Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
LiquidText Installer.exe

Overview

General Information

Sample name:LiquidText Installer.exe
Analysis ID:1501320
MD5:9ab59b8d383a6ab6c131c5e96b4d68de
SHA1:22192dab0ce673ae164d0fb25cf3a015c3e9c37c
SHA256:967552d901dbdcc34498c2e57a61bc2846400f90726d951d4075ade86e4af545
Infos:

Detection

Score:4
Range:0 - 100
Whitelisted:false
Confidence:20%

Signatures

Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Contains functionality for execution timing, often used to detect debuggers
Contains long sleeps (>= 3 min)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
May sleep (evasive loops) to hinder dynamic analysis
Monitors certain registry keys / values for changes (often done to protect autostart functionality)
PE file contains an invalid checksum
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • LiquidText Installer.exe (PID: 4760 cmdline: "C:\Users\user\Desktop\LiquidText Installer.exe" MD5: 9AB59B8D383A6AB6C131C5E96B4D68DE)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: C:\Users\user\Desktop\LiquidText Installer.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\LiquidText Installer.exe.logJump to behavior
Source: LiquidText Installer.exeStatic PE information: certificate valid
Source: LiquidText Installer.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: Binary string: D:\a\_work\1\s\src\StoreInstaller\obj\Release\net472\StoreInstaller.pdb source: LiquidText Installer.exe
Source: Binary string: D:\a\_work\1\s\src\StoreInstaller\obj\Release\net472\StoreInstaller.pdbSHA256Oy source: LiquidText Installer.exe
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F713000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://defaultcontainer/StoreInstaller;component/Resources/StoreAppList.Light.png
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5FA55000.00000004.00000800.00020000.00000000.sdmp, LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F81C000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://e12564.dspb.akamaiedge.net
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F7F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://e16646.g.akamaiedge.net
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F713000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://foo/Resources/StoreAppList.Light.png
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F713000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://foo/bar/resources/storeapplist.light.png
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5FA55000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.datacontract.org
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F68E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.datacontract.org/2004/07/
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5FA55000.00000004.00000800.00020000.00000000.sdmp, LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F8EB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.datacontract.org/2004/07/Microsoft.UniversalStore.DisplayCatalog.Contracts.Version7.R
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F68E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.datacontract.org/2004/07/StoreInstaller.Models
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F7AB000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F68E000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.w3.oh
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E841ED0_2_00007FF848E841ED
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E946CE0_2_00007FF848E946CE
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848EB66720_2_00007FF848EB6672
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E901BD0_2_00007FF848E901BD
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E81A150_2_00007FF848E81A15
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848F940A80_2_00007FF848F940A8
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848F90CBC0_2_00007FF848F90CBC
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848F91B500_2_00007FF848F91B50
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848F977E00_2_00007FF848F977E0
Source: LiquidText Installer.exeBinary or memory string: OriginalFilenameStoreInstaller.exe@ vs LiquidText Installer.exe
Source: classification engineClassification label: clean4.winEXE@1/5@0/0
Source: C:\Users\user\Desktop\LiquidText Installer.exeFile created: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WPF8517.tmpJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeMutant created: NULL
Source: C:\Users\user\Desktop\LiquidText Installer.exeMutant created: \Sessions\1\BaseNamedObjects\Global\{f6bec8ba-58ff-4dfc-9981-2ec5ebd23734}-9N9Z9NSV47FL
Source: C:\Users\user\Desktop\LiquidText Installer.exeFile created: C:\Users\user\AppData\Local\Temp\Tmp816B.tmpJump to behavior
Source: LiquidText Installer.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: LiquidText Installer.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 50.01%
Source: C:\Users\user\Desktop\LiquidText Installer.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: LiquidText Installer.exeString found in binary or memory: Expired)UnknownInstallerType%ProductUnavailableECompatibilityArchitectureCheckFail1CompatibilityOSCheckFail)InstallationStarting-InstallationInProgress%InstallationPaused=InstallationDownloadingPercent+InstallState.CanceledGInstallationDownloadProgressDetails
Source: LiquidText Installer.exeString found in binary or memory: 0.0-InstallState.Completed
Source: LiquidText Installer.exeString found in binary or memory: I-install
Source: LiquidText Installer.exeString found in binary or memory: )Gusto mo bang kanselahin ang pag-install?
Source: LiquidText Installer.exeString found in binary or memory: Nakumpleto ang pag-install
Source: LiquidText Installer.exeString found in binary or memory: Ini-install
Source: LiquidText Installer.exeString found in binary or memory: &Naka-install ang pinakabagong bersyon.
Source: LiquidText Installer.exeString found in binary or memory: ella l-installazzjoni?
Source: LiquidText Installer.exeString found in binary or memory: L-installazzjoni tlestiet
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: msvcp140_clr0400.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.applicationmodel.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: d3d9.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: msasn1.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: msisip.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: wshext.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: appxsip.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: opcservices.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: esdsip.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ncryptprov.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dcomp.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: winmm.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: msctfui.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: d3dcompiler_47.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: rasapi32.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: rasman.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: rtutils.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dhcpcsvc6.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dhcpcsvc.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: winnsi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: mskeyprotect.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ncryptsslp.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: gpapi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: mscms.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: coloradapterclient.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windowscodecsext.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: icm32.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.applicationmodel.store.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: webservices.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: installservice.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: rometadata.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.web.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: slc.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: sppc.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: ieframe.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: edputil.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: mlang.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: policymanager.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: twinui.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: execmodelproxy.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: mrmcorer.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.staterepositorycore.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: appxdeploymentclient.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windows.ui.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: windowmanagementapi.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeSection loaded: inputhost.dllJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41945702-8302-44A6-9445-AC98E8AFA086}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\LiquidText Installer.exeFile opened: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorrc.dllJump to behavior
Source: LiquidText Installer.exeStatic PE information: certificate valid
Source: initial sampleStatic PE information: Valid certificate with Microsoft Issuer
Source: LiquidText Installer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
Source: LiquidText Installer.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Source: LiquidText Installer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\a\_work\1\s\src\StoreInstaller\obj\Release\net472\StoreInstaller.pdb source: LiquidText Installer.exe
Source: Binary string: D:\a\_work\1\s\src\StoreInstaller\obj\Release\net472\StoreInstaller.pdbSHA256Oy source: LiquidText Installer.exe
Source: LiquidText Installer.exeStatic PE information: 0xC2ABFCEE [Fri Jun 30 12:28:30 2073 UTC]
Source: LiquidText Installer.exeStatic PE information: real checksum: 0xe0df9 should be: 0xe0d26
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848D6D2A5 pushad ; iretd 0_2_00007FF848D6D2A6
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E8E468 pushad ; ret 0_2_00007FF848E8E4E1
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E955B8 push eax; ret 0_2_00007FF848E95851
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E95598 push eax; ret 0_2_00007FF848E95851
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E99E8C push eax; ret 0_2_00007FF848E99EA4
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E957D8 push eax; ret 0_2_00007FF848E95851
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E957B8 push eax; ret 0_2_00007FF848E95851
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848E8201D push esi; ret 0_2_00007FF848E82022
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848F96048 pushad ; ret 0_2_00007FF848F9612D
Source: LiquidText Installer.exeStatic PE information: section name: .text entropy: 6.809768386929733
Source: C:\Users\user\Desktop\LiquidText Installer.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\LiquidText Installer.exe.logJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\AutoUpdateJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeRegistry key monitored for changes: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRootJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeMemory allocated: 17E5D8E0000 memory reserve | memory write watchJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeMemory allocated: 17E77420000 memory reserve | memory write watchJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848F977E0 rdtsc 0_2_00007FF848F977E0
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598771Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598645Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598517Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598405Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598293Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598109Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597957Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597828Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597703Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597602Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597496Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597384Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597277Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597160Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597033Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596906Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596781Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596670Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596557Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596453Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596333Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596206Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596078Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595967Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595856Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595719Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595441Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595105Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594994Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594884Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594772Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594671Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594549Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594437Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594328Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594215Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594104Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594000Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593880Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593766Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593656Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593547Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593432Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593328Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeWindow / User API: threadDelayed 7889Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeWindow / User API: threadDelayed 1883Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -23058430092136925s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5520Thread sleep time: -2767011611056431s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -598771s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -598645s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -598517s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -598405s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -598293s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -598109s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597957s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597828s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597703s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597602s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597496s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597384s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597277s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597160s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -597033s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596906s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596781s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596670s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596557s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596453s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596333s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596206s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -596078s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -595967s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -595856s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -595719s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -595441s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -595105s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594994s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594884s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594772s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594671s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594549s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594437s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594328s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594215s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594104s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -594000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -593880s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -593766s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -593656s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -593547s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -593432s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exe TID: 5604Thread sleep time: -593328s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598771Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598645Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598517Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598405Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598293Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 598109Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597957Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597828Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597703Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597602Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597496Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597384Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597277Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597160Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 597033Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596906Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596781Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596670Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596557Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596453Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596333Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596206Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 596078Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595967Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595856Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595719Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595441Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 595105Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594994Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594884Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594772Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594671Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594549Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594437Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594328Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594215Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594104Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 594000Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593880Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593766Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593656Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593547Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593432Jump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeThread delayed: delay time: 593328Jump to behavior
Source: LiquidText Installer.exe, 00000000.00000002.2500441740.0000017E7BD53000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\user\Desktop\LiquidText Installer.exeCode function: 0_2_00007FF848F977E0 rdtsc 0_2_00007FF848F977E0
Source: C:\Users\user\Desktop\LiquidText Installer.exeProcess token adjusted: DebugJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Users\user\Desktop\LiquidText Installer.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Globalization.winmd VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Controls.Ribbon\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Controls.Ribbon.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.InteropServices.WindowsRuntime\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Runtime.InteropServices.WindowsRuntime.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Deployment\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WPF8517.tmp VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Data.winmd VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Users\user\AppData\Local\Microsoft\Windows\INetCache\IE\WPFFFD4.tmp VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeQueries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\LiquidText Installer.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
DLL Side-Loading
1
Masquerading
OS Credential Dumping1
Query Registry
Remote Services1
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization ScriptsBoot or Logon Initialization Scripts1
Disable or Modify Tools
LSASS Memory11
Security Software Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)32
Virtualization/Sandbox Evasion
Security Account Manager32
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook2
Obfuscated Files or Information
NTDS1
Application Window Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Software Packing
LSA Secrets12
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Timestomp
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
DLL Side-Loading
DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
No Antivirus matches
No Antivirus matches
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://schemas.datacontract.org/2004/07/0%URL Reputationsafe
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name0%URL Reputationsafe
http://foo/Resources/StoreAppList.Light.png0%Avira URL Cloudsafe
http://foo/bar/resources/storeapplist.light.png0%Avira URL Cloudsafe
http://defaultcontainer/StoreInstaller;component/Resources/StoreAppList.Light.png0%Avira URL Cloudsafe
http://schemas.datacontract.org/2004/07/Microsoft.UniversalStore.DisplayCatalog.Contracts.Version7.R0%Avira URL Cloudsafe
http://schemas.datacontract.org/2004/07/StoreInstaller.Models0%Avira URL Cloudsafe
http://www.w3.oh0%Avira URL Cloudsafe
http://schemas.datacontract.org0%Avira URL Cloudsafe
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://schemas.datacontract.org/2004/07/StoreInstaller.ModelsLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F68E000.00000004.00000800.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://foo/Resources/StoreAppList.Light.pngLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F713000.00000004.00000800.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://defaultcontainer/StoreInstaller;component/Resources/StoreAppList.Light.pngLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F713000.00000004.00000800.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://schemas.datacontract.orgLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5FA55000.00000004.00000800.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://schemas.datacontract.org/2004/07/LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F68E000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://schemas.xmlsoap.org/ws/2005/05/identity/claims/nameLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F7AB000.00000004.00000800.00020000.00000000.sdmpfalse
  • URL Reputation: safe
unknown
http://schemas.datacontract.org/2004/07/Microsoft.UniversalStore.DisplayCatalog.Contracts.Version7.RLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5FA55000.00000004.00000800.00020000.00000000.sdmp, LiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F8EB000.00000004.00000800.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://foo/bar/resources/storeapplist.light.pngLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F713000.00000004.00000800.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
http://www.w3.ohLiquidText Installer.exe, 00000000.00000002.2494440349.0000017E5F68E000.00000004.00000800.00020000.00000000.sdmpfalse
  • Avira URL Cloud: safe
unknown
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1501320
Start date and time:2024-08-29 18:33:35 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 4m 19s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:11
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • HCA enabled
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:LiquidText Installer.exe
Detection:CLEAN
Classification:clean4.winEXE@1/5@0/0
EGA Information:
  • Successful, ratio: 100%
HCA Information:
  • Successful, ratio: 62%
  • Number of executed functions: 39
  • Number of non-executed functions: 2
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe, wuapihost.exe
  • Excluded IPs from analysis (whitelisted): 184.28.90.29, 88.221.169.124, 20.82.228.9
  • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, data-edge.smartscreen.microsoft.com, store-images.s-microsoft.com-c.edgekey.net, nav.smartscreen.microsoft.com, storesdk.dsx.mp.microsoft.com.edgekey.net, e12564.dspb.akamaiedge.net, rp-consumer-prod-displaycatalog-geomap.trafficmanager.net, ocsp.digicert.com, login.live.com, displaycatalog.mp.microsoft.com, storeedgefd.dsx.mp.microsoft.com, fs.microsoft.com, ctldl.windowsupdate.com, da.xboxservices.com, purchase.mp.microsoft.com, fe3cr.delivery.mp.microsoft.com, licensing.mp.microsoft.com, browser.events.data.microsoft.com, storesdk.dsx.mp.microsoft.com, store-images.s-microsoft.com, e16646.g.akamaiedge.net, neus2c-displaycatalog.frontdoor.bigcatalog.commerce.microsoft.com, storesdk.xbetservices.akadns.net, www.microsoft.com, livetileedge.dsx.mp.microsoft.com, displaycatalog-rp.md.mp.microsoft.com.akadns.net
  • Report size getting too big, too many NtAllocateVirtualMemory calls found.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
  • Report size getting too big, too many NtReadVirtualMemory calls found.
  • VT rate limit hit for: LiquidText Installer.exe
TimeTypeDescription
12:34:30API Interceptor3808x Sleep call for process: LiquidText Installer.exe modified
No context
No context
No context
No context
No context
Process:C:\Users\user\Desktop\LiquidText Installer.exe
File Type:CSV text
Category:dropped
Size (bytes):4123
Entropy (8bit):5.367551725214397
Encrypted:false
SSDEEP:96:iqbYqGSI6ou/fmOYqSqtzHeqKksvoqdqZ4UqqIKXWWTvqnqtY:iqbYqGcn/uHqXtzHeqKksvoqdqZrqqlm
MD5:98EAF0107CE35D6B8105EB6A028BD758
SHA1:CC14B15DC9D0C75F0E50F4DAA08508AADC530F06
SHA-256:AE1F300DBA5C185450FB806D7BEB4DF8B0B8CE1CE7160E7BE3964814D41DBD75
SHA-512:CE0126E0EEEE849EDCADA4B930EC2BC700B1BEE64BC7635633991711D390AA914758D80A7E7648F30D843D064561153CB8CC29D2BB0B92075E3966CCFF12F5F4
Malicious:false
Reputation:low
Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni.dll",0..3,"WindowsBase, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35","C:\Windows\assembly\NativeImages_v4.0.30319_64\WindowsBase\95a5c1baa004b986366d34856f0a5a75\WindowsBase.ni.dll",0..3,"PresentationCore, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35","C:\Windows\assembly\NativeImages_v4.0.30319_64\PresentationCore\ef4e808cb158d79ab9a2b049f8fab733\PresentationCore.ni.dll",0..3,"PresentationFramework, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35","C:\Windows\assembly\NativeImages_v4.0.30319_64\Presentatio5ae0f00f#\
Process:C:\Users\user\Desktop\LiquidText Installer.exe
File Type:PNG image data, 100 x 100, 8-bit/color RGBA, non-interlaced
Category:dropped
Size (bytes):12712
Entropy (8bit):7.918649791578471
Encrypted:false
SSDEEP:384:KVDrMg5Cag0nKSoSnIxJ+AplLtfSc3md19aOAX:KVDrMg5Ca5qeSLtfS5TSX
MD5:B3FCC431866A877C1E12C75CD797D430
SHA1:4B44D7626DA58D207FCDEE18464AD9DE185D86E6
SHA-256:7A248353396344A50E23A405E38E3226AF84AD51604D72E5B63BA8E4AC5A0BEC
SHA-512:E4438893B5796F7B070E3F5A7F6D5FE19219CA4F00D702D25B51717ECC8A48902244276EC750E4631A93DB43616AFF8052DE204D425BD9C017CB5D89CB8918A3
Malicious:false
Reputation:low
Preview:.PNG........IHDR...d...d.....p.T...oiCCPDisplay..H..WwT.w.~....F@AF...(.d..a...ATB. .._.D..RE..Q.u.].Z.....,.U..G...|.$P......w..=...>oNN....+.E.!P.P1.....L!.>80..L..KJ.!.....{~f........&V*.....TV*..,.9.RI1@..t.D..v...I*..`...0....{*.A.._.@...7..0."......L.`..@X&.S.....+.r........?......).....L....[...|.....>~.8..........*...Oi.....{k8...g......ZaIL".=..R....0..7r.Fw...R4x.RR*..`...RqX..K..P...j.9..h...Y.WE'ks..J........^?...hs.......SB....e../*......W&O..`.P............b.ub.....+SD.j...\&"Q.W....KU...~.*?9J...]".O.....d...^.Yizl.,RYX.fv.].H..K.V.B......-...E&...h..$m.=B.$k....T%$k......4..e...a.B.!rP...... ..D@..y..M...H.....#......P...1..P..>.E5O7.B..e....x...A.dP.....j........A..P............W..E...a.(v.{.mA...t,.D..A...K..v.7...u.u.u....>A^.|..ht@.UJ...'..i...... ..B.....E..!.H:.... .....R_L..Z..Kr.q..._f...x.....>.^s.T...|Y_...R. .K$5..K...P'..T#..a..:C...?.......j..A.B.A......d(u........*Y...D%..</_%.Q*.d.h.d.`....;...)..L=7...0;.w..[ ...
Process:C:\Users\user\Desktop\LiquidText Installer.exe
File Type:PNG image data, 68 x 68, 8-bit/color RGBA, non-interlaced
Category:dropped
Size (bytes):777
Entropy (8bit):7.581516394833844
Encrypted:false
SSDEEP:24:+mQsOlh5Gn7KtkosCDKCIggagJUCVhdlEkPGq52c:+EmAvVCI5+8hdl9NT
MD5:A5F45979E0C15389FDB29216EBB19BBF
SHA1:7CD1E4338E4A0E40D79BDADB431D5F0AE9603DE6
SHA-256:1B121A7E399FB053BF529883299B0BA0B958FA806CB0CD2B4D255BED58AA8492
SHA-512:17267975D299B074B7167530ACF3B5C5A4D1D9AA7FF3040D39ACDB36FCE059CF246BEC7B83FBF35CFCA7AC75F00E7347DB6B79040AFE5C083B924552017083E6
Malicious:false
Reputation:moderate, very likely benign file
Preview:.PNG........IHDR...D...D.....8.......pHYs...........~.....IDATx..KC1..._8.. ].t... ......b....IT....I-..C......A..AA.|..4.M^^............J.(.2=..t.wF.$.266.J....^..V."@../ .w3..qY.U7:....P...WOo....aM.>.j..y./.... L..,...I^@|a....b..q.:........%i.m4@._....X...........%..u.p..PX.9.XL..|.H.@.?....\..xm..3...&..~...HREa........b. ...*e.@|$M........ {..,l-$D......i...2.MP....:.tk@#..T.!..a.bP.$..Z.......>@0... C...+...E.3%w..nX...G..;.(...C..I.d....l2U.t<.).....$...L<.......2.....I{.,...=..KA"..H..k. .-.......TR.?&lj.k....D.....?.... ].?g.*._....9..S.c.R.....J..G..%..lb ..j6.....!...4..&S(...........A.....J...2@.k>@Z.......h-D.#....... ......... t...3$.`.............4..&.N..Lg...m..2t).J.B.P..".3!.bZV.5.A).2.+T_:R..T.0......c....s0P....IEND.B`.
Process:C:\Users\user\Desktop\LiquidText Installer.exe
File Type:ASCII text, with very long lines (1136), with no line terminators
Category:dropped
Size (bytes):1136
Entropy (8bit):5.884313058724772
Encrypted:false
SSDEEP:24:QmeWUJxBiiAFaUlbJ2Hr1mI+Ic2iFerfnmj6BmKHnsZu:ZeX/ZkXgHr1m52iwrPvQInsZu
MD5:A10F31FA140F2608FF150125F3687920
SHA1:EC411CC7005AAA8E3775CF105FCD4E1239F8ED4B
SHA-256:28C871238311D40287C51DC09AEE6510CAC5306329981777071600B1112286C6
SHA-512:CF915FB34CD5ECFBD6B25171D6E0D3D09AF2597EDF29F9F24FA474685D4C5EC9BC742ADE9F29ABAC457DD645EE955B1914A635C90AF77C519D2ADA895E7ECF12
Malicious:false
Reputation:moderate, very likely benign file
Preview:MIIDUDCCAjigAwIBAgIQImsjBGfFTk6M7sZzNVcAwDANBgkqhkiG9w0BAQsFADAlMSMwIQYDVQQDExphdXRoLmluc3RhbGxlcnNlcnZpY2VzLmNvbTAeFw0yMzEwMjUyMzEzNDhaFw0yODEwMjUyMzIzNDhaMCUxIzAhBgNVBAMTGmF1dGguaW5zdGFsbGVyc2VydmljZXMuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwnTHlqfx0MmiBSvhwkjmo2Y53B2ED6kyYgNgsSoX090DwL9g08Q2LnfEEFH+mif1Zv6jztT5QvWXjjroucDJQzZFBz/xbd1zilX80JFxD/8TIiKdmg73eXcrkSTsQUz97HwnpZbQDWbQJh/QxbvRIrJrcU2ADGsC5KBpRVXJ3t9m3TKNrfbAtKpPonso6+6GHvwUNTZUU9UgvDV3qGpDSniqumK3a1U9hphJJBb8us3o3538CM3tJAJ2w/bDGA/MOaTInkspZIQpecv16wkMWuLyHUxAaMDIO0tuIKxeIka0PaTAaZdw6BXofnNqwDD5JloOGm323JAR3pe+hJmSmQIDAQABo3wwejAOBgNVHQ8BAf8EBAMCBaAwCQYDVR0TBAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHwYDVR0jBBgwFoAUL8Xv6MyxPZ8/T+cj4fEkfSpVzqEwHQYDVR0OBBYEFC/F7+jMsT2fP0/nI+HxJH0qVc6hMA0GCSqGSIb3DQEBCwUAA4IBAQASgm1VIK9vC88LPaCv7qPEd2TUtRrOi/VG2HkcpmBIKGoDeFa41jzKpO25iMg4MQhlXuljIYMDch8YpZETcFvBXHzfCF7Rc+kl/K5tFd8kHGMItiPuwZV/BfvL9Wu4gY4g1skfRpiemP1gZvlc1fZlEoYDqAIzODkRyXOd2nsa7zt8iGTdNujZ8A/IyQzGNeqtmt+bpNvKojkB
Process:C:\Users\user\Desktop\LiquidText Installer.exe
File Type:ASCII text, with very long lines (1136), with no line terminators
Category:dropped
Size (bytes):1136
Entropy (8bit):5.884313058724772
Encrypted:false
SSDEEP:24:QmeWUJxBiiAFaUlbJ2Hr1mI+Ic2iFerfnmj6BmKHnsZu:ZeX/ZkXgHr1m52iwrPvQInsZu
MD5:A10F31FA140F2608FF150125F3687920
SHA1:EC411CC7005AAA8E3775CF105FCD4E1239F8ED4B
SHA-256:28C871238311D40287C51DC09AEE6510CAC5306329981777071600B1112286C6
SHA-512:CF915FB34CD5ECFBD6B25171D6E0D3D09AF2597EDF29F9F24FA474685D4C5EC9BC742ADE9F29ABAC457DD645EE955B1914A635C90AF77C519D2ADA895E7ECF12
Malicious:false
Reputation:moderate, very likely benign file
Preview:MIIDUDCCAjigAwIBAgIQImsjBGfFTk6M7sZzNVcAwDANBgkqhkiG9w0BAQsFADAlMSMwIQYDVQQDExphdXRoLmluc3RhbGxlcnNlcnZpY2VzLmNvbTAeFw0yMzEwMjUyMzEzNDhaFw0yODEwMjUyMzIzNDhaMCUxIzAhBgNVBAMTGmF1dGguaW5zdGFsbGVyc2VydmljZXMuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAwnTHlqfx0MmiBSvhwkjmo2Y53B2ED6kyYgNgsSoX090DwL9g08Q2LnfEEFH+mif1Zv6jztT5QvWXjjroucDJQzZFBz/xbd1zilX80JFxD/8TIiKdmg73eXcrkSTsQUz97HwnpZbQDWbQJh/QxbvRIrJrcU2ADGsC5KBpRVXJ3t9m3TKNrfbAtKpPonso6+6GHvwUNTZUU9UgvDV3qGpDSniqumK3a1U9hphJJBb8us3o3538CM3tJAJ2w/bDGA/MOaTInkspZIQpecv16wkMWuLyHUxAaMDIO0tuIKxeIka0PaTAaZdw6BXofnNqwDD5JloOGm323JAR3pe+hJmSmQIDAQABo3wwejAOBgNVHQ8BAf8EBAMCBaAwCQYDVR0TBAIwADAdBgNVHSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHwYDVR0jBBgwFoAUL8Xv6MyxPZ8/T+cj4fEkfSpVzqEwHQYDVR0OBBYEFC/F7+jMsT2fP0/nI+HxJH0qVc6hMA0GCSqGSIb3DQEBCwUAA4IBAQASgm1VIK9vC88LPaCv7qPEd2TUtRrOi/VG2HkcpmBIKGoDeFa41jzKpO25iMg4MQhlXuljIYMDch8YpZETcFvBXHzfCF7Rc+kl/K5tFd8kHGMItiPuwZV/BfvL9Wu4gY4g1skfRpiemP1gZvlc1fZlEoYDqAIzODkRyXOd2nsa7zt8iGTdNujZ8A/IyQzGNeqtmt+bpNvKojkB
File type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Entropy (8bit):6.892151745584676
TrID:
  • Win32 Executable (generic) Net Framework (10011505/4) 50.01%
  • Win32 Executable (generic) a (10002005/4) 49.97%
  • Generic Win/DOS Executable (2004/3) 0.01%
  • DOS Executable Generic (2002/1) 0.01%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:LiquidText Installer.exe
File size:887'840 bytes
MD5:9ab59b8d383a6ab6c131c5e96b4d68de
SHA1:22192dab0ce673ae164d0fb25cf3a015c3e9c37c
SHA256:967552d901dbdcc34498c2e57a61bc2846400f90726d951d4075ade86e4af545
SHA512:b6491537e103f37529fa76b43e447e09beef0bf0304e95e4c5deb4e65cbbb1ccd7b8ae95e9ada8615faba6be54515afa25b64d47a91b830e37804ee43a074f5a
SSDEEP:24576:uh2YBcrQm+2DR7BWYpWUo44kEOKBWppwF:UvOM07VZ5EOa+k
TLSH:9F154C6123EC0439E7770B7ABD7B18511735BC385942E5AE0A8E263C18E2B5789F2737
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................."...0......(........... ... ....@.. ....................................`................................
Icon Hash:136cb2b27171b24d
Entrypoint:0x4c0e1a
Entrypoint Section:.text
Digitally signed:true
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
Time Stamp:0xC2ABFCEE [Fri Jun 30 12:28:30 2073 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:4
OS Version Minor:0
File Version Major:4
File Version Minor:0
Subsystem Version Major:4
Subsystem Version Minor:0
Import Hash:f34d5f2d4577ed6d9ceec516c1f5a744
Signature Valid:true
Signature Issuer:CN=Microsoft Marketplace CA G 026, OU=EOC, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Signature Validation Error:The operation completed successfully
Error Number:0
Not Before, Not After
  • 07/08/2024 22:09:58 10/08/2024 22:09:58
Subject Chain
  • CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Version:3
Thumbprint MD5:DA4F8E77CBCCC7073945FD8813A14177
Thumbprint SHA-1:B87BF925B2F005F71FD06A187C7945458EAA6F6F
Thumbprint SHA-256:C3D08F5D79365578B49276DBD45D4362CA7A1CFEAB94B73F6425E8E7E31841A4
Serial:330045F94DDCA9588216DC9E2D00010045F94D
Instruction
jmp dword ptr [00402000h]
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
add byte ptr [eax], al
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0xc0dc70x4f.text
IMAGE_DIRECTORY_ENTRY_RESOURCE0xc20000x12520.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0xd1a000x7220
IMAGE_DIRECTORY_ENTRY_BASERELOC0xd60000xc.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0xc0cec0x54.text
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x20000x8.text
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x20080x48.text
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x20000xbee200xbf000c90d953cbcaef046e323bbd26e736bdeFalse0.435125061354712data6.809768386929733IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rsrc0xc20000x125200x126001c09ed0bb710b875abcf80fded951bd7False0.9542676445578231data7.935534959106625IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0xd60000xc0x2002a5cbd3e673e328fbf0220018b870a96False0.041015625data0.07763316234324169IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_ICON0xc21e00xd5e7PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced1.0004748077941525
RT_ICON0xcf7d80x1363PNG image data, 64 x 64, 8-bit/color RGBA, non-interlaced1.0022164013701391
RT_ICON0xd0b4c0xc9dPNG image data, 48 x 48, 8-bit/color RGBA, non-interlaced1.0034066274388356
RT_ICON0xd17fc0x9daPNG image data, 40 x 40, 8-bit/color RGBA, non-interlaced1.0043616177636796
RT_ICON0xd21e80x691PNG image data, 32 x 32, 8-bit/color RGBA, non-interlaced1.006543723973825
RT_ICON0xd288c0x490PNG image data, 24 x 24, 8-bit/color RGBA, non-interlaced1.009417808219178
RT_ICON0xd2d2c0x396PNG image data, 20 x 20, 8-bit/color RGBA, non-interlaced1.0119825708061003
RT_ICON0xd30d40x299PNG image data, 16 x 16, 8-bit/color RGBA, non-interlaced1.0165413533834586
RT_GROUP_ICON0xd33800x76data0.7542372881355932
RT_VERSION0xd34080x3e0data0.4324596774193548
RT_MANIFEST0xd37f80xd21XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators0.3924427253793514
DLLImport
mscoree.dll_CorExeMain
No network behavior found

Click to jump to process

Click to jump to process

Click to dive into process behavior distribution

Target ID:0
Start time:12:34:25
Start date:29/08/2024
Path:C:\Users\user\Desktop\LiquidText Installer.exe
Wow64 process (32bit):false
Commandline:"C:\Users\user\Desktop\LiquidText Installer.exe"
Imagebase:0x17e5d4e0000
File size:887'840 bytes
MD5 hash:9AB59B8D383A6AB6C131C5E96B4D68DE
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:low
Has exited:true

Reset < >

    Execution Graph

    Execution Coverage:16.1%
    Dynamic/Decrypted Code Coverage:100%
    Signature Coverage:0%
    Total number of Nodes:3
    Total number of Limit Nodes:0
    execution_graph 18159 7ff848e80fa8 18160 7ff848e80fb1 K32EnumProcessModules 18159->18160 18162 7ff848e81072 18160->18162

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 273 7ff848e946ce-7ff848e94705 call 7ff848e93cf0 276 7ff848e94707 273->276 277 7ff848e94708-7ff848e9474e 273->277 276->277 280 7ff848e94750 277->280 281 7ff848e94751-7ff848e9475b 277->281 280->281 282 7ff848e9475d 281->282 283 7ff848e9475e-7ff848e9476e call 7ff848e93cf8 281->283 282->283 286 7ff848e94770-7ff848e94776 283->286 287 7ff848e947c6-7ff848e947cc 283->287 288 7ff848e94791-7ff848e947c1 286->288 289 7ff848e94778-7ff848e9478f 286->289 290 7ff848e947ce 287->290 291 7ff848e947cf-7ff848e947d9 287->291 299 7ff848e948ad-7ff848e948b5 288->299 289->288 290->291 294 7ff848e947db 291->294 295 7ff848e947dc-7ff848e947ec call 7ff848e93cf8 291->295 294->295 295->299 300 7ff848e947f2-7ff848e947f8 295->300 301 7ff848e948b7 299->301 302 7ff848e948b8-7ff848e948c2 299->302 303 7ff848e947fa-7ff848e94800 300->303 304 7ff848e9480c-7ff848e94817 300->304 301->302 305 7ff848e948c4 302->305 306 7ff848e948c5-7ff848e948d5 call 7ff848e93cf8 302->306 307 7ff848e94802 303->307 308 7ff848e94803-7ff848e9480a 303->308 309 7ff848e94840-7ff848e94876 304->309 310 7ff848e94819-7ff848e9482a 304->310 305->306 315 7ff848e94926-7ff848e9492c 306->315 316 7ff848e948d7-7ff848e948dd 306->316 307->308 308->304 309->299 330 7ff848e94878-7ff848e9487b 309->330 310->309 319 7ff848e9492e 315->319 320 7ff848e9492f-7ff848e94939 315->320 317 7ff848e948f1-7ff848e94921 316->317 318 7ff848e948df-7ff848e948e5 316->318 331 7ff848e94a0d-7ff848e94a15 317->331 322 7ff848e948e7 318->322 323 7ff848e948e8-7ff848e948ef 318->323 319->320 325 7ff848e9493b 320->325 326 7ff848e9493c-7ff848e9494c call 7ff848e93cf8 320->326 322->323 323->317 325->326 326->331 337 7ff848e94952-7ff848e94958 326->337 333 7ff848e94881-7ff848e948a1 330->333 334 7ff848e94adb-7ff848e94b29 330->334 335 7ff848e94a17 331->335 336 7ff848e94a18-7ff848e94a22 331->336 359 7ff848e948a3-7ff848e948a5 333->359 360 7ff848e948a7 333->360 357 7ff848e94b2b 334->357 358 7ff848e94b2c-7ff848e94b3a call 7ff848e80388 334->358 335->336 338 7ff848e94a24 336->338 339 7ff848e94a25-7ff848e94a35 call 7ff848e93cf8 336->339 340 7ff848e9495a-7ff848e94960 337->340 341 7ff848e9496c-7ff848e94977 337->341 338->339 355 7ff848e94a37-7ff848e94a3d 339->355 356 7ff848e94aad-7ff848e94ada 339->356 343 7ff848e94962 340->343 344 7ff848e94963-7ff848e9496a 340->344 346 7ff848e949a0-7ff848e949d6 341->346 347 7ff848e94979-7ff848e9498a 341->347 343->344 344->341 346->331 378 7ff848e949d8-7ff848e949db 346->378 347->346 363 7ff848e94a51-7ff848e94a5c 355->363 364 7ff848e94a3f-7ff848e94a45 355->364 357->358 376 7ff848e94b84-7ff848e94b8c 358->376 377 7ff848e94b3b-7ff848e94b40 358->377 368 7ff848e948ab 359->368 360->368 365 7ff848e94a85-7ff848e94aa1 363->365 366 7ff848e94a5e-7ff848e94a6f 363->366 370 7ff848e94a47 364->370 371 7ff848e94a48-7ff848e94a4f 364->371 386 7ff848e94aa3-7ff848e94aa5 365->386 387 7ff848e94aa7 365->387 366->365 368->299 370->371 371->363 380 7ff848e94b42-7ff848e94b77 call 7ff848e94b8d 377->380 381 7ff848e94b49-7ff848e94b50 call 7ff848e80468 377->381 378->334 382 7ff848e949e1-7ff848e94a01 378->382 395 7ff848e94b82 380->395 388 7ff848e94b55-7ff848e94b81 call 7ff848e94b8d 381->388 396 7ff848e94a03-7ff848e94a05 382->396 397 7ff848e94a07 382->397 391 7ff848e94aab 386->391 387->391 388->395 391->356 395->376 400 7ff848e94a0b 396->400 397->400 400->331
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2501816750.00007FF848E80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848E80000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848e80000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: X[Bo$x6Bo$x6Bo$x6Bo$x6Bo$'Do$'Do$'Do$'Do$'Do
    • API String ID: 0-2341873655
    • Opcode ID: 1c8b23e5f53a25aa2f3795ea588e38f8da7f4f94fbd4ec8307c08e016b105a6d
    • Instruction ID: a17115d963076a3659a860e6ff806e5ec319cab46c5f7f2f564bcdff833f8aa6
    • Opcode Fuzzy Hash: 1c8b23e5f53a25aa2f3795ea588e38f8da7f4f94fbd4ec8307c08e016b105a6d
    • Instruction Fuzzy Hash: 0E02287091D6894FE759E768841667ABBE1FF96348F0404BED089DB2D2DBB8AC05C306

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 550 7ff848eb6672-7ff848eb667e 551 7ff848eb6680 550->551 552 7ff848eb6644 550->552 553 7ff848eb6681 551->553 554 7ff848eb66fa-7ff848eb66fd 551->554 555 7ff848eb6646-7ff848eb6659 call 7ff848eaa250 call 7ff848eb66b8 552->555 556 7ff848eb66be-7ff848eb66c4 552->556 557 7ff848eb6682 553->557 558 7ff848eb66ac-7ff848eb66b7 553->558 562 7ff848eb6683 555->562 589 7ff848eb665b 555->589 559 7ff848eb66c6 556->559 560 7ff848eb668a-7ff848eb669a 556->560 557->562 558->556 563 7ff848eb6740-7ff848eb6761 559->563 564 7ff848eb66c8-7ff848eb66cd 559->564 565 7ff848eb66a5-7ff848eb66a8 560->565 566 7ff848eb669b-7ff848eb66a4 560->566 568 7ff848eb6685-7ff848eb6688 562->568 569 7ff848eb66a9-7ff848eb66aa 562->569 571 7ff848eb6763 563->571 572 7ff848eb6764-7ff848eb6779 563->572 570 7ff848eb66d0-7ff848eb66e0 564->570 565->569 566->565 568->560 569->558 569->570 574 7ff848eb66e2-7ff848eb66e3 570->574 575 7ff848eb66eb-7ff848eb66ee 570->575 571->572 577 7ff848eb677b 572->577 578 7ff848eb677c-7ff848eb6791 572->578 574->575 580 7ff848eb66f0 575->580 581 7ff848eb6718-7ff848eb673e 575->581 577->578 582 7ff848eb6793 578->582 583 7ff848eb6794-7ff848eb67b5 578->583 586 7ff848eb66f2-7ff848eb66f9 580->586 587 7ff848eb6716 580->587 581->563 582->583 590 7ff848eb67b7-7ff848eb67f7 call 7ff848e837c8 583->590 591 7ff848eb67ff-7ff848eb6805 583->591 586->554 587->581 589->553 595 7ff848eb665d-7ff848eb6668 589->595 596 7ff848eb67fc-7ff848eb67fd 590->596 593 7ff848eb6807 591->593 594 7ff848eb6808-7ff848eb6819 591->594 593->594 597 7ff848eb681b 594->597 598 7ff848eb681c-7ff848eb6863 call 7ff848eb3d40 594->598 596->591 597->598 603 7ff848eb6865-7ff848eb686b 598->603 604 7ff848eb68b8-7ff848eb68c0 598->604 607 7ff848eb686e-7ff848eb6883 603->607 608 7ff848eb686d 603->608 605 7ff848eb68c2-7ff848eb68c5 604->605 606 7ff848eb6919-7ff848eb6922 604->606 609 7ff848eb6946-7ff848eb6976 call 7ff848e837c8 605->609 610 7ff848eb68c7-7ff848eb68db 605->610 611 7ff848eb6924 606->611 612 7ff848eb6925-7ff848eb693e 606->612 615 7ff848eb6886-7ff848eb6895 607->615 616 7ff848eb6885 607->616 608->607 621 7ff848eb6977-7ff848eb698d 609->621 610->606 611->612 612->609 619 7ff848eb6897 615->619 620 7ff848eb6898-7ff848eb68b3 call 7ff848e91230 615->620 616->615 619->620 620->604 622 7ff848eb6990-7ff848eb69a1 621->622 623 7ff848eb698f 621->623 625 7ff848eb69a3 622->625 626 7ff848eb69a4-7ff848eb69ba 622->626 623->622 625->626 626->621 628 7ff848eb69bc-7ff848eb69cb 626->628 629 7ff848eb69ce-7ff848eb69df 628->629 630 7ff848eb69cd 628->630 631 7ff848eb69e2-7ff848eb6a0a call 7ff848eb3d40 629->631 632 7ff848eb69e1 629->632 630->629 635 7ff848eb6a10-7ff848eb6a9f call 7ff848eb5c80 631->635 632->631 637 7ff848eb6aa4-7ff848eb6b38 635->637 645 7ff848eb6b3a 637->645 646 7ff848eb6b3b-7ff848eb6b49 637->646 645->646 649 7ff848eb6bc5-7ff848eb6bc9 646->649 650 7ff848eb6b4a 646->650 651 7ff848eb6bd4-7ff848eb6c27 649->651 652 7ff848eb6bcb-7ff848eb6bce 649->652 653 7ff848eb6bbb-7ff848eb6bc3 650->653 654 7ff848eb6b4b-7ff848eb6b50 650->654 666 7ff848eb6c30-7ff848eb6c34 651->666 667 7ff848eb6c29-7ff848eb6c2e 651->667 655 7ff848eb6bd1-7ff848eb6bd3 652->655 653->649 654->655 657 7ff848eb6b52-7ff848eb6b6a 654->657 655->651 659 7ff848eb6ba8-7ff848eb6bb9 657->659 660 7ff848eb6b6c-7ff848eb6b8b 657->660 662 7ff848eb6b8e-7ff848eb6ba0 660->662 663 7ff848eb6b8d 660->663 664 7ff848eb6ba2-7ff848eb6ba5 662->664 663->662 664->659 668 7ff848eb6c37-7ff848eb6c4d 666->668 667->668 670 7ff848eb6c88-7ff848eb6c8b 668->670 671 7ff848eb6c4f-7ff848eb6c5b 668->671 672 7ff848eb6cc6-7ff848eb6cc9 670->672 673 7ff848eb6c8d-7ff848eb6c99 670->673 671->670 674 7ff848eb6c5d-7ff848eb6c81 671->674 675 7ff848eb6d04-7ff848eb6d1b 672->675 676 7ff848eb6ccb-7ff848eb6cd7 672->676 673->672 678 7ff848eb6c9b-7ff848eb6cbf 673->678 674->670 684 7ff848eb6d1c 675->684 676->675 679 7ff848eb6cd9-7ff848eb6cfd 676->679 678->672 679->675 684->684
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2501816750.00007FF848E80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848E80000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848e80000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: [Bo$`SGo$hSGo$pSGo$pSGo$x6Bo$x6Bo$xSGo
    • API String ID: 0-1413590523
    • Opcode ID: 8e10323d8e7867f14a3aacb38d4a2db39953d34ecbf646119dd33bebe8a13f82
    • Instruction ID: baa88fb8a3838e5f144a2242dab867db711f8b378eedbef47a6584c110fd6277
    • Opcode Fuzzy Hash: 8e10323d8e7867f14a3aacb38d4a2db39953d34ecbf646119dd33bebe8a13f82
    • Instruction Fuzzy Hash: 1E42C371D0DA898FE799EB2888556A97BE0FF56340F0401FED08DDB1A2DF38A845C746
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$H&Do$P&Do$X&Do$x6Bo$x6Bo
    • API String ID: 0-1456816284
    • Opcode ID: 0454a7da0913c63476eeb180357c5c1348808afc7164135803bb58d019a716c7
    • Instruction ID: eb16b8c8644d1714ba5305ba407b198e730a0cf89ad54e47168de032356f4cde
    • Opcode Fuzzy Hash: 0454a7da0913c63476eeb180357c5c1348808afc7164135803bb58d019a716c7
    • Instruction Fuzzy Hash: CD921530A0CA894FE799EB2C9455A757BE1EF56354F0401BED04EC72E3DE28AC86C785

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1130 7ff848f940a8-7ff848f940c0 1132 7ff848f940c2-7ff848f940c3 1130->1132 1133 7ff848f94123-7ff848f9412e 1130->1133 1134 7ff848f94143-7ff848f9414d 1132->1134 1135 7ff848f940c5-7ff848f9411c 1132->1135 1139 7ff848f94134-7ff848f94142 1133->1139 1140 7ff848f941d8-7ff848f941dc 1133->1140 1141 7ff848f94195-7ff848f94196 1134->1141 1142 7ff848f9414f-7ff848f94159 1134->1142 1163 7ff848f9411e-7ff848f94122 1135->1163 1139->1134 1149 7ff848f941ee 1140->1149 1150 7ff848f941de-7ff848f941ec 1140->1150 1145 7ff848f941b0-7ff848f941c1 1141->1145 1146 7ff848f94198-7ff848f941a5 1141->1146 1147 7ff848f9415b 1142->1147 1148 7ff848f9415c-7ff848f9416b 1142->1148 1161 7ff848f941a6 1146->1161 1147->1148 1155 7ff848f9416d 1148->1155 1156 7ff848f9416e-7ff848f94187 1148->1156 1151 7ff848f941f3-7ff848f941f6 1149->1151 1150->1151 1159 7ff848f941f8-7ff848f941fc 1151->1159 1160 7ff848f94239-7ff848f9424a 1151->1160 1155->1156 1162 7ff848f9418d-7ff848f94194 1156->1162 1164 7ff848f94214 1159->1164 1165 7ff848f941fe-7ff848f941ff 1159->1165 1168 7ff848f94202-7ff848f94212 1160->1168 1169 7ff848f9424c-7ff848f94272 1160->1169 1161->1145 1167 7ff848f941a8-7ff848f941a9 1161->1167 1162->1141 1163->1133 1170 7ff848f94216-7ff848f94218 1164->1170 1165->1168 1167->1161 1176 7ff848f941ab-7ff848f941ae 1167->1176 1168->1170 1172 7ff848f94273-7ff848f94299 1170->1172 1173 7ff848f9421a-7ff848f94233 1170->1173 1181 7ff848f942a3-7ff848f942bb 1172->1181 1182 7ff848f9429b-7ff848f942a2 1172->1182 1173->1160 1173->1163 1176->1145 1183 7ff848f9433b-7ff848f9433c 1181->1183 1184 7ff848f942bc 1181->1184 1182->1181 1185 7ff848f9433e-7ff848f9434e 1183->1185 1186 7ff848f942bd-7ff848f942be 1184->1186 1187 7ff848f942bf-7ff848f942d0 1184->1187 1193 7ff848f94354-7ff848f94357 1185->1193 1194 7ff848f9445e-7ff848f94462 1185->1194 1186->1187 1190 7ff848f942d2-7ff848f942d4 1187->1190 1191 7ff848f94314-7ff848f94317 1187->1191 1192 7ff848f94318-7ff848f94339 1190->1192 1195 7ff848f942d6-7ff848f942d8 1190->1195 1191->1192 1192->1183 1198 7ff848f9435b-7ff848f94399 1193->1198 1199 7ff848f94474 1194->1199 1200 7ff848f94464-7ff848f94472 1194->1200 1195->1183 1196 7ff848f942da-7ff848f942db 1195->1196 1196->1198 1201 7ff848f942dd-7ff848f94313 1196->1201 1223 7ff848f943a3-7ff848f943a7 1198->1223 1224 7ff848f9439b-7ff848f9439e 1198->1224 1202 7ff848f94479-7ff848f9447c 1199->1202 1200->1202 1201->1191 1206 7ff848f9447e-7ff848f94482 1202->1206 1207 7ff848f944bf-7ff848f944f8 1202->1207 1210 7ff848f94484-7ff848f94498 1206->1210 1211 7ff848f9449a 1206->1211 1214 7ff848f9449c-7ff848f9449e 1210->1214 1211->1214 1218 7ff848f944a0-7ff848f944ad 1214->1218 1219 7ff848f944f9-7ff848f9451d 1214->1219 1225 7ff848f944af-7ff848f944b9 1218->1225 1232 7ff848f94527-7ff848f94544 1219->1232 1233 7ff848f9451f-7ff848f94526 1219->1233 1228 7ff848f943e5-7ff848f943ee 1223->1228 1229 7ff848f943a9-7ff848f943b5 1223->1229 1227 7ff848f94436-7ff848f9445c 1224->1227 1225->1185 1225->1207 1227->1225 1230 7ff848f943f0 1228->1230 1231 7ff848f943f1-7ff848f94400 1228->1231 1234 7ff848f943c0-7ff848f943e3 1229->1234 1235 7ff848f943b7-7ff848f943b8 1229->1235 1230->1231 1237 7ff848f94402 1231->1237 1238 7ff848f94403-7ff848f9441c 1231->1238 1239 7ff848f94546 1232->1239 1240 7ff848f94547-7ff848f945bc 1232->1240 1233->1232 1234->1227 1235->1234 1237->1238 1238->1227 1246 7ff848f9441e-7ff848f94434 1238->1246 1239->1240 1254 7ff848f945be-7ff848f945ce 1240->1254 1246->1227 1256 7ff848f945d4-7ff848f9460b 1254->1256 1257 7ff848f94678-7ff848f9467c 1254->1257 1271 7ff848f9460d-7ff848f94627 1256->1271 1258 7ff848f9468e 1257->1258 1259 7ff848f9467e-7ff848f9468c 1257->1259 1260 7ff848f94693-7ff848f94696 1258->1260 1259->1260 1263 7ff848f94698-7ff848f9469c 1260->1263 1264 7ff848f946d9-7ff848f94712 1260->1264 1266 7ff848f946b4 1263->1266 1267 7ff848f9469e-7ff848f946b2 1263->1267 1270 7ff848f946b6-7ff848f946b8 1266->1270 1267->1270 1274 7ff848f94713-7ff848f94739 1270->1274 1275 7ff848f946ba-7ff848f946c7 1270->1275 1276 7ff848f9462d-7ff848f94636 1271->1276 1286 7ff848f94743-7ff848f9475b 1274->1286 1287 7ff848f9473b-7ff848f94742 1274->1287 1281 7ff848f946c9-7ff848f946d3 1275->1281 1278 7ff848f94650-7ff848f94676 1276->1278 1279 7ff848f94638-7ff848f9464e 1276->1279 1278->1281 1279->1278 1281->1254 1281->1264 1288 7ff848f947db-7ff848f947e4 1286->1288 1289 7ff848f9475c 1286->1289 1287->1286 1290 7ff848f947e6-7ff848f947fa 1288->1290 1291 7ff848f9475d-7ff848f9475e 1289->1291 1292 7ff848f9475f-7ff848f94778 1289->1292 1296 7ff848f947fb-7ff848f9480d 1290->1296 1291->1292 1292->1288 1294 7ff848f9477a-7ff848f9477b 1292->1294 1294->1296 1297 7ff848f9477d-7ff848f947cc 1294->1297 1301 7ff848f94812-7ff848f94816 1296->1301 1297->1290 1305 7ff848f947ce-7ff848f947da 1297->1305 1302 7ff848f9481c-7ff848f94830 1301->1302 1303 7ff848f94f5f-7ff848f94f72 1301->1303 1302->1303 1308 7ff848f94836-7ff848f94851 1302->1308 1305->1288 1308->1301 1310 7ff848f94853-7ff848f94867 1308->1310 1310->1303
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$@&Do$@&Do$x6Bo$x6Bo$x6Bo
    • API String ID: 0-29637834
    • Opcode ID: ec6f7e46877462eeef9d745c2ba21c95afc0d45ae03711acbae41554554aa36e
    • Instruction ID: 44566b0c68da31ac8ca747a62592b44b4854eacea899696f309f3cca09edea68
    • Opcode Fuzzy Hash: ec6f7e46877462eeef9d745c2ba21c95afc0d45ae03711acbae41554554aa36e
    • Instruction Fuzzy Hash: 5052F431A0CA894FE799A72C98196707BD1EF76354F0401FED08EC72E3DE19AC468795

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1430 7ff848e841ed-7ff848e841f1 1431 7ff848e841f9 1430->1431 1432 7ff848e841f3 1430->1432 1433 7ff848e841fd-7ff848e84210 1431->1433 1434 7ff848e841fb 1431->1434 1432->1431 1436 7ff848e841bb-7ff848e841d8 1433->1436 1437 7ff848e84212-7ff848e84238 1433->1437 1434->1433 1435 7ff848e8423d-7ff848e84251 1434->1435 1444 7ff848e8429d-7ff848e842ab 1435->1444 1445 7ff848e84253-7ff848e84260 1435->1445 1437->1435 1446 7ff848e84cd0-7ff848e84d0c 1444->1446 1445->1446 1451 7ff848e84d0e-7ff848e84d18 1446->1451 1452 7ff848e84d56 1446->1452 1453 7ff848e84d19-7ff848e84d1e 1451->1453 1454 7ff848e84dd7-7ff848e84dda 1452->1454 1455 7ff848e84d57 1452->1455 1456 7ff848e84d77-7ff848e84d7d 1453->1456 1457 7ff848e84d20-7ff848e84d23 1453->1457 1460 7ff848e84ddc 1454->1460 1461 7ff848e84e56-7ff848e84e5c 1454->1461 1458 7ff848e84d9e-7ff848e84da0 1455->1458 1459 7ff848e84d58-7ff848e84d5c 1455->1459 1469 7ff848e84d84-7ff848e84d8a 1456->1469 1463 7ff848e84d25-7ff848e84d48 1457->1463 1464 7ff848e84da4-7ff848e84dc0 1457->1464 1458->1464 1465 7ff848e84d5e-7ff848e84d62 1459->1465 1466 7ff848e84dcd-7ff848e84dd0 1459->1466 1467 7ff848e84ddf-7ff848e84de2 1460->1467 1468 7ff848e84dde 1460->1468 1462 7ff848e84e5d-7ff848e84e64 1461->1462 1470 7ff848e84e6a-7ff848e84e89 1462->1470 1488 7ff848e84d97-7ff848e84d9c 1463->1488 1492 7ff848e84d4a-7ff848e84d50 1463->1492 1472 7ff848e84dc1-7ff848e84dc4 1464->1472 1471 7ff848e84de3 1465->1471 1474 7ff848e84d64 1465->1474 1473 7ff848e84dd1-7ff848e84dd4 1466->1473 1467->1471 1468->1467 1469->1471 1475 7ff848e84d8c-7ff848e84d8f 1469->1475 1489 7ff848e84e8b-7ff848e84e8e 1470->1489 1490 7ff848e84efa-7ff848e84f08 1470->1490 1471->1462 1476 7ff848e84de4 1471->1476 1472->1466 1478 7ff848e84dd5 1473->1478 1479 7ff848e84e50-7ff848e84e54 1473->1479 1474->1456 1480 7ff848e84d91-7ff848e84d96 1475->1480 1481 7ff848e84e10-7ff848e84e2f 1475->1481 1483 7ff848e84e3d 1476->1483 1484 7ff848e84de5-7ff848e84de9 1476->1484 1486 7ff848e84e46-7ff848e84e4e 1478->1486 1487 7ff848e84dd6 1478->1487 1479->1461 1480->1488 1504 7ff848e84e31-7ff848e84e35 1481->1504 1505 7ff848e84ea0-7ff848e84eae 1481->1505 1493 7ff848e84e3f-7ff848e84e43 1483->1493 1494 7ff848e84eb7-7ff848e84ebe 1483->1494 1484->1470 1491 7ff848e84deb-7ff848e84e0a 1484->1491 1486->1479 1487->1454 1488->1458 1495 7ff848e84f0a-7ff848e84f18 1489->1495 1496 7ff848e84e90 1489->1496 1490->1495 1491->1481 1492->1472 1498 7ff848e84d52-7ff848e84d53 1492->1498 1499 7ff848e84e45 1493->1499 1500 7ff848e84ec4-7ff848e84ee3 1493->1500 1494->1500 1501 7ff848e84f1e-7ff848e84f3d 1495->1501 1502 7ff848e84e93-7ff848e84e98 1496->1502 1503 7ff848e84e92 1496->1503 1498->1453 1506 7ff848e84d55 1498->1506 1499->1486 1507 7ff848e84ee5-7ff848e84ef0 1500->1507 1508 7ff848e84f54-7ff848e84f5b 1500->1508 1521 7ff848e84f3f-7ff848e84f43 1501->1521 1522 7ff848e84fae-7ff848e84fbe 1501->1522 1509 7ff848e84e9a-7ff848e84e9d 1502->1509 1510 7ff848e84ef1 1502->1510 1503->1502 1511 7ff848e84e37-7ff848e84e3b 1504->1511 1512 7ff848e84eb6 1504->1512 1505->1512 1506->1452 1506->1473 1507->1510 1513 7ff848e84f5e-7ff848e84f67 1508->1513 1514 7ff848e84f5d 1508->1514 1509->1501 1518 7ff848e84e9f 1509->1518 1515 7ff848e84f6b-7ff848e84f77 1510->1515 1516 7ff848e84ef2 1510->1516 1511->1483 1512->1494 1513->1515 1514->1513 1524 7ff848e84f78-7ff848e84fa6 1515->1524 1519 7ff848e84f4b-7ff848e84f4d 1516->1519 1520 7ff848e84ef3-7ff848e84ef7 1516->1520 1518->1505 1520->1524 1525 7ff848e84ef9 1520->1525 1526 7ff848e84f45-7ff848e84f4a 1521->1526 1527 7ff848e84fc4-7ff848e84fd9 1521->1527 1530 7ff848e84fc1-7ff848e84fc3 1522->1530 1531 7ff848e84fc0 1522->1531 1536 7ff848e84fa9-7ff848e84fad 1524->1536 1537 7ff848e84fa8 1524->1537 1525->1490 1526->1519 1534 7ff848e84fdc-7ff848e85004 1527->1534 1535 7ff848e84fdb 1527->1535 1530->1527 1531->1530 1542 7ff848e85007-7ff848e8501c 1534->1542 1543 7ff848e85006 1534->1543 1535->1534 1536->1522 1537->1536 1546 7ff848e8501f-7ff848e85037 call 7ff848e851e5 1542->1546 1547 7ff848e8501e 1542->1547 1543->1542 1551 7ff848e8503a-7ff848e8503f 1546->1551 1552 7ff848e85039 1546->1552 1547->1546 1554 7ff848e85040-7ff848e85062 1551->1554 1552->1551 1557 7ff848e85065-7ff848e8506c 1554->1557 1558 7ff848e85064 1554->1558 1559 7ff848e8506d-7ff848e8507a 1557->1559 1560 7ff848e850a1-7ff848e850c0 1557->1560 1558->1557 1563 7ff848e8507d-7ff848e85084 1559->1563 1564 7ff848e8507c 1559->1564 1566 7ff848e850c3-7ff848e850d8 1560->1566 1567 7ff848e850c2 1560->1567 1563->1554 1568 7ff848e85085 1563->1568 1564->1563 1571 7ff848e850db-7ff848e850f3 1566->1571 1572 7ff848e850da 1566->1572 1567->1566 1569 7ff848e85086-7ff848e85095 1568->1569 1574 7ff848e85098-7ff848e8509c 1569->1574 1575 7ff848e85097 1569->1575 1578 7ff848e850f6-7ff848e8510e 1571->1578 1579 7ff848e850f5 1571->1579 1572->1571 1574->1569 1577 7ff848e8509d-7ff848e850a0 1574->1577 1575->1574 1577->1560 1582 7ff848e85111-7ff848e85122 1578->1582 1583 7ff848e85110 1578->1583 1579->1578 1583->1582
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2501816750.00007FF848E80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848E80000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848e80000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: L_H$ZBo$ZBo$ZBo$ZBo
    • API String ID: 0-691317972
    • Opcode ID: 518f5c9710f3562cad56b83b275300300246b37ae8b7bb478f4db62472d10bf6
    • Instruction ID: 392c365481069d4620497833a6cc7e1d8abd20fd9212a6b241dabf0d36e5d250
    • Opcode Fuzzy Hash: 518f5c9710f3562cad56b83b275300300246b37ae8b7bb478f4db62472d10bf6
    • Instruction Fuzzy Hash: B0223A61D0D6C94FE75AA7788812AADBFE0FF52384F4802FED089CB1D3DE2864098755

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1675 7ff848f90cbc-7ff848f90cf8 1679 7ff848f90d02-7ff848f90d06 1675->1679 1680 7ff848f90cfa-7ff848f90cfd 1675->1680 1682 7ff848f90d45-7ff848f90d4e 1679->1682 1683 7ff848f90d08-7ff848f90d14 1679->1683 1681 7ff848f90d9c-7ff848f90da8 1680->1681 1689 7ff848f90daa-7ff848f90dd6 1681->1689 1690 7ff848f90e0b-7ff848f90e23 1681->1690 1687 7ff848f90d50 1682->1687 1688 7ff848f90d51-7ff848f90d60 1682->1688 1684 7ff848f90d16-7ff848f90d17 1683->1684 1685 7ff848f90d1f-7ff848f90d43 1683->1685 1684->1685 1685->1681 1687->1688 1691 7ff848f90d62 1688->1691 1692 7ff848f90d63-7ff848f90d7c 1688->1692 1689->1690 1699 7ff848f90e29-7ff848f90e2d 1690->1699 1700 7ff848f910ce-7ff848f910ee 1690->1700 1691->1692 1692->1681 1698 7ff848f90d7e-7ff848f90d9a 1692->1698 1698->1681 1704 7ff848f90e33-7ff848f90e3f 1699->1704 1705 7ff848f91166-7ff848f91186 1699->1705 1718 7ff848f910f0 1700->1718 1719 7ff848f910f1-7ff848f91113 1700->1719 1708 7ff848f90e45-7ff848f90e49 1704->1708 1709 7ff848f9111a-7ff848f91135 1704->1709 1720 7ff848f91188 1705->1720 1721 7ff848f91189-7ff848f911a2 1705->1721 1712 7ff848f90e54-7ff848f90e9a 1708->1712 1713 7ff848f90e4b-7ff848f90e4c 1708->1713 1725 7ff848f91137-7ff848f9113a 1709->1725 1713->1712 1718->1719 1719->1709 1720->1721 1734 7ff848f911a4-7ff848f911b4 1721->1734 1729 7ff848f9113c 1725->1729 1730 7ff848f9113d-7ff848f9115f 1725->1730 1729->1730 1730->1705 1734->1725 1738 7ff848f911b6-7ff848f911d2 1734->1738 1741 7ff848f911d4 1738->1741 1742 7ff848f911d5-7ff848f911fa 1738->1742 1741->1742 1742->1734 1745 7ff848f911fc-7ff848f9121e 1742->1745 1749 7ff848f91220 1745->1749 1750 7ff848f91221-7ff848f9126a 1745->1750 1749->1750 1756 7ff848f9126c 1750->1756 1757 7ff848f9126d-7ff848f912e1 1750->1757 1756->1757 1760 7ff848f912e3-7ff848f912ea 1757->1760 1761 7ff848f912eb-7ff848f91320 1757->1761 1760->1761 1763 7ff848f91322-7ff848f91323 1761->1763 1764 7ff848f91383-7ff848f9139d 1761->1764 1765 7ff848f913a3-7ff848f913a4 1763->1765 1766 7ff848f91325-7ff848f91382 1763->1766 1764->1765 1769 7ff848f913a5-7ff848f913a9 1765->1769 1770 7ff848f91498-7ff848f914a1 1765->1770 1766->1764 1773 7ff848f913aa-7ff848f913ae 1769->1773 1772 7ff848f914a3-7ff848f914b3 1770->1772 1783 7ff848f91586-7ff848f9158a 1772->1783 1784 7ff848f914b9-7ff848f914cb 1772->1784 1774 7ff848f913b7-7ff848f913c8 1773->1774 1775 7ff848f913af-7ff848f913b5 1773->1775 1778 7ff848f913ca-7ff848f913cd 1774->1778 1775->1778 1781 7ff848f913d3-7ff848f913d6 1778->1781 1782 7ff848f915e7-7ff848f915fa 1778->1782 1785 7ff848f915fb-7ff848f9160a 1781->1785 1786 7ff848f913dc-7ff848f91400 1781->1786 1787 7ff848f9159c 1783->1787 1788 7ff848f9158c-7ff848f9159a 1783->1788 1791 7ff848f914d8-7ff848f914df 1784->1791 1792 7ff848f914cd-7ff848f914d1 1784->1792 1803 7ff848f91611-7ff848f91635 1785->1803 1807 7ff848f91402-7ff848f91411 1786->1807 1808 7ff848f91415-7ff848f91439 1786->1808 1789 7ff848f915a1-7ff848f915a4 1787->1789 1788->1789 1789->1782 1796 7ff848f915a6-7ff848f915aa 1789->1796 1797 7ff848f914e1-7ff848f914ed 1791->1797 1798 7ff848f914ef-7ff848f9150c 1791->1798 1792->1791 1799 7ff848f915c2 1796->1799 1800 7ff848f915ac-7ff848f915c0 1796->1800 1797->1798 1818 7ff848f91520-7ff848f9153d 1798->1818 1819 7ff848f9150e-7ff848f91517 1798->1819 1801 7ff848f915c4-7ff848f915c6 1799->1801 1800->1801 1801->1803 1804 7ff848f915c8-7ff848f915d5 1801->1804 1821 7ff848f91637-7ff848f9163e 1803->1821 1822 7ff848f9163f-7ff848f9165b 1803->1822 1817 7ff848f915d7-7ff848f915e1 1804->1817 1807->1808 1812 7ff848f9143b 1808->1812 1813 7ff848f9143c-7ff848f9145a 1808->1813 1812->1813 1823 7ff848f91460-7ff848f91469 1813->1823 1817->1772 1817->1782 1829 7ff848f91546-7ff848f91584 1818->1829 1830 7ff848f9153f-7ff848f91543 1818->1830 1819->1818 1821->1822 1824 7ff848f916db-7ff848f916e4 1822->1824 1825 7ff848f9165d-7ff848f91678 1822->1825 1826 7ff848f91482-7ff848f91493 1823->1826 1827 7ff848f9146b-7ff848f91480 1823->1827 1833 7ff848f916e6-7ff848f916fa 1824->1833 1825->1824 1835 7ff848f9167a-7ff848f9167b 1825->1835 1826->1773 1827->1826 1829->1817 1830->1829 1839 7ff848f916fb-7ff848f9170d 1833->1839 1835->1839 1840 7ff848f9167d-7ff848f91690 1835->1840 1846 7ff848f91712-7ff848f91716 1839->1846 1841 7ff848f91692-7ff848f916a7 1840->1841 1842 7ff848f916a8-7ff848f916cc 1840->1842 1841->1842 1842->1833 1851 7ff848f916ce-7ff848f916da 1842->1851 1849 7ff848f9171c-7ff848f91730 1846->1849 1850 7ff848f91add-7ff848f91ae1 1846->1850 1849->1850 1858 7ff848f91736-7ff848f91751 1849->1858 1853 7ff848f91ae3 1850->1853 1854 7ff848f91af4-7ff848f91b32 1850->1854 1851->1824 1857 7ff848f91b3a-7ff848f91b4d 1853->1857 1854->1857 1858->1846 1862 7ff848f91753-7ff848f91767 1858->1862 1862->1850
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: &Do$&<_H$x6Bo$x6Bo
    • API String ID: 0-2145163841
    • Opcode ID: ec6eac8e0d235d0787d25e2bfabba98f9035f0de205d6a745cd7307d248a4039
    • Instruction ID: 55d5ba1cb789c2e36551129bebbf3886cc4042cddd305adb308d08b5b2dc18f4
    • Opcode Fuzzy Hash: ec6eac8e0d235d0787d25e2bfabba98f9035f0de205d6a745cd7307d248a4039
    • Instruction Fuzzy Hash: 2C622630A0DA894FE79AEB2884156757BE1EF56354F0801FED08ECB2E3DE28AC45C755

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1864 7ff848f977e0-7ff848f977f0 1866 7ff848f977f2-7ff848f977fb 1864->1866 1867 7ff848f97869-7ff848f9786e 1864->1867 1871 7ff848f9787b-7ff848f97899 1866->1871 1874 7ff848f977fd-7ff848f97813 1866->1874 1868 7ff848f97918-7ff848f9791c 1867->1868 1869 7ff848f9786f-7ff848f97877 1867->1869 1872 7ff848f9792e 1868->1872 1873 7ff848f9791e-7ff848f9792c 1868->1873 1869->1871 1888 7ff848f9789b 1871->1888 1889 7ff848f9789c-7ff848f978ab 1871->1889 1876 7ff848f97933-7ff848f97936 1872->1876 1873->1876 1879 7ff848f97814-7ff848f97819 1874->1879 1880 7ff848f97938-7ff848f9793c 1876->1880 1881 7ff848f97979-7ff848f979b2 1876->1881 1890 7ff848f9781b-7ff848f9785c 1879->1890 1885 7ff848f97954 1880->1885 1886 7ff848f9793e-7ff848f97952 1880->1886 1887 7ff848f97956-7ff848f97958 1885->1887 1886->1887 1891 7ff848f979b3-7ff848f979d9 1887->1891 1892 7ff848f9795a-7ff848f97967 1887->1892 1888->1889 1894 7ff848f978ad 1889->1894 1895 7ff848f978ae-7ff848f978c7 1889->1895 1907 7ff848f9785e-7ff848f97865 1890->1907 1910 7ff848f979e3-7ff848f979fc 1891->1910 1911 7ff848f979db-7ff848f979e2 1891->1911 1905 7ff848f97969-7ff848f97973 1892->1905 1894->1895 1901 7ff848f978cd-7ff848f978d6 1895->1901 1902 7ff848f978f0-7ff848f97916 1901->1902 1903 7ff848f978d8-7ff848f978ee 1901->1903 1902->1905 1903->1902 1905->1881 1905->1907 1907->1867 1912 7ff848f979fe 1910->1912 1913 7ff848f979ff-7ff848f97a1b 1910->1913 1911->1910 1912->1913 1918 7ff848f97a9b-7ff848f97aac 1913->1918 1919 7ff848f97a1d-7ff848f97a33 1913->1919 1925 7ff848f97a57-7ff848f97a6d 1918->1925 1926 7ff848f97aae-7ff848f97ab9 1918->1926 1922 7ff848f97a34-7ff848f97a39 1919->1922 1927 7ff848f97a3b-7ff848f97a56 1922->1927 1934 7ff848f97a78-7ff848f97a7c 1925->1934 1928 7ff848f97abb 1926->1928 1929 7ff848f97abc-7ff848f97acb 1926->1929 1927->1925 1928->1929 1932 7ff848f97acd 1929->1932 1933 7ff848f97ace-7ff848f97ae7 1929->1933 1932->1933 1936 7ff848f97aed-7ff848f97af6 1933->1936 1935 7ff848f97a7e-7ff848f97a8e 1934->1935 1942 7ff848f97a94-7ff848f97a97 1935->1942 1943 7ff848f97b38-7ff848f97b3c 1935->1943 1937 7ff848f97b10-7ff848f97b36 1936->1937 1938 7ff848f97af8-7ff848f97b0e 1936->1938 1947 7ff848f97b89-7ff848f97b93 1937->1947 1938->1937 1942->1918 1945 7ff848f97b4e 1943->1945 1946 7ff848f97b3e-7ff848f97b4c 1943->1946 1948 7ff848f97b53-7ff848f97b56 1945->1948 1946->1948 1947->1935 1949 7ff848f97b99-7ff848f97bd2 1947->1949 1948->1949 1951 7ff848f97b58-7ff848f97b5c 1948->1951 1953 7ff848f97b74 1951->1953 1954 7ff848f97b5e-7ff848f97b72 1951->1954 1955 7ff848f97b76-7ff848f97b78 1953->1955 1954->1955 1956 7ff848f97bd3-7ff848f97bf9 1955->1956 1957 7ff848f97b7a-7ff848f97b87 1955->1957 1963 7ff848f97c03-7ff848f97c1c 1956->1963 1964 7ff848f97bfb-7ff848f97c02 1956->1964 1957->1947 1965 7ff848f97c1e 1963->1965 1966 7ff848f97c1f-7ff848f97c3b 1963->1966 1964->1963 1965->1966 1971 7ff848f97cbb-7ff848f97ccd 1966->1971 1972 7ff848f97c3d-7ff848f97c5f 1966->1972 1976 7ff848f97cd2-7ff848f97cd6 1971->1976 1980 7ff848f97c61-7ff848f97c8c 1972->1980 1978 7ff848f98467-7ff848f9847a 1976->1978 1979 7ff848f97cdc-7ff848f97cf0 1976->1979 1979->1978 1983 7ff848f97cf6-7ff848f97d11 1979->1983 1984 7ff848f97ca6-7ff848f97cba 1980->1984 1985 7ff848f97c8e-7ff848f97c9f 1980->1985 1983->1976 1990 7ff848f97d13-7ff848f97d27 1983->1990 1984->1971 1985->1980 1989 7ff848f97ca1-7ff848f97ca4 1985->1989 1989->1984 1990->1978
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$@&Do$x6Bo$x6Bo
    • API String ID: 0-1010489272
    • Opcode ID: 7ee342facbec4a364d9f683115c4b25fef17ed0c8b2e21279d6b2f11671a8f7a
    • Instruction ID: 5e42fdc39a3d1e1296c9d3192ea6e6c0ae1c2a64ca57fe18855628e8506efe6a
    • Opcode Fuzzy Hash: 7ee342facbec4a364d9f683115c4b25fef17ed0c8b2e21279d6b2f11671a8f7a
    • Instruction Fuzzy Hash: 0612F431A0CF8A5FE399AB2858196747BD1EF56264F1801FED08DC72E3DF19AC428785

    Control-flow Graph

    • Executed
    • Not Executed
    control_flow_graph 1311 7ff848f95741-7ff848f95743 1312 7ff848f957c3-7ff848f957d9 1311->1312 1313 7ff848f95745-7ff848f9579c 1311->1313 1317 7ff848f957db 1312->1317 1318 7ff848f957dc-7ff848f957eb 1312->1318 1326 7ff848f9579e-7ff848f957ae 1313->1326 1317->1318 1320 7ff848f957ed 1318->1320 1321 7ff848f957ee-7ff848f95807 1318->1321 1320->1321 1322 7ff848f9580d-7ff848f95816 1321->1322 1324 7ff848f95830-7ff848f95856 1322->1324 1325 7ff848f95818-7ff848f9582e 1322->1325 1333 7ff848f958a9-7ff848f958b3 1324->1333 1325->1324 1331 7ff848f957b4-7ff848f957c2 1326->1331 1332 7ff848f95858-7ff848f9585c 1326->1332 1331->1312 1334 7ff848f9586e 1332->1334 1335 7ff848f9585e-7ff848f9586c 1332->1335 1333->1326 1336 7ff848f958b9-7ff848f958f2 1333->1336 1338 7ff848f95873-7ff848f95876 1334->1338 1335->1338 1338->1336 1341 7ff848f95878-7ff848f9587c 1338->1341 1342 7ff848f95894 1341->1342 1343 7ff848f9587e-7ff848f95892 1341->1343 1344 7ff848f95896-7ff848f95898 1342->1344 1343->1344 1347 7ff848f958f3-7ff848f95919 1344->1347 1348 7ff848f9589a-7ff848f958a7 1344->1348 1352 7ff848f95923-7ff848f9593c 1347->1352 1353 7ff848f9591b-7ff848f95922 1347->1353 1348->1333 1354 7ff848f9593d-7ff848f9593e 1352->1354 1355 7ff848f9593f-7ff848f95958 1352->1355 1353->1352 1354->1355 1357 7ff848f9595a-7ff848f9595b 1355->1357 1358 7ff848f959bb-7ff848f959bc 1355->1358 1359 7ff848f959db-7ff848f959f9 1357->1359 1360 7ff848f9595d-7ff848f959b9 1357->1360 1361 7ff848f959be-7ff848f959ce 1358->1361 1372 7ff848f959fb 1359->1372 1373 7ff848f959fc-7ff848f95a0b 1359->1373 1360->1358 1366 7ff848f959d4-7ff848f959d7 1361->1366 1367 7ff848f95a78-7ff848f95a7c 1361->1367 1366->1359 1370 7ff848f95a8e 1367->1370 1371 7ff848f95a7e-7ff848f95a8c 1367->1371 1374 7ff848f95a93-7ff848f95a96 1370->1374 1371->1374 1372->1373 1375 7ff848f95a0d 1373->1375 1376 7ff848f95a0e-7ff848f95a27 1373->1376 1379 7ff848f95a98-7ff848f95a9c 1374->1379 1380 7ff848f95ad9-7ff848f95b12 1374->1380 1375->1376 1384 7ff848f95a2d-7ff848f95a36 1376->1384 1382 7ff848f95ab4 1379->1382 1383 7ff848f95a9e-7ff848f95ab2 1379->1383 1387 7ff848f95ab6-7ff848f95ab8 1382->1387 1383->1387 1385 7ff848f95a50-7ff848f95a76 1384->1385 1386 7ff848f95a38-7ff848f95a4e 1384->1386 1397 7ff848f95ac9-7ff848f95ad3 1385->1397 1386->1385 1392 7ff848f95b13-7ff848f95b2e 1387->1392 1393 7ff848f95aba-7ff848f95ac7 1387->1393 1399 7ff848f95b2f-7ff848f95b39 1392->1399 1393->1397 1397->1361 1397->1380 1400 7ff848f95b43-7ff848f95b59 1399->1400 1401 7ff848f95b3b 1399->1401 1400->1399 1402 7ff848f95b5a-7ff848f95b5b 1400->1402 1403 7ff848f95b3c-7ff848f95b42 1401->1403 1404 7ff848f95bdb-7ff848f95be4 1402->1404 1405 7ff848f95b5c 1402->1405 1403->1400 1406 7ff848f95be6-7ff848f95beb 1404->1406 1407 7ff848f95b5d-7ff848f95b5e 1405->1407 1408 7ff848f95b5f-7ff848f95b60 1405->1408 1409 7ff848f95bed-7ff848f95bfa 1406->1409 1407->1408 1408->1403 1410 7ff848f95b62-7ff848f95b78 1408->1410 1414 7ff848f95bfb-7ff848f95c0d 1409->1414 1410->1404 1413 7ff848f95b7a-7ff848f95b7b 1410->1413 1413->1414 1415 7ff848f95b7d-7ff848f95b90 1413->1415 1419 7ff848f95c12-7ff848f95c16 1414->1419 1415->1409 1416 7ff848f95b92-7ff848f95bcc 1415->1416 1416->1406 1425 7ff848f95bce-7ff848f95bda 1416->1425 1421 7ff848f96032-7ff848f96045 1419->1421 1422 7ff848f95c1c-7ff848f95c30 1419->1422 1422->1421 1426 7ff848f95c36-7ff848f95c51 1422->1426 1425->1404 1426->1419 1429 7ff848f95c53-7ff848f95c67 1426->1429 1429->1421
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$@&Do$x6Bo$x6Bo$;_H
    • API String ID: 0-483666434
    • Opcode ID: 7cb6c6aae3fe15c70a52dfeb5cfe3809ed0cba3d93b78c86ef97743ba2980fca
    • Instruction ID: a4a765da36e833b1fe31a4fa47e95c98f5aa443b01d279513ba833e0127a391c
    • Opcode Fuzzy Hash: 7cb6c6aae3fe15c70a52dfeb5cfe3809ed0cba3d93b78c86ef97743ba2980fca
    • Instruction Fuzzy Hash: 42123731A0CA894FE359AB2898556703FD1EF5A364F1801FED08EC72E3DE19BC468795
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$x6Bo
    • API String ID: 0-3943323974
    • Opcode ID: ecf0da8765e9ae62337ed2a0df2fdad4083c52b557dfe0dc4d9c7163216b91ca
    • Instruction ID: 676f4647657d6d7b10dedf1e00ee6ee9be1747a734cd79daf49e335ecbd0ebe0
    • Opcode Fuzzy Hash: ecf0da8765e9ae62337ed2a0df2fdad4083c52b557dfe0dc4d9c7163216b91ca
    • Instruction Fuzzy Hash: 4DD12631A0DA8A4FE35AA77C98596743BD1EF56254F0801FFD08DC72E3DE18AC068396
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$x6Bo
    • API String ID: 0-3943323974
    • Opcode ID: 525c9b22458d053c981aa24eba6bab110003614e16040dc117f4d1fedab32929
    • Instruction ID: 3c3dc09f418eba07f04ee023865632d6b6bf2472c4be4932c783832a87db8951
    • Opcode Fuzzy Hash: 525c9b22458d053c981aa24eba6bab110003614e16040dc117f4d1fedab32929
    • Instruction Fuzzy Hash: 40B13431A0CA8A4FE359A72898256707FD1EF5A254F0801FFD08EC72E3DA59AC468395
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: &Do$x6Bo
    • API String ID: 0-3077167330
    • Opcode ID: 5408c6845fb42e142231d131eed66f883b4b76748ccb081970e86327bc0af69d
    • Instruction ID: 0b5b61914d891c2cfbf6474a6374804096820b6017a5d0a4d1e418638d1c2239
    • Opcode Fuzzy Hash: 5408c6845fb42e142231d131eed66f883b4b76748ccb081970e86327bc0af69d
    • Instruction Fuzzy Hash: A0D12870A0DE854FE396EB2884216B57BE1FF56390F0941FED08EC72D3DE28A8458765
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: &Do$x6Bo
    • API String ID: 0-3077167330
    • Opcode ID: 598cf8a8494763009960c5f2e9aee046718bd5039adf7190125b8404c1a4ae0d
    • Instruction ID: 2f4d65d754b6193a5889bdd65cba7410b349398b4c1abb92eee3f5baa9bd4da4
    • Opcode Fuzzy Hash: 598cf8a8494763009960c5f2e9aee046718bd5039adf7190125b8404c1a4ae0d
    • Instruction Fuzzy Hash: 8AC11430A0DB858FE796EB388454A757BE1EF56354F0901FAD08DCB2E3DA28AC85C751
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$x6Bo
    • API String ID: 0-3943323974
    • Opcode ID: 8990d81bb95849a1eded0898fe4d2b2b42ab448f17293f82d9a26cd1c30aafb0
    • Instruction ID: a07c6f781c1067b286e665a90a54d1fad6400641e0e15d40c9ca2a99d68f835d
    • Opcode Fuzzy Hash: 8990d81bb95849a1eded0898fe4d2b2b42ab448f17293f82d9a26cd1c30aafb0
    • Instruction Fuzzy Hash: 2341F571F0C94E5FE29CA72C681657177C2EBAA754F1402BEE44DC37D3EE45AC02868A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: 1Do$x6Bo
    • API String ID: 0-3239567568
    • Opcode ID: 570203c0446d03aa8cd761420b4f36586457d9aabb0bf6390bda8e42e4a76f3d
    • Instruction ID: 4e2b017fd3b2dc2912c0a86cd73c2f1788b78ba0143d713397ae2f1c88dd3e0a
    • Opcode Fuzzy Hash: 570203c0446d03aa8cd761420b4f36586457d9aabb0bf6390bda8e42e4a76f3d
    • Instruction Fuzzy Hash: 6541E672E1DA898FE39CE72C58162747BD1FF65258F1411BED04EC72E2DB1AAC05834A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo$x6Bo
    • API String ID: 0-1636319133
    • Opcode ID: da2e6008acd244aeda3c9c2c384e11cf2a98e2698ec00ea374969d32c5990662
    • Instruction ID: 35ea5d2f1cb27418ff25d8b089a674c73a96c4f37c729879eb42ebc4167ebacc
    • Opcode Fuzzy Hash: da2e6008acd244aeda3c9c2c384e11cf2a98e2698ec00ea374969d32c5990662
    • Instruction Fuzzy Hash: 6641E572E1DA894FE399FB2C481AA743BD1EFA5354F1401BED48DC72E3DA189C01874A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: (1Do$x6Bo
    • API String ID: 0-2060403400
    • Opcode ID: 299e5aacb90304a72383084661df1163c409c710d5f9f65c7db6f44e17472c48
    • Instruction ID: 05da124ca2ea750877372bdcf522ba524efaf15917acb440c87800cacfd6fd77
    • Opcode Fuzzy Hash: 299e5aacb90304a72383084661df1163c409c710d5f9f65c7db6f44e17472c48
    • Instruction Fuzzy Hash: B4412632E1DAC54FE39CEB2C54162B4BBD0FB75359F1401BEC48AC72D2DE1958468346
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: 81Do$x6Bo
    • API String ID: 0-3591307449
    • Opcode ID: 1d0b21f22d45a090c8356250ad949142a8f80e057922587ead3d9e410d98af59
    • Instruction ID: e083b43e9fd8d9c9874ace5c67b13da035274a20f9c1ec4ba324c6c9e9e462d0
    • Opcode Fuzzy Hash: 1d0b21f22d45a090c8356250ad949142a8f80e057922587ead3d9e410d98af59
    • Instruction Fuzzy Hash: A241E272E1DA894FE399EF2C54162B47BD1FB7A254F0401BED08EC72D2EA195806874A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: 01Do$x6Bo
    • API String ID: 0-1842848417
    • Opcode ID: d32aa8c3ca07d9099f33cda60811b2c875f12974868f29eed215e6f04ccff322
    • Instruction ID: c6dc099acdcff7ef4e79ba837985abaf24d644f7507aae7b911e6a325a0b89fb
    • Opcode Fuzzy Hash: d32aa8c3ca07d9099f33cda60811b2c875f12974868f29eed215e6f04ccff322
    • Instruction Fuzzy Hash: 1221D571B1CA894FE39CEB2C941A3B477C1FB6A355F0400BED08EC7292DA199C428746
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo$%Do
    • API String ID: 0-1708500522
    • Opcode ID: 0fe418c35253bb01209d5e25c2de711fcd7aef233481d5bd6d891346026625d5
    • Instruction ID: e26aa1be8aaef983523d52b5c0c38ce6d534fbf34c61380987a482db4592f462
    • Opcode Fuzzy Hash: 0fe418c35253bb01209d5e25c2de711fcd7aef233481d5bd6d891346026625d5
    • Instruction Fuzzy Hash: 9C21B671D0DA895FE399FB2848195747BD1EFA6644F0400FED489C72E3DA285C448319
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: @&Do$x6Bo
    • API String ID: 0-3943323974
    • Opcode ID: 6e59f9488651b70f8cc57e80a777a11ccfb3cc953e8498834b575e949500f069
    • Instruction ID: f92f8e1b89c539a60af7c7baccaed3a6eabbb4aefb5fe628ec57c5045126d9b9
    • Opcode Fuzzy Hash: 6e59f9488651b70f8cc57e80a777a11ccfb3cc953e8498834b575e949500f069
    • Instruction Fuzzy Hash: B011A771B1DA894FD39CE76C5456A747BD1EB59644F0401FFC08ACB2E3EA159C418386
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: bcae45a391650bae09c9a9bca31506aed7b4da649169197148668c5eeae27cbb
    • Instruction ID: a7bcf2e92760ad13a8cf6962ec582e47ba9360b51a607ee9195457d151d47ad2
    • Opcode Fuzzy Hash: bcae45a391650bae09c9a9bca31506aed7b4da649169197148668c5eeae27cbb
    • Instruction Fuzzy Hash: 3EF1F331A0CA8A4FE759EB2C8459A757BE1EF56354F1401BED04EC72E3DE29AC42C781
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: a920f9ddd14624607f3e1dd10689f49afc8205e3025d7d07a369fefe4605f36e
    • Instruction ID: 168be7def9b5515df5b4c50aa24011cedc8f5982ade157aaaad4f5e4edb1e8d8
    • Opcode Fuzzy Hash: a920f9ddd14624607f3e1dd10689f49afc8205e3025d7d07a369fefe4605f36e
    • Instruction Fuzzy Hash: 62B13A31A1CA891FE759A72C98196713BD1EF56364F4801FFD08EC72E3DE18AC468B85
    APIs
    Memory Dump Source
    • Source File: 00000000.00000002.2501816750.00007FF848E80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848E80000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848e80000_LiquidText Installer.jbxd
    Similarity
    • API ID: EnumModulesProcess
    • String ID:
    • API String ID: 1082081703-0
    • Opcode ID: f507c65259ccddd2b6e1399ee85c6560a8f9f08e432e78aee74aa89b4cf62cfd
    • Instruction ID: 121d70e15098b44f93b1b475f88d18d6df918e288395910382bf9ad0976f265c
    • Opcode Fuzzy Hash: f507c65259ccddd2b6e1399ee85c6560a8f9f08e432e78aee74aa89b4cf62cfd
    • Instruction Fuzzy Hash: 7A31043190CB484FDB18EB98984A6F9BBE1FB55321F04426FD049D3292CF746846CB95
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: c25eeb4e906035bbc0c3e4a0cc71d39b2aa1699a671f6ed4f3a4ed073e6b86cc
    • Instruction ID: 86b87df5377153a9700cf73d129b47fcde50c813da7ae9770575035caebe3735
    • Opcode Fuzzy Hash: c25eeb4e906035bbc0c3e4a0cc71d39b2aa1699a671f6ed4f3a4ed073e6b86cc
    • Instruction Fuzzy Hash: 89811231E0DA864FE39AE73C48166707BD1EF6A254F0901FED089C72E3DA59AC458386
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: d3bb5ee30d2478703dfc9ebed389fb711ecfef2f7fe5d39dcc6ebdf944c354c4
    • Instruction ID: 65d8d0409152043fc1d58bb9279b31fb881498116f821a1e1a531b40763e31c1
    • Opcode Fuzzy Hash: d3bb5ee30d2478703dfc9ebed389fb711ecfef2f7fe5d39dcc6ebdf944c354c4
    • Instruction Fuzzy Hash: B8713631A0DA894FE34AAB7C88557703BD1EF56354F0801FED089CB2E3DA68AC468345
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: 3ae665a8bf180965f064f618d07cdc89b97c6e15950fd8ba8afd4b52fffe11db
    • Instruction ID: b4845a220d18b5c34fb5d8253afb8184454cc47bd7a232b24414e518d472744c
    • Opcode Fuzzy Hash: 3ae665a8bf180965f064f618d07cdc89b97c6e15950fd8ba8afd4b52fffe11db
    • Instruction Fuzzy Hash: 05412532F1DA8A4FE35DAB2C58262B4BBD1FB55264F0401BED08EC72E2DE1D5C028346
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: 15aac3259b1f1bf960ada3a4921878eacf7f6ade516c61f6d3e0cd1fa59b055a
    • Instruction ID: 1f1e52c7b477737ac5f51e2cb4b79ae75561b02fb203f7a6b8e9a2ade0064769
    • Opcode Fuzzy Hash: 15aac3259b1f1bf960ada3a4921878eacf7f6ade516c61f6d3e0cd1fa59b055a
    • Instruction Fuzzy Hash: 99412572F1DA894FE35DAB2C58266B47BD0FF69215F0401BED08EC72E2DE195C05834A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: 050e64eacfc4ab6aec191ccc9a4db59e90553b59b13c2523d5fac322990af43c
    • Instruction ID: 860975ae8424e92b4bf342817438167fd8ab989db3cb09a9f9a606c8f441aaa0
    • Opcode Fuzzy Hash: 050e64eacfc4ab6aec191ccc9a4db59e90553b59b13c2523d5fac322990af43c
    • Instruction Fuzzy Hash: 6A410532E1CA894FE399E72C58666B4BBD1EB56254F0400BED08EC72D2DF1D6C45830A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: 34e53dec52ee06415c3650ef9e18b560049a7907296d55e9d87fe922534b806b
    • Instruction ID: ef2d1aed51867dea7835ec56b49fc22ca7c607f5f5077294ff1fb16da78f0a72
    • Opcode Fuzzy Hash: 34e53dec52ee06415c3650ef9e18b560049a7907296d55e9d87fe922534b806b
    • Instruction Fuzzy Hash: 1E41D272D1DE864FE399EB3848595647BE0FF25254B1800FEE48DC72E2DB196801C719
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: ce5e8fce527e1b31869403b0696a31da548f8610d28521f8c52e9ac5ddcb2e70
    • Instruction ID: b8b76333aa62cfb2a7a257fad8cf1a1433839c6a1b48552863b9ba30c52a28d8
    • Opcode Fuzzy Hash: ce5e8fce527e1b31869403b0696a31da548f8610d28521f8c52e9ac5ddcb2e70
    • Instruction Fuzzy Hash: 7D212672E0EB894FE399F72848196743BD0EF95254F1500FED489CB2E3DA585C008386
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: b21fad0c4ca6697bfb12546c44dcbed49ea99415d23b5618d31389377675ff3d
    • Instruction ID: 6ab5fa85b07e5cd7db392b0c640885ea10fb962449608c3af440400816d56b38
    • Opcode Fuzzy Hash: b21fad0c4ca6697bfb12546c44dcbed49ea99415d23b5618d31389377675ff3d
    • Instruction Fuzzy Hash: 1E21F272E0EE865FE359EB38845AAB47BE1FF15250B1800FED489C71E2EB196C41C349
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: 6b3b2f91327150c3c8af5664e0adf5acfd08d9104868a3d2dd6b3b5bde3285e5
    • Instruction ID: 9d0bed5213567fcea27a66d76290f589866005344f3fcd87a02dd8fe6df4ec88
    • Opcode Fuzzy Hash: 6b3b2f91327150c3c8af5664e0adf5acfd08d9104868a3d2dd6b3b5bde3285e5
    • Instruction Fuzzy Hash: C921F532E0DA854FE359E72C441A6747BE0EF66254F1801FED48DCB2E3DA185C05871A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: 4c7b07960c1f7c4bdb2de2708769b3f1a88abeb019339554ac6e5e83069a2cde
    • Instruction ID: 9a570dc6acb097fee66cd0a08b2a22449a83a71f1b7df660a0312dcf82c91770
    • Opcode Fuzzy Hash: 4c7b07960c1f7c4bdb2de2708769b3f1a88abeb019339554ac6e5e83069a2cde
    • Instruction Fuzzy Hash: F121A172E0DA855FE358EB2C881A5B47BE1EF65354B1401BED08ACB2F2DA185C04C709
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: af6f06728130155968c755a331ada289a43a7cac21c377a3bbdde81e59dba8ba
    • Instruction ID: e94f6d13e585b5cd23317184054ec497ae8942ca3e0491de678018a4e3894786
    • Opcode Fuzzy Hash: af6f06728130155968c755a331ada289a43a7cac21c377a3bbdde81e59dba8ba
    • Instruction Fuzzy Hash: 9F21A472E0CE865FE799EB284455A7477E1EF65384B1440BAD84DC72D2DB186C008715
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: aa271cbdba92c788dc39c0c4ff288e81af32e104a8ee084a2bb0d102885d219d
    • Instruction ID: 1f5752ec47a8efb521e170656b02ddfe09199db406ac97f19518daf8b3eb5705
    • Opcode Fuzzy Hash: aa271cbdba92c788dc39c0c4ff288e81af32e104a8ee084a2bb0d102885d219d
    • Instruction Fuzzy Hash: 3A119371D0EA865FE399AB3C48565B47BE0FF15350B1410FED08AD72F6DA185C058346
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: x6Bo
    • API String ID: 0-2959843075
    • Opcode ID: f54ca7460b288537e24d1081b51d0d09fc6ee8764f999aa27855802134c9bfdb
    • Instruction ID: 2dc5946e100d62276e819c5e76b86e170809d33888d4216345b9a4ac683e862c
    • Opcode Fuzzy Hash: f54ca7460b288537e24d1081b51d0d09fc6ee8764f999aa27855802134c9bfdb
    • Instruction Fuzzy Hash: A3019271A0DA454FE39CDB2C945AA7477E1EF6A254B1000BFC08DCB3A2EA655C41C705
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: fd1557edbf7e23179f5b1a7431c03790556460044b6f683a4b04bbf661b5a777
    • Instruction ID: d5ce351d9133d940f63d685728be7fe87d0bbf4140d967475b3e66b67d720387
    • Opcode Fuzzy Hash: fd1557edbf7e23179f5b1a7431c03790556460044b6f683a4b04bbf661b5a777
    • Instruction Fuzzy Hash: 1BF1F330A0CA4A4FEB99EB2CD854A747BD1EF56354F0401BAE04EC72E3DE29AC45C785
    Memory Dump Source
    • Source File: 00000000.00000002.2501488523.00007FF848D6D000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848D6D000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848d6d000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: 036711324addaf4522f59713abba96d6d65c565d76f2c165a3cfa9821c6423a6
    • Instruction ID: 8c3c86b35a28caaf062261419e68602ac71a25d20790aae5d8a59053c13b8c8b
    • Opcode Fuzzy Hash: 036711324addaf4522f59713abba96d6d65c565d76f2c165a3cfa9821c6423a6
    • Instruction Fuzzy Hash: 3841C33180DBC44FD356DB389845A663FF0EF56251B1506EFE088CB1A7D625B84ACB92
    Memory Dump Source
    • Source File: 00000000.00000002.2502398359.00007FF848F90000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848F90000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848f90000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID:
    • API String ID:
    • Opcode ID: b54895b79d0c644f409e774c637cd50703585187ff8e38f68b9292aa4075b1f4
    • Instruction ID: 05e1d4b7d11f864831dab1a0e929b901450664771cc5f9a9d92d8ec060f6d717
    • Opcode Fuzzy Hash: b54895b79d0c644f409e774c637cd50703585187ff8e38f68b9292aa4075b1f4
    • Instruction Fuzzy Hash: 8911BF31A0D98A8FEB85FB288869A247BE1EF55304B2801B9D44EC72D3CB18BC45C785
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2501816750.00007FF848E80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848E80000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848e80000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: :L_^$@
    • API String ID: 0-4216884312
    • Opcode ID: 2acce7a58a84ee6237d0f18770f9e9d774803ca4405e93581e4c687772660f91
    • Instruction ID: 5321f6335ed598c682727651e3cc934389dfb14a9ae84a4bf74037204f0baecb
    • Opcode Fuzzy Hash: 2acce7a58a84ee6237d0f18770f9e9d774803ca4405e93581e4c687772660f91
    • Instruction Fuzzy Hash: 37526B21A5D6C54FE31EBA6C5C520B47BD0FF82359F5801BED4CBC7193EA78A407868A
    Strings
    Memory Dump Source
    • Source File: 00000000.00000002.2501816750.00007FF848E80000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FF848E80000, based on PE: false
    Joe Sandbox IDA Plugin
    • Snapshot File: hcaresult_0_2_7ff848e80000_LiquidText Installer.jbxd
    Similarity
    • API ID:
    • String ID: (M_^$)M_^
    • API String ID: 0-2926074235
    • Opcode ID: 45c6212d711c085e5d52edee8aee82d8d774c43c1b6892223667661db9129fd2
    • Instruction ID: 7eaa8473714b9b31a1e2bf7b9d9ad5c3f344e9ac72aeb2cdf400072880c93f2c
    • Opcode Fuzzy Hash: 45c6212d711c085e5d52edee8aee82d8d774c43c1b6892223667661db9129fd2
    • Instruction Fuzzy Hash: 5881632390E7DA9FD7066A3C58A50E93FA0EF536A5B0D02F7C5D48F093EE1A584B8315