017C76B0C1B77BA9CF36605B76EBC23B66BA675E11053E3F5A8D02492057808960AD5B4507236912DC36B0CB23017ECAC
      Malicious:false
      Reputation:unknown
      Preview:L..................F.... ...25.......$.}c..25.............................A....P.O. .:i.....+00.../C:\...................V.1.....*ZJ...Windows.@......OwH*ZP.....3.......................'.W.i.n.d.o.w.s.....Z.1.....*ZI...SysWOW64..B......O.I*ZJ.....Y..................... ..S.y.s.W.O.W.6.4.....b.2......OBI .msiexec.exe.H......OBI*ZW...............................m.s.i.e.x.e.c...e.x.e.......N...............-.......M............vz.....C:\Windows\SysWOW64\msiexec.exe..1.....\.....\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.S.y.s.W.O.W.6.4.\.m.s.i.e.x.e.c...e.x.e.)./.x. .{.D.E.0.4.E.5.3.C.-.A.E.5.B.-.4.6.3.0.-.A.D.9.5.-.5.C.6.3.C.3.3.3.3.0.2.7.}.........)................1R..WH.....}'....`.......X.......287400...........hT..CrF.f4... .g:..p..../....%..hT..CrF.f4... .g:..p..../....%.........A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
      Process:C:\Windows\System32\msiexec.exe
      File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Archive, ctime=Sat Dec 7 08:10:02 2019, mtime=Fri Jan 10 15:34:56 2025, atime=Sat Dec 7 08:10:02 2019, length=59904, window=hide
      Category:dropped
      Size (bytes):984
      Entropy (8bit):4.705667322100935
      Encrypted:false
      SSDEEP:
      MD5:2D3CF693B82E3C5A75BBADB4E02F3305
      SHA1:0EBE1A719A5FB8812CC3800E02E811895879D8D9
      SHA-256:6F941E0BFF3A7CB22E99EC20D3A1EF71B1E0C3F072A11F21EA55DAF9EA954D2F
      SHA-512:C882177B3002D83FD0FC5069A5392D19E119D5DC325CF9DCB6C21E1355BCF68A4611A341E599706594898ECFC2B79349224E638A1494E7709FCCDCC4AF932C98
      Malicious:false
      Reputation:unknown
      Preview:L..................F.... ...25.......$.}c..25.............................A....P.O. .:i.....+00.../C:\...................V.1.....*ZJ...Windows.@......OwH*ZP.....3.......................'.W.i.n.d.o.w.s.....Z.1.....*ZI...SysWOW64..B......O.I*ZJ.....Y..................... ..S.y.s.W.O.W.6.4.....b.2......OBI .msiexec.exe.H......OBI*ZW...............................m.s.i.e.x.e.c...e.x.e.......N...............-.......M............vz.....C:\Windows\SysWOW64\msiexec.exe..1.....\.....\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.S.y.s.W.O.W.6.4.\.m.s.i.e.x.e.c...e.x.e.)./.x. .{.D.E.0.4.E.5.3.C.-.A.E.5.B.-.4.6.3.0.-.A.D.9.5.-.5.C.6.3.C.3.3.3.3.0.2.7.}.........)................1R..WH.....}'....`.......X.......287400...........hT..CrF.f4... .g:..p..../....%..hT..CrF.f4... .g:..p..../....%.........-...1SPSU(L.y.9K....-........................A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
      Process:C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Installs Ems Client, Author: AudioCodes, Keywords: Installer, Comments: AudioCodes Company, Template: x64;1033, Revision Number: {4A16C067-3D3A-48E9-90AF-DF5E841F98BF}, Create Time/Date: Mon Apr 24 13:59:14 2023, Last Saved Time/Date: Mon Apr 24 13:59:14 2023, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:270EB2BF2FDDE99770F8DFCEBB44A13C
      SHA1:E78305B70172F45E6C5499E8B65E1C02BF8B7A35
      SHA-256:29926801543291EE5A16170D10E6BE5E77B720B0308AE0C8F9DB030DE55F68BA
      SHA-512:4AE6B0206734A422F59E669A890CF7AE6B04B7895FEAAD73AE02F307A89270DF50B72A882C98C7CA72D57E34014C299096002E02226BA87E9EBF9ACEA52DB1A2
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: AudioCodes Device Duo, Author: AudioCodes, Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2013 - Professional Edition 20, Last Saved Time/Date: Sun Oct 24 15:10:40 2021, Create Time/Date: Sun Oct 24 15:10:40 2021, Last Printed: Sun Oct 24 15:10:40 2021, Revision Number: {C27498F1-9FD0-4B76-AFE4-6BE0742869B1}, Code page: 1252, Template: Intel;1033
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:306DBE2F4BC72884D96EF08DBDD1396C
      SHA1:DB2DEEE31781DE32639A48E74F184D1CD665242B
      SHA-256:CE49494809E105DBFB49AA45612E2E0C42205D74449BBC7E85EF34C92124D7FD
      SHA-512:48967DCB0B5D9FFA5A7E356CC1A4CA84C52955699014544FC2C5AF4BB212477C42D4746C6DB1EDFA34C3753F3D64396E64CD54C9A24CE560AD2F122C77FD9C57
      Malicious:false
      Reputation:unknown
      Preview:......................>...................................8........6..................................................w........................................................................................................................................................................................................................ ... ...!...!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...*...*...+...+...,...,...-...-.........../.../...0...0...1...1...2...2...3...3...4...4...5...5..........;.......................................................................................................%........... ...!..."...#...$.......&.../...(...)...*...+...,...-.......1...0...3...2...F...4...5...6...7...A...M...:...<.......=.......?...@.......B...C...D...E...H...G...{...I...J...a...L...N.......O.......Q...Z...S...T...U...V...W...X...Y...K...[...\...]...g..._...`...b...u...c...d...e...f...P...h...i...j...k...l...m...n...o...p...q...r...s...t...>...v...w...x...y...z...
      Process:C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe
      File Type:ASCII text, with no line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:CFE260590D0669F46AC503D60F9A35C5
      SHA1:1608BB75347CD8C40187E5F3C0A969ED73A98D51
      SHA-256:D7E9F590CCC53E236F6E389F0E160908F898FAD9B886395C003E6B1F869BF816
      SHA-512:412888DD9C7C139F325B672E9D42D2E5AB1E5EDA102589DE112CD45CF914A2D76488650F6815BDA856B35B8AD391B8988749D96BF89B54645BBAE91B251A51D8
      Malicious:false
      Reputation:unknown
      Preview:%*
      Process:C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe
      File Type:ASCII text, with no line terminators
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:CFE260590D0669F46AC503D60F9A35C5
      SHA1:1608BB75347CD8C40187E5F3C0A969ED73A98D51
      SHA-256:D7E9F590CCC53E236F6E389F0E160908F898FAD9B886395C003E6B1F869BF816
      SHA-512:412888DD9C7C139F325B672E9D42D2E5AB1E5EDA102589DE112CD45CF914A2D76488650F6815BDA856B35B8AD391B8988749D96BF89B54645BBAE91B251A51D8
      Malicious:false
      Reputation:unknown
      Preview:%*
      Process:C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Installs Ems Client, Author: AudioCodes, Keywords: Installer, Comments: AudioCodes Company, Template: x64;1033, Revision Number: {4A16C067-3D3A-48E9-90AF-DF5E841F98BF}, Create Time/Date: Mon Apr 24 13:59:14 2023, Last Saved Time/Date: Mon Apr 24 13:59:14 2023, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:270EB2BF2FDDE99770F8DFCEBB44A13C
      SHA1:E78305B70172F45E6C5499E8B65E1C02BF8B7A35
      SHA-256:29926801543291EE5A16170D10E6BE5E77B720B0308AE0C8F9DB030DE55F68BA
      SHA-512:4AE6B0206734A422F59E669A890CF7AE6B04B7895FEAAD73AE02F307A89270DF50B72A882C98C7CA72D57E34014C299096002E02226BA87E9EBF9ACEA52DB1A2
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: AudioCodes Device Duo, Author: AudioCodes, Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2013 - Professional Edition 20, Last Saved Time/Date: Sun Oct 24 15:10:40 2021, Create Time/Date: Sun Oct 24 15:10:40 2021, Last Printed: Sun Oct 24 15:10:40 2021, Revision Number: {C27498F1-9FD0-4B76-AFE4-6BE0742869B1}, Code page: 1252, Template: Intel;1033
      Category:dropped
      Size (bytes):0
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:306DBE2F4BC72884D96EF08DBDD1396C
      SHA1:DB2DEEE31781DE32639A48E74F184D1CD665242B
      SHA-256:CE49494809E105DBFB49AA45612E2E0C42205D74449BBC7E85EF34C92124D7FD
      SHA-512:48967DCB0B5D9FFA5A7E356CC1A4CA84C52955699014544FC2C5AF4BB212477C42D4746C6DB1EDFA34C3753F3D64396E64CD54C9A24CE560AD2F122C77FD9C57
      Malicious:false
      Reputation:unknown
      Preview:......................>...................................8........6..................................................w........................................................................................................................................................................................................................ ... ...!...!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...*...*...+...+...,...,...-...-.........../.../...0...0...1...1...2...2...3...3...4...4...5...5..........;.......................................................................................................%........... ...!..."...#...$.......&.../...(...)...*...+...,...-.......1...0...3...2...F...4...5...6...7...A...M...:...<.......=.......?...@.......B...C...D...E...H...G...{...I...J...a...L...N.......O.......Q...Z...S...T...U...V...W...X...Y...K...[...\...]...g..._...`...b...u...c...d...e...f...P...h...i...j...k...l...m...n...o...p...q...r...s...t...>...v...w...x...y...z...
      Process:C:\Windows\Temp\{EE890EE3-7A5E-4021-87B7-D3F99EED8AB5}\.be\AudioCodes App Suite_1.2.0.10.exe
      File Type:data
      Category:dropped
      Size (bytes):838
      Entropy (8bit):2.153642713972309
      Encrypted:false
      SSDEEP:
      MD5:AD9E036C69E1ABDE41C6EFCAA99FC576
      SHA1:77FA9116A639E944C6F5AECA439E142878468E46
      SHA-256:FF1062420B065556EF298349A063C296A1B44C84F4F0EECF0D2297D4C75A7C1B
      SHA-512:4EE20837C2603B9656C62DEBCDC4B60D2B8FD5BF72A9875790308C5E1D34E83FE2B59AC17AA4DA8AAFBD2C20063DC0541EDA00A3554E299741E3E8C9840CC6D2
      Malicious:false
      Reputation:unknown
      Preview:W...................................................................................................................................................................................................................................................................W.i.x.B.u.n.d.l.e.F.o.r.c.e.d.R.e.s.t.a.r.t.P.a.c.k.a.g.e.....................W.i.x.B.u.n.d.l.e.L.a.s.t.U.s.e.d.S.o.u.r.c.e.............................................W.i.x.B.u.n.d.l.e.N.a.m.e.........A.u.d.i.o.C.o.d.e.s. .A.p.p. .S.u.i.t.e.............W.i.x.B.u.n.d.l.e.O.r.i.g.i.n.a.l.S.o.u.r.c.e.........C.:.\.U.s.e.r.s.\.t.o.r.r.e.s.\.D.e.s.k.t.o.p.\.A.u.d.i.o.C.o.d.e.s.A.p.p.S.u.i.t.e...e.x.e.............W.i.x.B.u.n.d.l.e.O.r.i.g.i.n.a.l.S.o.u.r.c.e.F.o.l.d.e.r.........C.:.\.U.s.e.r.s.\.t.o.r.r.e.s.\.D.e.s.k.t.o.p.\.....................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-16, little-endian text, with very long lines (319), with CRLF line terminators
      Category:dropped
      Size (bytes):198678
      Entropy (8bit):3.848816831945226
      Encrypted:false
      SSDEEP:
      MD5:EB8420BDA2CA219CD13C4694D2572D2E
      SHA1:DECC43D53443760A59E3AA20183066DDD4FC074F
      SHA-256:A40D2C43E296356F62165B58FE9A208C2F214C78E47873CAA0988FAD9BA603D0
      SHA-512:2A30C9F1B74488A4DB25132A5392C5041F811092CF6AABF754F7E6CDE60113DF1F8FC51C7A2F9858696DC1ABCD0F1C54253FA6971D45DE9D857D2C1A023A39E2
      Malicious:false
      Reputation:unknown
      Preview:..=.=.=. .V.e.r.b.o.s.e. .l.o.g.g.i.n.g. .s.t.a.r.t.e.d.:. .1.0./.0.1./.2.0.2.5. . .1.1.:.3.4.:.4.5. . .B.u.i.l.d. .t.y.p.e.:. .S.H.I.P. .U.N.I.C.O.D.E. .5...0.0...1.0.0.1.1...0.0. . .C.a.l.l.i.n.g. .p.r.o.c.e.s.s.:. .C.:.\.W.i.n.d.o.w.s.\.T.e.m.p.\.{.E.E.8.9.0.E.E.3.-.7.A.5.E.-.4.0.2.1.-.8.7.B.7.-.D.3.F.9.9.E.E.D.8.A.B.5.}.\...b.e.\.A.u.d.i.o.C.o.d.e.s. .A.p.p. .S.u.i.t.e._.1...2...0...1.0...e.x.e. .=.=.=.....M.S.I. .(.c.). .(.B.8.:.0.C.). .[.1.1.:.3.4.:.4.5.:.2.8.7.].:. .R.e.s.e.t.t.i.n.g. .c.a.c.h.e.d. .p.o.l.i.c.y. .v.a.l.u.e.s.....M.S.I. .(.c.). .(.B.8.:.0.C.). .[.1.1.:.3.4.:.4.5.:.2.8.7.].:. .M.a.c.h.i.n.e. .p.o.l.i.c.y. .v.a.l.u.e. .'.D.e.b.u.g.'. .i.s. .0.....M.S.I. .(.c.). .(.B.8.:.0.C.). .[.1.1.:.3.4.:.4.5.:.2.8.7.].:. .*.*.*.*.*.*.*. .R.u.n.E.n.g.i.n.e.:..... . . . . . . . . . . .*.*.*.*.*.*.*. .P.r.o.d.u.c.t.:. .C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.P.a.c.k.a.g.e. .C.a.c.h.e.\.{.9.C.7.3.A.8.6.1.-.D.F.1.5.-.4.E.B.8.-.A.2.0.B.-.6.6.9.6.D.7.E.1.5.3.F.9.}.v.1...2...0...1.0.\.A.u.d.i.o.
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-16, little-endian text, with very long lines (319), with CRLF line terminators
      Category:dropped
      Size (bytes):202176
      Entropy (8bit):3.8409210437436365
      Encrypted:false
      SSDEEP:
      MD5:176CAA24F53A7BE3F5F86B431E63E6EF
      SHA1:737CAF879D70AAD89D4169942D3829ADA5ACAD11
      SHA-256:4FE08673B389FC4E8D6043D6B8C7F77421B002035C3B99EEFD7C0976AB6C2583
      SHA-512:095D3FA905B85008784E36456F6ECD175C22B347C33046C4E0BED892AE7993DA2C7A5D12C53452427E283CF0DF71AA03221D2322B12C52C5B7F0D4BEAE8ECB10
      Malicious:false
      Reputation:unknown
      Preview:..=.=.=. .V.e.r.b.o.s.e. .l.o.g.g.i.n.g. .s.t.a.r.t.e.d.:. .1.0./.0.1./.2.0.2.5. . .1.1.:.3.4.:.4.9. . .B.u.i.l.d. .t.y.p.e.:. .S.H.I.P. .U.N.I.C.O.D.E. .5...0.0...1.0.0.1.1...0.0. . .C.a.l.l.i.n.g. .p.r.o.c.e.s.s.:. .C.:.\.W.i.n.d.o.w.s.\.T.e.m.p.\.{.E.E.8.9.0.E.E.3.-.7.A.5.E.-.4.0.2.1.-.8.7.B.7.-.D.3.F.9.9.E.E.D.8.A.B.5.}.\...b.e.\.A.u.d.i.o.C.o.d.e.s. .A.p.p. .S.u.i.t.e._.1...2...0...1.0...e.x.e. .=.=.=.....M.S.I. .(.c.). .(.B.8.:.8.8.). .[.1.1.:.3.4.:.4.9.:.8.3.7.].:. .R.e.s.e.t.t.i.n.g. .c.a.c.h.e.d. .p.o.l.i.c.y. .v.a.l.u.e.s.....M.S.I. .(.c.). .(.B.8.:.8.8.). .[.1.1.:.3.4.:.4.9.:.8.3.7.].:. .M.a.c.h.i.n.e. .p.o.l.i.c.y. .v.a.l.u.e. .'.D.e.b.u.g.'. .i.s. .0.....M.S.I. .(.c.). .(.B.8.:.8.8.). .[.1.1.:.3.4.:.4.9.:.8.3.7.].:. .*.*.*.*.*.*.*. .R.u.n.E.n.g.i.n.e.:..... . . . . . . . . . . .*.*.*.*.*.*.*. .P.r.o.d.u.c.t.:. .C.:.\.P.r.o.g.r.a.m.D.a.t.a.\.P.a.c.k.a.g.e. .C.a.c.h.e.\.{.7.4.C.F.F.2.9.1.-.6.D.9.4.-.4.7.8.F.-.8.9.0.D.-.C.E.C.D.2.5.A.A.E.B.0.1.}.v.1...2...0...1.0.\.A.u.d.i.o.
      Process:C:\Windows\SysWOW64\msiexec.exe
      File Type:PE32+ executable (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):151368
      Entropy (8bit):6.073319173988209
      Encrypted:false
      SSDEEP:
      MD5:0F316043BFD136A509347148D203D541
      SHA1:9573614DEAA1FEC42A299752E0AD63174C85BD69
      SHA-256:081491C300116646E02FCA9982E69F663893E8B7B29708D2BAC2CE8DADEB245A
      SHA-512:99B28953A79A9AEA7F24A2ABE97B54384E2DA5D7D9D9A25E5301C83E432C97473ABC0263CFAE704650A255DD4C62A8940FB51D816E9EF06E55660CFED5D6FE60
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........q..."..."..."..M"..."..["..."..J"..".@."...".@.".."..."u.."..D"..."..Z"...".._"..."Rich..."........................PE..d.....Q.........."......h....................@..........................................@..........................................................`..h....@..h....6..H.......x....................................................................................text...ng.......h.................. ..`.rdata...y.......z...l..............@..@.data...8?..........................@....pdata..h....@......................@..@.rsrc...h....`......................@..@.reloc...............0..............@..B........................................................................................................................................................................................................................................................
      Process:C:\Windows\SysWOW64\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, PECompact2 compressed
      Category:dropped
      Size (bytes):286536
      Entropy (8bit):7.948770055532932
      Encrypted:false
      SSDEEP:
      MD5:8AC078212DE9D00591C55E6F7B61AFF0
      SHA1:CC0B24116701F000F86D2EEBDBBA1430558EC43E
      SHA-256:8181FF7960A3B4115576977AABB807B2B553BFBAB392AC376B15A04E1AF5D51C
      SHA-512:1183D5F2A438F5F498D29394B1D4CB8444EE845EABD9131D9CC6298074727450B9B902EDDC910A875C3AB316109829056CC1D007F43DFA5A14FB8F84567FFD6A
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Q.G.0...0...0.......0...Ho..0...b~..0...Hy..0.......0.......0...0...1...H~..0...Hh..0...bn..0...Hk..0..Rich.0..................PE..L...2.KR...........!.....x...|.......x.............................................................................zU.......u.......P..r............F..H............................................................................................text....@..............PEC2MO...... ....rsrc....@...P...4.................. ....reloc...............D..............@...........................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\SysWOW64\msiexec.exe
      File Type:Generic INItialization configuration [f1]
      Category:dropped
      Size (bytes):264
      Entropy (8bit):5.284227621266176
      Encrypted:false
      SSDEEP:
      MD5:A1551B7C752649DA84317132F90EAB94
      SHA1:CA0BDF905657A635FD2154E59E08A4653471F067
      SHA-256:7399A157F06818864FB3E28545898B627DAD36E5133FC66F9C9205A10A47C46A
      SHA-512:90D3CFB224C61E26F6D1E397CF76D9E81AA6836600BA829413E1D2682EF858F70C460255DBD60E7CF4632CDF8B4FAFE15A9872E473ED914461CE6DC3149B70FE
      Malicious:false
      Reputation:unknown
      Preview:[SetupDefaults]..LangID=1033..ProductCode={DE04E53C-AE5B-4630-AD95-5C63C3333027}..TempPathGuid={91F46B7A-A9D6-4BCA-8807-8389BD905774}..[f1]..Function=DeleteLogDir..[f2]..Function=AddFireWallRule..[f4]..Function=DeleteRegEntries..[f3]..Function=DeleteFireWallRule..
      Process:C:\Windows\SysWOW64\msiexec.exe
      File Type:Unicode text, UTF-16, little-endian text, with very long lines (332), with CRLF line terminators
      Category:dropped
      Size (bytes):175440
      Entropy (8bit):3.6501318465338923
      Encrypted:false
      SSDEEP:
      MD5:9D85FC6B53F4824DD6DC99E9D9194F18
      SHA1:F7D0DD058EF36E84D32A8ECEE92D861D528237F5
      SHA-256:70252D1283CFF214BAE25C6398896132D18150C9ADF7AA728295F896994174B2
      SHA-512:6BD00F6BD4BC31796D07E111237CE8C92C4A9CE7631426C664D0E148E4647A10F2E76CB72E49F9837156182DB514480ACB2443227F31F4FAB537A7B93EA2B630
      Malicious:false
      Reputation:unknown
      Preview:..B.T.O.E._.S.E.R.V.I.C.E._.N.A.M.E._.S.T.R.I.N.G.=.A.u.d.i.o.C.o.d.e.s. .D.e.v.i.c.e. .D.u.o.....B.e.t.t.e.r.2.G.e.t.h.e.r.O.l.d.D.i.r.=.B.e.t.t.e.r.2.G.e.t.h.e.r.....C.O.M.P.A.N.Y._.N.A.M.E.=.A.u.d.i.o.C.o.d.e.s.....D.N._.A.l.w.a.y.s.I.n.s.t.a.l.l.=.A.l.w.a.y.s. .I.n.s.t.a.l.l.....I.D.P.R.O.P._.E.X.P.R.E.S.S._.L.A.U.N.C.H._.C.O.N.D.I.T.I.O.N._.C.O.L.O.R.=.T.h.e. .c.o.l.o.r. .s.e.t.t.i.n.g.s. .o.f. .y.o.u.r. .s.y.s.t.e.m. .a.r.e. .n.o.t. .a.d.e.q.u.a.t.e. .f.o.r. .r.u.n.n.i.n.g. .[.P.r.o.d.u.c.t.N.a.m.e.].......I.D.P.R.O.P._.E.X.P.R.E.S.S._.L.A.U.N.C.H._.C.O.N.D.I.T.I.O.N._.D.O.T.N.E.T.V.E.R.S.I.O.N.4.0.F.U.L.L.=.M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k. .4...0. .F.u.l.l. .p.a.c.k.a.g.e. .o.r. .g.r.e.a.t.e.r. .n.e.e.d.s. .t.o. .b.e. .i.n.s.t.a.l.l.e.d. .f.o.r. .t.h.i.s. .i.n.s.t.a.l.l.a.t.i.o.n. .t.o. .c.o.n.t.i.n.u.e.......I.D.P.R.O.P._.E.X.P.R.E.S.S._.L.A.U.N.C.H._.C.O.N.D.I.T.I.O.N._.O.S.=.T.h.e. .o.p.e.r.a.t.i.n.g. .s.y.s.t.e.m. .i.s. .n.o.t. .a.d.e.q.u.a.t.e. .f.o.r. .r.u.
      Process:C:\Windows\SysWOW64\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):553067
      Entropy (8bit):4.803237748201968
      Encrypted:false
      SSDEEP:
      MD5:4877B077F4CC7EFD4FC7D972D253FA7C
      SHA1:CC94EA41121131A79255B5A828696C1381DFC3C9
      SHA-256:DC81AB0B00B42FED0098E7FDC981DC177A681A6B33B2691807B190D46FE5F4B2
      SHA-512:B89EA50FF416D1FE6AAC6C44B942EBF3190DC25C00DA4528E8809C949BE1A06D4716C2B56086ADA53F4257A43C532BFBBC61AD69BC48304121EDEED555D0F9E5
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^..(...{...{...{...{...{,..{J..{...{P..{..{...{,..{...{..{...{Rich...{........PE..L....KR...........!.........................................................................................................@..(....P.......................p.......................................................A...............................text...@........................... ..`.rdata........... ..................@..@.data....f.......P..................@....idata.......@....... ..............@....rsrc........P... ...0..............@..@.reloc..q....p... ...P..............@..B................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\SysWOW64\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):266862
      Entropy (8bit):7.348938234393837
      Encrypted:false
      SSDEEP:
      MD5:74B1BA13E9EBCE46DBE6F25B0E218A7C
      SHA1:03345CCAD65A1CBFC57E01C27F2A448897EDE1D9
      SHA-256:B9B6A068F4B3C57D655554D2830683E293981A2B52180970EE0273C5EAF6BCA9
      SHA-512:250A270DE0CA2FD1B5493CF983E37F3B3A9FAB62E2B821163EF25F69F6BA8FE041F83D5DA76FB9DCE4D7E09A635E5DD97E3FBD5E0A5F5413F0F8D28A2FDAAEEA
      Malicious:false
      Reputation:unknown
      Preview:t.,....(... <$.M. .=..........l.............o.c...gWSl..SW..WS[//d.d l$.XX%.......................q.y}a.!mQ.Y]AT.M1..-!.)........................................}...m..q]}}aMm.U=].E-M.5.=.%.-.......................}.......W.....v.@....qeymee1m.......c.)!!.)g..?.....K.7.+.OH..... .D@..0....e..dXH......P..(..]UU-]......kS.kk.....C.WO7'.[.<X44....,..$.8... ...}..\......@.5km!U.gL.8..g....-....._..k#+G##.LP8.H.@......0...T.......Y..D.........1II.1.o.s..Cg..G.....O.Og.CL<L.P.......p.d$........Y..L......<.. ...III.1..k_.....o.oGO?.....H.,@.X.P. ......p..,...\......m..<.....]YMEE.M..w[..[..{os.....O.C_G.t$l.D8\..........,.......}..]..`.........)5M.5.o.W_...sO3.SGk....h$.`,...4.L.$.<..........@...d...e}}1e.D.....o...S)!!.)g.GsK?..0.....#.h$P(.\\...........x(..am.I...p....H.......=9.!S3.wgksK.......3[C ......(.......,...........q.ayyaa.YQQYYc9E%11%9._.......W{7;wSo.......`(h<......L.4..........ay.q...a}Qii]Q....5MM!5.wSl.-.....w'.+k3/..+d.....
      Process:C:\Windows\System32\msiexec.exe
      File Type:Generic INItialization configuration [BeginLog]
      Category:dropped
      Size (bytes):2501282
      Entropy (8bit):5.2169942415067165
      Encrypted:false
      SSDEEP:
      MD5:6FA5C9BB7149D439515325E212E90A04
      SHA1:9CE062C53DDEFE4F3ECF6AE4B082F40D44BCF6D0
      SHA-256:52D8B3F33ADD5C0F19AC258106F5B224AFBADB9AA136077520A3721D09B030EC
      SHA-512:9C5EEADA25F80451ED980EFAA2D2DF9A81FD12CC5CFF3E8EB53C33DACE1FD32DF5563594E069D7A469E1E2F1095468F01F0B2644420862E4EEEA4FD9E277F306
      Malicious:false
      Reputation:unknown
      Preview:[Device Install Log].. OS Version = 10.0.19045.. Service Pack = 0.0.. Suite = 0x0100.. ProductType = 1.. Architecture = amd64....[BeginLog]....[Boot Session: 2023/10/03 09:57:02.288]....>>> [Setup Import Driver Package - C:\Windows\system32\spool\tools\Microsoft Print To PDF\prnms009.Inf]..>>> Section start 2023/10/03 09:57:37.904.. cmd: C:\Windows\System32\spoolsv.exe.. inf: Provider: Microsoft.. inf: Class GUID: {4D36E979-E325-11CE-BFC1-08002BE10318}.. inf: Driver Version: 06/21/2006,10.0.19041.1806.. inf: Catalog File: prnms009.cat.. ump: Import flags: 0x0000000D.. pol: {Driver package policy check} 09:57:37.920.. pol: {Driver package policy check - exit(0x00000000)} 09:57:37.920.. sto: {Stage Driver Package: C:\Windows\system32\spool\tools\Microsoft Print To PDF\prnms009.Inf} 09:57:37.920.. inf: {Query Configurability: C:\Windows\system32\spool\tools\Microsoft Print To PDF\prnms009.Inf} 09:57:37.920.. inf:
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: AudioCodes Camera Service, Author: AudioCodes, Keywords: Installer, Comments: AudioCodes Company, Template: x64;1033, Revision Number: {DA9B471C-955A-4B43-95F2-CC82DB5476BA}, Create Time/Date: Mon Apr 24 13:59:26 2023, Last Saved Time/Date: Mon Apr 24 13:59:26 2023, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
      Category:dropped
      Size (bytes):9392128
      Entropy (8bit):7.873654871593939
      Encrypted:false
      SSDEEP:
      MD5:04A00768A39C2B32D566D950F4A40AE5
      SHA1:681652C4758D2757DF656183D58C771ECC1469BE
      SHA-256:BD54D7E38B20725F1E737E8BB9888616686B275B82FF559A4CEA014308575309
      SHA-512:6ACA8AA5D4331F1969C93986E0E65CD1305695066488EDC907C1C3719D9FE1A7D063320FE07AB524CBCD20ECE147B758602DA8726FB1FD79E119B0945C424424
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):216496
      Entropy (8bit):6.646208142644182
      Encrypted:false
      SSDEEP:
      MD5:A3AE5D86ECF38DB9427359EA37A5F646
      SHA1:EB4CB5FF520717038ADADCC5E1EF8F7C24B27A90
      SHA-256:C8D190D5BE1EFD2D52F72A72AE9DFA3940AB3FACEB626405959349654FE18B74
      SHA-512:96ECB3BC00848EEB2836E289EF7B7B2607D30790FFD1AE0E0ACFC2E14F26A991C6E728B8DC67280426E478C70231F9E13F514E52C8CE7D956C1FAD0E322D98E0
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........................^.......\......].........................,.......<.........L...'.....'.....'.P.......8.....'.....Rich............................PE..L...Ap.]...........!.........P............................................................@.........................@................P..x....................`..........T...............................@...............<............................text...[........................... ..`.rdata..............................@..@.data...."... ......................@....rsrc...x....P......................@..@.reloc.......`......................@..B........................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):710671
      Entropy (8bit):6.666957803275315
      Encrypted:false
      SSDEEP:
      MD5:A84B37A4B4A3EBE2772CFE5CB46022D0
      SHA1:83AA7073C0CB6B2BCC9332175B6773EBC8CCA05B
      SHA-256:1D4AA1EA4A02DA550020337D622876813DFB5EAABA327231673BE055407CF2AE
      SHA-512:561D17E5DF3D41073E2CD14F7AEAF2D7196CA16C8AA224BC85412CF97F664596F21F644FA4AFDF04F6A54045E532396A02A5AE9E9B9D9E1C6244CFADAA2ADB0B
      Malicious:false
      Reputation:unknown
      Preview:...@IXOS.@.....@X\*Z.@.....@.....@.....@.....@.....@......&.{9C73A861-DF15-4EB8-A20B-6696D7E153F9}..AudioCodes DM Client!.AudioCodes DM Client_1.2.0.10.msi.@.....@.....@.....@........&.{4A16C067-3D3A-48E9-90AF-DF5E841F98BF}.....@.....@.....@.....@.......@.....@.....@.......@......AudioCodes DM Client......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{B23D3133-6A90-5F78-B046-85A553389C3A}8.C:\Program Files\AudioCodes\DM Client\acl_env_params.exe.@.......@.....@.....@......&.{47C03B18-8A62-58FB-B943-6B18ACFA9CDD}6.C:\Program Files\AudioCodes\DM Client\ac_cfg_gtest.exe.@.......@.....@.....@......&.{601E4BF1-19F0-5333-94FF-0EFDDE0BC483}3.C:\Program Files\AudioCodes\DM Client\ac_common.dll.@.......@.....@.....@......&.{34B3CFF6-2C43-549A-AB66-6A940A095F20}6.C:\Program Files\AudioCodes\DM Client\ac_curl_tftp.exe.@.......@.....@.....@......&.{A0AFD448-AF43-5
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):130480
      Entropy (8bit):6.659038836767763
      Encrypted:false
      SSDEEP:
      MD5:93394D2866590FB66759F5F0263453F2
      SHA1:2F0903D4B21A0231ADD1B4CD02E25C7C4974DA84
      SHA-256:5C29B8255ACE0CD94C066C528C8AD04F0F45EBA12FCF94DA7B9CA1B64AD4288B
      SHA-512:F2033997B7622BD7CD6F30FCA676AB02ECF6C732BD44E43358E4857B2CF5B227A5AA6BBBF2828C69DD902CBCC6FF983306787A46104CA000187F0CBA3743C622
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........v.....................}.......|.........................o............5~.....5~.....5~q..........5~.....Rich............................PE..L....p.]...........!.....2...........E.......P...............................@............@.........................0........................................ ..........T...............................@............P...............................text....0.......2.................. ..`.rdata.......P.......6..............@..@.data...4"..........................@....rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):451779
      Entropy (8bit):6.655349759011776
      Encrypted:false
      SSDEEP:
      MD5:09E73A8C7ACC98CED691EE3381B68CFD
      SHA1:5F56C5A7B599D44808542E814054AF72BA58E63B
      SHA-256:8361D6CE3B4D826AA6501BE0DA51D577A131AA3A8A3D0A4617C02FB242490036
      SHA-512:E18C7A5EE670680728E551FFCA2C6355D28DE15CBBF09ED7591EA1900AD0ED4190F9BC59E7F57DCC37CC7D3BB975973D49C5D3C6A422F67D8DE18FE84CB7094F
      Malicious:false
      Reputation:unknown
      Preview:...@IXOS.@.....@Z\*Z.@.....@.....@.....@.....@.....@......&.{74CFF291-6D94-478F-890D-CECD25AAEB01}..AudioCodes Camera Service&.AudioCodes Camera Service_1.2.0.10.msi.@.....@.....@.....@........&.{DA9B471C-955A-4B43-95F2-CC82DB5476BA}.....@.....@.....@.....@.......@.....@.....@.......@......AudioCodes Camera Service......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@)....@.....@.]....&.{DCA2AAFE-BC34-57DE-8714-378F47919BBD}8.C:\Program Files\AudioCodes\Camera Service\ac_common.dll.@.......@.....@.....@......&.{A68D6528-11E7-5E15-B592-077BD4DB8AC3}6.C:\Program Files\AudioCodes\Camera Service\ac_des3.dll.@.......@.....@.....@......&.{C81436EB-6BB1-5C94-97FA-AC9C980A2271}2.C:\Program Files\AudioCodes\Camera Service\app.dll.@.......@.....@.....@......&.{75F3B301-1E4F-555D-822D-706823339A34}H.C:\Program Files\AudioCodes\Camera Service\AudioCodes Camera Service.exe.@.......@....
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):154960
      Entropy (8bit):6.024226219618248
      Encrypted:false
      SSDEEP:
      MD5:147B7F7427D9FFE61EA784C3B5E245C8
      SHA1:2CCF676AA59561F0F30FCD04D5DF48831054CB3E
      SHA-256:68653956EA7674EC9E8E643B573C9C8FBEE00B7D07D4FC89FB0E233844C68683
      SHA-512:7A63E0D33D462FB73B6EC57EF2B1C4A21D873694E4D5E37F86B34FB33392D760D4C1D2AEA313246A2618E2DD4537AFCFC8006DAEBF8C1ABC26435BC462D2B53C
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........w............[...................[......[.......nF....nV.......x.........................R...........Rich....................PE..L.....Q...........!.....H..................`......................................c...................................E...\........@...............D..P....P..(.......................................@............`...............................text....G.......H.................. ..`.rdata.......`.......L..............@..@.data...t2..........................@....rsrc........@......................@..@.reloc..:J...P...L..................@..B........................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):1879445
      Entropy (8bit):7.560041923212796
      Encrypted:false
      SSDEEP:
      MD5:F91B150B05D5D44F6A99862666B0BE67
      SHA1:AEAB7F465342B368E65760C44BF0329A1FE71481
      SHA-256:B662E7CA6C35F80257AD5582871EEBCD13A616E0F7A3CEA8E788FE2BBA782D67
      SHA-512:06947C369C90E849EC8C3A8BD21581C03600D314EE76DFDF6D8CF38C524016495BA3F4B987C546CDE24CC3808F8E8CDA8268A26244A73E24981E43195A1EE6BF
      Malicious:false
      Reputation:unknown
      Preview:...@IXOS.@.....@]\*Z.@.....@.....@.....@.....@.....@......&.{DE04E53C-AE5B-4630-AD95-5C63C3333027}..AudioCodes Device Duo..AudioCodes Device Duo.msi.@.....@e....@.....@......ARPPRODUCTICON.exe..&.{C27498F1-9FD0-4B76-AFE4-6BE0742869B1}.....@.....@.....@.....@.......@.....@.....@.......@......AudioCodes Device Duo......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@.....@.....@.]....&.{D175F57B-97F2-4AF0-8B39-079FC92D3256}-.C:\Program Files (x86)\AudioCodes\Device Duo\.@.......@.....@.....@......&.{CBB5694A-8071-4864-9983-50339D81DE58}...@.......@.....@.....@......&.{5C07B3A1-D7F3-49CF-9074-36EB1CECFEEC}...@.......@.....@.....@......&.{CADEBEA5-3412-4705-8302-2F146AD1A69D}...@.......@.....@.....@......&.{04D675C9-CC57-4F42-B1BE-7F8190CF7A33}D.C:\Program Files (x86)\AudioCodes\Device Duo\DeviceDuoController.exe.@.......@.....@.....@......&.{499831A6-57B9-4C2B-B5D1-EA2A0B3A0CC2}
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, PECompact2 compressed
      Category:dropped
      Size (bytes):1408412
      Entropy (8bit):7.896682811392689
      Encrypted:false
      SSDEEP:
      MD5:4809156AA5C272EB95D042A9AB117CC2
      SHA1:9D6269E6420C7C3071D6E6DF46A564BDD66EC088
      SHA-256:5DDC82BEE6DE6425946962C1B5F5A865CECDFB210A378A4E34513762496D76EE
      SHA-512:E0B4F3AE911105B97F88A9D6596DBF28A2A29325B8352D10CC879857159ED3C2F2E9D348FC2B04DCBEAA53094A3A3C13D4196EFD7749EBE428BB356D4F8FA796
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......s2..7S.}7S.}7S.}>+t}=S.}>+k}.S.}).z}2S.}...}?S.}>+}}.S.}...}/S.}7S.}$Q.}.$G}4S.}>+z}.S.}>+l}6S.}).j}6S.}>+o}6S.}Rich7S.}................PE..L...#.KR...........!.....r...........................................................................................k..[;......>....p...............................................................................................................text....`..............PEC2MO...... ....rsrc....P...p...F.................. ....reloc...............@..............@...................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
      Category:dropped
      Size (bytes):123904
      Entropy (8bit):6.107552012467646
      Encrypted:false
      SSDEEP:
      MD5:63A8E9DC54E594FB3A0C15BF8B9CD36C
      SHA1:56F6CA9C4CA0615798628F8AFAFD1DEFE6F95C62
      SHA-256:3A3CBD058C5E603F6ACCE77972AF5F17F075DD179267D2FAB48059AC63D405C9
      SHA-512:30E17DF926E41524B436780EFE21FD8DB6427F59010FFD107C46F962C66098847D9D1A9D44AA5E6FA832CB24A4F63C80DD86AB9957FC96259E52B54A992F9EB7
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........h..;..;..;W..;..;W..;...;W..;..;...:..;...:...;...:..;...;..;..;...;v..:..;v..:..;q..;..;v..:..;Rich..;........PE..d....`.........." .........................................................@............`.............................................|...<...d.... ..........X............0..(......p...........................@................ .. ............................text...`........................... ..`.rdata..2.... ......................@..@.data...`...........................@....pdata..X...........................@..@.gfids..............................@..@.rsrc........ ......................@..@.reloc..(....0......................@..B........................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.1766764766562707
      Encrypted:false
      SSDEEP:
      MD5:A5363520A793A9DE3F74A34C417B1814
      SHA1:9A4FAA452290719E5B2CED8F421391DF480593DF
      SHA-256:FE80392BCB23D91F4651D51407E23B1CEFA1AD277A346E195DC7740F567A42F6
      SHA-512:7B87704A7CB9D390FAAF2D81340E6E4FBF5E13733B9C5247EEBB60589ED4EFB9947DF255C0E0819BCA5ADD8A46311F8966F556490F66E19498DB341F61D2B546
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.1740432075067053
      Encrypted:false
      SSDEEP:
      MD5:7ECBE2EA6404FE6BABD3550FB6BCF2E9
      SHA1:FC926A15578346236BFF123FBF84B5FFEA5BD8E9
      SHA-256:DCF0F6D7E1D60DE7F396911CDAA4D5E8967093DF9ED6D970244D349A213162C8
      SHA-512:BCCC9A52727CCFD83D1B65F4D49A4A3C1DE845FC8EC30C210DFA4E18975E217F95DD4030B532F9FB6120A8525160BCE4C6DBC561DF5FD82291632960B93369FE
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.933465564900113
      Encrypted:false
      SSDEEP:
      MD5:E7DE5B54885067B5C6A49E05692BF249
      SHA1:02AAD0E786306B3BA6FA4790078B3BE98132B160
      SHA-256:2BE16FB2546D72546EB99D68955FCDE2548EF062680057AAE0C815C60579B975
      SHA-512:F65AD4C8CB3558D36AAEF3E7763D591C2193CA3E1580AE9A1ED6CECA2A4998924DA0026B9E07DC5C9C00B5ECC9135EC94F37612D26B3D244FB6D821C80D05983
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):45056
      Entropy (8bit):4.346061989623295
      Encrypted:false
      SSDEEP:
      MD5:579F1A1AB20ABEBEC5709A345B4F85AF
      SHA1:CBFFE031EF9997032A3C5B6491A5AC7713AF035D
      SHA-256:F176B9A9FA9793E3E5B55B8E0B5ABAAEB11FE8FA7D02026F5BAD407F977C9825
      SHA-512:009C0792D4A25E5301DFDA9323B0357334474D52EBB959DD393BEDD14EAAF82E66B89EF2FDC647F3909F2FF5B72E618E1E42D6C443E1BE1419E2346E047D5D69
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L...e.Q.................@...`...............P....@.........................................................................4T..(....................................................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc............ ..................@..@................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
      Category:dropped
      Size (bytes):403156
      Entropy (8bit):5.359653318470148
      Encrypted:false
      SSDEEP:
      MD5:E379B511127CED86E7C150B078DCDDC1
      SHA1:A7AA34D34F4025C25187DB4BC1980CDE9CA46647
      SHA-256:7DBFEB1F4D8DD7521DBD23E4D7D4894A52791B7E0BA1A22700D443940ACAAB45
      SHA-512:87815E899BFB1D7A85B29991C63B3FBE41D75C60BF8E294D844FB81E4E8EBD34C1E19AD00688324AC09FA9F5786DED18CF889E5B4D9FAB141EF08D64DAAEA4E9
      Malicious:false
      Reputation:unknown
      Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
      Process:C:\Program Files\Windows Defender\MpCmdRun.exe
      File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
      Category:dropped
      Size (bytes):2464
      Entropy (8bit):3.250005211702334
      Encrypted:false
      SSDEEP:
      MD5:90290F165BC560FCF8F7278A6666505A
      SHA1:CC33A8E3E1691521C426C58BD610AB9214B289B7
      SHA-256:8B1A063A2F50FFFC51ECB86A8BBBC2D5437D4A53A0EA1D3C8F186D262E53CAD0
      SHA-512:1EE6159C84758284D4CAF6B51E2F50E5109392556CB0AC1AF2A29E322F01DD134D6AA9327EBF95D52A3B455EDC671E1D83CFA938D6794BD9F587866D6F786DAF
      Malicious:false
      Reputation:unknown
      Preview:..........-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.-.....M.p.C.m.d.R.u.n.:. .C.o.m.m.a.n.d. .L.i.n.e.:. .".C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.\.m.p.c.m.d.r.u.n...e.x.e.". .-.w.d.e.n.a.b.l.e..... .S.t.a.r.t. .T.i.m.e.:. .. F.r.i. .. J.a.n. .. 1.0. .. 2.0.2.5. .1.1.:.3.5.:.2.9.........M.p.E.n.s.u.r.e.P.r.o.c.e.s.s.M.i.t.i.g.a.t.i.o.n.P.o.l.i.c.y.:. .h.r. .=. .0.x.1.....W.D.E.n.a.b.l.e.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .W.S.C. .S.t.a.t.e. .I.n.f.o. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*. .A.n.t.i.V.i.r.u.s.P.r.o.d.u.c.t. .*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.*.....d.i.s.p.l.a.y.N.a.m.e. .=. .[.W.i.n.d.o.w.s. .D.e.f.e.n.d.e.r.].....p.a.t.h.T.o.S.i.g.n.e.d.P.r.o.d.u.c.t.E.x.e. .=. .[.w.i.n.d.o.w.s.d.
      Process:C:\Windows\System32\msiexec.exe
      File Type:Windows Precompiled iNF, version 3.3 (Windows 10), flags 0x1000083, unicoded, has strings, at 0x1cd8 "Signature", at 0x68 WinDirPath, LanguageID 809
      Category:dropped
      Size (bytes):9676
      Entropy (8bit):3.594799690276797
      Encrypted:false
      SSDEEP:
      MD5:C96E101F1816AB3D1163594A5DE06240
      SHA1:A87EA246A3FE67D4F006E1FB68C646E50697BB4A
      SHA-256:E1D6B7887869F135A30FEE5D724A5EF90836ECE10D748D8F0950EE4DE3974689
      SHA-512:365C323F066DD82ED09870FED477DE6B1E3ACE1930D84463EB22DA42EA2F7EEED589B4789381CFC9453636249323015AD48EE56BC8446C361ACD1B3C0267A32E
      Malicious:false
      Reputation:unknown
      Preview:................D........X.\.%..............T....... ................!.......#..h................%......C.:.\.W.i.n.d.o.w.s.............................l.......................................................................................................t...................................................p...............<.......t...t...................................h...............................................................................P.......................................X...........................X...|...........4.......................................`...............................................................................................................................................................H...T...........................................................................T................................................... ...........................<.......................................................................................................
      Process:C:\Windows\System32\drvinst.exe
      File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
      Category:dropped
      Size (bytes):1732376
      Entropy (8bit):7.978059947674261
      Encrypted:false
      SSDEEP:
      MD5:BF5257B2CE982CF3EA43B3B3377C6B3A
      SHA1:C1451F9268F62023824F5DC6BD025D62C1F7F7AB
      SHA-256:48AD1205D6834C4546D21BBF9C8EEEEEFDA388840D63D99A5A0836361F54C024
      SHA-512:B1F3428E096D8FAB6290EB9F5DA06A15AA1A211283615AB26F27FF6134214B07FDFE8EFC95A28F7EBEECB56B4A7CA12F8EDFDB5700AC5C73912C6EF057FAB8DD
      Malicious:false
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........t.v...%...%...%.m+%...%.m:%...%...% ..%.m-%...%.m=%...%.m,%...%.m7%...%...%...%.m*%...%.m/%...%Rich...%........................PE..d.....[J.........." .........0......................................................\f....@.........................................`................p..l!...`..,....,...C...........................................................................................text...L........................... ..`.data....J..........................@....pdata..,....`......................@..@.rsrc...l!...p..."..................@..@.reloc...............*..............@..B........................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\drvinst.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):74026
      Entropy (8bit):5.389759664309314
      Encrypted:false
      SSDEEP:
      MD5:D4AD288D04FDD3E1C9043A751C08940A
      SHA1:E93CBDCACCD209E801CC611DF11F6850481DB59F
      SHA-256:98E453C92EFF5C7D7B7432460CF28F89AAE66BAECAD5B99085EE9F1E604960F9
      SHA-512:24737D30BC90C0AE5F18D9D97EA2822888450B001D16FE613AB0165E5AC190D28A0C141AA814A4C4A7415A0375518892E76326632C8F7B1E260AD1761A1AA3B9
      Malicious:false
      Reputation:unknown
      Preview:CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #6041 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #6699 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #4398 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #6041 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #6699 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #4398 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #2083 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #2459 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: SyncAllDBs Corruption or Schema Change..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #891 encountered JET error -1409..CatalogDB: 08:57:12 03/10/2023: catdbsvc.cpp at line #1307 encountered JET error -1601..CatalogDB: 08:57:12 03/10/2023: SyncDB:: Sync sta
      Process:C:\Users\user\Desktop\AudioCodesAppSuite.exe
      File Type:PE32 executable (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):583992
      Entropy (8bit):7.083589160362997
      Encrypted:false
      SSDEEP:
      MD5:713FBE0DFE40D0F29D8EA60D5839AEC5
      SHA1:874751F62F9F7B5611075F28F3F4F28B2A5E1EF5
      SHA-256:5F7789D0920F4ADA4BD1C7B7AF0AE594E1D58953C88FBA52905B98588B2B93E6
      SHA-512:46B6CDE53B1990CBE8AE51223F9CDCA7E012E0AE96D5B09D813362CA8E1D3F5FF03E1FAD03022205BB109C02DB562973AB6F34A31E7383FA6EDC95998C6735C9
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9.o.}k..}k..}k.....wk......k.....ek../...nk../...ik../...Vk..t...xk..t...lk..}k..(j......6k......|k..}k...k......|k..Rich}k..........PE..L...2p.].....................~......q.............@..........................P............@..............................................:..............@).......=..0p..T....................p.......j..@...................4|.......................text............................... ..`.rdata..`...........................@..@.data...............................@....wixburn8...........................@..@.rsrc....:.......<..................@..@.reloc...=.......>..................@..B........................................................................................................................................................................................................................................................
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (643), with CRLF line terminators
      Category:dropped
      Size (bytes):9356
      Entropy (8bit):3.7070418916776453
      Encrypted:false
      SSDEEP:
      MD5:1DC5AF250577CE928F1D3726D7A0399D
      SHA1:16B9EF8DF0D5414BB592E6A0551446E2A2336BF2
      SHA-256:9A8FC1271464C32C008571C3A3434E64DA710C65760A24F22A171DDFF6373626
      SHA-512:0797A87367EE552E273BBFC0D304D3EDF02F75EC28AB550C69A4D6470105B214BE19F06487191D8E7B9E92703C4D18EBED5EB06306006215D62C1BC1892312B7
      Malicious:false
      Reputation:unknown
      Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.w.i.x./.2.0.1.0./.B.o.o.t.s.t.r.a.p.p.e.r.A.p.p.l.i.c.a.t.i.o.n.D.a.t.a.".>..... . .<.W.i.x.B.u.n.d.l.e.P.r.o.p.e.r.t.i.e.s. .D.i.s.p.l.a.y.N.a.m.e.=.".A.u.d.i.o.C.o.d.e.s. .A.p.p. .S.u.i.t.e.". .L.o.g.P.a.t.h.V.a.r.i.a.b.l.e.=.".W.i.x.B.u.n.d.l.e.L.o.g.". .C.o.m.p.r.e.s.s.e.d.=.".n.o.". .I.d.=.".{.b.e.5.4.e.6.9.9.-.b.b.8.b.-.4.3.b.f.-.8.8.2.9.-.0.9.5.6.5.d.7.5.2.5.f.b.}.". .U.p.g.r.a.d.e.C.o.d.e.=.".{.6.D.7.5.7.F.C.B.-.4.2.A.1.-.4.E.1.8.-.A.A.2.1.-.9.0.C.B.D.3.F.6.0.0.0.5.}.". .P.e.r.M.a.c.h.i.n.e.=.".y.e.s.". ./.>..... . .<.W.i.x.P.a.c.k.a.g.e.P.r.o.p.e.r.t.i.e.s. .P.a.c.k.a.g.e.=.".c.u.s.t.o.m._.a.c.t...c.m.d.". .V.i.t.a.l.=.".n.o.". .D.o.w.n.l.o.a.d.S.i.z.e.=.".2.". .P.a.c.k.a.g.e.S.i.z.e.=.".2.". .I.n.s.t.a.l.l.e.d.S.i.z.e.=.".2.". .P.a.c.k.a.g.e.T.y.p.e.=.".E.x.e.". .P.
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:JPEG image data, JFIF standard 1.01, resolution (DPI), density 96x96, segment length 16, baseline, precision 8, 64x64, components 3
      Category:dropped
      Size (bytes):2912
      Entropy (8bit):7.799278199243465
      Encrypted:false
      SSDEEP:
      MD5:E213DE194692394339C5D32B75095EC7
      SHA1:EEB0F63A055CC58702447140E38C705B98C5F539
      SHA-256:065FE5FEFAF143BE6A6599CDFD044F11BF1AAC930CFAA1E19E5E04A54A9F217B
      SHA-512:DC9B475B936B9EB70137FC87540B211ED674862F248DF4C0A03A010B410A6B4953A719A16FD2381C8D575EB050156FA1294A8E8419A91CAB8B6A2968558246D0
      Malicious:false
      Reputation:unknown
      Preview:......JFIF.....`.`.....C....................................................................C.......................................................................@.@.."............................................................}........!1A..Qa."q.2....#B...R..$3br........%&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz..............................................................................................................................w.......!1..AQ.aq."2...B.....#3R..br...$4.%.....&'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz....................................................................................?.....x.>...b6c..o8[5....m...72.$.n..xc.:..m4_...u)G..9/..t.#..n..Uu+.S.Y..>#C...(.....>V]..z..a.......4...W...pp.....A<&...88.H...... .A.~..x[X..e..a-...X.Ua.WT$.1T_R.C.Kax.6.8.k.z.S.8"...M....~.I....c..Zz_..g.hm?..!1I.+.A.P..y.r+Jxj...F.O.7..x.6.<.....K.<.....\.....c..q.~../x.......~..t.e?5.@^....A..7{v.).k*.*.%X...Y.,M.B..&....~....%...7...T?...^]
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):4865
      Entropy (8bit):5.016392653838953
      Encrypted:false
      SSDEEP:
      MD5:38D4000199D54D7F10B26A1E272365BB
      SHA1:7E2EC34C12CC284C71303908D53987975DA6D150
      SHA-256:206DC92DF96E694EAA3758AED798CE576983E5F14CC06C18D7EDF966D6A491D4
      SHA-512:E53EB1015E337E1845893DE0518626977153787CD37D829ACEFAE56A6858C484E41CC589CC5E905CA19D299925842424B6D98A86A301E6B43B0467FD4AF4C524
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<WixLocalization Culture="en-us" Language="1033" xmlns="http://schemas.microsoft.com/wix/2006/localization">.. <String Id="Caption">[WixBundleName] Setup</String>.. <String Id="Title">[WixBundleName]</String>.. <String Id="InstallHeader">Welcome</String>.. <String Id="InstallMessage">Setup will install [WixBundleName] on your computer. Click install to continue, options to set the install directory or Close to exit.</String>.. <String Id="InstallVersion">Version [WixBundleVersion]</String>.. <String Id="ConfirmCancelMessage">Are you sure you want to cancel?</String>.. <String Id="ExecuteUpgradeRelatedBundleMessage">Previous version</String>.. <String Id="HelpHeader">Setup Help</String>.. <String Id="HelpText">/install | /repair | /uninsta
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:XML 1.0 document, ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):9172
      Entropy (8bit):5.210337409159364
      Encrypted:false
      SSDEEP:
      MD5:89965F7B249CA563462C8099BDD6C513
      SHA1:2B99EEF71832B52B622A6058D5805289404F2E0A
      SHA-256:AA4A546926DAB33183224B1F4A8340A76B722CD2E52C7798E10188C6D14B425A
      SHA-512:CCBBFC31B01D82860C6B5150DF68074A286F9C4A65B1A7A800DEC02CB35257905941AA7A54A32FECEDF963CC992939C3BEB400CE8709DE85F19D8E402CC1E78D
      Malicious:false
      Reputation:unknown
      Preview:<?xml version="1.0" encoding="utf-8"?>.. Copyright (c) .NET Foundation and contributors. All rights reserved. Licensed under the Microsoft Reciprocal License. See LICENSE.TXT file in the project root for full license information. -->......<Theme xmlns="http://wixtoolset.org/schemas/thmutil/2010">.. <Window Width="485" Height="300" HexStyle="100a0000" FontId="0">#(loc.Caption)</Window>.. <Font Id="0" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="1" Height="-24" Weight="500" Foreground="000000">Segoe UI</Font>.. <Font Id="2" Height="-22" Weight="500" Foreground="666666">Segoe UI</Font>.. <Font Id="3" Height="-12" Weight="500" Foreground="000000" Background="FFFFFF">Segoe UI</Font>.. <Font Id="4" Height="-12" Weight="500" Foreground="ff0000" Background="FFFFFF" Underline="yes">Segoe UI</Font>.... <Image X="11" Y="11" Width="64" Height="64" ImageFile="logo.png" Visible="yes"/>.. <Text X="80" Y="11" Width="-11" Heig
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Category:dropped
      Size (bytes):188848
      Entropy (8bit):6.598346436496911
      Encrypted:false
      SSDEEP:
      MD5:FE7E0BD53F52E6630473C31299A49FDD
      SHA1:F706F45768BFB95F4C96DFA0BE36DF57AA863898
      SHA-256:2BEA14D70943A42D344E09B7C9DE5562FA7E109946E1C615DD584DA30D06CC80
      SHA-512:FEED48286B1E182996A3664F0FACDF42AAE3692D3D938EA004350C85764DB7A0BEA996DFDDF7A77149C0D4B8B776FB544E8B1CE5E9944086A5B1ED6A8A239A3C
      Malicious:false
      Antivirus:
      • Antivirus: ReversingLabs, Detection: 0%
      • Antivirus: Virustotal, Detection: 0%, Browse
      Reputation:unknown
      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......:v.O~.c.~.c.~.c....t.c......c....f.c.,.g.n.c.,.`.l.c.,.f.a.c.wo..z.c.wo..c.c.~.b.|.c..~f.g.c..~c...c..~....c.~.....c..~a...c.Rich~.c.........PE..L...Yp.]...........!................................................................1.....@.........................`.......L...................................`.......T...........................H...@...............\............................text............................... ..`.rdata..2...........................@..@.data...............................@....rsrc...............................@..@.reloc..`...........................@..B........................................................................................................................................................................................................................................................................................
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Code page: 1252, Title: Installation Database, Subject: Installs Ems Client, Author: AudioCodes, Keywords: Installer, Comments: AudioCodes Company, Template: x64;1033, Revision Number: {4A16C067-3D3A-48E9-90AF-DF5E841F98BF}, Create Time/Date: Mon Apr 24 13:59:14 2023, Last Saved Time/Date: Mon Apr 24 13:59:14 2023, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
      Category:dropped
      Size (bytes):5144576
      Entropy (8bit):7.6759833809416005
      Encrypted:false
      SSDEEP:
      MD5:270EB2BF2FDDE99770F8DFCEBB44A13C
      SHA1:E78305B70172F45E6C5499E8B65E1C02BF8B7A35
      SHA-256:29926801543291EE5A16170D10E6BE5E77B720B0308AE0C8F9DB030DE55F68BA
      SHA-512:4AE6B0206734A422F59E669A890CF7AE6B04B7895FEAAD73AE02F307A89270DF50B72A882C98C7CA72D57E34014C299096002E02226BA87E9EBF9ACEA52DB1A2
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: AudioCodes Device Duo, Author: AudioCodes, Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2013 - Professional Edition 20, Last Saved Time/Date: Sun Oct 24 15:10:40 2021, Create Time/Date: Sun Oct 24 15:10:40 2021, Last Printed: Sun Oct 24 15:10:40 2021, Revision Number: {C27498F1-9FD0-4B76-AFE4-6BE0742869B1}, Code page: 1252, Template: Intel;1033
      Category:dropped
      Size (bytes):10093056
      Entropy (8bit):7.726719569464103
      Encrypted:false
      SSDEEP:
      MD5:306DBE2F4BC72884D96EF08DBDD1396C
      SHA1:DB2DEEE31781DE32639A48E74F184D1CD665242B
      SHA-256:CE49494809E105DBFB49AA45612E2E0C42205D74449BBC7E85EF34C92124D7FD
      SHA-512:48967DCB0B5D9FFA5A7E356CC1A4CA84C52955699014544FC2C5AF4BB212477C42D4746C6DB1EDFA34C3753F3D64396E64CD54C9A24CE560AD2F122C77FD9C57
      Malicious:false
      Reputation:unknown
      Preview:......................>...................................8........6..................................................w........................................................................................................................................................................................................................ ... ...!...!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...*...*...+...+...,...,...-...-.........../.../...0...0...1...1...2...2...3...3...4...4...5...5..........;.......................................................................................................%........... ...!..."...#...$.......&.../...(...)...*...+...,...-.......1...0...3...2...F...4...5...6...7...A...M...:...<.......=.......?...@.......B...C...D...E...H...G...{...I...J...a...L...N.......O.......Q...Z...S...T...U...V...W...X...Y...K...[...\...]...g..._...`...b...u...c...d...e...f...P...h...i...j...k...l...m...n...o...p...q...r...s...t...>...v...w...x...y...z...
      Process:C:\Windows\Temp\{C5AB7AD0-8B6B-4A78-99F0-FC3C7E87CC9B}\.cr\AudioCodesAppSuite.exe
      File Type:ASCII text, with no line terminators
      Category:dropped
      Size (bytes):2
      Entropy (8bit):1.0
      Encrypted:false
      SSDEEP:
      MD5:CFE260590D0669F46AC503D60F9A35C5
      SHA1:1608BB75347CD8C40187E5F3C0A969ED73A98D51
      SHA-256:D7E9F590CCC53E236F6E389F0E160908F898FAD9B886395C003E6B1F869BF816
      SHA-512:412888DD9C7C139F325B672E9D42D2E5AB1E5EDA102589DE112CD45CF914A2D76488650F6815BDA856B35B8AD391B8988749D96BF89B54645BBAE91B251A51D8
      Malicious:false
      Reputation:unknown
      Preview:%*
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):0.08090594682299918
      Encrypted:false
      SSDEEP:
      MD5:F105B532854809BD404673081933028B
      SHA1:233A1C2A1ECA99D740C37B24E1F66180DCA64FFD
      SHA-256:5B879E715047729478C42E048579F006F62B3E485508A15107F82EAA297FD983
      SHA-512:FF230D99DDD430C18B96FA5C0C70F221878F916CC00F93EEAC6E2197EB7860141672003C66A7FFD1FD7B9DABCA963B4EDE08333162621D7EC49CF7D053E6E4C4
      Malicious:false
      Reputation:unknown
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.4517106215564621
      Encrypted:false
      SSDEEP:
      MD5:E09F5AE79A5D7546E1E6FC5BA8F4781D
      SHA1:B31FC878A88E4CED2D6F9251D58896128A719BA6
      SHA-256:F115592D00DA009B3CC8ACD884129D05003C5BDE8F9B69DDB96812DAF89122C8
      SHA-512:765ABB3F1F43561399D85D17E4DC9F05032D7DCC42673924332E74906D1160FACEAB934E44ACC75E27D84EB855FE0E6B2C61E74C7D5EB9F4B7A0D30C81EC8CAC
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.5235624318362462
      Encrypted:false
      SSDEEP:
      MD5:1BE52132E8E7574F7DDA561FDFACA09A
      SHA1:D47523693B6AE49286137392D93A4B2807B2FEE9
      SHA-256:02986BFD9018949F33FA78A2779E82975D3A65018F1059EF4E2E3AF489D173F9
      SHA-512:6234DDF08A2631D9B0303546C4A881B393426E54F0D29EEC512EA8F31631CB0B9B20A208DDE5923B9115314130504C7913330E5325055E05B821561EEE12928E
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):512
      Entropy (8bit):0.0
      Encrypted:false
      SSDEEP:
      MD5:BF619EAC0CDF3F68D496EA9344137E8B
      SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
      SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
      SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
      Malicious:false
      Reputation:unknown
      Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):69632
      Entropy (8bit):0.17144352867615023
      Encrypted:false
      SSDEEP:
      MD5:810A425C4FBEC95AE9B8C41E6347C63D
      SHA1:99381198C3D3E37178770B5592BC5C2335231CC1
      SHA-256:329435471F2498EAA5B8DCC8FF30BB16BD6B0A680A3E7ECA06AC002DE12D1DE0
      SHA-512:AD2E91784A2E3E11358B74315ED605D60DAEACE4D3E3D5D1268781A9E74F1CC68DF1DC90D1A2E99C859B4D8EBF2D02E050C529CC5DF007C7DB39633BF502708C
      Malicious:false
      Reputation:unknown
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):20480
      Entropy (8bit):1.635071210955037
      Encrypted:false
      SSDEEP:
      MD5:A10D5078E008F223368D4399AD9FC5F0
      SHA1:92ACA329CD12DAFB3D1B4879140F8A116BDAD700
      SHA-256:C60BCF287D5043D35FD7D2136FB6CE8612EBFE5E26B93FC1C49886A4A50EBA54
      SHA-512:E8CB5EF31C8ABD74F62EAAD89925AD82ED5A423FA8D02DD6E131758F53F3EB1077ACA698D5348B1D8E937938DEDB5EC98E29CCBAA89AD9C9AA61CA7D41B72525
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):69632
      Entropy (8bit):0.29382666246101724
      Encrypted:false
      SSDEEP:
      MD5:CA056EB39445EB90A034A68AC2A25FFF
      SHA1:C5AF4CABEACD22CB81839F715E9EA14F2A66317A
      SHA-256:B06C768B9BB6BEF873B3DE45195F7C350F789BEC179F337BEC0A9A3A56B32131
      SHA-512:8113C9954982E42E0C4D0EA8C9AB065685B7AC9EFF0C344B2FAFF18C68FF63C526ADE5FFD13FD2EA0F6B18D96E3EE2D34ED8C7E3F2CF0FE5D3F260AE487D297F
      Malicious:false
      Reputation:unknown
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:data
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):0.07902550023114197
      Encrypted:false
      SSDEEP:
      MD5:59649C9344A13774D9712223C6C511D6
      SHA1:B41C18ACEB46168C768BE6419CB77EA12D23A5D7
      SHA-256:8C30B92660A7509C2E1EE9EEB6B7E9C6A2065C32AF0064BEA5274CA5FE83E0CA
      SHA-512:D9544B1A9DB2BEB00CC2B8EC15EFFC8E805FF15AC05A9FED64943ABD2F38CEB11E6917D54AC224F646AA5F4AAF6297FDC882F79CC536E60EDE3E764EE18033AE
      Malicious:false
      Reputation:unknown
      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\System32\msiexec.exe
      File Type:Composite Document File V2 Document, Cannot read section info
      Category:dropped
      Size (bytes):32768
      Entropy (8bit):1.3029516112779753
      Encrypted:false
      SSDEEP:
      MD5:0DB26CD861AFC2FB6D1D08553A37366F
      SHA1:6034FCC951836788A373CD922E6A6A4E15125E72
      SHA-256:50CE7A61F09E43E7417E9BFB4243EF01DD5F5C682BF447AAB1E96061087007C9
      SHA-512:5D22DEBA68BF9D67ABC15E81EC8306D8A70F3B1F999B505ACCC23B9D74681E67BBF353A4096F9B3A19A76EC338B408A35EB3CF520975482CB4BFA0D0824DD546
      Malicious:false
      Reputation:unknown
      Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
      Process:C:\Windows\SysWOW64\netsh.exe
      File Type:ASCII text, with CRLF line terminators
      Category:dropped
      Size (bytes):44
      Entropy (8bit):4.073210744553412
      Encrypted:false
      SSDEEP:
      MD5:656D246C6CE9A47F07EC793B6BB27F07
      SHA1:0C098838274F64DBB02500A68B855E6703DDDAF1
      SHA-256:77429FFF9C65F96BC190C4C14916423F0196A2A570970A095285364743172AF4
      SHA-512:9E47C89948CF63770F5E59B793B8625364C9F9B679B80B9CD821ABC9866C0BC23608AEEE9794AC45E547FF11BBD47DA7BDA640D72218507EE2FA9382A9419476
      Malicious:false
      Reputation:unknown
      Preview:..No rules match the specified criteria.....
      File type:PE32 executable (GUI) Intel 80386, for MS Windows
      Entropy (8bit):7.998152165138868
      TrID:
      • Win32 Executable (generic) a (10002005/4) 99.96%
      • Generic Win/DOS Executable (2004/3) 0.02%
      • DOS Executable Generic (2002/1) 0.02%
      • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
      File name:AudioCodesAppSuite.exe
      File size:25'993'192 bytes
      MD5:e8b8f253038fa8d6b0fc92e5e13bc185
      SHA1:2b453e43890063bfa80cbeafaf21128f17d43213
      SHA256:940a36dc38446f4a878b29474138bdf1c8e8faa59a680301456726f937eada80
      SHA512:0901ca6703368c29c9d26b0bd25aca1e040fbbddb9a4d3e783fe195c85a25f3957c942879256daa55aac9169344d266df3492a148aab5cf22f654763d19db8da
      SSDEEP:786432:7pVotqdCTAl3TkhhvC/v1zlGGi0FTgDu/b:D7dfiha/Bl5xFYu/b
      TLSH:9F473332AAA0127AF3F51433896996643E3CB3180B2199ADD7CCEC19BF754D567B3183
      File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......9.o.}k..}k..}k......wk.......k......ek../...nk../...ik../...Vk..t...xk..t...lk..}k..(j......6k......|k..}k...k......|k..Rich}k.
      Icon Hash:2d2e3797b32b2b99
      Entrypoint:0x42df71
      Entrypoint Section:.text
      Digitally signed:true
      Imagebase:0x400000
      Subsystem:windows gui
      Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
      Time Stamp:0x5D807032 [Tue Sep 17 05:33:38 2019 UTC]
      TLS Callbacks:
      CLR (.Net) Version:
      OS Version Major:5
      OS Version Minor:1
      File Version Major:5
      File Version Minor:1
      Subsystem Version Major:5
      Subsystem Version Minor:1
      Import Hash:42d651751c1d75ed4fa8fe71751854ff
      Signature Valid:true
      Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
      Signature Validation Error:The operation completed successfully
      Error Number:0
      Not Before, Not After
      • 01/05/2023 02:00:00 06/05/2026 01:59:59
      Subject Chain
      • CN=AudioCodes Ltd, O=AudioCodes Ltd, L=Tel Aviv-Yafo, C=IL, SERIALNUMBER=520044132, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.3=IL
      Version:3
      Thumbprint MD5:118DE50C691406BB5B471B730AB7F2AB
      Thumbprint SHA-1:8DBCD8FCD62A4A6679565606E8DD7D96256E61CA
      Thumbprint SHA-256:3DB9F88F8D06ED2794FAAF89A5751A078D8190733CEF6AB1FCB6CA88812CE5B9
      Serial:0E6E2800F8865B7F6D49EA8D93BA825E
      Instruction
      call 00007FAC94E7BE5Fh
      jmp 00007FAC94E7B79Fh
      int3
      int3
      int3
      int3
      int3
      mov eax, dword ptr [esp+08h]
      mov ecx, dword ptr [esp+10h]
      or ecx, eax
      mov ecx, dword ptr [esp+0Ch]
      jne 00007FAC94E7B92Bh
      mov eax, dword ptr [esp+04h]
      mul ecx
      retn 0010h
      push ebx
      mul ecx
      mov ebx, eax
      mov eax, dword ptr [esp+08h]
      mul dword ptr [esp+14h]
      add ebx, eax
      mov eax, dword ptr [esp+08h]
      mul ecx
      add edx, ebx
      pop ebx
      retn 0010h
      int3
      int3
      int3
      int3
      int3
      int3
      int3
      int3
      int3
      int3
      int3
      int3
      cmp cl, 00000040h
      jnc 00007FAC94E7B937h
      cmp cl, 00000020h
      jnc 00007FAC94E7B928h
      shrd eax, edx, cl
      shr edx, cl
      ret
      mov eax, edx
      xor edx, edx
      and cl, 0000001Fh
      shr eax, cl
      ret
      xor eax, eax
      xor edx, edx
      ret
      push ebp
      mov ebp, esp
      jmp 00007FAC94E7B92Fh
      push dword ptr [ebp+08h]
      call 00007FAC94E81D08h
      pop ecx
      test eax, eax
      je 00007FAC94E7B931h
      push dword ptr [ebp+08h]
      call 00007FAC94E81D91h
      pop ecx
      test eax, eax
      je 00007FAC94E7B908h
      pop ebp
      ret
      cmp dword ptr [ebp+08h], FFFFFFFFh
      je 00007FAC94E7C224h
      jmp 00007FAC94E7C201h
      push ebp
      mov ebp, esp
      push dword ptr [ebp+08h]
      call 00007FAC94E7C23Dh
      pop ecx
      pop ebp
      ret
      push ebp
      mov ebp, esp
      test byte ptr [ebp+08h], 00000001h
      push esi
      mov esi, ecx
      mov dword ptr [esi], 0046030Ch
      je 00007FAC94E7B92Ch
      push 0000000Ch
      push esi
      call 00007FAC94E7B8FDh
      pop ecx
      Programming Language:
      • [ C ] VS2008 SP1 build 30729
      • [IMP] VS2008 SP1 build 30729
      NameVirtual AddressVirtual Size Is in Section
      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_IMPORT0x680b40xb4.rdata
      IMAGE_DIRECTORY_ENTRY_RESOURCE0x6d0000x3a84.rsrc
      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
      IMAGE_DIRECTORY_ENTRY_SECURITY0x18c76a80x2940
      IMAGE_DIRECTORY_ENTRY_BASERELOC0x710000x3dd0.reloc
      IMAGE_DIRECTORY_ENTRY_DEBUG0x670300x54.rdata
      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
      IMAGE_DIRECTORY_ENTRY_TLS0x670840x18.rdata
      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x66a100x40.rdata
      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
      IMAGE_DIRECTORY_ENTRY_IAT0x4a0000x3e0.rdata
      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x67c340x100.rdata
      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
      .text0x10000x48ff70x49000c66f549d5fc7d10a5f63350701c6b3f9False0.5367883133561644data6.572059575788497IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      .rdata0x4a0000x1f7600x1f8005a2f02dbbbda51cfac50fb52cea6d11bFalse0.30963231646825395data5.137524712720983IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .data0x6a0000x16fc0xa008fe8ba25b04a7beb04c2ab2d5e9ea736False0.27265625data3.1551613029957557IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
      .wixburn0x6c0000x380x200aee7f6d3e6c462aa2a1df8c1620576adFalse0.130859375data0.7382437744532455IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .rsrc0x6d0000x3a840x3c009839863cbd53ac20286ff2c46bd0ca42False0.330859375data5.52925708426747IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
      .reloc0x710000x3dd00x3e007cc10e0060080262550138057fd6b87dFalse0.8069556451612904data6.788270717274864IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
      NameRVASizeTypeLanguageCountryZLIB Complexity
      RT_ICON0x6d1780x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishUnited States0.43185920577617326
      RT_MESSAGETABLE0x6da200x2840dataEnglishUnited States0.28823757763975155
      RT_GROUP_ICON0x702600x14dataEnglishUnited States1.15
      RT_VERSION0x702740x33cdataEnglishUnited States0.428743961352657
      RT_MANIFEST0x705b00x4d2XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (1174), with CRLF line terminatorsEnglishUnited States0.47568881685575365
      DLLImport
      ADVAPI32.dllRegCloseKey, RegOpenKeyExW, OpenProcessToken, AdjustTokenPrivileges, LookupPrivilegeValueW, InitiateSystemShutdownExW, GetUserNameW, RegQueryValueExW, RegDeleteValueW, CloseEventLog, OpenEventLogW, ReportEventW, ConvertStringSecurityDescriptorToSecurityDescriptorW, DecryptFileW, CreateWellKnownSid, InitializeAcl, SetEntriesInAclW, ChangeServiceConfigW, CloseServiceHandle, ControlService, OpenSCManagerW, OpenServiceW, QueryServiceStatus, SetNamedSecurityInfoW, CheckTokenMembership, AllocateAndInitializeSid, SetEntriesInAclA, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegSetValueExW, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, RegDeleteKeyW, RegCreateKeyExW, GetTokenInformation, CryptDestroyHash, CryptHashData, CryptCreateHash, CryptGetHashParam, CryptReleaseContext, CryptAcquireContextW, QueryServiceConfigW
      USER32.dllPeekMessageW, PostMessageW, IsWindow, WaitForInputIdle, PostQuitMessage, GetMessageW, TranslateMessage, MsgWaitForMultipleObjects, PostThreadMessageW, GetMonitorInfoW, MonitorFromPoint, IsDialogMessageW, LoadCursorW, LoadBitmapW, SetWindowLongW, GetWindowLongW, GetCursorPos, MessageBoxW, CreateWindowExW, UnregisterClassW, RegisterClassW, DefWindowProcW, DispatchMessageW
      OLEAUT32.dllVariantInit, SysAllocString, VariantClear, SysFreeString
      GDI32.dllDeleteDC, DeleteObject, SelectObject, StretchBlt, GetObjectW, CreateCompatibleDC
      SHELL32.dllCommandLineToArgvW, SHGetFolderPathW, ShellExecuteExW
      ole32.dllCoUninitialize, CoInitializeEx, CoInitialize, StringFromGUID2, CoCreateInstance, CoTaskMemFree, CLSIDFromProgID, CoInitializeSecurity
      KERNEL32.dllGetCPInfo, GetOEMCP, IsValidCodePage, CloseHandle, CreateFileW, GetProcAddress, LocalFree, HeapSetInformation, GetLastError, GetModuleHandleW, FormatMessageW, lstrlenA, lstrlenW, MultiByteToWideChar, WideCharToMultiByte, LCMapStringW, Sleep, GetLocalTime, GetModuleFileNameW, ExpandEnvironmentStringsW, GetTempPathW, GetTempFileNameW, CreateDirectoryW, GetFullPathNameW, CompareStringW, GetCurrentProcessId, WriteFile, SetFilePointer, LoadLibraryW, GetSystemDirectoryW, CreateFileA, HeapAlloc, HeapReAlloc, HeapFree, HeapSize, GetProcessHeap, FindClose, GetCommandLineA, GetCurrentDirectoryW, RemoveDirectoryW, SetFileAttributesW, GetFileAttributesW, DeleteFileW, FindFirstFileW, FindNextFileW, MoveFileExW, GetCurrentProcess, GetCurrentThreadId, InitializeCriticalSection, DeleteCriticalSection, ReleaseMutex, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, CreateProcessW, GetVersionExW, VerSetConditionMask, FreeLibrary, EnterCriticalSection, LeaveCriticalSection, GetSystemTime, GetNativeSystemInfo, GetModuleHandleExW, GetWindowsDirectoryW, GetSystemWow64DirectoryW, GetCommandLineW, VerifyVersionInfoW, GetVolumePathNameW, GetDateFormatW, GetUserDefaultUILanguage, GetSystemDefaultLangID, GetUserDefaultLangID, GetStringTypeW, ReadFile, SetFilePointerEx, DuplicateHandle, InterlockedExchange, InterlockedCompareExchange, LoadLibraryExW, CreateEventW, ProcessIdToSessionId, OpenProcess, GetProcessId, WaitForSingleObject, ConnectNamedPipe, SetNamedPipeHandleState, CreateNamedPipeW, CreateThread, GetExitCodeThread, SetEvent, WaitForMultipleObjects, InterlockedIncrement, InterlockedDecrement, ResetEvent, SetEndOfFile, SetFileTime, LocalFileTimeToFileTime, DosDateTimeToFileTime, CompareStringA, GetExitCodeProcess, SetThreadExecutionState, CopyFileExW, MapViewOfFile, UnmapViewOfFile, CreateMutexW, CreateFileMappingW, GetThreadLocale, FindFirstFileExW, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetStdHandle, GetConsoleCP, GetConsoleMode, FlushFileBuffers, DecodePointer, WriteConsoleW, GetModuleHandleA, GlobalAlloc, GlobalFree, GetFileSizeEx, CopyFileW, VirtualAlloc, VirtualFree, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, SystemTimeToFileTime, GetSystemInfo, VirtualProtect, VirtualQuery, GetComputerNameW, SetCurrentDirectoryW, GetFileType, GetACP, ExitProcess, GetStdHandle, InitializeCriticalSectionAndSpinCount, SetLastError, RtlUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TerminateProcess, IsProcessorFeaturePresent, QueryPerformanceCounter, GetSystemTimeAsFileTime, InitializeSListHead, IsDebuggerPresent, GetStartupInfoW, RaiseException, LoadLibraryExA
      RPCRT4.dllUuidCreate
      Language of compilation systemCountry where language is spokenMap
      EnglishUnited States