Loading ...

Play interactive tourEdit tour

Windows Analysis Report 35N4PXWcmC.msi

Overview

General Information

Sample Name:35N4PXWcmC.msi
Analysis ID:473965
MD5:82013cf110edfeac59808ca15fac2bee
SHA1:1fa2db4a755db612f6385f325721eb324462de4b
SHA256:af5986b366517ffd2290fa47348243ea53b22105b6160d2a97d0512989feb1f7
Infos:

Most interesting Screenshot:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Tries to load missing DLLs
Sample execution stops while process was sleeping (likely an evasion)
JA3 SSL client fingerprint seen in connection with other malware
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
Checks for available system drives (often done to infect USB drives)
Creates a process in suspended mode (likely to inject code)

Classification

Process Tree

  • System is w10x64
  • msiexec.exe (PID: 6916 cmdline: 'C:\Windows\System32\msiexec.exe' /i 'C:\Users\user\Desktop\35N4PXWcmC.msi' MD5: 4767B71A318E201188A0D0A420C8B608)
  • msiexec.exe (PID: 6676 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding CE54F576F3746C389F9942FCF9B3593A MD5: 12C17B5A5C2A7B97342C362CA467E9A2)
    • WMIC.exe (PID: 6388 cmdline: wmic OS get Caption/Format:List MD5: 79A01FCD1C8166C5642F37D1E0FB7BA8)
      • conhost.exe (PID: 6416 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

AV Detection:

barindex
Multi AV Scanner detection for submitted fileShow sources
Source: 35N4PXWcmC.msiReversingLabs: Detection: 50%
Source: unknownHTTPS traffic detected: 162.125.65.18:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.125.65.15:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: Binary string: C:\JobRelease\win\Release\custact\x86\AICustAct.pdb source: 35N4PXWcmC.msi
Source: Binary string: C:\JobRelease\win\Release\custact\x86\AICustAct.pdbg source: 35N4PXWcmC.msi
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile opened: c:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: Joe Sandbox ViewJA3 fingerprint: ce5f3254611a8c095a3d821d44539877
Source: unknownNetwork traffic detected: HTTP traffic on port 49736 -> 443
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49737
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49736
Source: unknownNetwork traffic detected: HTTP traffic on port 49737 -> 443
Source: 35N4PXWcmC.msiString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
Source: 35N4PXWcmC.msiString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
Source: 35N4PXWcmC.msiString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
Source: 35N4PXWcmC.msiString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
Source: 35N4PXWcmC.msiString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
Source: 35N4PXWcmC.msiString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
Source: 35N4PXWcmC.msiString found in binary or memory: http://ocsp.digicert.com0C
Source: 35N4PXWcmC.msiString found in binary or memory: http://ocsp.digicert.com0O
Source: 35N4PXWcmC.msiString found in binary or memory: http://t1.symcb.com/ThawtePCA.crl0
Source: 35N4PXWcmC.msiString found in binary or memory: http://t2.symcb.com0
Source: 35N4PXWcmC.msiString found in binary or memory: http://tl.symcb.com/tl.crl0
Source: 35N4PXWcmC.msiString found in binary or memory: http://tl.symcb.com/tl.crt0
Source: 35N4PXWcmC.msiString found in binary or memory: http://tl.symcd.com0&
Source: 35N4PXWcmC.msiString found in binary or memory: http://www.digicert.com/CPS0
Source: 35N4PXWcmC.msiString found in binary or memory: https://www.advancedinstaller.com
Source: 35N4PXWcmC.msiString found in binary or memory: https://www.digicert.com/CPS0
Source: 35N4PXWcmC.msiString found in binary or memory: https://www.thawte.com/cps0/
Source: 35N4PXWcmC.msiString found in binary or memory: https://www.thawte.com/repository0W
Source: unknownDNS traffic detected: queries for: www.dropbox.com
Source: unknownHTTPS traffic detected: 162.125.65.18:443 -> 192.168.2.4:49736 version: TLS 1.2
Source: unknownHTTPS traffic detected: 162.125.65.15:443 -> 192.168.2.4:49737 version: TLS 1.2
Source: 35N4PXWcmC.msiBinary or memory string: OriginalFilenameAICustAct.dllF vs 35N4PXWcmC.msi
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dllJump to behavior
Source: 35N4PXWcmC.msiReversingLabs: Detection: 50%
Source: C:\Windows\SysWOW64\wbem\WMIC.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Windows\System32\msiexec.exe 'C:\Windows\System32\msiexec.exe' /i 'C:\Users\user\Desktop\35N4PXWcmC.msi'
Source: unknownProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding CE54F576F3746C389F9942FCF9B3593A
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic OS get Caption/Format:List
Source: C:\Windows\SysWOW64\wbem\WMIC.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic OS get Caption/Format:ListJump to behavior
Source: 35N4PXWcmC.msiStatic file information: TRID: Microsoft Windows Installer (77509/1) 43.40%
Source: C:\Windows\SysWOW64\wbem\WMIC.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32Jump to behavior
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6416:120:WilError_01
Source: classification engineClassification label: mal48.winMSI@5/0@2/2
Source: C:\Windows\SysWOW64\msiexec.exeFile read: C:\Users\desktop.iniJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeFile read: C:\Windows\System32\drivers\etc\hostsJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeWindow found: window name: TComboBoxJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: 35N4PXWcmC.msiStatic file information: File size 9071616 > 1048576
Source: Binary string: C:\JobRelease\win\Release\custact\x86\AICustAct.pdb source: 35N4PXWcmC.msi
Source: Binary string: C:\JobRelease\win\Release\custact\x86\AICustAct.pdbg source: 35N4PXWcmC.msi
Source: C:\Windows\SysWOW64\msiexec.exeRegistry key monitored for changes: HKEY_CURRENT_USER_ClassesJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\SysWOW64\wbem\WMIC.exe wmic OS get Caption/Format:ListJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Replication Through Removable Media1Windows Management InstrumentationDLL Side-Loading1Process Injection11Process Injection11OS Credential DumpingQuery Registry1Replication Through Removable Media1Data from Local SystemExfiltration Over Other Network MediumEncrypted Channel2Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsScheduled Task/JobBoot or Logon Initialization ScriptsDLL Side-Loading1DLL Side-Loading1LSASS MemoryPeripheral Device Discovery11Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothNon-Application Layer Protocol1Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerFile and Directory Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationApplication Layer Protocol2Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Information Discovery12Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud AccountsCronNetwork Logon ScriptNetwork Logon ScriptSoftware PackingLSA SecretsRemote System Discovery1SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 signatures2 2 Behavior Graph ID: 473965 Sample: 35N4PXWcmC.msi Startdate: 30/08/2021 Architecture: WINDOWS Score: 48 22 Multi AV Scanner detection for submitted file 2->22 7 msiexec.exe 3 1 2->7         started        10 msiexec.exe 2 2->10         started        process3 dnsIp4 16 edge-block-www-env.dropbox-dns.com 162.125.65.15, 443, 49737 DROPBOXUS United States 7->16 18 www-env.dropbox-dns.com 162.125.65.18, 443, 49736 DROPBOXUS United States 7->18 20 2 other IPs or domains 7->20 12 WMIC.exe 1 7->12         started        process5 process6 14 conhost.exe 12->14         started       

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
35N4PXWcmC.msi6%MetadefenderBrowse
35N4PXWcmC.msi50%ReversingLabsWin32.Infostealer.ClipBanker

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

NameIPActiveMaliciousAntivirus DetectionReputation
edge-block-www-env.dropbox-dns.com
162.125.65.15
truefalse
    unknown
    www-env.dropbox-dns.com
    162.125.65.18
    truefalse
      unknown
      ucdd2fc710a0d9b0bc926ff3d256.dl.dropboxusercontent.com
      unknown
      unknownfalse
        high
        www.dropbox.com
        unknown
        unknownfalse
          high

          URLs from Memory and Binaries

          NameSourceMaliciousAntivirus DetectionReputation
          https://www.advancedinstaller.com35N4PXWcmC.msifalse
            high
            https://www.thawte.com/cps0/35N4PXWcmC.msifalse
              high
              https://www.thawte.com/repository0W35N4PXWcmC.msifalse
                high

                Contacted IPs

                • No. of IPs < 25%
                • 25% < No. of IPs < 50%
                • 50% < No. of IPs < 75%
                • 75% < No. of IPs

                Public

                IPDomainCountryFlagASNASN NameMalicious
                162.125.65.15
                edge-block-www-env.dropbox-dns.comUnited States
                19679DROPBOXUSfalse
                162.125.65.18
                www-env.dropbox-dns.comUnited States
                19679DROPBOXUSfalse

                General Information

                Joe Sandbox Version:33.0.0 White Diamond
                Analysis ID:473965
                Start date:30.08.2021
                Start time:14:22:48
                Joe Sandbox Product:CloudBasic
                Overall analysis duration:0h 5m 0s
                Hypervisor based Inspection enabled:false
                Report type:full
                Sample file name:35N4PXWcmC.msi
                Cookbook file name:default.jbs
                Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                Number of analysed new started processes analysed:20
                Number of new started drivers analysed:0
                Number of existing processes analysed:0
                Number of existing drivers analysed:0
                Number of injected processes analysed:0
                Technologies:
                • HCA enabled
                • EGA enabled
                • HDC enabled
                • AMSI enabled
                Analysis Mode:default
                Analysis stop reason:Timeout
                Detection:MAL
                Classification:mal48.winMSI@5/0@2/2
                EGA Information:Failed
                HDC Information:Failed
                HCA Information:
                • Successful, ratio: 100%
                • Number of executed functions: 0
                • Number of non-executed functions: 0
                Cookbook Comments:
                • Adjust boot time
                • Enable AMSI
                • Found application associated with file extension: .msi
                Warnings:
                Show All
                • Exclude process from analysis (whitelisted): BackgroundTransferHost.exe, backgroundTaskHost.exe, svchost.exe, wuapihost.exe
                • Excluded IPs from analysis (whitelisted): 51.104.136.2, 23.211.6.115, 20.82.210.154, 20.72.88.19, 40.112.88.60, 67.27.158.254, 8.253.204.121, 67.27.233.254, 67.26.83.254, 8.253.95.249, 20.50.102.62, 80.67.82.235, 80.67.82.211
                • Excluded domains from analysis (whitelisted): displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, ris-prod.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, settings-win.data.microsoft.com, store-images.s-microsoft.com-c.edgekey.net, ctldl.windowsupdate.com, iris-de-prod-azsc-neu-b.northeurope.cloudapp.azure.com, consumerrp-displaycatalog-aks2aks-europe.md.mp.microsoft.com.akadns.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, a1449.dscg2.akamai.net, arc.msn.com, consumerrp-displaycatalog-aks2eap-europe.md.mp.microsoft.com.akadns.net, settingsfd-geo.trafficmanager.net, eus2-consumerrp-displaycatalog-aks2aks-useast.md.mp.microsoft.com.akadns.net, ris.api.iris.microsoft.com, e12564.dspb.akamaiedge.net, store-images.s-microsoft.com, audownload.windowsupdate.nsatc.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, auto.au.download.windowsupdate.com.c.footprint.net, img-prod-cms-rt-microsoft-com.akamaized.net, au-bg-shim.trafficmanager.net, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                • Not all processes where analyzed, report is missing behavior information
                • Report size getting too big, too many NtOpenKeyEx calls found.
                • VT rate limit hit for: /opt/package/joesandbox/database/analysis/473965/sample/35N4PXWcmC.msi

                Simulations

                Behavior and APIs

                TimeTypeDescription
                14:23:47API Interceptor1x Sleep call for process: WMIC.exe modified

                Joe Sandbox View / Context

                IPs

                No context

                Domains

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                edge-block-www-env.dropbox-dns.com0195+judiciario+0048+_22208202101UCwJ.msiGet hashmaliciousBrowse
                • 162.125.69.15
                QjG40uXnZR.exeGet hashmaliciousBrowse
                • 162.125.66.15
                Schoeller-Bleckmann Oilfield Equipment AG - EFT.REMITTANCE77252177282021.htmGet hashmaliciousBrowse
                • 162.125.69.15
                Hola-Setup-Abexeoff-Agreed.exeGet hashmaliciousBrowse
                • 162.125.66.15
                2YNXbr8FtP.exeGet hashmaliciousBrowse
                • 162.125.66.15
                Fences3-sd-setup.exeGet hashmaliciousBrowse
                • 162.125.66.15
                jfidler@fultonbank.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                cgates@fult.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                test.htmlGet hashmaliciousBrowse
                • 162.125.66.15
                ausgangsrechnung@condor.com_ProjectDocument.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                x6I8ze0ztQ.exeGet hashmaliciousBrowse
                • 162.125.69.15
                rklein@vertexeng.com_80280265Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                AWB783079370872.docmGet hashmaliciousBrowse
                • 162.125.66.15
                y0CRLCaQxA.exeGet hashmaliciousBrowse
                • 162.125.66.15
                Roomimglist Para Reserva.vbsGet hashmaliciousBrowse
                • 162.125.66.15
                https://www.dropbox.com/s/1jk3ia2o2kx0p1n/Invitation_2036.doc?dl=1Get hashmaliciousBrowse
                • 162.125.67.15
                https://uc7b53be34470077fa5a225e12df.dl.dropboxusercontent.com/cd/0/get/BFOurBML9LTrYESsgZVnt-7s_XcT1zeXR_UKUe727s4pkHr9HASCTbLCGqW4UetiP2mCY9lexFN5bUjD5CxShlCu3wHWVLxNCOSCmgAvE_LtIaQIjaEAJPiqPF2MmSeHZlw/file?dl=1Get hashmaliciousBrowse
                • 162.125.66.15
                yorkcountygov.comPaymentCopy.htmGet hashmaliciousBrowse
                • 162.125.66.15
                https://ucf2e159dcdc627dd91c5955a5b2.dl.dropboxusercontent.com/cd/0/get/BFIJR_DLx5TrpQ0LUrIdtB-TiMb8hXWBtyaxeUO96o9pDO2kuhn8C1M100sfcNRduSe85JbdWYokMfX07myXHHCiJews_d8d9AU4Vbqsj4mNqfzUgaLCJ-Q80my2kOBIkNQ/file?dl=1Get hashmaliciousBrowse
                • 162.125.66.15
                digiturk.com.trPaymentCopy.htmGet hashmaliciousBrowse
                • 162.125.66.15
                www-env.dropbox-dns.comSWIFT CONFIRMATION COPY.xlsmGet hashmaliciousBrowse
                • 162.125.69.18
                0195+judiciario+0048+_22208202101UCwJ.msiGet hashmaliciousBrowse
                • 162.125.69.18
                QjG40uXnZR.exeGet hashmaliciousBrowse
                • 162.125.66.15
                Schoeller-Bleckmann Oilfield Equipment AG - EFT.REMITTANCE77252177282021.htmGet hashmaliciousBrowse
                • 162.125.69.15
                Payment_Advice.docGet hashmaliciousBrowse
                • 162.125.66.18
                Hola-Setup-Abexeoff-Agreed.exeGet hashmaliciousBrowse
                • 162.125.66.18
                2YNXbr8FtP.exeGet hashmaliciousBrowse
                • 162.125.66.18
                UtCpzrmwGu.exeGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                de725d13_by_Libranalysis.exeGet hashmaliciousBrowse
                • 162.125.66.18
                MUrCVpcnKl3TR9r.exeGet hashmaliciousBrowse
                • 162.125.66.18
                Fences3-sd-setup.exeGet hashmaliciousBrowse
                • 162.125.66.15
                jfidler@fultonbank.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                cgates@fult.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                test.htmlGet hashmaliciousBrowse
                • 162.125.66.15
                ausgangsrechnung@condor.com_ProjectDocument.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                bootlocker.exeGet hashmaliciousBrowse
                • 162.125.66.18
                VESSELS DETAILS.exeGet hashmaliciousBrowse
                • 162.125.66.18

                ASN

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                DROPBOXUSSWIFT CONFIRMATION COPY.xlsmGet hashmaliciousBrowse
                • 162.125.69.18
                0195+judiciario+0048+_22208202101UCwJ.msiGet hashmaliciousBrowse
                • 162.125.69.15
                QjG40uXnZR.exeGet hashmaliciousBrowse
                • 162.125.66.15
                tajmWT78GhGet hashmaliciousBrowse
                • 162.125.153.90
                Schoeller-Bleckmann Oilfield Equipment AG - EFT.REMITTANCE77252177282021.htmGet hashmaliciousBrowse
                • 162.125.69.15
                d8dgn3wGJLGet hashmaliciousBrowse
                • 162.125.189.94
                Payment_Advice.docGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                TrueKey.exeGet hashmaliciousBrowse
                • 162.125.66.14
                N7ECQG6IZu.exeGet hashmaliciousBrowse
                • 162.125.66.14
                7HrLQSNR5v.exeGet hashmaliciousBrowse
                • 162.125.66.14
                Qgc2Nreer3.exeGet hashmaliciousBrowse
                • 162.125.66.18
                de725d13_by_Libranalysis.exeGet hashmaliciousBrowse
                • 162.125.66.18
                MUrCVpcnKl3TR9r.exeGet hashmaliciousBrowse
                • 162.125.66.18
                jfidler@fultonbank.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                cgates@fult.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                test.htmlGet hashmaliciousBrowse
                • 162.125.66.15
                ausgangsrechnung@condor.com_ProjectDocument.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                DROPBOXUSSWIFT CONFIRMATION COPY.xlsmGet hashmaliciousBrowse
                • 162.125.69.18
                0195+judiciario+0048+_22208202101UCwJ.msiGet hashmaliciousBrowse
                • 162.125.69.15
                QjG40uXnZR.exeGet hashmaliciousBrowse
                • 162.125.66.15
                tajmWT78GhGet hashmaliciousBrowse
                • 162.125.153.90
                Schoeller-Bleckmann Oilfield Equipment AG - EFT.REMITTANCE77252177282021.htmGet hashmaliciousBrowse
                • 162.125.69.15
                d8dgn3wGJLGet hashmaliciousBrowse
                • 162.125.189.94
                Payment_Advice.docGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                PRODUCT.xlsmGet hashmaliciousBrowse
                • 162.125.66.18
                TrueKey.exeGet hashmaliciousBrowse
                • 162.125.66.14
                N7ECQG6IZu.exeGet hashmaliciousBrowse
                • 162.125.66.14
                7HrLQSNR5v.exeGet hashmaliciousBrowse
                • 162.125.66.14
                Qgc2Nreer3.exeGet hashmaliciousBrowse
                • 162.125.66.18
                de725d13_by_Libranalysis.exeGet hashmaliciousBrowse
                • 162.125.66.18
                MUrCVpcnKl3TR9r.exeGet hashmaliciousBrowse
                • 162.125.66.18
                jfidler@fultonbank.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                cgates@fult.com_63963965Application.HTMLGet hashmaliciousBrowse
                • 162.125.66.15
                test.htmlGet hashmaliciousBrowse
                • 162.125.66.15
                ausgangsrechnung@condor.com_ProjectDocument.HTMLGet hashmaliciousBrowse
                • 162.125.66.15

                JA3 Fingerprints

                MatchAssociated Sample Name / URLSHA 256DetectionLinkContext
                ce5f3254611a8c095a3d821d44539877P9SKP1tr9T.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                6x0rVsO6SM.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                P9SKP1tr9T.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                6x0rVsO6SM.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                ATTzc6pREK.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                N47g2R8WZi.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                0xCDByczSX.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                N47g2R8WZi.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                wWePpFLkJN.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                0xCDByczSX.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                3eb7ffbfa401fcfac54abc23f156c158739984ef654d8.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                wWePpFLkJN.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                YrR6WKxtKV.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                YrR6WKxtKV.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                Fb7ZwGygGK.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                243afbc5dfb2ce1b27d5c1b92c82f6b8e37234368d2cb.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                Fb7ZwGygGK.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                243afbc5dfb2ce1b27d5c1b92c82f6b8e37234368d2cb.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                9L66vvHkzN.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18
                9L66vvHkzN.exeGet hashmaliciousBrowse
                • 162.125.65.15
                • 162.125.65.18

                Dropped Files

                No context

                Created / dropped Files

                No created / dropped files found

                Static File Info

                General

                File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, MSI Installer, Last Printed: Fri Dec 11 11:47:44 2009, Create Time/Date: Fri Dec 11 11:47:44 2009, Last Saved Time/Date: Fri Sep 18 15:06:51 2020, Security: 0, Code page: 1252, Revision Number: {D30C6F8A-FA01-4532-941E-23CD4836B0B1}, Number of Words: 10, Subject: Visual C++ 2019 X64 Additional Runtime, Author: Visual C++ 2019 X64 Additional Runtime, Name of Creating Application: Advanced Installer 18.1.1 build 4b2255d8, Template: ;1033, Title: Installation Database, Keywords: Installer, MSI, Database, Number of Pages: 200
                Entropy (8bit):7.461939743498868
                TrID:
                • Microsoft Windows Installer (77509/1) 43.40%
                • Windows SDK Setup Transform Script (63028/2) 35.29%
                • Microsoft Excel sheet (30009/1) 16.80%
                • Generic OLE2 / Multistream Compound File (8008/1) 4.48%
                • Corel Photo Paint (41/41) 0.02%
                File name:35N4PXWcmC.msi
                File size:9071616
                MD5:82013cf110edfeac59808ca15fac2bee
                SHA1:1fa2db4a755db612f6385f325721eb324462de4b
                SHA256:af5986b366517ffd2290fa47348243ea53b22105b6160d2a97d0512989feb1f7
                SHA512:078c7bafb0e774e3a3d5ee61c679431f8a0599bee9912312e6d28beaf04b2614cf9be73c59c2323d088581fe2612317f96f6b6901ff3fc034664d559b50d397d
                SSDEEP:196608:dkxY9gQLJQLzQLIQLfQLtQLSowWSKf0K:dkxY9gks/qYBWSKf0K
                File Content Preview:........................>.......................................................w...x...y...z...{...|...}...~..................................................................................................................................................

                File Icon

                Icon Hash:a2a0b496b2caca72

                Static OLE Info

                General

                Document Type:OLE
                Number of OLE Files:1

                OLE File "35N4PXWcmC.msi"

                Indicators

                Has Summary Info:True
                Application Name:Advanced Installer 18.1.1 build 4b2255d8
                Encrypted Document:False
                Contains Word Document Stream:False
                Contains Workbook/Book Stream:False
                Contains PowerPoint Document Stream:False
                Contains Visio Document Stream:False
                Contains ObjectPool Stream:
                Flash Objects Count:
                Contains VBA Macros:False

                Summary

                Code Page:1252
                Title:Installation Database
                Subject:Visual C++ 2019 X64 Additional Runtime
                Author:Visual C++ 2019 X64 Additional Runtime
                Keywords:Installer, MSI, Database
                Comments:
                Template:;1033
                Last Saved By:
                Revion Number:{D30C6F8A-FA01-4532-941E-23CD4836B0B1}
                Last Printed:2009-12-11 11:47:44.850000
                Create Time:2009-12-11 11:47:44.850000
                Last Saved Time:2020-09-18 14:06:51.913000
                Number of Pages:200
                Number of Words:10
                Creating Application:Advanced Installer 18.1.1 build 4b2255d8
                Security:0

                Streams

                Stream Path: \x5SummaryInformation, File Type: data, Stream Size: 556
                General
                Stream Path:\x5SummaryInformation
                File Type:data
                Stream Size:556
                Entropy:4.53537473067
                Base64 Encoded:True
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . O h . . . . . + ' . . 0 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . . . . . . . T . . . . . . . ` . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . @ . . . # . . W z . . @ . . . # . . W z . . @ . . . . _ . . . . . . . . . . . . . . . . . . . . . . . . . . ' . . . { D 3 0 C 6 F 8 A - F A
                Data Raw:fe ff 00 00 0a 00 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 00 e0 85 9f f2 f9 4f 68 10 ab 91 08 00 2b 27 b3 d9 30 00 00 00 fc 01 00 00 10 00 00 00 0b 00 00 00 88 00 00 00 0c 00 00 00 94 00 00 00 0d 00 00 00 a0 00 00 00 13 00 00 00 ac 00 00 00 01 00 00 00 b4 00 00 00 09 00 00 00 bc 00 00 00 0f 00 00 00 ec 00 00 00 03 00 00 00 f4 00 00 00 04 00 00 00 24 01 00 00
                Stream Path: \x17163\x16689\x18229\x15870\x18088, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318
                General
                Stream Path:\x17163\x16689\x18229\x15870\x18088
                File Type:MS Windows icon resource - 1 icon, 16x16, 16 colors
                Stream Size:318
                Entropy:2.03444158006
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . ( . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:00 00 01 00 01 00 10 10 10 00 00 00 00 00 28 01 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 00 00 ff 00 ff 00 ff ff 00 00 ff ff ff 00 00 00
                Stream Path: \x17163\x16689\x18229\x16318\x18483, File Type: MS Windows icon resource - 1 icon, 16x16, 16 colors, Stream Size: 318
                General
                Stream Path:\x17163\x16689\x18229\x16318\x18483
                File Type:MS Windows icon resource - 1 icon, 16x16, 16 colors
                Stream Size:318
                Entropy:2.03693614652
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . ( . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:00 00 01 00 01 00 10 10 10 00 00 00 00 00 28 01 00 00 16 00 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00 00 00 ff 00 ff 00 ff ff 00 00 ff ff ff 00 00 00
                Stream Path: \x17163\x16689\x18229\x16702\x16812\x17848\x16695\x17894\x16894\x17391, File Type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, Stream Size: 385960
                General
                Stream Path:\x17163\x16689\x18229\x16702\x16812\x17848\x16695\x17894\x16894\x17391
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Stream Size:385960
                Entropy:6.40538671056
                Base64 Encoded:True
                Data ASCII:M Z . . . . . . . . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . L . ! T h i s p r o g r a m c a n n o t b e r u n i n D O S m o d e . . . . $ . . . . . . . . . { . . . . . . . . . . . . . . . . . . . . . . . . . ? . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . C . . . . . . . C . . . . . . . C . . . . . . . . . . . . . . . C . . . . . . .
                Data Raw:4d 5a 90 00 03 00 00 00 04 00 00 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 10 01 00 00 0e 1f ba 0e 00 b4 09 cd 21 b8 01 4c cd 21 54 68 69 73 20 70 72 6f 67 72 61 6d 20 63 61 6e 6e 6f 74 20 62 65 20 72 75 6e 20 69 6e 20 44 4f 53 20 6d 6f 64 65 2e 0d 0d 0a 24 00 00 00 00 00 00 00
                Stream Path: \x17163\x16689\x18229\x16766\x17508\x16945\x18485, File Type: JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 500x59, frames 3, Stream Size: 2818
                General
                Stream Path:\x17163\x16689\x18229\x16766\x17508\x16945\x18485
                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, baseline, precision 8, 500x59, frames 3
                Stream Size:2818
                Entropy:7.55703063679
                Base64 Encoded:True
                Data ASCII:. . . . . . J F I F . . . . . . . . . . . . . C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . $ . ' " , # . . ( 7 ) , 0 1 4 4 4 . ' 9 = 8 2 < . 3 4 2 . . . C . . . . . . . . . . . 2 ! . ! 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 2 . . . . . . ; . . . . " . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . } . . . . . . . . ! 1 A . . Q a . " q . 2 . . . . #
                Data Raw:ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 08 06 06 07 06 05 08 07 07 07 09 09 08 0a 0c 14 0d 0c 0b 0b 0c 19 12 13 0f 14 1d 1a 1f 1e 1d 1a 1c 1c 20 24 2e 27 20 22 2c 23 1c 1c 28 37 29 2c 30 31 34 34 34 1f 27 39 3d 38 32 3c 2e 33 34 32 ff db 00 43 01 09 09 09 0c 0b 0c 18 0d 0d 18 32 21 1c 21 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32 32
                Stream Path: \x17163\x16689\x18229\x16830\x16880\x17199\x17329\x17764\x17589\x18490, File Type: MS Windows icon resource - 3 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel, Stream Size: 2862
                General
                Stream Path:\x17163\x16689\x18229\x16830\x16880\x17199\x17329\x17764\x17589\x18490
                File Type:MS Windows icon resource - 3 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel
                Stream Size:2862
                Entropy:3.16043065194
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . ( . . . 6 . . . . . . . . . . . h . . . ^ . . . . . . . . . . h . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w v . . . . . " " " " " o . . " " " " " o . . w w w " " . . . . . . " / . . . .
                Data Raw:00 00 01 00 03 00 10 10 10 00 00 00 04 00 28 01 00 00 36 00 00 00 10 10 00 00 00 00 08 00 68 05 00 00 5e 01 00 00 10 10 00 00 00 00 20 00 68 04 00 00 c6 06 00 00 28 00 00 00 10 00 00 00 20 00 00 00 01 00 04 00 00 00 00 00 80 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 80 80 80 00 c0 c0
                Stream Path: \x17163\x16689\x18229\x16830\x17458\x17395\x17896\x18476, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998
                General
                Stream Path:\x17163\x16689\x18229\x16830\x17458\x17395\x17896\x18476
                File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32
                Stream Size:2998
                Entropy:4.35906224297
                Base64 Encoded:True
                Data ASCII:. . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . . . . p . . . . . . . . . . x . { . w p . . . . . . . . . . . . { . w . . . . . . . .
                Data Raw:00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00
                Stream Path: \x17163\x16689\x18229\x16830\x17848\x17207\x17574\x18481, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998
                General
                Stream Path:\x17163\x16689\x18229\x16830\x17848\x17207\x17574\x18481
                File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32
                Stream Size:2998
                Entropy:4.29856879699
                Base64 Encoded:True
                Data ASCII:. . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . . . . p . . . . . . . . . . x . { . w p . . . . . . . . . . . . { . w . . . . . . . .
                Data Raw:00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00
                Stream Path: \x17163\x16689\x18229\x16894\x16684\x17583\x18474, File Type: JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x316, frames 3, Stream Size: 11791
                General
                Stream Path:\x17163\x16689\x18229\x16894\x16684\x17583\x18474
                File Type:JPEG image data, JFIF standard 1.01, aspect ratio, density 1x1, segment length 16, progressive, precision 8, 500x316, frames 3
                Stream Size:11791
                Entropy:7.71486251579
                Base64 Encoded:True
                Data ASCII:. . . . . . J F I F . . . . . . . . . . . . . C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . C . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . < . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . s .
                Data Raw:ff d8 ff e0 00 10 4a 46 49 46 00 01 01 00 00 01 00 01 00 00 ff db 00 43 00 04 02 03 03 03 02 04 03 03 03 04 04 04 04 05 09 06 05 05 05 05 0b 08 08 06 09 0d 0b 0d 0d 0d 0b 0c 0c 0e 10 14 11 0e 0f 13 0f 0c 0c 12 18 12 13 15 16 17 17 17 0e 11 19 1b 19 16 1a 14 16 17 16 ff db 00 43 01 04 04 04 05 05 05 0a 06 06 0a 16 0f 0c 0f 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16 16
                Stream Path: \x17163\x16689\x18229\x16958\x16827\x16687\x17200\x18470, File Type: MS Windows icon resource - 1 icon, 32x32, 16 colors, Stream Size: 766
                General
                Stream Path:\x17163\x16689\x18229\x16958\x16827\x16687\x17200\x18470
                File Type:MS Windows icon resource - 1 icon, 32x32, 16 colors
                Stream Size:766
                Entropy:3.3484862649
                Base64 Encoded:True
                Data ASCII:. . . . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 3 1 . . . . . . . . . . . . 3 3 2 3 3 3 3 3 3 3 3 3 3 3 3 . 3 3 $ D D D D D D D D D D D @ 1 . 2 D D D D D D D D D D D D D . . 2 D D D D D D @ D D D D D D C . 2 D D D D D D 3 4 D D D D D C . 2 D D D D D @ 3 0 D D D D D . . 3 $ D D D D D 3 4 D D D D D 1 . 3 $
                Data Raw:00 00 01 00 01 00 20 20 10 00 00 00 00 00 e8 02 00 00 16 00 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 c0 c0 c0 00 80 80 80 00 00 80 80 00 00 00 00 00 00 ff ff 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 33 33
                Stream Path: \x17163\x16689\x18229\x17150\x14528\x14965\x17667\x17195\x17383\x14378\x17075\x17779\x16894\x17391, File Type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, Stream Size: 8458240
                General
                Stream Path:\x17163\x16689\x18229\x17150\x14528\x14965\x17667\x17195\x17383\x14378\x17075\x17779\x16894\x17391
                File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                Stream Size:8458240
                Entropy:7.52105426672
                Base64 Encoded:True
                Data ASCII:M Z P . . . . . . . . . . . . . . . . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . L . ! . . T h i s p r o g r a m m u s t b e r u n u n d e r W i n 3 2 . . $ 7 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:4d 5a 50 00 02 00 00 00 04 00 0f 00 ff ff 00 00 b8 00 00 00 00 00 00 00 40 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 01 00 00 ba 10 00 0e 1f b4 09 cd 21 b8 01 4c cd 21 90 90 54 68 69 73 20 70 72 6f 67 72 61 6d 20 6d 75 73 74 20 62 65 20 72 75 6e 20 75 6e 64 65 72 20 57 69 6e 33 32 0d 0a 24 37 00 00 00 00 00 00 00 00
                Stream Path: \x17163\x16689\x18229\x17214\x17009\x18482, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors, Stream Size: 1078
                General
                Stream Path:\x17163\x16689\x18229\x17214\x17009\x18482
                File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors
                Stream Size:1078
                Entropy:2.86422695486
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . & . . . . . . . . . . . ( . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . w p . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . p . . . . . . . . . . w w . . . w w . . . . . .
                Data Raw:00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 10 10 10 00 00 00 00 00 28 01 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 80 80 80 00 c0 c0 c0 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00
                Stream Path: \x17163\x16689\x18229\x17214\x17841\x17207\x17574\x18481, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998
                General
                Stream Path:\x17163\x16689\x18229\x17214\x17841\x17207\x17574\x18481
                File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32
                Stream Size:2998
                Entropy:4.40653521205
                Base64 Encoded:True
                Data ASCII:. . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . w . . . . . . . . . . p . . x . . . . w . . . . . . . . x . . . w . . w . . . . . . . p . . x x . . w ~ . . . . . . . . x . . . . . ~ . . . . . . .
                Data Raw:00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00
                Stream Path: \x17163\x16689\x18229\x17790\x17448\x18034\x16812\x18482, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998
                General
                Stream Path:\x17163\x16689\x18229\x17790\x17448\x18034\x16812\x18482
                File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32
                Stream Size:2998
                Entropy:4.92283562852
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . p . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . w w . . . . . . . . . . . . w . f . w . . . . . . w . . . . . v v f . w . . . . . . . . . . . n f f l . w . . . .
                Data Raw:00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00
                Stream Path: \x17163\x16689\x18229\x17790\x17640\x17188\x17205\x18470, File Type: MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32, Stream Size: 2998
                General
                Stream Path:\x17163\x16689\x18229\x17790\x17640\x17188\x17205\x18470
                File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 32x32
                Stream Size:2998
                Entropy:4.6676615263
                Base64 Encoded:True
                Data ASCII:. . . . . . . . . . . . . . . . & . . . . . . . . . . . . . . . . . ( . . . . . . @ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . w . . . . . . . . . . . . . . . . { . . . . . . . . . . . . . . . . . . p . . . . . . . . . . x . { . w p . . . . . . . . ( . . . { . w . . . . . . . . . ( x x x . . . . . . . . . . .
                Data Raw:00 00 01 00 02 00 20 20 10 00 00 00 00 00 e8 02 00 00 26 00 00 00 20 20 00 00 00 00 00 00 a8 08 00 00 0e 03 00 00 28 00 00 00 20 00 00 00 40 00 00 00 01 00 04 00 00 00 00 00 80 02 00 00 00 00 00 00 00 00 00 00 10 00 00 00 00 00 00 00 00 00 00 00 00 00 80 00 00 80 00 00 00 80 80 00 80 00 00 00 80 00 80 00 80 80 00 00 c0 c0 c0 00 80 80 80 00 00 00 ff 00 00 ff 00 00 00 ff ff 00 ff 00
                Stream Path: \x17163\x16689\x18229\x17918\x16740\x16677\x17318, File Type: PC bitmap, Windows 3.x format, 1 x 200 x 24, Stream Size: 854
                General
                Stream Path:\x17163\x16689\x18229\x17918\x16740\x16677\x17318
                File Type:PC bitmap, Windows 3.x format, 1 x 200 x 24
                Stream Size:854
                Entropy:3.80253159876
                Base64 Encoded:False
                Data ASCII:B M V . . . . . . . 6 . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:42 4d 56 03 00 00 00 00 00 00 36 00 00 00 28 00 00 00 01 00 00 00 c8 00 00 00 01 00 18 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ee f3 f4 00 ef f3 f4 00 ef f3 f4 00 ef f3 f4 00 ef f4 f4 00 ef f4 f4 00 ef f4 f5 00 ef f4 f5 00 ef f4 f5 00 ef f4
                Stream Path: \x18496\x15167\x17394\x17464\x17841, File Type: data, Stream Size: 1312
                General
                Stream Path:\x18496\x15167\x17394\x17464\x17841
                File Type:data
                Stream Size:1312
                Entropy:4.86814231206
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % . % . % . % . % . % . % . % . % . % . / . / . 4 . 4 . 8 . 8 . 8 . 8 . 8 . 8 . 8 . ; . ; . @ . @ . @ . B . B . B . E . E . E . G . G . G . G . G . G . G . G . G . K . K . K . K . K . P . P . P . Q . Q . Q . Q . S . S . S . T . T . V . V . V . V . V . W . W . W . W . W . W . Z . Z . Z . Z . Z . Z . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ` . ` . ` . ` . ` . b . b . b . b . f . f . f . m . m . m .
                Data Raw:04 00 04 00 04 00 04 00 04 00 04 00 07 00 07 00 07 00 11 00 11 00 11 00 1b 00 1b 00 20 00 20 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 2f 00 2f 00 34 00 34 00 38 00 38 00 38 00 38 00 38 00 38 00 38 00 3b 00 3b 00 40 00 40 00 40 00 42 00 42 00 42 00 45 00 45 00 45 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 4b 00 4b 00 4b 00 4b 00 4b 00 50 00 50 00
                Stream Path: \x18496\x15518\x16925\x17915, File Type: data, Stream Size: 444
                General
                Stream Path:\x18496\x15518\x16925\x17915
                File Type:data
                Stream Size:444
                Entropy:5.13282930045
                Base64 Encoded:False
                Data ASCII:! . E . G . H . J . L . N . O . Q . R . S . U . V . X . Z . [ . ] . _ . a . c . e . g . h . j . l . n . p . r . t . v . x . z . | . } . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . F . . . I . K . M . N . P . Q . . . T . U . W . Y . Z . \\ . ^ .
                Data Raw:21 01 45 06 47 06 48 06 4a 06 4c 06 4e 06 4f 06 51 06 52 06 53 06 55 06 56 06 58 06 5a 06 5b 06 5d 06 5f 06 61 06 63 06 65 06 67 06 68 06 6a 06 6c 06 6e 06 70 06 72 06 74 06 76 06 78 06 7a 06 7c 06 7d 06 7f 06 81 06 83 06 85 06 87 06 89 06 8b 06 8d 06 8f 06 91 06 93 06 95 06 97 06 99 06 9b 06 9d 06 9f 06 a1 06 a3 06 a5 06 a6 06 a8 06 aa 06 ac 06 ae 06 b0 06 b2 06 b4 06 b6 06 b7 06
                Stream Path: \x18496\x16191\x17783\x17516\x15210\x17892\x18468, File Type: ASCII text, with very long lines, Stream Size: 78898
                General
                Stream Path:\x18496\x16191\x17783\x17516\x15210\x17892\x18468
                File Type:ASCII text, with very long lines
                Stream Size:78898
                Entropy:4.87770021891
                Base64 Encoded:True
                Data ASCII:A t t r i b u t e s P a t c h S i z e F i l e _ P a t c h T y p e A c t i o n C o n d i t i o n S e q u e n c e C o s t F i n a l i z e C o s t I n i t i a l i z e T a b l e N a m e I n s t a l l F i n a l i z e I n s t a l l I n i t i a l i z e I n s t a l l V a l i d a t e A d v t E x e c u t e S e q u e n c e C r e a t e S h o r t c u t s M s i P u b l i s h A s s e m b l i e s P u b l i s h C o m p o n e n t s P u b l i s h F e a t u r e s P u b l i s h P r o d u c t R e g i s t e r C l a s s I n f o R
                Data Raw:41 74 74 72 69 62 75 74 65 73 50 61 74 63 68 53 69 7a 65 46 69 6c 65 5f 50 61 74 63 68 54 79 70 65 41 63 74 69 6f 6e 43 6f 6e 64 69 74 69 6f 6e 53 65 71 75 65 6e 63 65 43 6f 73 74 46 69 6e 61 6c 69 7a 65 43 6f 73 74 49 6e 69 74 69 61 6c 69 7a 65 54 61 62 6c 65 4e 61 6d 65 49 6e 73 74 61 6c 6c 46 69 6e 61 6c 69 7a 65 49 6e 73 74 61 6c 6c 49 6e 69 74 69 61 6c 69 7a 65 49 6e 73 74 61
                Stream Path: \x18496\x16191\x17783\x17516\x15978\x17586\x18479, File Type: data, Stream Size: 7240
                General
                Stream Path:\x18496\x16191\x17783\x17516\x15978\x17586\x18479
                File Type:data
                Stream Size:7240
                Entropy:3.45772735702
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ( . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 3 . . . . . . . . . . . K . . . . . * . . . . . . . . . a . . . 6 . ' . . . . . . . . . . . ` . . . . . . . . . . . $ . . . 6 . . . . . . .
                Data Raw:e4 04 00 00 0a 00 0e 00 09 00 02 00 05 00 02 00 05 00 0d 00 04 00 04 00 06 00 12 00 09 00 28 00 08 00 10 00 0c 00 06 00 0e 00 06 00 00 00 00 00 05 00 02 00 04 00 02 00 0f 00 03 00 11 00 03 00 0f 00 04 00 13 00 07 00 0f 00 03 00 14 00 03 00 11 00 03 00 0f 00 01 00 0e 00 01 00 11 00 03 00 15 00 03 00 10 00 03 00 12 00 03 00 0c 00 05 00 07 00 02 00 06 00 02 00 06 00 02 00 0a 00 02 00
                Stream Path: \x18496\x16255\x16740\x16943\x18486, File Type: data, Stream Size: 72
                General
                Stream Path:\x18496\x16255\x16740\x16943\x18486
                File Type:data
                Stream Size:72
                Entropy:3.58496250072
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . % . / . 4 . 8 . ; . @ . B . E . G . K . P . Q . S . T . V . W . Z . \\ . ^ . ` . b . f . m . p . w . x . y . . . . . . . . .
                Data Raw:04 00 07 00 11 00 1b 00 20 00 25 00 2f 00 34 00 38 00 3b 00 40 00 42 00 45 00 47 00 4b 00 50 00 51 00 53 00 54 00 56 00 57 00 5a 00 5c 00 5e 00 60 00 62 00 66 00 6d 00 70 00 77 00 78 00 79 00 80 00 b5 00 d3 00 d7 00
                Stream Path: \x18496\x16383\x17380\x16876\x17892\x17580\x18481, File Type: data, Stream Size: 3936
                General
                Stream Path:\x18496\x16383\x17380\x16876\x17892\x17580\x18481
                File Type:data
                Stream Size:3936
                Entropy:2.54122078101
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . % . % . % . % . % . % . % . % . % . % . / . / . 4 . 4 . 8 . 8 . 8 . 8 . 8 . 8 . 8 . ; . ; . @ . @ . @ . B . B . B . E . E . E . G . G . G . G . G . G . G . G . G . K . K . K . K . K . P . P . P . Q . Q . Q . Q . S . S . S . T . T . V . V . V . V . V . W . W . W . W . W . W . Z . Z . Z . Z . Z . Z . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . \\ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ^ . ` . ` . ` . ` . ` . b . b . b . b . f . f . f . m . m . m .
                Data Raw:04 00 04 00 04 00 04 00 04 00 04 00 07 00 07 00 07 00 11 00 11 00 11 00 1b 00 1b 00 20 00 20 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 25 00 2f 00 2f 00 34 00 34 00 38 00 38 00 38 00 38 00 38 00 38 00 38 00 3b 00 3b 00 40 00 40 00 40 00 42 00 42 00 42 00 45 00 45 00 45 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 47 00 4b 00 4b 00 4b 00 4b 00 4b 00 50 00 50 00
                Stream Path: \x18496\x16661\x17528\x17126\x17548\x16881\x17900\x17580\x18481, File Type: data, Stream Size: 16
                General
                Stream Path:\x18496\x16661\x17528\x17126\x17548\x16881\x17900\x17580\x18481
                File Type:data
                Stream Size:16
                Entropy:2.5
                Base64 Encoded:False
                Data ASCII:$ . 6 . 8 . : . < . 7 . 9 . ; .
                Data Raw:24 06 36 06 38 06 3a 06 3c 06 37 06 39 06 3b 06
                Stream Path: \x18496\x16667\x17191\x15090\x17912\x17591\x18481, File Type: data, Stream Size: 36
                General
                Stream Path:\x18496\x16667\x17191\x15090\x17912\x17591\x18481
                File Type:data
                Stream Size:36
                Entropy:3.49590659848
                Base64 Encoded:False
                Data ASCII:> . > . . . . . ? . > . . . . . . . . . @ . @ . . . . . = . ? . . . . .
                Data Raw:3e 01 3e 01 01 80 02 80 3f 01 3e 06 05 80 05 80 05 80 19 80 40 81 40 81 14 80 0f 80 3d 06 3f 06 00 00 00 00
                Stream Path: \x18496\x16778\x17207\x17522\x16925\x17915, File Type: data, Stream Size: 420
                General
                Stream Path:\x18496\x16778\x17207\x17522\x16925\x17915
                File Type:data
                Stream Size:420
                Entropy:5.04335394717
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . & . ( . / . 2 . 5 . 7 . : . < . ? . A . C . E . H . J . L . N . P . R . T . V . X . Z . \\ . ^ . . . . . . . . . . . . . . . . . . . . . + . - . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . $ . ' . ) . 0 . 3 . 6 . 8 . ; . = . @ . B . D . F .
                Data Raw:09 00 0a 00 10 00 12 00 13 00 14 00 15 00 16 00 17 00 18 00 19 00 1a 00 1d 01 20 01 c6 01 c8 01 cd 01 d2 01 d4 01 d9 01 db 01 e0 01 e2 01 e5 01 e6 01 e8 01 ec 01 ef 01 f2 01 f3 01 f6 01 f8 01 fb 01 fd 01 ff 01 02 02 05 02 07 02 0c 02 0f 02 11 02 13 02 17 02 1b 02 20 02 23 02 26 02 28 02 2f 02 32 02 35 02 37 02 3a 02 3c 02 3f 02 41 02 43 02 45 02 48 02 4a 02 4c 02 4e 02 50 02 52 02
                Stream Path: \x18496\x16842\x17200\x15281\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 48
                General
                Stream Path:\x18496\x16842\x17200\x15281\x16955\x17958\x16951\x16924\x17972\x17512\x16934
                File Type:data
                Stream Size:48
                Entropy:3.38186998233
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . < . . .
                Data Raw:09 00 0a 00 0e 00 0f 00 10 00 f2 01 f8 01 fd 01 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 83 20 83 c8 99 dc 85 78 85 84 83 3c 8f a0 8f
                Stream Path: \x18496\x16842\x17200\x16305\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 66
                General
                Stream Path:\x18496\x16842\x17200\x16305\x16146\x17704\x16952\x16817\x18472
                File Type:data
                Stream Size:66
                Entropy:3.79732461185
                Base64 Encoded:False
                Data ASCII:. . . . . . _ . ` . a . b . c . d . e . f . . . . . . . . . . . 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:09 00 0a 00 f2 01 5f 02 60 02 61 02 62 02 63 02 64 02 65 02 66 02 00 00 00 00 00 00 00 00 00 00 33 01 00 00 00 00 00 00 00 00 00 00 e8 83 20 83 84 83 00 85 ce 84 01 80 14 85 ff 7f fd 7f 8c 80 fe 7f
                Stream Path: \x18496\x16842\x17913\x18126\x16808\x17912\x16168\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 72
                General
                Stream Path:\x18496\x16842\x17913\x18126\x16808\x17912\x16168\x17704\x16952\x16817\x18472
                File Type:data
                Stream Size:72
                Entropy:3.44607361183
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . x . . . j . 8 . . . \\ . $ . . .
                Data Raw:09 00 0a 00 0e 00 0f 00 10 00 12 00 13 00 14 00 17 00 18 00 19 00 1a 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 e8 83 20 83 c8 99 dc 85 78 85 94 91 6a 98 38 98 f8 91 5c 92 24 93 c0 92
                Stream Path: \x18496\x16911\x17892\x17784\x15144\x17458\x17587\x16945\x17905\x18486, File Type: data, Stream Size: 4
                General
                Stream Path:\x18496\x16911\x17892\x17784\x15144\x17458\x17587\x16945\x17905\x18486
                File Type:data
                Stream Size:4
                Entropy:1.5
                Base64 Encoded:False
                Data ASCII:# . $ .
                Data Raw:23 00 24 00
                Stream Path: \x18496\x16911\x17892\x17784\x18472, File Type: data, Stream Size: 16
                General
                Stream Path:\x18496\x16911\x17892\x17784\x18472
                File Type:data
                Stream Size:16
                Entropy:2.22460175271
                Base64 Encoded:False
                Data ASCII:# . . . # . . . . . . . $ . . .
                Data Raw:23 00 00 00 23 00 2e 00 01 80 01 80 24 00 00 80
                Stream Path: \x18496\x16925\x17915\x17884\x17404\x18472, File Type: data, Stream Size: 48
                General
                Stream Path:\x18496\x16925\x17915\x17884\x17404\x18472
                File Type:data
                Stream Size:48
                Entropy:3.09028891162
                Base64 Encoded:False
                Data ASCII:. . @ . C . D . B . A . B . B . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:a1 01 40 06 43 06 44 06 42 06 41 06 42 06 42 06 08 80 0d 80 08 80 08 80 00 00 00 80 00 00 00 80 00 00 00 80 ff ff ff 80 00 80 01 80 01 80 00 80
                Stream Path: \x18496\x17100\x16808\x15086\x18162, File Type: data, Stream Size: 12
                General
                Stream Path:\x18496\x17100\x16808\x15086\x18162
                File Type:data
                Stream Size:12
                Entropy:2.35538854221
                Base64 Encoded:False
                Data ASCII:. . j . k . 3 . 3 . 3 .
                Data Raw:ba 01 6a 02 6b 02 33 01 33 01 33 01
                Stream Path: \x18496\x17163\x16689\x18229, File Type: data, Stream Size: 60
                General
                Stream Path:\x18496\x17163\x16689\x18229
                File Type:data
                Stream Size:60
                Entropy:2.7112204457
                Base64 Encoded:False
                Data ASCII:5 . x . . . . . . . . . . . . . . . . . . . . . g . h . i . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:35 01 78 01 9f 01 a5 01 a7 01 a9 01 ab 01 ad 01 af 01 b1 01 b5 01 be 01 67 02 68 02 69 02 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00 01 00
                Stream Path: \x18496\x17165\x16949\x17894\x17778\x18492, File Type: data, Stream Size: 12
                General
                Stream Path:\x18496\x17165\x16949\x17894\x17778\x18492
                File Type:data
                Stream Size:12
                Entropy:2.68872187554
                Base64 Encoded:False
                Data ASCII:$ . . . . . . . . . . .
                Data Raw:24 00 a4 02 a4 02 00 00 96 03 95 03
                Stream Path: \x18496\x17165\x17380\x17074, File Type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.163, Stream Size: 616
                General
                Stream Path:\x18496\x17165\x17380\x17074
                File Type:MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.163
                Stream Size:616
                Entropy:4.17798348327
                Base64 Encoded:False
                Data ASCII:c . _ . ` . c . d . e . f . l . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . " . ' . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . 2 . . . r . r . r . r . r . r . r . r . r . ( . r . r . r . . . r . r . r . r . r . r . r . r . r . r . r . r . . . i . . . . . . . . . . . . . . . . . . . G . . . . . . . U . . .
                Data Raw:63 01 5f 02 60 02 63 02 64 02 65 02 66 02 6c 02 83 02 9b 02 9f 02 a3 02 b3 02 b8 02 ba 02 c3 02 d8 02 fb 02 05 03 09 03 0d 03 10 03 18 03 1a 03 1e 03 21 03 22 03 27 03 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80 32 80
                Stream Path: \x18496\x17490\x17910\x17380\x15279\x16955\x17958\x16951\x16924\x17972\x17512\x16934, File Type: data, Stream Size: 432
                General
                Stream Path:\x18496\x17490\x17910\x17380\x15279\x16955\x17958\x16951\x16924\x17972\x17512\x16934
                File Type:data
                Stream Size:432
                Entropy:5.74288381672
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . # . & . ( . / . 2 . 7 . : . < . ? . A . C . E . H . J . L . N . P . R . T . V . X . Z . \\ . ^ . i . t . x . { . } . ~ . . . . . . . . . . . % . ' . 0 . . . . . . . . . . . . . . . . . . . * . . . . . . . # . . . $ . # . . . 6 . . . $ . . . . . . . 6 . . . ) . . . & . . . . . 6 . / . . . . . 6 . . . . . . . . . & . + . . . . . , . . . 6 . 6 . $ . $ . 6 . . . 6 . 6 . 6 . 6 .
                Data Raw:09 00 0a 00 0e 00 0f 00 10 00 12 00 13 00 14 00 17 00 18 00 19 00 1a 00 1d 01 20 01 c6 01 c8 01 d4 01 e0 01 e2 01 e8 01 ec 01 ef 01 f2 01 f3 01 fb 01 fd 01 ff 01 02 02 05 02 0c 02 0f 02 11 02 13 02 20 02 23 02 26 02 28 02 2f 02 32 02 37 02 3a 02 3c 02 3f 02 41 02 43 02 45 02 48 02 4a 02 4c 02 4e 02 50 02 52 02 54 02 56 02 58 02 5a 02 5c 02 5e 02 69 02 74 03 78 03 7b 03 7d 03 7e 03
                Stream Path: \x18496\x17490\x17910\x17380\x16303\x16146\x17704\x16952\x16817\x18472, File Type: data, Stream Size: 180
                General
                Stream Path:\x18496\x17490\x17910\x17380\x16303\x16146\x17704\x16952\x16817\x18472
                File Type:data
                Stream Size:180
                Entropy:5.09930005046
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . _ . b . c . d . e . f . . . . . . . " . t . v . x . } . ~ . . . . . . . . . . . . . . . . . . . . . . . # . . . . . . . . . . . 3 . . . . . 4 . = . A . B . < . 5 . . . . . . . . . . . B . 2 . # . 1 . ) . - . . . . d . . . . . . . L . . . . . . . . . K . . . . . . . . . . . . . 4 . 3 . 5 . . . . . . . . . . . . . . . . . . .
                Data Raw:09 00 0a 00 1d 01 20 01 f2 01 f3 01 0c 02 5f 02 62 02 63 02 64 02 65 02 66 02 9b 02 10 03 18 03 22 03 74 03 76 03 78 03 7d 03 7e 03 84 03 86 03 8a 03 8d 03 8e 03 8f 03 90 03 91 03 00 00 00 00 00 00 23 06 00 00 00 00 00 00 00 00 00 00 33 06 00 00 00 00 34 06 3d 03 41 03 42 03 3c 03 35 06 00 00 00 00 00 00 20 06 20 06 2e 06 42 03 32 06 23 06 31 06 29 06 2d 06 e8 83 20 83 64 80 90 81
                Stream Path: \x18496\x17547\x17906\x17910\x16693\x17651\x17768\x15518\x16924\x17972\x17512\x16934, File Type: SVr4 curses screen image, little-endian, Stream Size: 54
                General
                Stream Path:\x18496\x17547\x17906\x17910\x16693\x17651\x17768\x15518\x16924\x17972\x17512\x16934
                File Type:SVr4 curses screen image, little-endian
                Stream Size:54
                Entropy:3.87852986267
                Base64 Encoded:False
                Data ASCII:. . . . . ! . # . $ . & . ' . ( . . . . . . . " . " . % . % . " . ) . . . , . ^ . . . . . X . . . . . .
                Data Raw:1d 01 1f 01 20 01 21 01 23 01 24 01 26 01 27 01 28 01 1e 01 1e 01 1e 01 22 01 22 01 25 01 25 01 22 01 29 01 fa 80 2c 81 5e 81 90 81 c2 81 58 82 8a 82 bc 82 20 83
                Stream Path: \x18496\x17548\x17648\x17522\x17512\x18487, File Type: data, Stream Size: 12
                General
                Stream Path:\x18496\x17548\x17648\x17522\x17512\x18487
                File Type:data
                Stream Size:12
                Entropy:1.04085208297
                Base64 Encoded:False
                Data ASCII:$ . . . $ . . . . . . .
                Data Raw:24 00 00 00 24 00 00 80 00 00 00 00
                Stream Path: \x18496\x17548\x17905\x17589\x15151\x17522\x17191\x17207\x17522, File Type: data, Stream Size: 72
                General
                Stream Path:\x18496\x17548\x17905\x17589\x15151\x17522\x17191\x17207\x17522
                File Type:data
                Stream Size:72
                Entropy:3.42994500824
                Base64 Encoded:False
                Data ASCII:c . c . c . c . d . d . . . . . . . . . . . . . . . . . . . t . . . . . 5 . 5 . 5 . 5 . 9 . 9 . 5 . 5 . 5 . 8 . 8 . 7 . 7 . : . : . 6 . 6 . 6 .
                Data Raw:63 02 63 02 63 02 63 02 64 02 64 02 c3 02 c3 02 c3 02 eb 02 ed 02 ef 02 f1 02 f7 02 f8 02 74 02 cb 02 cd 02 35 03 35 03 35 03 35 03 39 03 39 03 35 03 35 03 35 03 38 03 38 03 37 03 37 03 3a 03 3a 03 36 03 36 03 36 03
                Stream Path: \x18496\x17548\x17905\x17589\x15279\x16953\x17905, File Type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.99, Stream Size: 1536
                General
                Stream Path:\x18496\x17548\x17905\x17589\x15279\x16953\x17905
                File Type:MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.99
                Stream Size:1536
                Entropy:4.98673799888
                Base64 Encoded:False
                Data ASCII:c . c . c . c . c . c . c . _ . ` . ` . ` . c . c . c . c . d . d . d . e . f . f . l . l . l . l . l . l . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . ! . ! . ! . ! . ! . ! . ! . ! . ! . ! . ! . " . " . ' .
                Data Raw:63 01 63 01 63 01 63 01 63 01 63 01 63 01 5f 02 60 02 60 02 60 02 63 02 63 02 63 02 63 02 64 02 64 02 64 02 65 02 66 02 66 02 6c 02 6c 02 6c 02 6c 02 6c 02 6c 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 83 02 9b 02 9b 02 9b 02 9f 02 a3 02 a3 02 a3 02 a3 02 a3 02 a3 02 b3 02 b3 02 b3 02 b3 02 b3 02 b8 02 b8 02
                Stream Path: \x18496\x17548\x17905\x17589\x18479, File Type: MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.95, Stream Size: 7280
                General
                Stream Path:\x18496\x17548\x17905\x17589\x18479
                File Type:MIPSEB-LE MIPS-II ECOFF executable not stripped - version 2.95
                Stream Size:7280
                Entropy:4.53364756052
                Base64 Encoded:False
                Data ASCII:c . c . c . c . c . c . c . c . c . _ . _ . _ . _ . _ . _ . _ . _ . _ . _ . _ . _ . ` . ` . ` . ` . ` . ` . ` . c . c . c . c . c . c . c . c . c . c . c . d . d . d . d . d . d . d . d . d . d . e . e . e . e . e . e . e . e . e . f . f . f . f . f . f . f . f . l . l . l . l . l . l . l . l . l . l . l . l . l . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:63 01 63 01 63 01 63 01 63 01 63 01 63 01 63 01 63 01 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 5f 02 60 02 60 02 60 02 60 02 60 02 60 02 60 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 63 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 64 02 65 02 65 02 65 02 65 02 65 02 65 02 65 02 65 02 65 02 66 02 66 02 66 02 66 02 66 02 66 02
                Stream Path: \x18496\x17630\x17770\x16868\x18472, File Type: x86 executable, Stream Size: 32
                General
                Stream Path:\x18496\x17630\x17770\x16868\x18472
                File Type:x86 executable
                Stream Size:32
                Entropy:2.76201589562
                Base64 Encoded:False
                Data ASCII:H . H . ; . . . . . ; . . . . . . . . . . . . . . . . . 5 . . .
                Data Raw:48 01 48 01 3b 01 10 07 00 00 3b 01 00 00 00 00 02 00 00 80 01 01 00 80 00 00 00 00 35 06 11 07
                Stream Path: \x18496\x17740\x16680\x16951\x17551\x16879\x17768, File Type: data, Stream Size: 4
                General
                Stream Path:\x18496\x17740\x16680\x16951\x17551\x16879\x17768
                File Type:data
                Stream Size:4
                Entropy:1.0
                Base64 Encoded:False
                Data ASCII:$ . $ .
                Data Raw:24 00 24 00
                Stream Path: \x18496\x17742\x17589\x18485, File Type: data, Stream Size: 2572
                General
                Stream Path:\x18496\x17742\x17589\x18485
                File Type:data
                Stream Size:2572
                Entropy:6.54317952801
                Base64 Encoded:False
                Data ASCII:. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . ! . . . M . . . . . . . . . . . . . . . . . . . . . . . . ! . " . # . $ . % . & . ' . ( . ) . * . + . , . - . . . / . 0 . 1 . 2 . 3 . 4 . 5 . 6 . 7 . 8 . y . z . { . | . } . ~ . . . . . . . . . . . . . . . . . A . B . C . D . E . F . G . H . I . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . m . n . o . p .
                Data Raw:00 80 01 80 02 80 03 80 04 80 05 80 06 80 07 80 08 80 09 80 0a 80 0b 80 0c 80 0d 80 0e 80 0f 80 10 80 11 80 12 80 13 80 14 80 15 80 16 80 17 80 20 80 21 80 e9 83 4d 84 15 85 16 85 17 85 18 85 19 85 1a 85 1b 85 1c 85 1d 85 1e 85 1f 85 20 85 21 85 22 85 23 85 24 85 25 85 26 85 27 85 28 85 29 85 2a 85 2b 85 2c 85 2d 85 2e 85 2f 85 30 85 31 85 32 85 33 85 34 85 35 85 36 85 37 85 38 85
                Stream Path: \x18496\x17753\x17650\x17768\x18231, File Type: data, Stream Size: 340
                General
                Stream Path:\x18496\x17753\x17650\x17768\x18231
                File Type:data
                Stream Size:340
                Entropy:4.62234252689
                Base64 Encoded:False
                Data ASCII:. . . . * . , . . . 0 . 2 . 4 . 6 . 8 . : . < . > . @ . A . C . E . G . I . K . L . O . Q . R . T . V . W . X . Y . [ . ] . _ . ` . b . d . f . h . j . k . m . o . q . s . u . w . z . | . ~ . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . H . N . + . - . / . 1 . 3 . 5 . 7 . 9 . ; . = . ? . 3 . B . D . F . D . J . F . M . P . P . S . U . U . X . y . Z . \\ . ^ . \\ . a . c . e . g . i . 3 . l . n . p . r . t .
                Data Raw:b1 00 01 01 2a 01 2c 01 2e 01 30 01 32 01 34 01 36 01 38 01 3a 01 3c 01 3e 01 40 01 41 01 43 01 45 01 47 01 49 01 4b 01 4c 01 4f 01 51 01 52 01 54 01 56 01 57 01 58 01 59 01 5b 01 5d 01 5f 01 60 01 62 01 64 01 66 01 68 01 6a 01 6b 01 6d 01 6f 01 71 01 73 01 75 01 77 01 7a 01 7c 01 7e 01 80 01 82 01 84 01 86 01 88 01 8a 01 8c 01 8e 01 90 01 92 01 93 01 95 01 97 01 98 01 9a 01 9c 01
                Stream Path: \x18496\x17932\x17910\x17458\x16778\x17207\x17522, File Type: data, Stream Size: 240
                General
                Stream Path:\x18496\x17932\x17910\x17458\x16778\x17207\x17522
                File Type:data
                Stream Size:240
                Entropy:3.68898065651
                Base64 Encoded:False
                Data ASCII:a . i . Y . e . t . v . x . { . } . ~ . . . . . . . . . . . . . . . . . . . . . 3 . . . . . A . . . . . A . A . . . A . 3 . 3 . 3 . 3 . 3 . 3 . 3 . 3 . 3 . . . . . i . g . g . . . g . g . g . g . g . . . $ . . . . . < . B . < . = . A . g . 3 . . . z . . . u . w . y . | . } . . . . . . . . . . . . . 3 . 3 . 3 . 3 . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . .
                Data Raw:61 02 69 02 59 03 65 03 74 03 76 03 78 03 7b 03 7d 03 7e 03 81 03 84 03 86 03 88 03 8a 03 8d 03 8e 03 8f 03 90 03 91 03 33 80 01 80 01 80 41 80 13 80 01 80 41 81 41 80 01 80 41 80 33 80 33 81 33 81 33 80 33 80 33 80 33 80 33 80 33 80 01 80 8c 03 69 02 67 02 67 02 00 00 67 02 67 02 67 02 67 02 67 02 82 03 24 00 87 03 a4 02 3c 03 42 03 3c 03 3d 03 41 03 67 02 33 01 89 03 7a 03 80 03
                Stream Path: \x18496\x17998\x17512\x15799\x17636\x17203\x17073, File Type: data, Stream Size: 128
                General
                Stream Path:\x18496\x17998\x17512\x15799\x17636\x17203\x17073
                File Type:data
                Stream Size:128
                Entropy:4.11408297472
                Base64 Encoded:False
                Data ASCII:_ . _ . e . e . . . . . . . . . . . . . . . . . . . . . . . . . B . . . B . . . B . . . . . . . . . . . . . . . . . . . . . . . B . . . B . . . B . . . . . . . . . . . . . . . . . . . . . . . < . . . < . < . < . . . . . . . . . . . . . . . < . . . < . < .
                Data Raw:5f 02 5f 02 65 02 65 02 9f 02 9f 02 a3 02 b8 02 c3 02 c3 02 c3 02 c3 02 c3 02 c3 02 c3 02 c3 02 42 00 a0 02 42 00 14 03 42 00 a0 02 a8 02 a8 02 81 01 c7 02 c9 02 cb 02 cd 02 cd 02 d2 02 d4 02 42 00 15 06 42 00 14 03 42 00 15 06 17 06 17 06 18 06 18 06 18 06 1d 06 1c 06 1d 06 1b 06 1a 06 3c 00 16 06 3c 00 3c 00 3c 00 16 06 17 06 17 06 19 06 19 06 19 06 1e 06 3c 00 1e 06 3c 00 3c 00

                Network Behavior

                Network Port Distribution

                TCP Packets

                TimestampSource PortDest PortSource IPDest IP
                Aug 30, 2021 14:23:55.681875944 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:55.704962969 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:55.705121040 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:55.713620901 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:55.737919092 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:55.737951994 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:55.738030910 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:55.738046885 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:55.738142014 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:55.746073961 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:55.769239902 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:55.772831917 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:55.828044891 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:56.309103966 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:56.332580090 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:56.518338919 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:56.518378019 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:56.580656052 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:56.600362062 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:56.600469112 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:56.600496054 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:56.623593092 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:56.888870001 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:56.888901949 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:23:56.889061928 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:23:56.932391882 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:56.955691099 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:56.955810070 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:56.956268072 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:56.979582071 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:56.992074966 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:56.992113113 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:56.992136002 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:56.992280006 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:56.998800039 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:57.023611069 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.024528980 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.027854919 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:57.051068068 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.781831980 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.781867027 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.781878948 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.781894922 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.781912088 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.781928062 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.782042027 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:57.783576012 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.783597946 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.783673048 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:57.786345005 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.786369085 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.786438942 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:57.787452936 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.787475109 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.787533045 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:57.789114952 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.789139986 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.789221048 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:23:57.805515051 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:23:57.859430075 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:25:17.890589952 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:25:17.890620947 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:25:17.890743017 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:25:17.891783953 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:25:17.891822100 CEST49736443192.168.2.4162.125.65.18
                Aug 30, 2021 14:25:17.914962053 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:25:17.914980888 CEST44349736162.125.65.18192.168.2.4
                Aug 30, 2021 14:25:18.783674002 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:25:18.783709049 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:25:18.783919096 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:25:18.784115076 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:25:18.784182072 CEST49737443192.168.2.4162.125.65.15
                Aug 30, 2021 14:25:18.807580948 CEST44349737162.125.65.15192.168.2.4
                Aug 30, 2021 14:25:18.807629108 CEST44349737162.125.65.15192.168.2.4

                UDP Packets

                TimestampSource PortDest PortSource IPDest IP
                Aug 30, 2021 14:23:32.458566904 CEST53580288.8.8.8192.168.2.4
                Aug 30, 2021 14:23:32.692558050 CEST5309753192.168.2.48.8.8.8
                Aug 30, 2021 14:23:32.733536005 CEST53530978.8.8.8192.168.2.4
                Aug 30, 2021 14:23:35.128690004 CEST4925753192.168.2.48.8.8.8
                Aug 30, 2021 14:23:35.166141033 CEST53492578.8.8.8192.168.2.4
                Aug 30, 2021 14:23:55.636085033 CEST6238953192.168.2.48.8.8.8
                Aug 30, 2021 14:23:55.671299934 CEST53623898.8.8.8192.168.2.4
                Aug 30, 2021 14:23:56.893455029 CEST4991053192.168.2.48.8.8.8
                Aug 30, 2021 14:23:56.931031942 CEST53499108.8.8.8192.168.2.4
                Aug 30, 2021 14:24:06.379709959 CEST5585453192.168.2.48.8.8.8
                Aug 30, 2021 14:24:06.423870087 CEST53558548.8.8.8192.168.2.4
                Aug 30, 2021 14:24:24.293128014 CEST6454953192.168.2.48.8.8.8
                Aug 30, 2021 14:24:24.403808117 CEST53645498.8.8.8192.168.2.4
                Aug 30, 2021 14:24:25.234452009 CEST6315353192.168.2.48.8.8.8
                Aug 30, 2021 14:24:25.337203979 CEST53631538.8.8.8192.168.2.4
                Aug 30, 2021 14:24:25.823318958 CEST5299153192.168.2.48.8.8.8
                Aug 30, 2021 14:24:25.864193916 CEST53529918.8.8.8192.168.2.4
                Aug 30, 2021 14:24:26.150804996 CEST5370053192.168.2.48.8.8.8
                Aug 30, 2021 14:24:26.183402061 CEST53537008.8.8.8192.168.2.4
                Aug 30, 2021 14:24:27.026832104 CEST5172653192.168.2.48.8.8.8
                Aug 30, 2021 14:24:27.053077936 CEST5679453192.168.2.48.8.8.8
                Aug 30, 2021 14:24:27.063266993 CEST53517268.8.8.8192.168.2.4
                Aug 30, 2021 14:24:27.081921101 CEST53567948.8.8.8192.168.2.4
                Aug 30, 2021 14:24:27.899326086 CEST5653453192.168.2.48.8.8.8
                Aug 30, 2021 14:24:27.932271004 CEST53565348.8.8.8192.168.2.4
                Aug 30, 2021 14:24:28.681787014 CEST5662753192.168.2.48.8.8.8
                Aug 30, 2021 14:24:28.717428923 CEST53566278.8.8.8192.168.2.4
                Aug 30, 2021 14:24:29.903620005 CEST5662153192.168.2.48.8.8.8
                Aug 30, 2021 14:24:29.928581953 CEST53566218.8.8.8192.168.2.4
                Aug 30, 2021 14:24:31.215326071 CEST6311653192.168.2.48.8.8.8
                Aug 30, 2021 14:24:31.251028061 CEST53631168.8.8.8192.168.2.4
                Aug 30, 2021 14:24:32.494565964 CEST6407853192.168.2.48.8.8.8
                Aug 30, 2021 14:24:32.530257940 CEST53640788.8.8.8192.168.2.4
                Aug 30, 2021 14:24:34.281099081 CEST6480153192.168.2.48.8.8.8
                Aug 30, 2021 14:24:34.316649914 CEST53648018.8.8.8192.168.2.4
                Aug 30, 2021 14:24:41.484410048 CEST6172153192.168.2.48.8.8.8
                Aug 30, 2021 14:24:41.486259937 CEST5125553192.168.2.48.8.8.8
                Aug 30, 2021 14:24:41.531339884 CEST53617218.8.8.8192.168.2.4
                Aug 30, 2021 14:24:41.536827087 CEST53512558.8.8.8192.168.2.4
                Aug 30, 2021 14:24:44.597460985 CEST6152253192.168.2.48.8.8.8
                Aug 30, 2021 14:24:44.640105009 CEST53615228.8.8.8192.168.2.4
                Aug 30, 2021 14:25:16.144350052 CEST5233753192.168.2.48.8.8.8
                Aug 30, 2021 14:25:16.187133074 CEST53523378.8.8.8192.168.2.4
                Aug 30, 2021 14:25:17.372715950 CEST5504653192.168.2.48.8.8.8
                Aug 30, 2021 14:25:17.416802883 CEST53550468.8.8.8192.168.2.4

                DNS Queries

                TimestampSource IPDest IPTrans IDOP CodeNameTypeClass
                Aug 30, 2021 14:23:55.636085033 CEST192.168.2.48.8.8.80x67b8Standard query (0)www.dropbox.comA (IP address)IN (0x0001)
                Aug 30, 2021 14:23:56.893455029 CEST192.168.2.48.8.8.80x27f6Standard query (0)ucdd2fc710a0d9b0bc926ff3d256.dl.dropboxusercontent.comA (IP address)IN (0x0001)

                DNS Answers

                TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClass
                Aug 30, 2021 14:23:55.671299934 CEST8.8.8.8192.168.2.40x67b8No error (0)www.dropbox.comwww-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)
                Aug 30, 2021 14:23:55.671299934 CEST8.8.8.8192.168.2.40x67b8No error (0)www-env.dropbox-dns.com162.125.65.18A (IP address)IN (0x0001)
                Aug 30, 2021 14:23:56.931031942 CEST8.8.8.8192.168.2.40x27f6No error (0)ucdd2fc710a0d9b0bc926ff3d256.dl.dropboxusercontent.comedge-block-www-env.dropbox-dns.comCNAME (Canonical name)IN (0x0001)
                Aug 30, 2021 14:23:56.931031942 CEST8.8.8.8192.168.2.40x27f6No error (0)edge-block-www-env.dropbox-dns.com162.125.65.15A (IP address)IN (0x0001)

                HTTPS Packets

                TimestampSource IPSource PortDest IPDest PortSubjectIssuerNot BeforeNot AfterJA3 SSL Client FingerprintJA3 SSL Client Digest
                Aug 30, 2021 14:23:55.738046885 CEST162.125.65.18443192.168.2.449736CN=*.dropbox.com, O="Dropbox, Inc", L=San Francisco, ST=California, C=US CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=US CN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Oct 27 01:00:00 CET 2020 Tue Oct 22 14:00:00 CEST 2013Mon Nov 22 00:59:59 CET 2021 Sun Oct 22 14:00:00 CEST 2028771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0ce5f3254611a8c095a3d821d44539877
                CN=DigiCert SHA2 High Assurance Server CA, OU=www.digicert.com, O=DigiCert Inc, C=USCN=DigiCert High Assurance EV Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Oct 22 14:00:00 CEST 2013Sun Oct 22 14:00:00 CEST 2028
                Aug 30, 2021 14:23:56.992136002 CEST162.125.65.15443192.168.2.449737CN=*.dl.dropboxusercontent.com, O="Dropbox, Inc", L=San Francisco, ST=California, C=US CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=USCN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=US CN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USTue Jan 19 01:00:00 CET 2021 Thu Sep 24 02:00:00 CEST 2020Tue Feb 15 00:59:59 CET 2022 Tue Sep 24 01:59:59 CEST 2030771,49196-49195-49200-49199-159-158-49188-49187-49192-49191-49162-49161-49172-49171-157-156-61-60-53-47-10,0-5-10-11-13-35-23-65281,29-23-24,0ce5f3254611a8c095a3d821d44539877
                CN=DigiCert TLS RSA SHA256 2020 CA1, O=DigiCert Inc, C=USCN=DigiCert Global Root CA, OU=www.digicert.com, O=DigiCert Inc, C=USThu Sep 24 02:00:00 CEST 2020Tue Sep 24 01:59:59 CEST 2030

                Code Manipulations

                Statistics

                CPU Usage

                Click to jump to process

                Memory Usage

                Click to jump to process

                High Level Behavior Distribution

                Click to dive into process behavior distribution

                Behavior

                Click to jump to process

                System Behavior

                General

                Start time:14:23:40
                Start date:30/08/2021
                Path:C:\Windows\System32\msiexec.exe
                Wow64 process (32bit):false
                Commandline:'C:\Windows\System32\msiexec.exe' /i 'C:\Users\user\Desktop\35N4PXWcmC.msi'
                Imagebase:0x7ff777c90000
                File size:66048 bytes
                MD5 hash:4767B71A318E201188A0D0A420C8B608
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high

                General

                Start time:14:23:41
                Start date:30/08/2021
                Path:C:\Windows\SysWOW64\msiexec.exe
                Wow64 process (32bit):true
                Commandline:C:\Windows\syswow64\MsiExec.exe -Embedding CE54F576F3746C389F9942FCF9B3593A
                Imagebase:0xe70000
                File size:59904 bytes
                MD5 hash:12C17B5A5C2A7B97342C362CA467E9A2
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high

                General

                Start time:14:23:46
                Start date:30/08/2021
                Path:C:\Windows\SysWOW64\wbem\WMIC.exe
                Wow64 process (32bit):true
                Commandline:wmic OS get Caption/Format:List
                Imagebase:0xeb0000
                File size:391680 bytes
                MD5 hash:79A01FCD1C8166C5642F37D1E0FB7BA8
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high

                General

                Start time:14:23:46
                Start date:30/08/2021
                Path:C:\Windows\System32\conhost.exe
                Wow64 process (32bit):false
                Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Imagebase:0x7ff724c50000
                File size:625664 bytes
                MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                Has elevated privileges:true
                Has administrator privileges:true
                Programmed in:C, C++ or other language
                Reputation:high

                Disassembly

                Code Analysis

                Reset < >