Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
EasyLogUSB+Installer.exe

Overview

General Information

Sample name:EasyLogUSB+Installer.exe
Analysis ID:1501388
MD5:d3d4273692e34102b88c513ad1c10040
SHA1:1b75e5c2644fbf075040df437b15d4d2c128c2cf
SHA256:cc2652dc33020fab609750a6f627e2f8e6597960b25f210981e62f5ad92f7d70
Infos:

Detection

Score:6
Range:0 - 100
Whitelisted:false
Confidence:40%

Compliance

Score:45
Range:0 - 100

Signatures

Checks for available system drives (often done to infect USB drives)
Creates driver files
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Launches processes in debugging mode, may be used to hinder debugging
Queries the volume information (name, serial number etc) of a device
Sigma detected: Suspicious Execution From GUID Like Folder Names
Stores files to the Windows start menu directory
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • EasyLogUSB+Installer.exe (PID: 7032 cmdline: "C:\Users\user\Desktop\EasyLogUSB+Installer.exe" MD5: D3D4273692E34102B88C513AD1C10040)
    • msiexec.exe (PID: 5672 cmdline: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe" MD5: 9D09DC1EDA745A5F87553048E57620CF)
  • msiexec.exe (PID: 1216 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 5912 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding C16B6E8B33D4F0B5DAD7A01ECF725878 C MD5: 9D09DC1EDA745A5F87553048E57620CF)
    • msiexec.exe (PID: 7048 cmdline: C:\Windows\syswow64\MsiExec.exe -Embedding 27BDE6E8EAF7545954F65D95558F90D2 MD5: 9D09DC1EDA745A5F87553048E57620CF)
      • conhost.exe (PID: 1992 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • EL-USB Driver Setup.exe (PID: 4888 cmdline: "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe" MD5: 4BD3D58BEB869D0895D93ACCADC08032)
  • cleanup
No yara matches
Source: Process startedAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Command: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe", CommandLine: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe", CommandLine|base64offset|contains: , Image: C:\Windows\SysWOW64\msiexec.exe, NewProcessName: C:\Windows\SysWOW64\msiexec.exe, OriginalFileName: C:\Windows\SysWOW64\msiexec.exe, ParentCommandLine: "C:\Users\user\Desktop\EasyLogUSB+Installer.exe", ParentImage: C:\Users\user\Desktop\EasyLogUSB+Installer.exe, ParentProcessId: 7032, ParentProcessName: EasyLogUSB+Installer.exe, ProcessCommandLine: "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe", ProcessId: 5672, ProcessName: msiexec.exe
No Suricata rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Compliance

barindex
Source: EasyLogUSB+Installer.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: EasyLogUSB+Installer.exeStatic PE information: certificate valid
Source: C:\Windows\System32\msiexec.exeFile opened: z:
Source: C:\Windows\System32\msiexec.exeFile opened: x:
Source: C:\Windows\System32\msiexec.exeFile opened: v:
Source: C:\Windows\System32\msiexec.exeFile opened: t:
Source: C:\Windows\System32\msiexec.exeFile opened: r:
Source: C:\Windows\System32\msiexec.exeFile opened: p:
Source: C:\Windows\System32\msiexec.exeFile opened: n:
Source: C:\Windows\System32\msiexec.exeFile opened: l:
Source: C:\Windows\System32\msiexec.exeFile opened: j:
Source: C:\Windows\System32\msiexec.exeFile opened: h:
Source: C:\Windows\System32\msiexec.exeFile opened: f:
Source: C:\Windows\System32\msiexec.exeFile opened: b:
Source: C:\Windows\System32\msiexec.exeFile opened: y:
Source: C:\Windows\System32\msiexec.exeFile opened: w:
Source: C:\Windows\System32\msiexec.exeFile opened: u:
Source: C:\Windows\System32\msiexec.exeFile opened: s:
Source: C:\Windows\System32\msiexec.exeFile opened: q:
Source: C:\Windows\System32\msiexec.exeFile opened: o:
Source: C:\Windows\System32\msiexec.exeFile opened: m:
Source: C:\Windows\System32\msiexec.exeFile opened: k:
Source: C:\Windows\System32\msiexec.exeFile opened: i:
Source: C:\Windows\System32\msiexec.exeFile opened: g:
Source: C:\Windows\System32\msiexec.exeFile opened: e:
Source: C:\Windows\System32\msiexec.exeFile opened: c:
Source: C:\Windows\System32\msiexec.exeFile opened: a:
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sys
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3eab17.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIADF5.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSIAEF0.tmp
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\SiUSBXp.dll
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3eab19.msi
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3eab19.msi
Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSIADF5.tmp
Source: EasyLogUSB+Installer.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: clean6.winEXE@11/44@0/0
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB
Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\Public\Desktop\EasyLog USB.lnk
Source: C:\Windows\System32\conhost.exeMutant created: \BaseNamedObjects\Local\SM0:1992:120:WilError_03
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile created: C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\
Source: EasyLogUSB+Installer.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile read: C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\Setup.INI
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile read: C:\Users\user\Desktop\EasyLogUSB+Installer.exe
Source: unknownProcess created: C:\Users\user\Desktop\EasyLogUSB+Installer.exe "C:\Users\user\Desktop\EasyLogUSB+Installer.exe"
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe"
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding C16B6E8B33D4F0B5DAD7A01ECF725878 C
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 27BDE6E8EAF7545954F65D95558F90D2
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess created: C:\Windows\SysWOW64\msiexec.exe "C:\Windows\system32\MSIEXEC.EXE" /i "C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\EasyLog USB.msi" SETUPEXEDIR="C:\Users\user\Desktop" SETUPEXENAME="EasyLogUSB+Installer.exe"
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding C16B6E8B33D4F0B5DAD7A01ECF725878 C
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 27BDE6E8EAF7545954F65D95558F90D2
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Windows\SysWOW64\msiexec.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: apphelp.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: msi.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: srpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textinputframework.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coreuicomponents.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: coremessaging.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wintypes.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: textshaping.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msasn1.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptsp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: rsaenh.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: cryptbase.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msisip.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: gpapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: version.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msihnd.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: dwmapi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: oleacc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: windowscodecs.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: riched20.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: usp10.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msls31.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: version.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dll
Source: C:\Windows\System32\msiexec.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exeSection loaded: msi.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: apphelp.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: acgenral.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: uxtheme.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: winmm.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: samcli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: msacm32.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: version.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: userenv.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: dwmapi.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: urlmon.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: mpr.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: sspicli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: winmmbase.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: winmmbase.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: iertutil.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: srvcli.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: netutils.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: aclayers.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: sfc.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: sfc_os.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: windows.storage.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wldp.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: textinputframework.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: coremessaging.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: ntmarta.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: coremessaging.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: wintypes.dll
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile written: C:\Users\user\AppData\Local\Temp\{7F3BB4D9-1954-41B0-8FC6-1687CA4E557E}\Setup.INI
Source: EasyLogUSB+Installer.exeStatic PE information: certificate valid
Source: EasyLogUSB+Installer.exeStatic file information: File size 19500624 > 1048576
Source: EasyLogUSB+Installer.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\ExportToExcel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\EasyLog USB.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\SiUSBXp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI96C5.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\x64\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\CustomControls.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI9656.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files (x86)\EasyLog USB\WPFToolkit.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\SysWOW64\SiUSBXp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB\EasyLog USB.lnk
Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EasyLog USB\EasyLogGraph.lnk
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOGPFAULTERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\ExportToExcel.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\EasyLog USB.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\SysWOW64\SiUSBXp.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x86\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exeJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI96C5.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\x64\SiLib.sysJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\CustomControls.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files (x86)\EasyLog USB\WPFToolkit.dllJump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI9656.tmpJump to dropped file
Source: C:\Users\user\Desktop\EasyLogUSB+Installer.exeFile Volume queried: C:\Users\user\AppData\Local\Temp FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\SysWOW64\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformation
Source: C:\Windows\System32\msiexec.exeProcess created: C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe "C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe"
Source: C:\Windows\SysWOW64\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire Infrastructure1
Replication Through Removable Media
Windows Management Instrumentation1
Windows Service
1
Windows Service
22
Masquerading
OS Credential Dumping1
Process Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
1
Process Injection
1
Disable or Modify Tools
LSASS Memory11
Peripheral Device Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAt1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
1
Process Injection
Security Account Manager2
File and Directory Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
NTDS12
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
File Deletion
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
EasyLogUSB+Installer.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Program Files (x86)\EasyLog USB\CustomControls.dll0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\EL-USB Driver Setup.exe0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\EasyLogGraph.exe0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\ExportToExcel.dll0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\WPFToolkit.dll0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x64\SiLib.sys0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x64\SiUSBXp.sys0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x86\SiLib.sys0%ReversingLabs
C:\Program Files (x86)\EasyLog USB\x86\SiUSBXp.sys0%ReversingLabs
C:\Users\user\AppData\Local\Temp\MSI9656.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\MSI96C5.tmp0%ReversingLabs
C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\ARPPRODUCTICON.exe0%ReversingLabs
C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLogGraph.exe_3D39C605F6D0484A88F3AD4B82B13993.exe0%ReversingLabs
C:\Windows\Installer\{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}\EasyLog_USB.exe_63257A9301FB4EABA085D3C69F470EC4.exe0%ReversingLabs
C:\Windows\SysWOW64\SiUSBXp.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1501388
Start date and time:2024-08-29 20:51:13 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:19
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Analysis stop reason:Timeout
Sample name:EasyLogUSB+Installer.exe
Detection:CLEAN
Classification:clean6.winEXE@11/44@0/0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): dllhost.exe
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
  • VT rate limit hit for: EasyLogUSB+Installer.exe
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:modified
Size (bytes):14060
Entropy (8bit):5.729042366049827
Encrypted:false
SSDEEP:
MD5:7BE4DD488B5F73A58993D89780421231
SHA1:0A872C95794C761083F2A96E135E5DF18271AA27
SHA-256:CA2ED180236A8119FF0F03D09E78A6991D26C66C8794E07D04ACB048CDF13A2A
SHA-512:0A5E418B11E19BE83D6E7DE94CCC05CAC0C25011183CCB80448AB3D42623B109B8E5E17B33618301D538395D701DE1D2E6FDF436B64F60BCE01F0D390B602F07
Malicious:false
Reputation:unknown
Preview:...@IXOS.@.....@{v.Y.@.....@.....@.....@.....@.....@......&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}..EasyLog USB..EasyLog USB.msi.@.....@.....@.....@......ARPPRODUCTICON.exe..&.{8C7E2C80-4C6F-4A5C-9FDD-5AA316A9E29A}.....@.....@.....@.....@.......@.....@.....@.......@......EasyLog USB......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{429FE619-EEB7-4E48-AF7A-4F56DD1C7491}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{1D213698-CDE4-4051-B5BD-2BBDFE318583}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{B2ECCF77-395E-4A26-A4BF-5EC89425F03F}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{AFECBE12-FD2C-45CC-80F8-C71798C38400}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{A058DD12-721A-4A06-81C5-933F86CBD9A8}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{C7CB0A68-EC59-41D8-B200-84E9EA2E80DD}&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}.@......&.{782F7E0F-9847-4B86-B5B0-33A2239F1B52}&
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):83968
Entropy (8bit):6.294061771215002
Encrypted:false
SSDEEP:
MD5:D45DC6705A858837B48002B099259447
SHA1:7381790B9470B8120D40CC8170EF31625AFA41FC
SHA-256:625364E42240CCD4D34DCEDDDA385C5B999C82254866886FDECF71E2E51EAA82
SHA-512:BBD23EBB9C171F599FCD7FBFBCC4074364A892402A40BBA1F501C1E6EFF9803B239F5C46D834D5C19D00630DA5C87D3BB4633E09871685FE25981815918EAD6C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....N............" ..0..@..........r_... ...`....... ....................................`................................. _..O....`..............................l^..8............................................ ............... ..H............text...x?... ...@.................. ..`.rsrc........`.......B..............@..@.reloc...............F..............@..B................T_......H...........dl..............xm..........................................6.(.....(....*..,..{.......+..,..{....o......(....*2.s....}....*"..(....*"..(....*...0..C.......s ...%....s!...o"...%..o#...%..o$...%(i...o%.....(&....o'....o(...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*..{....*:..}.....()...*....0...........(*....(........(+.... . ...(+.... .....(+..........(,...}......O.O.O(,...}......O.O.O(,...}
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):636816
Entropy (8bit):6.215505980302389
Encrypted:false
SSDEEP:
MD5:4BD3D58BEB869D0895D93ACCADC08032
SHA1:9005888DFBC0B2483DC4DA69683B46AA70A54283
SHA-256:604330AE230A4FDE9A3C4401CDD544394910D55DDF651A84259E0B03B39DF35E
SHA-512:6966206E8E3A038B3F142459E334C3D47AD67CAE95091EB1C022C5FE00BA14EF9EDBC0010AD9795E045CC6DEE63A81EFF262E0A7A8EF30373159BBFA25C9556B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........j.:..ki..ki..ki3.4i..ki3.6i..ki...i..ki...ih.ki.(xi..ki..ji..ki...i..ki...i..ki...i..kiRich..ki........PE..L....HM.................p... ....................@.................................%......................................../..........................................................................@..................../..@....................text....f.......p.................. ..`.rdata..............................@..@.data....`...`...0...`..............@....rsrc...............................@..@........................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Windows setup INFormation
Category:dropped
Size (bytes):1774
Entropy (8bit):5.242834253911726
Encrypted:false
SSDEEP:
MD5:4AE3D4215836D424C461C60E841509A8
SHA1:155EFD4F098E9A5294AFF18E2A0E45AAC5ED0310
SHA-256:6737F7F6737B4E37004D3F3FE3DBC9A2DB68FB74DF481B39AA0ACDBD238EDA79
SHA-512:5CB6C95906B6DC23622FDE07C5A04554B90DA8DC74E87B8A42BB60ED5B7B0A47678FD241250144BB345FB61DFDE4E183DF2F3D9563C7C9DF08D6A1782F3E5C5A
Malicious:false
Reputation:unknown
Preview:; EasyLog USB Device Driver..; Silabs USBXpress, Copyright (c) 2010, Silicon Laboratories......[Version]..Signature=$WINDOWS NT$..Class=USB..ClassGUID={36fc9e60-c465-11cf-8056-444553540000}..Provider=%MFGNAME%..DriverVer=07/14/2009,3.3..CatalogFile=SiUSBXp.cat....[Manufacturer]..%MFGNAME%=DeviceList, NTamd64....[DestinationDirs]..DefaultDestDir=10..;System32\Drivers..DriverCopyFiles=10..,System32\Drivers....[SourceDisksNames.x86]..1=%INSTDISK%,,,....[SourceDisksFiles.x86]..SiUSBXp.sys=1,\x86..SiLib.sys=1,\x86....[SourceDisksNames.amd64]..1=%INSTDISK%,,,....[SourceDisksFiles.amd64]..SiUSBXp.sys=1,\x64..SiLib.sys=1,\x64....[DeviceList]..%DESCRIPTION%=DriverInstall,USB\VID_10C4&PID_0002....[DeviceList.NTamd64]..%DESCRIPTION%=DriverInstall,USB\VID_10C4&PID_0002....[ControlFlags]..ExcludeFromSelect=*....;------------------------------------------------------------------------------..; Windows 2000 Sections..;------------------------------------------------------------------------------....
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows HtmlHelp Data
Category:dropped
Size (bytes):11118090
Entropy (8bit):7.999336140233879
Encrypted:true
SSDEEP:
MD5:B40F9A166584B9979C4DDF94E9C58B84
SHA1:7A885114A83F0A73ADEAF1180FD8182BDE270678
SHA-256:A7B13BEB1F0EE9EB22CB72B41D4396B27834FCB8A0C98DFBB1DE7283C6DBF345
SHA-512:7D19BF6F1951759209DCD58B5EEDC813645E8F688117C09E2E09B987F6F8EBE7EB9CBD67D009AEA970BE99AFC72FF76C9F9AA7589CC35A91DD8DB41E364B81BF
Malicious:false
Reputation:unknown
Preview:ITSF....`.......^G!........|.{.......".....|.{......."..`...............x.......T.......................................ITSP....T...........................................j..].!......."..T...............PMGL................./..../#IDXHDR......../#ITBITS..../#IVB....A.../#STRINGS......}./#SYSTEM....../#TOPICS......P./#URLSTR....d.+./#URLTBL....h.|./$FIftiMain......../$OBJINST....U.?./$WWAssociativeLinks/..../$WWAssociativeLinks/Property....Q../$WWKeywordLinks/..../$WWKeywordLinks/Property....M../EasyLogUSB.hhc...../images/..../images/help_file_usb-v8.gif..Q..../index.htm....A./pdf/..../pdf/EL-GFX-1.pdf...T..../pdf/EL-GFX-2.pdf..d..q./pdf/EL-GFX-DTC.pdf..U..../pdf/EL-OEM-3.pdf.......#./pdf/EL-USB-1-LCD.pdf...3..4./pdf/EL-USB-1-PRO.pdf....g..../pdf/EL-USB-1-RCG.pdf....w..../pdf/EL-USB-1.pdf.......0./pdf/EL-USB-2+.pdf........./pdf/EL-USB-2-LCD+.pdf....~..../pdf/EL-USB-2-LCD.pdf....!..]./pdf/EL-USB-2.pdf........./pdf/EL-USB-3.pdf......~./pdf/EL-USB-4.pdf.......Z./pdf/EL-USB-5.pdf....s.
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):2468864
Entropy (8bit):7.154456571356211
Encrypted:false
SSDEEP:
MD5:3B858BC0334BA720B83C388E909ADB76
SHA1:D7E5D67093A04417127BCB78B3D429157E7D668B
SHA-256:19A191AAE469323D2BF25E1C7FB80BDD09E98F88BC4A6B3907BE12B57BE739AD
SHA-512:59375F6F2E2FAC2B4E226C850C37E03985399C99EF9FBEBDA953528723B62577E5E9BA8F74E5284B1CDFC90D7B5DC52D43B265DE05A4337A2952D30FDA6B9431
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......`..............0..L%..^.......j%.. ....%...@.. ........................&...........`.................................tj%.O.....%.LZ....................%.....<i%.............................................. ............... ..H............text....K%.. ...L%................. ..`.rsrc...LZ....%..\...N%.............@..@.reloc........%.......%.............@..B.................j%.....H...........8.......x...D.................................................(.........(.......(....}......(....}....*..0............(.....+..**...(.....*..0............{.....+..*&...}....*...0............(.....+..**...(.....*..0............{.....+..*&...}....*...0............(........( .......(!....#Y..#..("....(#.......,...o$...s%.....o&...s%........+...{....s%.....{....s%..........o'....o(...."...."...@o).....(.....o*.....o+.....o,....**...(-....*..0............}.....#......g
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):12519936
Entropy (8bit):5.976511471374955
Encrypted:false
SSDEEP:
MD5:99A338CA1E3B2F789BEBF09E5DA98DB6
SHA1:BF360B9A4A311350FF65EA63D18ED8823F9299F0
SHA-256:27767F40E341717951DCDF231C09ADFB0C85A411A541DEB59A18EC773D09D800
SHA-512:3A14BE46C94A4A2779FC8FF1C9E468A87C2D1981B0EB2461553B6B46A2D69C6D05540BF4874002D71288991708521D9ED91065F562575C49600042A82F812ECA
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...q./`..............0.................. ... ....@.. .......................`............`.................................0...O.... .......................@....................................................... ............... ..H............text........ ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B................d.......H........8.. ............0..P...........................................0............ 4......("....+..*.0.................o#....+..*B.........o$....*...0..1.........o%...r...p $...........%...%....o&...t.....+..*.....o'....*".((....*>..s....%.}....*...0..U..............,D..(...+.......,.....o)....o*...o+.....(...+...o,....o-...t!.......+....+...*....0..O.........o,....o-...t...........,...o.......o/....o0...o1.....o,....o-...t........+..*..0..o.................(2......+I...(
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):1656320
Entropy (8bit):6.478623936096293
Encrypted:false
SSDEEP:
MD5:7DBCED1DFC2BA8632169292C78DB9023
SHA1:C7902951A4853BDFA7074261F0C5444CF6137845
SHA-256:615536B9FBF5B1F79C081224D136EC6AD2DB6B51B73BC455F2D7F2F18A0F9C19
SHA-512:FD1E297513F66633DA1A7E61C3584A84E86144C7D1AECBE9FC3CF3CDECDAC20EA6D49E0E3C0F092B48026BA1E5FD94490896B9C045E2055415CB14380819567A
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N[-U/5~U/5~U/5~\W.~Y/5~\W.~v/5~U/4~.-5~:Y.~~/5~:Y.~./5~:Y.~'.5~:Y.~Q/5~:Y.~T/5~:Y.~T/5~:Y.~T/5~RichU/5~................PE..L....{qO...........!.........N......-................................................................................6..p.......T.... ..$E...................p.....................................`...@............................................text............................... ..`.rdata...'.......(..................@..@.data........@...\... ..............@....rsrc...$E... ...F...|..............@..@.reloc..B....p......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):12278
Entropy (8bit):3.757781663348975
Encrypted:false
SSDEEP:
MD5:8506D085E11D902F8A1823E7E321BBDE
SHA1:ADBAD1E5A097730E6B887D813962AC725DAB4231
SHA-256:791BE0332C3BDCC86842EA3C144CF37E00192F0A318EDBC57A020979CF229417
SHA-512:E6E3050B4ABAC5E2BADBA0094E3D2712D315FB30E2B746ABFC41E0F864B6EDA675BBD92D26C21DF1F79D2DA5D2122AAE71522560B890E89B4C88CE8E05E3D3B9
Malicious:false
Reputation:unknown
Preview:Room 1 CO,Time,CO(ppm),Warning Level,Serial Number,Sensor Life Expiry,Overrange Exposure..1,15/03/2006 16:00:00,0.0,25.0,000000123,06/02/2011,No..2,15/03/2006 16:00:10,0.0,25.0..3,15/03/2006 16:00:20,0.0,25.0..4,15/03/2006 16:00:30,0.0,25.0..5,15/03/2006 16:00:40,0.0,25.0..6,15/03/2006 16:00:50,0.0,25.0..7,15/03/2006 16:01:00,5.0,25.0..8,15/03/2006 16:01:10,3.0,25.0..9,15/03/2006 16:01:20,0.0,25.0..10,15/03/2006 16:01:30,3.5,25.0..11,15/03/2006 16:01:40,4.0,25.0..12,15/03/2006 16:01:50,0.0,25.0..13,15/03/2006 16:02:00,0.0,25.0..14,15/03/2006 16:02:10,0.0,25.0..15,15/03/2006 16:02:20,0.0,25.0..16,15/03/2006 16:02:30,3.5,25.0..17,15/03/2006 16:02:40,3.0,25.0..18,15/03/2006 16:02:50,0.0,25.0..19,15/03/2006 16:03:00,0.0,25.0..20,15/03/2006 16:03:10,3.5,25.0..21,15/03/2006 16:03:20,0.0,25.0..22,15/03/2006 16:03:30,3.0,25.0..23,15/03/2006 16:03:40,0.0,25.0..24,15/03/2006 16:03:50,0.0,25.0..25,15/03/2006 16:04:00,0.0,25.0..26,15/03/2006 16:04:10,4.0,25.0..27,15/03/2006 16:04:20,4.5,25.0..28,1
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):9484
Entropy (8bit):3.8494259019457355
Encrypted:false
SSDEEP:
MD5:B293E1467C132E759298BC9C6D6DED7D
SHA1:38326172C6A6146F0BF0F12A18144A1C38B379C6
SHA-256:4B0F35D8B010E8BFC24942AF1635DD6FDF8432AE5DD8B88D361EB1DF1AE06DD3
SHA-512:4D44BA05D56718B6AF663D0305B6646F0F7A8181BAD066C6C82D68F8608E4366B8F931F32E4B3DBE74D7747F6CADE5CA3B1099AE10B1CF8E233F79FFA44B76FF
Malicious:false
Reputation:unknown
Preview:EasyLog USB,Time,Current(%),High Alarm,Low Alarm,Serial Number..1,31/03/2005 16:35:00,14.2,80.0,20.0,987654322..2,31/03/2005 16:35:01,22.0,80.0,20.0..3,31/03/2005 16:35:02,28.2,80.0,20.0..4,31/03/2005 16:35:03,34.4,80.0,20.0..5,31/03/2005 16:35:04,39.2,80.0,20.0..6,31/03/2005 16:35:05,42.8,80.0,20.0..7,31/03/2005 16:35:06,46.0,80.0,20.0..8,31/03/2005 16:35:07,48.6,80.0,20.0..9,31/03/2005 16:35:08,50.6,80.0,20.0..10,31/03/2005 16:35:09,53.6,80.0,20.0..11,31/03/2005 16:35:10,55.6,80.0,20.0..12,31/03/2005 16:35:11,56.6,80.0,20.0..13,31/03/2005 16:35:12,58.2,80.0,20.0..14,31/03/2005 16:35:13,59.0,80.0,20.0..15,31/03/2005 16:35:14,59.6,80.0,20.0..16,31/03/2005 16:35:15,60.2,80.0,20.0..17,31/03/2005 16:35:16,60.8,80.0,20.0..18,31/03/2005 16:35:17,61.2,80.0,20.0..19,31/03/2005 16:35:18,61.6,80.0,20.0..20,31/03/2005 16:35:19,62.0,80.0,20.0..21,31/03/2005 16:35:20,62.4,80.0,20.0..22,31/03/2005 16:35:21,62.8,80.0,20.0..23,31/03/2005 16:35:22,63.2,80.0,20.0..24,31/03/2005 16:35:23,63.6,80.0,20.0.
Process:C:\Windows\System32\msiexec.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):15477
Entropy (8bit):3.633119065723989
Encrypted:false
SSDEEP:
MD5:489A922F2345B000FD6D82CD4217F1D5
SHA1:3DEF20F03E42CD21F273D5031BC4CE2C79716675
SHA-256:0AC3BFFE44A6FF29323208F95D6487F84F8FE172065AE5C37714E46C2690BFE1
SHA-512:1B655780BDDAB2AD1312F5BC10683A15312ED06E7288A702EB1BCE7ACAB94269D197929718EF99C8AB6BC154403087DA549B08A49637211163CBB7888459C216
Malicious:false
Reputation:unknown
Preview:EasyLog USB,Time,Celsius(.C),High Alarm,Low Alarm,Serial Number..1,24/03/2006 15:00:00,20,18,4,987654321..2,24/03/2006 15:30:00,20,18,4..3,24/03/2006 16:00:00,20,18,4..4,24/03/2006 16:30:00,19,18,4..5,24/03/2006 17:00:00,19,18,4..6,24/03/2006 17:30:00,23,18,4..7,24/03/2006 18:00:00,25,18,4..8,24/03/2006 18:30:00,15,18,4..9,24/03/2006 19:00:00,18,18,4..10,24/03/2006 19:30:00,19,18,4..11,24/03/2006 20:00:00,18,18,4..12,24/03/2006 20:30:00,16,18,4..13,24/03/2006 21:00:00,15,18,4..14,24/03/2006 21:30:00,13,18,4..15,24/03/2006 22:00:00,12,18,4..16,24/03/2006 22:30:00,11,18,4..17,24/03/2006 23:00:00,10,18,4..18,24/03/2006 23:30:00,9,18,4..19,25/03/2006 00:00:00,9,18,4..20,25/03/2006 00:30:00,8,18,4..21,25/03/2006 01:00:00,8,18,4..22,25/03/2006 01:30:00,8,18,4..23,25/03/2006 02:00:00,7,18,4..24,25/03/2006 02:30:00,7,18,4..25,25/03/2006 03:00:00,7,18,4..26,25/03/2006 03:30:00,7,18,4..27,25/03/2006 04:00:00,7,18,4..28,25/03/2006 04:30:00,7,18,4..29,25/03/2006 05:00:00,6,18,4..30,25/03/2006 05:3
Process:C:\Windows\System32\msiexec.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):44219
Entropy (8bit):3.527582608719269
Encrypted:false
SSDEEP:
MD5:F8F1C58AA92A4C8850F434A77FE4411A
SHA1:CCCADD7400963855821CD1A849D5A184B54591AF
SHA-256:4ED4C172605C504B5FDB6660DE03B708D4174814DD738FC8DA38B9C439BA7447
SHA-512:053416800239F53B64D9622C97BEEF1C50C85442FFC3A0C1DF5304AFE667AB43B3BDBC489F94F250E5D4D595C3F4A02835213F0B12653F468B64D95D94CDDFDF
Malicious:false
Reputation:unknown
Preview:Logger Name,Time,Celsius(.C),High Alarm,Low Alarm,Humidity(%rh),High Alarm rh,Low Alarm rh,dew point(.C),Serial Number..1,05/01/2005 12:30:00,24.5,50.0,5.0,38.0,80.0,20.0,9.3,987654321..2,05/01/2005 12:30:10,24.5,50.0,5.0,38.0,80.0,20.0,9.3..3,05/01/2005 12:30:20,24.5,50.0,5.0,37.0,80.0,20.0,8.9..4,05/01/2005 12:30:30,24.5,50.0,5.0,37.0,80.0,20.0,8.9..5,05/01/2005 12:30:40,24.5,50.0,5.0,37.0,80.0,20.0,8.9..6,05/01/2005 12:30:50,24.5,50.0,5.0,37.0,80.0,20.0,8.9..7,05/01/2005 12:31:00,24.5,50.0,5.0,37.0,80.0,20.0,8.9..8,05/01/2005 12:31:10,24.5,50.0,5.0,37.0,80.0,20.0,8.9..9,05/01/2005 12:31:20,24.5,50.0,5.0,37.0,80.0,20.0,8.9..10,05/01/2005 12:31:30,24.5,50.0,5.0,36.5,80.0,20.0,8.7..11,05/01/2005 12:31:40,24.5,50.0,5.0,36.5,80.0,20.0,8.7..12,05/01/2005 12:31:50,24.5,50.0,5.0,36.5,80.0,20.0,8.7..13,05/01/2005 12:32:00,24.5,50.0,5.0,36.5,80.0,20.0,8.7..14,05/01/2005 12:32:10,25.0,50.0,5.0,36.5,80.0,20.0,9.1..15,05/01/2005 12:32:20,25.0,50.0,5.0,36.5,80.0,20.0,9.1..16,05/01/2005 12:32:30,2
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):125852
Entropy (8bit):3.6068372981211265
Encrypted:false
SSDEEP:
MD5:E5477135B40BAFC5CDBC0887E9F43E91
SHA1:4A98CBD1BF41A7BDB4BABB53085131072914C832
SHA-256:ACCD81ED3E1A0DE10AB90D303C50B35185FFFBAC3ADB65675B22F923551D5792
SHA-512:E9BE123D171F9A5B5AD5E71CEC9457B7DB6B8B4B3AC253BBCE56973E14FE293EBCFF0A685D3D6786575716EFA27EB8CF70CD19DB2CD074A54884EFE248A9BC21
Malicious:false
Reputation:unknown
Preview:EasyLogUSB,Time,Celsius,Low Alarm,Serial Number..1,13/02/2004 22:30:00,20.5,10.0,987654321..2,13/02/2004 22:31:00,21.0,10.0..3,13/02/2004 22:32:00,21.5,10.0..4,13/02/2004 22:33:00,21.5,10.0..5,13/02/2004 22:34:00,21.0,10.0..6,13/02/2004 22:35:00,20.5,10.0..7,13/02/2004 22:36:00,20.0,10.0..8,13/02/2004 22:37:00,20.0,10.0..9,13/02/2004 22:38:00,19.5,10.0..10,13/02/2004 22:39:00,19.5,10.0..11,13/02/2004 22:40:00,19.5,10.0..12,13/02/2004 22:41:00,19.0,10.0..13,13/02/2004 22:42:00,19.0,10.0..14,13/02/2004 22:43:00,19.0,10.0..15,13/02/2004 22:44:00,19.0,10.0..16,13/02/2004 22:45:00,18.5,10.0..17,13/02/2004 22:46:00,18.5,10.0..18,13/02/2004 22:47:00,18.5,10.0..19,13/02/2004 22:48:00,18.5,10.0..20,13/02/2004 22:49:00,18.5,10.0..21,13/02/2004 22:50:00,18.5,10.0..22,13/02/2004 22:51:00,18.5,10.0..23,13/02/2004 22:52:00,18.0,10.0..24,13/02/2004 22:53:00,18.0,10.0..25,13/02/2004 22:54:00,18.0,10.0..26,13/02/2004 22:55:00,18.0,10.0..27,13/02/2004 22:56:00,18.0,10.0..28,13/02/2004 22:57:00,18.0,10.0
Process:C:\Windows\System32\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):8679
Entropy (8bit):3.717253632972772
Encrypted:false
SSDEEP:
MD5:86086555543DDAF5B4703A617984C70C
SHA1:CD3921237802C1958A888D0273519A6B6E3C3AD1
SHA-256:8A10FFA4AEDBDA127188FBC46437A04DE0618F3E056C084A76017990EB559C3F
SHA-512:011DE120A8EEDAF8A569567CBBBE6EA1D73AB7F30A6FF45B59735657107ED454EC7598A5C7B69A0E7C50E7CC246D8DC90F6D5AB615E19BD67EE27E2D77EC82D7
Malicious:false
Reputation:unknown
Preview:EasyLog USB,Time,Voltage(Volts),High Alarm,Low Alarm,Serial Number..1,31/03/2005 10:20:00,24.45,17.50,2.50,987654322..2,31/03/2005 10:20:01,24.05,17.50,2.50..3,31/03/2005 10:20:02,23.65,17.50,2.50..4,31/03/2005 10:20:03,23.30,17.50,2.50..5,31/03/2005 10:20:04,22.90,17.50,2.50..6,31/03/2005 10:20:05,22.55,17.50,2.50..7,31/03/2005 10:20:06,22.20,17.50,2.50..8,31/03/2005 10:20:07,21.85,17.50,2.50..9,31/03/2005 10:20:08,21.55,17.50,2.50..10,31/03/2005 10:20:09,21.20,17.50,2.50..11,31/03/2005 10:20:10,20.90,17.50,2.50..12,31/03/2005 10:20:11,20.55,17.50,2.50..13,31/03/2005 10:20:12,20.25,17.50,2.50..14,31/03/2005 10:20:13,19.95,17.50,2.50..15,31/03/2005 10:20:14,19.65,17.50,2.50..16,31/03/2005 10:20:15,19.35,17.50,2.50..17,31/03/2005 10:20:16,19.05,17.50,2.50..18,31/03/2005 10:20:17,18.80,17.50,2.50..19,31/03/2005 10:20:18,18.50,17.50,2.50..20,31/03/2005 10:20:19,18.20,17.50,2.50..21,31/03/2005 10:20:20,17.95,17.50,2.50..22,31/03/2005 10:20:21,17.70,17.50,2.50..23,31/03/2005 10:20:22,17.40,
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
Category:dropped
Size (bytes):467288
Entropy (8bit):6.047761304423497
Encrypted:false
SSDEEP:
MD5:195ED09E0B4F3B09EA4A3B67A0D3F396
SHA1:01A250631397C93C4AAB9A777A86E39FD8D84F09
SHA-256:AEF9FCBB874FC82E151E32279330061F8F22A77C05F583A0CB5E5696654AC456
SHA-512:B801C03EFA3E8079366A7782D2634A3686D88F64C3C31A03AA5CE71B7BF472766724D209290C231D55DA89DD4F03BD1C0153FFEB514E1D5D408CC2C713CD4098
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....K...........!................> ... ...@....@.. ...............................>....@.....................................S....@..................X....`......h................................................ ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ ......H..........|q..........8.......P .......................................LO.K. 6}.5N..LA..D..|..=T.+.%.O..!@....D.tLl.....8..o...x"...&..C.@"}.dd..CZ..+..4l|<.V....Z....=..)...':..n.....*.....K..{....*"..}....*F.~....(H...t<...*6.~.....(I...*.r...p.<...(J........(J...(K........*..(L...*F.~....oH...t....*6.~.....oI...*...0.."........u'.....,...(M...t......,...o....*...0..F........(....,.r...psN...z..(......o............sO...oP...........sO...oQ...*...0..F........(....-.
Process:C:\Windows\System32\msiexec.exe
File Type:Generic INItialization configuration [Driver Version]
Category:dropped
Size (bytes):483
Entropy (8bit):5.319487317274177
Encrypted:false
SSDEEP:
MD5:0A73FF24BBBB30B912BFC115A24019AB
SHA1:EE921F92A90C13A153094E090A93EEA572EA22A4
SHA-256:E19491ADE2529A48A75E625E512175ACD5BB98CA6739BEE958AAE5822E3CA488
SHA-512:9EAE1A0E046253EB041AB7020627F037A9D9B3C8853DCD09D8A7B9846ADEEC6B113772429992776E0FB732034470F76D7E481374CCAA45C97BFD045C816A10DE
Malicious:false
Reputation:unknown
Preview:[Driver Type]..USBXpress....[Driver Version]..3.3....[Product Name]..EasyLog USB Device....[Company Name]..Lascar Electronics Ltd.....[VID_PID List]..10C4_0002....[Install Subdirectories]..x86..x64....[Install Quiet Mode]..Off....[Uninstall Quiet Mode]..Off....[Copy Driver Files]..No....[XP_2K_2K3_VISTA INF Files]..EL-USB.inf....[XP_2K_2K3_VISTA Driver Files]...\x64\SiUSBXp.sys...\x64\SiLib.sys...\x86\SiUSBXp.sys...\x86\SiLib.sys....[XP_2K_2K3_VISTA Catalog Files]..siusbxp.cat..
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):8984
Entropy (8bit):6.928193234859025
Encrypted:false
SSDEEP:
MD5:0F98B187AC70FCBC464912A833656EB3
SHA1:3A9DA589492C7B9C419DA9BD0018100628F9D55E
SHA-256:5FED39B28E3E4BB08403553C508DCC5E242A99463A957BDF0C1E42F16E2A19D6
SHA-512:1B26CE1BDB28B8C1550C33D835AAD5DDBA9A190C525CA507A103926A5C7410DAE81EBD3CF8DF30C634B273A6926271E69BEA7BE539393D82286DD38391FC0592
Malicious:false
Reputation:unknown
Preview:0.#...*.H........#.0.#....1.0...+......0.....+.....7......0...0...+.....7.....[dd v.8N..6....5..101112175240Z0...+.....7.....0...0....R1.5.5.E.F.D.4.F.0.9.8.E.9.A.5.2.9.4.A.F.F.1.8.E.2.A.0.E.4.5.A.A.C.5.E.D.0.3.1.0...1..g08..+.....7...1*0(...F.i.l.e........e.l.-.u.s.b...i.n.f...0a..+.....7...1S0Q0,..+.....7........<.<.<.O.b.s.o.l.e.t.e.>.>.>0!0...+.........^.O...R...*.E.....0b..+.....7...1T0R.L.{.D.E.3.5.1.A.4.2.-.8.E.5.9.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0d..+.....7...1V0T...O.S.A.t.t.r.......>2.:.5...0.0.,.2.:.5...1.,.2.:.5...2.,.2.:.6...0.,.2.:.6...1...0....R1.8.A.8.0.D.E.0.C.F.D.5.2.1.0.E.9.A.3.2.5.C.7.2.B.1.2.4.0.B.4.4.2.F.B.4.F.4.2.2...1..q0:..+.....7...1,0*...F.i.l.e........s.i.u.s.b.x.p...s.y.s...0b..+.....7...1T0R.L.{.C.6.8.9.A.A.B.8.-.8.E.7.8.-.1.1.D.0.-.8.C.4.7.-.0.0.C.0.4.F.C.2.9.5.E.E.}....0d..+.....7...1V0T...O.S.A.t.t.r.......>2.:.5...0.0.,.2.:.5...1.,.2.:.5...2.,.2.:.6...0.,.2.:.6...1...0i..+.....7...1[0Y04..+.....7...0&..... .....<.<.<.O.b.s.o.l.e.t.e
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):24576
Entropy (8bit):5.444427923348303
Encrypted:false
SSDEEP:
MD5:971FA2980AB94A90B6A9A8385267E653
SHA1:FC739185177A85ED04B71C6A8D5FDFB72D919306
SHA-256:25E3D0517AFCBD70C1EBB53097F096E1BDA49DC4524E3C858489E5EC12825608
SHA-512:6D905EC5FCEE1F8ED2870AF0714A6C630DE3E8D8611406486ADDA08ECFC1873BD57932ED73F42EF93E4F49D40FCED13CA5C1C99795E8C0CECBBE6B56327E1337
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............uc.uc.uc.ub.uc.....uc.....uc....uc....uc.....uc....uc....uc....uc....uc.Rich.uc.................PE..d....?L.........."......B..........d................................................-..........................................................(.......0.......................8...@q...............................................p..@............................text....".......$.................. ..hpage.........@.......(.............. ..hinit.........`.......>.............. ..h.rdata.......p.......@..............@..H.data................D..............@....pdata...............H..............@..H.edata...............L..............@..@INIT....b............T.............. ....rsrc...0............Z..............@..B.reloc...............^..............@..B........................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32+ executable (native) x86-64, for MS Windows
Category:dropped
Size (bytes):19456
Entropy (8bit):5.5838184446755195
Encrypted:false
SSDEEP:
MD5:CEDF7CFFCCD03451FD22DBAAC2E3DE8E
SHA1:3FD8383608DB769A1E2C8E0C1302C315DCA8B37E
SHA-256:A1F4B952099EBA4BA4E659782F85B45C4BBB411BF5B7C02D5BE0CC3DBF27AFF3
SHA-512:BBA0BF8C75E5A1B1AFC72F5B5A33CACA721DBB4589DE7B3430398AE147E2E2CF18A15932DF62D32423B1093453B55B48B9E99FB7549135E3CF33976229C47376
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......#d..g..g..g..n}w.e..g..B......b......e..n}g.d..n}q.f......f..n}n.b..n}p.f..n}u.f..Richg..........PE..d...A.?L.........."......:..........d...........................................................................................................P.......8...........................@a...............................................`..@............................text............................... ..hpage.........0...................... ..hinit....U....P.......6.............. ..h.rdata.......`.......8..............@..H.data...0....p.......>..............@....pdata...............@..............@..HINIT.................B.............. ....rsrc...8............H..............@..B................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):17408
Entropy (8bit):6.017219183396955
Encrypted:false
SSDEEP:
MD5:812318F3E7BD682E1C22F0B707F66E82
SHA1:AA17A293AEC2BF1239779A8D439F84B2602D76AD
SHA-256:9B4C47FAA4BD6F22E75CF8430BAC37E48108C35B6737850E583EFDC37C4D8A81
SHA-512:961BF96B873E269AD566B33243DF872D989AAB6EB51E29CC984D26BCCC331DDB60B45B301C2FD13D9F5E10BC26CAEFBD948D305D35EBAA22515453A3CD57CFD5
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................X...........!..L.!This program cannot be run in DOS mode....$.......................................................................................................................................................................................................................................................................................................................................................................................................>...z...z...z...z...J...#.......]#..{...]#..}...]#..{...]#..{...]#..{...Richz...........PE..L....?L.............................8.......-...............................D......................................1......D8..<....=..0....................A..4...P................................................-...............................text...L........................... ..hpage....x........................... ..hinit.........-.......-.............. ..h.rdata.......-.......-..........
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (native) Intel 80386, for MS Windows
Category:dropped
Size (bytes):14592
Entropy (8bit):6.033771703962439
Encrypted:false
SSDEEP:
MD5:599F3715602F4CB09AD0FDC606E3B9D9
SHA1:659F9A1CF662260F3FB197E6FE3592922014E831
SHA-256:589FEA41EF48ACD9F0FC54AB25A430E5627D17E8EC3C950F3C5CB71C348E9B8D
SHA-512:56E55D7FD6330E2BBE60BD79D7502E22CEDC9F448982C54E9C924BD57B3C0741E634883435BA4621DB80852D7F47A081FA4FA4302217BFB4BF87558F7EC233BB
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...................................`...........!..L.!This program cannot be run in DOS mode....$.........................................................................................................................................................................................................................................................................................................................................................................................................T.Q.:.Q.:.Q.:.v.G.R.:.v.A.S.:.Q.;.}.:...).V.:.v.W.T.:.v.T.T.:.v.F.P.:.v.B.P.:.RichQ.:.........PE..L...}.?L.................+...................+...............................9.......Y......................................D...d....3..8....................7.......+...............................+..@............+...............................text............................... ..hpage....~........................... ..hinit.........*.......*.............. ..h.rdata.. ....+.......+..
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
Category:dropped
Size (bytes):2769
Entropy (8bit):2.9214200185059975
Encrypted:false
SSDEEP:
MD5:AD6EDC97A8ADF247A41FCFF832386DFE
SHA1:F1FA6469F869F8FCEC7631D1F16FB11678CE2E15
SHA-256:CD5FEC9C4F4242B25DD753EC2F1B78849B380CFE82F880A07CA8BAB1F238F99C
SHA-512:DDB38AE427A584477A05E68949F51B77739EA18C72AED6FC1E60A69973A458F5993EB5F8404160B38F8B8062D26E52C57FC7646036DA7117232A6E861B8AFE78
Malicious:false
Reputation:unknown
Preview:L..................F.P......................................................-....P.O. .:i.....+00.../C:\...................V.1......Ys...Windows.@......OwH.Ys.....3.........................W.i.n.d.o.w.s.....\.1......Y|...Installer.D......O.I.Y|...............................I.n.s.t.a.l.l.e.r.......1......Y|...{B4E4E~1..~.......Y|..Y|.....7.........................{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.......2......Y|.!.EASYLO~1.EXE..........Y|..Y|.....;.........................E.a.s.y.L.o.g._.U.S.B...e.x.e._.6.3.2.5.7.A.9.3.0.1.F.B.4.E.A.B.A.0.8.5.D.3.C.6.9.F.4.7.0.E.C.4...e.x.e.............\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.\.E.a.s.y.L.o.g._.U.S.B...e.x.e._.6.3.2.5.7.A.9.3.0.1.F.B.4.E.A.B.A.0.8.5.D.3.C.6.9.F.4.7.0.E.C.4...e.x.e.#.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.p.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Has Relative path, Has Working directory, Icon number=0, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
Category:dropped
Size (bytes):2775
Entropy (8bit):2.9268640614950217
Encrypted:false
SSDEEP:
MD5:992A06209D6CBC7C25B1676E3979A571
SHA1:FD4B63B71157503A1244357A9B53293A575892FC
SHA-256:10D3A77D970556B6100ACBC821995AA7E5D88DBC5637613235E71F66DB176F4F
SHA-512:D921C07B0A62361DC5F14465E118C3590E9C4F28987909E01665652FE21331CE6732CF1338F68BBDC8852D476684D95FD7A1F17507FC9C1EF440A769F2BF6517
Malicious:false
Reputation:unknown
Preview:L..................F.P....................................................../....P.O. .:i.....+00.../C:\...................V.1......Ys...Windows.@......OwH.Ys.....3.........................W.i.n.d.o.w.s.....\.1......Y|...Installer.D......O.I.Y|...............................I.n.s.t.a.l.l.e.r.......1......Y|...{B4E4E~1..~.......Y|..Y|.....7........................{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.......2......Y|.!.EASYLO~2.EXE..........Y|..Y|.....<........................E.a.s.y.L.o.g.G.r.a.p.h...e.x.e._.3.D.3.9.C.6.0.5.F.6.D.0.4.8.4.A.8.8.F.3.A.D.4.B.8.2.B.1.3.9.9.3...e.x.e.............\.....\.....\.....\.....\.....\.W.i.n.d.o.w.s.\.I.n.s.t.a.l.l.e.r.\.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.\.E.a.s.y.L.o.g.G.r.a.p.h...e.x.e._.3.D.3.9.C.6.0.5.F.6.D.0.4.8.4.A.8.8.F.3.A.D.4.B.8.2.B.1.3.9.9.3...e.x.e.#.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.q.C.:.\.W.i.n.d.o.w.s.\.I.n.s.t.a
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Feb 18 18:11:02 2021, mtime=Thu Aug 29 17:51:54 2024, atime=Thu Feb 18 18:11:02 2021, length=2468864, window=hide
Category:dropped
Size (bytes):970
Entropy (8bit):4.7085217917161275
Encrypted:false
SSDEEP:
MD5:FC8B7CCD3FC06C093E4B7FB5FD9366EC
SHA1:FDEF120EA28081EE3E90EE03C92B76B464DB3F67
SHA-256:3570012FACBCA736F40EB89EC6626C2D8F715CAC37F05BF894E711234C1F2FFC
SHA-512:036B37EAB090033E3F9FDBDE33D8E0F3E80F362195EB5E501F3B53657E14576293233FCFE831080763CE86DBDD353F19A3A07252EDAA06F157E1F67910D9B52A
Malicious:false
Reputation:unknown
Preview:L..................F.... ....g2.)...}...D....g2.).....%..........................P.O. .:i.....+00.../C:\.....................1......Y{...PROGRA~2.........O.I.Y{.....................V.......6.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....`.1......Y|...EASYLO~1..H.......Y{..Y|..........................8...E.a.s.y.L.o.g. .U.S.B.....l.2...%.RRa. .EASYLO~1.EXE..P......RRa..Y|...............................E.a.s.y.L.o.g. .U.S.B...e.x.e.......a...............-.......`..............,.....C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe..8.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.E.a.s.y.L.o.g. .U.S.B...e.x.e.........*................@Z|...K.J.........`.......X.......506407...........hT..CrF.f4... .;.............%..hT..CrF.f4... .;.............%.........A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Feb 18 18:11:02 2021, mtime=Thu Aug 29 17:51:54 2024, atime=Thu Feb 18 18:11:02 2021, length=2468864, window=hide
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:FC8B7CCD3FC06C093E4B7FB5FD9366EC
SHA1:FDEF120EA28081EE3E90EE03C92B76B464DB3F67
SHA-256:3570012FACBCA736F40EB89EC6626C2D8F715CAC37F05BF894E711234C1F2FFC
SHA-512:036B37EAB090033E3F9FDBDE33D8E0F3E80F362195EB5E501F3B53657E14576293233FCFE831080763CE86DBDD353F19A3A07252EDAA06F157E1F67910D9B52A
Malicious:false
Reputation:unknown
Preview:L..................F.... ....g2.)...}...D....g2.).....%..........................P.O. .:i.....+00.../C:\.....................1......Y{...PROGRA~2.........O.I.Y{.....................V.......6.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....`.1......Y|...EASYLO~1..H.......Y{..Y|..........................8...E.a.s.y.L.o.g. .U.S.B.....l.2...%.RRa. .EASYLO~1.EXE..P......RRa..Y|...............................E.a.s.y.L.o.g. .U.S.B...e.x.e.......a...............-.......`..............,.....C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe..8.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.E.a.s.y.L.o.g. .U.S.B...e.x.e.........*................@Z|...K.J.........`.......X.......506407...........hT..CrF.f4... .;.............%..hT..CrF.f4... .;.............%.........A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Windows\System32\msiexec.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Feb 18 18:11:02 2021, mtime=Thu Aug 29 17:51:54 2024, atime=Thu Feb 18 18:11:02 2021, length=2468864, window=hide
Category:dropped
Size (bytes):1015
Entropy (8bit):4.728992866932944
Encrypted:false
SSDEEP:
MD5:DA45A723075941B2748E8D05EEC516FA
SHA1:0BF5D9DA505EDCDDFE560B73C79E2528B77783CF
SHA-256:DE0F68DC2211A92B69D8249005775A16AE22E73A175D02162AD33CB4B4B8C1C3
SHA-512:6C3E72FB19A10784545C3B0A541A4B924EAD534698728B5401DC386C643803E9C4CE0A9814CAF645360236F181C2214EE225B1CEF519FD8AABAEE74C4FD3C7B1
Malicious:false
Reputation:unknown
Preview:L..................F.... ....g2.)...}...D....g2.).....%..........................P.O. .:i.....+00.../C:\.....................1......Y{...PROGRA~2.........O.I.Y{.....................V.......6.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....`.1......Y|...EASYLO~1..H.......Y{..Y|..........................8...E.a.s.y.L.o.g. .U.S.B.....l.2...%.RRa. .EASYLO~1.EXE..P......RRa..Y|...............................E.a.s.y.L.o.g. .U.S.B...e.x.e.......a...............-.......`..............,.....C:\Program Files (x86)\EasyLog USB\EasyLog USB.exe..8.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.E.a.s.y.L.o.g. .U.S.B.\.E.a.s.y.L.o.g. .U.S.B...e.x.e.........*................@Z|...K.J.........`.......X.......506407...........hT..CrF.f4... .;.............%..hT..CrF.f4... .;.............%.........-...1SPSU(L.y.9K....-........................A...1SPS.XF.L8C....&.m.%................S.-.1.-.5.-.1.8.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?.
Process:C:\Windows\SysWOW64\msiexec.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):205
Entropy (8bit):5.239236705496828
Encrypted:false
SSDEEP:
MD5:52E37704F6B2D0A60914D4FC33BB8392
SHA1:865DE5AD56B952BC6A55A44A9B25C5982B08856D
SHA-256:80D350EEFE5A06D8D5939421EA8AA11227E1CB7531405D44D236F7C520BD1D26
SHA-512:19EBDD5C7765B6C4CF3F10B76550679345B51F0C38C6081DC9B8F6DE1ADD700F7124A8CF7CB948FB6E494DA607677A646ADDE50E6C748C41526DE6B698425215
Malicious:false
Reputation:unknown
Preview:[DLL1]..Return=void..Module=user32.dll..Func=MessageBoxA..Arg0=in,MsiWindowHandle,NUMBER..Arg1=in,[MESSAGEPROP],STRING..Arg2=in,[CAPTIONPROP],STRING..Arg3=in,1,NUMBER..Silent=Yes..Source=Local,user32.dll..
Process:C:\Windows\SysWOW64\msiexec.exe
File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):523512
Entropy (8bit):6.417003787731374
Encrypted:false
SSDEEP:
MD5:557E647D925831D32DA575BF45C849D7
SHA1:50B607E57D527CD076BE0BA23E1177890A401C12
SHA-256:E41012393DACFDF2632243323D5718EA962ED96FD8248D1C6747903E4C2A1D36
SHA-512:DB5F067EFADE41BB5B7E3B54CC1FF40AD3105CB2258329C13C92E38B29CB9E62EA2C1FFAA2401FA8E34BE16C7CBB87F6CBA5AEA88B79361181C9A81D3612E53E
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......b.o.&o..&o..&o....+o....Bo.....o../...-o..&o..\o......o.....'o.....'o..&o..'o.....'o..Rich&o..................PE..L....}.W...........!.....V..................p...............................0............@..........................(..rB......x................................d...r..8...............................@............p...............................text...#T.......V.................. ..`.rdata..R....p.......Z..............@..@.data...|4...p.......V..............@....rsrc................l..............@..@.reloc..Ne.......f...z..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\SysWOW64\msiexec.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):156928
Entropy (8bit):6.027572827219195
Encrypted:false
SSDEEP:
MD5:69E9BB71D4D394E87F0109734D328371
SHA1:82FBEF8F36AECEFBCA489D58C09CDF4B0386F787
SHA-256:C3A87617D5BA229A62DA7FD4E0929BE26CAC33C58470FD5E5F0B54C30FF4D172
SHA-512:867C051E8BEAD1B4B093833776B2643E2B077E5D0866FF0D5362EA51AD277C3FF0F6892475183F4308409742DE63FFEED6289FBE4BD6DA692F873EF647AE3414
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........;..;..;....#.*.... .=... .:....!...... .H..2.m.8..2.}.$..;..6...!.-...$.:...'.:..;.y.:...".:..Rich;..........PE..L...y..W...........!.....J..........F........`......................................7...............................p...E............@...............H.......P..@...................................H...@............`...............................text....I.......J.................. ..`.rdata.......`.......N..............@..@.data...t1..........................@....rsrc........@......................@..@.reloc...J...P...L..................@..B................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Unicode text, UTF-16, little-endian text, with very long lines (308), with CRLF line terminators
Category:dropped
Size (bytes):22480
Entropy (8bit):3.4851320007899904
Encrypted:false
SSDEEP:
MD5:A108F0030A2CDA00405281014F897241
SHA1:D112325FA45664272B08EF5E8FF8C85382EBB991
SHA-256:8B76DF0FFC9A226B532B60936765B852B89780C6E475C152F7C320E085E43948
SHA-512:D83894B039316C38915A789920758664257680DCB549A9B740CF5361ADDBEE4D4A96A3FF2999B5D8ACFB1D9336DA055EC20012D29A9F83EE5459F103FBEEC298
Malicious:false
Reputation:unknown
Preview:..[.0.x.0.4.0.9.].....1.1.0.0.=.S.e.t.u.p. .I.n.i.t.i.a.l.i.z.a.t.i.o.n. .E.r.r.o.r.....1.1.0.1.=.%.s.....1.1.0.2.=.%.1. .S.e.t.u.p. .i.s. .p.r.e.p.a.r.i.n.g. .t.h.e. .%.2.,. .w.h.i.c.h. .w.i.l.l. .g.u.i.d.e. .y.o.u. .t.h.r.o.u.g.h. .t.h.e. .p.r.o.g.r.a.m. .s.e.t.u.p. .p.r.o.c.e.s.s... . .P.l.e.a.s.e. .w.a.i.t.......1.1.0.3.=.C.h.e.c.k.i.n.g. .O.p.e.r.a.t.i.n.g. .S.y.s.t.e.m. .V.e.r.s.i.o.n.....1.1.0.4.=.C.h.e.c.k.i.n.g. .W.i.n.d.o.w.s.(.R.). .I.n.s.t.a.l.l.e.r. .V.e.r.s.i.o.n.....1.1.0.5.=.C.o.n.f.i.g.u.r.i.n.g. .W.i.n.d.o.w.s. .I.n.s.t.a.l.l.e.r.....1.1.0.6.=.C.o.n.f.i.g.u.r.i.n.g. .%.s.....1.1.0.7.=.S.e.t.u.p. .h.a.s. .c.o.m.p.l.e.t.e.d. .c.o.n.f.i.g.u.r.i.n.g. .t.h.e. .W.i.n.d.o.w.s. .I.n.s.t.a.l.l.e.r. .o.n. .y.o.u.r. .s.y.s.t.e.m... .T.h.e. .s.y.s.t.e.m. .n.e.e.d.s. .t.o. .b.e. .r.e.s.t.a.r.t.e.d. .i.n. .o.r.d.e.r. .t.o. .c.o.n.t.i.n.u.e. .w.i.t.h. .t.h.e. .i.n.s.t.a.l.l.a.t.i.o.n... .P.l.e.a.s.e. .c.l.i.c.k. .R.e.s.t.a.r.t. .t.o. .r.e.b.o.o.t. .t.h.e. .s.y.s.t.e.m.......1.1.0.8.
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.1, MSI Installer, Number of Characters: 0, Last Saved By: InstallShield, Number of Words: 0, Title: Installation Database, Comments: Contact: Your local administrator, Keywords: Installer,MSI,Database, Subject: EasyLog USB, Author: Lascar Electronics Ltd., Security: 1, Number of Pages: 200, Name of Creating Application: InstallShield 2016 - Professional Edition 23, Last Saved Time/Date: Mon Aug 8 16:29:11 2022, Create Time/Date: Mon Aug 8 16:29:11 2022, Last Printed: Mon Aug 8 16:29:11 2022, Revision Number: {8C7E2C80-4C6F-4A5C-9FDD-5AA316A9E29A}, Code page: 1252, Template: Intel;1033
Category:dropped
Size (bytes):19083776
Entropy (8bit):7.960074563695781
Encrypted:false
SSDEEP:
MD5:0667825A7C186AB1769BEF4A2D0D5CA6
SHA1:06EFBC582B852C4964CA6CA1DEFB5B13B182B0BA
SHA-256:A0875FA7ABF8474D2864DAFA61CCA887F0EA81ED0B82B57184046A1E946E4C10
SHA-512:ECCF9D7FA57095BF4CDECA50DA10BF8CA2B8AAD5C756D3B7E3CEE55D4976D894B1ED5AE9D512950835EED696FD3A7DB1DB0ADB878EEC178103461C9443C62697
Malicious:false
Reputation:unknown
Preview:......................>...................$...............8........6....................................................................................................................................................................................................................................................................... ... ...!...!..."..."...#...#...$...$...%...%...&...&...'...'...(...(...)...)...*...*...+...+...,...,...-...-.........../.../...0...0...1...1...2...2...3...3...4...4...5...5...6..........;...............................................................................................!................... ...#..."...-...$.......&...'...(...)...*...+...,.../.......1...0...D...2...3...4...5...6...7...A...M...:...<.......=.......?...@...R...B...C...F...E...Z...G...H...I...J...O...L...N...k.......P...Q...T...S...~...U...\...W...X...Y...|...[.......]...^..._...`...a...b...c...d...e...f...g...h...i...j...k...l...m...n...o...p...q...r...s...t...u...v...w...x...y...z...
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):606
Entropy (8bit):3.688532245445425
Encrypted:false
SSDEEP:
MD5:17E6BBD1E8595815759254889DE4FF8B
SHA1:F15138BF500C539F7E680D90A23C0FF43F1885F5
SHA-256:F470800E59BDDF14C139633534D9B7453DCBD8B5DB3EF3CB557B7AA21D77CDD4
SHA-512:D8212CB89A60ACAFE4397D4978541865698417FA866C996497E672DB951F930C08996EBF45571EBB4706593EE5FB04DE5462EE3F281586271563E9235C69B8DF
Malicious:false
Reputation:unknown
Preview:..[.F.i.l.e.s.].....0.x.0.4.0.9...i.n.i.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.{.7.F.3.B.B.4.D.9.-.1.9.5.4.-.4.1.B.0.-.8.F.C.6.-.1.6.8.7.C.A.4.E.5.5.7.E.}.\.0.x.0.4.0.9...i.n.i.....E.a.s.y.L.o.g. .U.S.B...m.s.i.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.{.7.F.3.B.B.4.D.9.-.1.9.5.4.-.4.1.B.0.-.8.F.C.6.-.1.6.8.7.C.A.4.E.5.5.7.E.}.\.E.a.s.y.L.o.g. .U.S.B...m.s.i.....S.e.t.u.p...I.N.I.=.C.:.\.U.s.e.r.s.\.c.a.l.i.\.A.p.p.D.a.t.a.\.L.o.c.a.l.\.T.e.m.p.\.{.7.F.3.B.B.4.D.9.-.1.9.5.4.-.4.1.B.0.-.8.F.C.6.-.1.6.8.7.C.A.4.E.5.5.7.E.}.\.S.e.t.u.p...I.N.I.....
Process:C:\Users\user\Desktop\EasyLogUSB+Installer.exe
File Type:Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):5252
Entropy (8bit):3.733760690252317
Encrypted:false
SSDEEP:
MD5:33F13D68A9E9F9845760A257286545AA
SHA1:A2B07B4FBF4BFCCFF550469FC12C7030892D9355
SHA-256:A231E341F8E0997464F740BEC5526711605B173DC2C3101D580DB82AB636E67A
SHA-512:55455655ADA80A5BFC15BD9878FE8DD7B60FCBD5800A13C06BCC8E5400D08FE5684E565DBC2B9E87FA8CCEF96CBF58B4045D59F60809A7B7C41A737D776F3C81
Malicious:false
Reputation:unknown
Preview:..[.I.n.f.o.].....N.a.m.e.=.I.N.T.L.....V.e.r.s.i.o.n.=.1...0.0...0.0.0.....D.i.s.k.S.p.a.c.e.=.8.0.0.0...;.D.i.s.k.S.p.a.c.e. .r.e.q.u.i.r.e.m.e.n.t. .i.n. .K.B.........[.S.t.a.r.t.u.p.].....C.m.d.L.i.n.e.=.....S.u.p.p.r.e.s.s.W.r.o.n.g.O.S.=.Y.....S.c.r.i.p.t.D.r.i.v.e.n.=.0.....S.c.r.i.p.t.V.e.r.=.1...0...0...1.....D.o.t.N.e.t.O.p.t.i.o.n.a.l.I.n.s.t.a.l.l.I.f.S.i.l.e.n.t.=.N.....O.n.U.p.g.r.a.d.e.=.0.....P.r.o.d.u.c.t.=.E.a.s.y.L.o.g. .U.S.B.....P.a.c.k.a.g.e.N.a.m.e.=.E.a.s.y.L.o.g. .U.S.B...m.s.i.....E.n.a.b.l.e.L.a.n.g.D.l.g.=.N.....L.o.g.R.e.s.u.l.t.s.=.N.....D.o.M.a.i.n.t.e.n.a.n.c.e.=.N.....P.r.o.d.u.c.t.C.o.d.e.=.{.B.4.E.4.E.F.E.5.-.9.3.D.9.-.4.3.5.B.-.B.D.E.9.-.3.5.2.5.A.9.6.8.9.E.B.9.}.....P.r.o.d.u.c.t.V.e.r.s.i.o.n.=.7...7...0.....U.p.g.r.a.d.e.C.o.d.e.=.{.3.1.5.0.0.6.0.B.-.C.0.3.B.-.4.0.B.D.-.8.5.9.1.-.5.A.E.7.5.2.0.9.7.F.0.B.}.....L.a.u.n.c.h.e.r.N.a.m.e.=.E.a.s.y.L.o.g.U.S.B._.V.7.-.7.0._.I.n.s.t.a.l.l._.U.p.d.a.t.e...e.x.e.....P.a.c.k.a.g.e.C.o.d.e.=.{.8.C.7.E.2.C.8.
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):207049
Entropy (8bit):5.187127303493844
Encrypted:false
SSDEEP:
MD5:F1C4E84781028AAD9477FCBE89B0D6A3
SHA1:F72E77E08ADFEFABC24DBC22782F88871CDEE00E
SHA-256:0077833AC391A6FDCE0E95B7867994D0A8BF0EEBA89B6B098A777D43CE05AF81
SHA-512:D30C68D6422F2A5E4BA0B61A57AA630424CC8F6F8AF8C4E79EB021BE9161C2090DBEA861BD9AD5312B5669872B4993EAEF600B5B7D766BB7403019CD67BA4BCD
Malicious:false
Reputation:unknown
Preview:...@IXOS.@.....@{v.Y.@.....@.....@.....@.....@.....@......&.{B4E4EFE5-93D9-435B-BDE9-3525A9689EB9}..EasyLog USB..EasyLog USB.msi.@.....@.....@.....@......ARPPRODUCTICON.exe..&.{8C7E2C80-4C6F-4A5C-9FDD-5AA316A9E29A}.....@.....@.....@.....@.......@.....@.....@.......@......EasyLog USB......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration...@.....@.....@.]....&.{429FE619-EEB7-4E48-AF7A-4F56DD1C7491}#.C:\Program Files (x86)\EasyLog USB\.@.......@.....@.....@......&.{1D213698-CDE4-4051-B5BD-2BBDFE318583}'.C:\Program Files (x86)\EasyLog USB\x86\.@.......@.....@.....@......&.{B2ECCF77-395E-4A26-A4BF-5EC89425F03F}'.C:\Program Files (x86)\EasyLog USB\x64\.@.......@.....@.....@......&.{AFECBE12-FD2C-45CC-80F8-C71798C38400}1.C:\Program Files (x86)\EasyLog USB\WPFToolkit.dll.@.......@.....@.....@......&.{A058DD12-721A-4A06-81C5-933F86CBD9A8}#.C:\Program Files (x86)\EasyLog USB\.@.......@....
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.1636092453135436
Encrypted:false
SSDEEP:
MD5:66F1B9EECDF5194B5E9683C0549EE498
SHA1:BD8D4F3ED82E74B7A078FA107B42322B2A29B192
SHA-256:2C018D5C479862D93C29E6125311976D2F03EE175BE7F00CE100449F4045298C
SHA-512:937B77904121DA94FA6D3D21D55BEFCF2A990D8BFCC707A4D7C07144494CED5849D429C5500A1A19487B8A0026B0FD677A3691B4CED184AC0513C28784E7E680
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):72944
Entropy (8bit):5.067944027835008
Encrypted:false
SSDEEP:
MD5:23C1D640A469D3086A14F9FDF449EB50
SHA1:2F277BA7EC429B93FE4D3879973024F8BACBE832
SHA-256:AE66EC7081CE696B549E39F70E5ADA5F57AC6F8173773EED1144039C24946945
SHA-512:585495B7A633B8F46ACB9D2A78703FB47A6057FC8F22171CC5F1B7EDF627D05571D39A164A15ED718C042C7B6C99AC927E00B83C95954E8EA9AE9E0FF58DC64B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.../..W.................@...................P....@.................................=;......................................4T..(........^...............,...........................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc....^.......`..................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):52464
Entropy (8bit):5.106173623429902
Encrypted:false
SSDEEP:
MD5:6E27FC142F298EEE2A5C37F3DF46975B
SHA1:0348059D4CE805D7099F3E24CF9AF5548C971176
SHA-256:70DCCB008ACA50A9F1925967DF3A15B581623FEF1AF005C5BD6BD59451AA8E79
SHA-512:CA5EC51965E9972946D80BFFFF617B2DFA08C743B1E3B5CF663DBFB79CC4769273B8BD28E6398F4B45E05DA48D8AC57548288018DD25812B001CE430E71A5599
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.../..W.................@...P...............P....@........................................................................4T..(.......,................,...........................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc...,...........................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):72944
Entropy (8bit):5.069498628939283
Encrypted:false
SSDEEP:
MD5:A2936C32057A1EC0E7F343B46A1C2D60
SHA1:6FA37460864A7452A0F0E82EB87D59EEAE1058ED
SHA-256:18F7E5E9E33F1A914EE9E64B239B7EB0D7FDC55C7BC2C06FFD97A23E76A8817C
SHA-512:3C78590D5BCE97502BE732683AF6B2B7A6AF14AF5DE80E431F7436C204E68E98D99F136E38317C8196ACB35414571B2253534B1858D01726268E917AFB71E67C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............C...C...C...C...CD..C...C...C...C=..C...C...C...C...C...CRich...C........................PE..L.../..W.................@...................P....@..................................?......................................4T..(........^...............,...........................................................P...............................text....5.......@.................. ..`.rdata.......P.......P..............@..@.data....)...`...0...`..............@....rsrc....^.......`..................@..@................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
Category:dropped
Size (bytes):454234
Entropy (8bit):5.356166206393021
Encrypted:false
SSDEEP:
MD5:2530EDE50E19F9419DAC8CC98DF2CFDC
SHA1:D67B7B8F014E382BEB7EA323CDFBA2135A9F3B26
SHA-256:DA4354C52FC97E32B539D9C90ED3EC6D2F61017C5861D885312A193F8BB9E6CD
SHA-512:A882DC0B62F051515B0EB6EEC95907F4EE4157ECC25B09A1990E56571DCAED38AD6BC06AB2528495E09CB9E733DFA4AB088336FE99B874F7D8E9EEEEB866A47B
Malicious:false
Reputation:unknown
Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
Process:C:\Windows\System32\msiexec.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):90112
Entropy (8bit):5.1088148238453925
Encrypted:false
SSDEEP:
MD5:372584E745A5A968AA02D7B969FB377B
SHA1:3333F82ED9FBD12CBF79C4E37EC65A7991BF60F5
SHA-256:77BAADD8CF594F91C20DA6F46A0AB939796D03F92AECB5D478049D419AA8DF13
SHA-512:ACE16FF6F7C2170712FCD4801B396BA54ECD0B20FCD82C7653F8294F69296493E0CA1748457D6A19AB060F3A43D4645A8A9C084E11F0C582C23E40A53AD5D6BC
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........=r..\...\...\..H@...\...z..\..C...\..C...\...\..\...z...\...Z...\..4|...\..Rich.\..................PE..L...y..I...........!................7Y.......................................`..............................................P...d....0.......................@..x.......................................................@............................text...b........................... ..`.rdata..h........ ..................@..@.data....9.......@..................@....rsrc........0.......0..............@..@.reloc..B....@... ...@..............@..B................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):73728
Entropy (8bit):0.2416905022648147
Encrypted:false
SSDEEP:
MD5:5D8AF881A7158C623712BC3CD1A76B09
SHA1:40E90FB951DE71DE72EBFBF0B2BFC7984B23FCA6
SHA-256:385152E36E0B50A64A9CEDF429C4FE0CD33A3029E6370759925B46E4330CE28B
SHA-512:F5A69BB387F3F07A39CBF970B9332033AE2D273208EF70016C457FF1E64B1C151415D7150D69D8354ACCC9208E975B24449CCF83A1932114A34C9971F6E6B93D
Malicious:false
Reputation:unknown
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):32768
Entropy (8bit):1.456853896277695
Encrypted:false
SSDEEP:
MD5:E2F3C1A2E03FA33972A9689A811CADD7
SHA1:BB937B16BD1C1425C4CA90A618FDA90588C11A4B
SHA-256:5053A5A5DF7585D4B44DA1D3EF24121927629F2E4BF1FEBB3EA5906AE5243806
SHA-512:31B89892E8727DB4CEA0288E25B90A704AAB09C0AD52783660CC30394E3A5B3BB7F4117D43B8B84F7CEEBEBBF56FC879F4ED79F99D7B4C7D82DE14C4FA301693
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):32768
Entropy (8bit):0.07156909361014326
Encrypted:false
SSDEEP:
MD5:C20051FAD9BF592298D88B23073C7758
SHA1:203F35B2A93DC8E0896D7E65C081AA593D8F5089
SHA-256:8EDE3DA36D4A8A1EEB706EABB21DC8B2DAAB0FC6CF0D74818EBBC8EECA02EE3B
SHA-512:043EE68EF5C36C158E5355BBBABC74AC6AEEBCC68AFEF6E7FEA368C31CD2B7451AF44F8DEFC6445FAFF0D631337F0D319B91AEC4FE8606BB9230B4DB5A18AA88
Malicious:false
Reputation:unknown
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):20480
Entropy (8bit):1.8450605709758332
Encrypted:false
SSDEEP:
MD5:3C00E3104F2C14F48B953DB825835ADC
SHA1:22869A1957060F00226DECCEDB1D4D489B4EBD7D
SHA-256:4F5F9714E0BE81639380FFDB141E3CE9CF0D2944CA73B1BD0C649717FBC94D85
SHA-512:13D6D99416908478B4B020C89D1DDE2DFD49D08DDCDEC8C83131755D8D156246208FB3E365B0C0D418F62CB82E3481EF4F040E6EA96A85792AF5ABF91B8FAA0D
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Windows\System32\msiexec.exe
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Reputation:unknown
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.982918880423008
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.96%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:EasyLogUSB+Installer.exe
File size:19'500'624 bytes
MD5:d3d4273692e34102b88c513ad1c10040
SHA1:1b75e5c2644fbf075040df437b15d4d2c128c2cf
SHA256:cc2652dc33020fab609750a6f627e2f8e6597960b25f210981e62f5ad92f7d70
SHA512:94ea2dedb53887a40b4995536211d94247b3bd9994e0b3888eedffa52a20b4cd500a4da86f110a7a203ba2802b011d29c349774df8d4bea5ea3237f216e1157b
SSDEEP:393216:BhQWQwqV7x2GH3mm+xaYzY4VGHxfwzXUxnIbG1vrMd:Bjqd9WJaYz7GRfwLUxnIbcYd
TLSH:49172323B581903ED5A102328C6FAD7081A97EB35E31465BF698FF1D1DF48827927F1A
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........wn.............................M.......M...7...@a......M.......@a..........!...................................Rich...........
Icon Hash:497971328ce1634d
Entrypoint:0x4575cc
Entrypoint Section:.text
Digitally signed:true
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
DLL Characteristics:NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x57B8A2BE [Sat Aug 20 18:34:38 2016 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:5
OS Version Minor:1
File Version Major:5
File Version Minor:1
Subsystem Version Major:5
Subsystem Version Minor:1
Import Hash:4da036c357ba9b57ad512acda2ab8f70
Signature Valid:true
Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
Signature Validation Error:The operation completed successfully
Error Number:0
Not Before, Not After
  • 25/01/2022 01:00:00 24/01/2023 00:59:59
Subject Chain
  • CN=Lascar Electronics Ltd., O=Lascar Electronics Ltd., L=Salisbury, C=GB
Version:3
Thumbprint MD5:B656567D8713E66AE810DFDEF09BAA4E
Thumbprint SHA-1:E120C7DAC8262B2FC234FFDD7FEF64DB785FF6E4
Thumbprint SHA-256:470E7DEBE4EF2ED0668130574D9D743A3146EC84E67B32537A42A506442399B0
Serial:0129746216985DDDF8A35EE9CD1C24B9
Instruction
call 00007F093D108A82h
jmp 00007F093D0F9D3Eh
push ebp
mov ebp, esp
mov eax, dword ptr [ebp+14h]
push esi
test eax, eax
je 00007F093D0F9F3Eh
cmp dword ptr [ebp+08h], 00000000h
jne 00007F093D0F9F15h
call 00007F093D0F82EEh
push 00000016h
pop esi
mov dword ptr [eax], esi
call 00007F093D0FCA6Eh
mov eax, esi
jmp 00007F093D0F9F27h
cmp dword ptr [ebp+10h], 00000000h
je 00007F093D0F9EE9h
cmp dword ptr [ebp+0Ch], eax
jnc 00007F093D0F9F0Bh
call 00007F093D0F82D0h
push 00000022h
jmp 00007F093D0F9EE2h
push eax
push dword ptr [ebp+10h]
push dword ptr [ebp+08h]
call 00007F093D0F5D7Bh
add esp, 0Ch
xor eax, eax
pop esi
pop ebp
ret
push ebp
mov ebp, esp
xor edx, edx
mov eax, edx
cmp dword ptr [ebp+0Ch], eax
jbe 00007F093D0F9F13h
mov ecx, dword ptr [ebp+08h]
cmp word ptr [ecx], dx
je 00007F093D0F9F0Bh
inc eax
add ecx, 02h
cmp eax, dword ptr [ebp+0Ch]
jc 00007F093D0F9EF4h
pop ebp
ret
test eax, eax
jne 00007F093D0F9F08h
pxor xmm0, xmm0
jmp 00007F093D0F9F13h
movd xmm0, eax
punpcklbw xmm0, xmm0
punpcklwd xmm0, xmm0
pshufd xmm0, xmm0, 00h
push ebx
push ecx
mov ebx, ecx
and ebx, 0Fh
test ebx, ebx
jne 00007F093D0F9F7Ah
mov ebx, edx
and edx, 7Fh
shr ebx, 07h
je 00007F093D0F9F32h
movdqa dqword ptr [ecx], xmm0
movdqa dqword ptr [ecx+10h], xmm0
movdqa dqword ptr [ecx+20h], xmm0
movdqa dqword ptr [ecx+30h], xmm0
movdqa dqword ptr [ecx+40h], xmm0
movdqa dqword ptr [ecx+50h], xmm0
movdqa dqword ptr [ecx+60h], xmm0
Programming Language:
  • [ C ] VS2012 UPD1 build 51106
  • [C++] VS2012 UPD1 build 51106
  • [RES] VS2012 UPD1 build 51106
  • [LNK] VS2012 UPD1 build 51106
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IMPORT0xe963c0xc8.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0xf50000x4cc9c.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x12961300x2d20
IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
IMAGE_DIRECTORY_ENTRY_DEBUG0xb56800x38.rdata
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0xcec400x40.rdata
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0xb50000x584.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xe8cf00xe0.rdata
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000xb31450xb32003c5019b481b36b50861c003b927571feFalse0.4942537508722959data6.587897407968807IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0xb50000x363a20x364009ccda080685d04b6d39abf90df4ddb2eFalse0.4168391777073733data5.111602563063982IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0xec0000x8c380x2800ac1123bbcdd1c65593b571a2c4af0630False0.29013671875data4.4690563880861IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0xf50000x4cc9c0x4ce004266bd2112a8e5f29d2d02ae8b566503False0.33817962398373985data6.561419459411344IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
GIF0xf5dcc0x33a7GIF image data, version 89a, 350 x 6240.9106859260379642
GIF0xf91740x339fGIF image data, version 89a, 350 x 624EnglishUnited States0.9129020052970109
PNG0xfc5140x39edPNG image data, 360 x 150, 8-bit/color RGBA, non-interlaced0.9975723244992919
PNG0xfff040x2fc9PNG image data, 240 x 227, 8-bit/color RGBA, non-interlaced0.9968119022316685
RT_BITMAP0x102ed00x14220Device independent bitmap graphic, 220 x 370 x 8, image size 814000.34390764454792394
RT_BITMAP0x1170f00x1b5cDevice independent bitmap graphic, 180 x 75 x 4, image size 69000.18046830382638493
RT_BITMAP0x118c4c0x38e4Device independent bitmap graphic, 180 x 75 x 8, image size 135000.26689096402087337
RT_BITMAP0x11c5300x1238Device independent bitmap graphic, 60 x 60 x 8, image size 36000.23499142367066894
RT_BITMAP0x11d7680x6588Device independent bitmap graphic, 161 x 152 x 8, image size 24928, resolution 3796 x 3796 px/m, 256 important colors0.3035934133579563
RT_BITMAP0x123cf00x11f88Device independent bitmap graphic, 161 x 152 x 24, image size 73568, resolution 3780 x 3780 px/m0.12790729268557766
RT_ICON0x135c780x468Device independent bitmap graphic, 16 x 32 x 32, image size 10240.21808510638297873
RT_ICON0x1360e00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 40960.099906191369606
RT_ICON0x1371880x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 92160.06109958506224066
RT_ICON0x1397300x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.35618279569892475
RT_ICON0x139a180x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 6400.42473118279569894
RT_DIALOG0x139d000x1cedata0.48917748917748916
RT_DIALOG0x139ed00x266data0.4527687296416938
RT_DIALOG0x13a1380x2b0data0.438953488372093
RT_DIALOG0x13a3e80x54data0.6904761904761905
RT_DIALOG0x13a43c0x34data0.8846153846153846
RT_DIALOG0x13a4700xd6data0.6495327102803738
RT_DIALOG0x13a5480x114data0.5036231884057971
RT_DIALOG0x13a65c0xd6data0.5841121495327103
RT_DIALOG0x13a7340x246data0.4690721649484536
RT_DIALOG0x13a97c0x3c8data0.4194214876033058
RT_DIALOG0x13ad440x14edata0.5359281437125748
RT_DIALOG0x13ae940x1e8data0.49385245901639346
RT_DIALOG0x13b07c0x1c6data0.5286343612334802
RT_DIALOG0x13b2440x1eedata0.49190283400809715
RT_DIALOG0x13b4340x7cdata0.7580645161290323
RT_DIALOG0x13b4b00x3bcdata0.4372384937238494
RT_DIALOG0x13b86c0x158data0.5581395348837209
RT_DIALOG0x13b9c40x1dadata0.5168776371308017
RT_DIALOG0x13bba00x10adata0.6015037593984962
RT_DIALOG0x13bcac0xdedata0.6441441441441441
RT_DIALOG0x13bd8c0x1d4data0.5085470085470085
RT_DIALOG0x13bf600x1dcdata0.5210084033613446
RT_DIALOG0x13c13c0x294data0.48787878787878786
RT_STRING0x13c3d00x160dataEnglishUnited States0.5340909090909091
RT_STRING0x13c5300x23edataEnglishUnited States0.40418118466898956
RT_STRING0x13c7700x378dataEnglishUnited States0.4222972972972973
RT_STRING0x13cae80x252dataEnglishUnited States0.4393939393939394
RT_STRING0x13cd3c0x1f4dataEnglishUnited States0.442
RT_STRING0x13cf300x66adataEnglishUnited States0.3617539585870889
RT_STRING0x13d59c0x366dataEnglishUnited States0.41379310344827586
RT_STRING0x13d9040x27edataEnglishUnited States0.4561128526645768
RT_STRING0x13db840x518dataEnglishUnited States0.39800613496932513
RT_STRING0x13e09c0x882dataEnglishUnited States0.3002754820936639
RT_STRING0x13e9200x23edataEnglishUnited States0.45121951219512196
RT_STRING0x13eb600x3badataEnglishUnited States0.3280922431865828
RT_STRING0x13ef1c0x12cdataEnglishUnited States0.5266666666666666
RT_STRING0x13f0480x4adataEnglishUnited States0.6756756756756757
RT_STRING0x13f0940xdadataEnglishUnited States0.6100917431192661
RT_STRING0x13f1700x110dataEnglishUnited States0.5845588235294118
RT_STRING0x13f2800x20adataEnglishUnited States0.4521072796934866
RT_STRING0x13f48c0xbaMatlab v4 mat-file (little endian) P, numeric, rows 0, columns 0EnglishUnited States0.5860215053763441
RT_STRING0x13f5480xa8dataEnglishUnited States0.6607142857142857
RT_STRING0x13f5f00x12adataEnglishUnited States0.5201342281879194
RT_STRING0x13f71c0x422dataEnglishUnited States0.2741020793950851
RT_STRING0x13fb400x5c2dataEnglishUnited States0.37720488466757124
RT_STRING0x1401040x40dataEnglishUnited States0.671875
RT_STRING0x1401440xcaadataEnglishUnited States0.2313386798272671
RT_STRING0x140df00x284dataEnglishUnited States0.4363354037267081
RT_GROUP_ICON0x1410740x30data0.8125
RT_GROUP_ICON0x1410a40x14data1.25
RT_GROUP_ICON0x1410b80x14data1.2
RT_VERSION0x1410cc0x424data0.4349056603773585
RT_MANIFEST0x1414f00x52aXML 1.0 document, ASCII text, with CRLF line terminators0.46520423600605143
RT_MANIFEST0x141a1c0x280XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.553125
DLLImport
COMCTL32.dll
KERNEL32.dllLoadLibraryW, lstrcmpW, lstrcmpiW, GetSystemDefaultLangID, GetUserDefaultLangID, VerLanguageNameW, CompareFileTime, CreateDirectoryW, FindClose, FindFirstFileW, FindNextFileW, SetFileAttributesW, GetSystemTimeAsFileTime, GetPrivateProfileStringW, MoveFileW, LocalFree, FormatMessageW, GetSystemInfo, MulDiv, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, LoadLibraryExW, GetVersion, GetLocalTime, IsValidLocale, GetCommandLineW, GetFileAttributesW, GlobalAlloc, GlobalFree, FlushFileBuffers, SetEndOfFile, VirtualQuery, lstrcpyA, IsBadReadPtr, GetDiskFreeSpaceExW, GetDriveTypeW, GetExitCodeProcess, GetCurrentThread, GetLocaleInfoW, InterlockedExchange, LoadLibraryExA, DecodePointer, LCMapStringW, RtlUnwind, IsDebuggerPresent, MoveFileExW, WriteProcessMemory, VirtualProtectEx, GetSystemDirectoryW, FreeLibrary, SetThreadContext, GetThreadContext, CreateProcessW, ResumeThread, TerminateProcess, ExitProcess, GetCurrentProcess, Sleep, WaitForSingleObject, DuplicateHandle, RemoveDirectoryW, DeleteFileW, SetCurrentDirectoryW, lstrlenW, lstrcpynA, LocalAlloc, lstrcmpA, SystemTimeToFileTime, ResetEvent, SetEvent, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, GetCurrentDirectoryW, FindResourceExW, GetEnvironmentVariableW, SetFileTime, GetFileTime, OpenProcess, GetProcessTimes, ReadConsoleW, WriteConsoleW, SetStdHandle, SetFilePointerEx, GetConsoleMode, GetConsoleCP, FatalAppExitA, EnumSystemLocalesW, GetUserDefaultLCID, GetTimeFormatW, GetDateFormatW, SetConsoleCtrlHandler, OutputDebugStringW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCurrentProcessId, QueryPerformanceCounter, GetFileType, HeapReAlloc, CreateSemaphoreW, GetStartupInfoW, TlsFree, TlsSetValue, IsProcessorFeaturePresent, CompareStringA, CompareStringW, lstrcatW, GetVersionExW, InterlockedDecrement, InterlockedIncrement, CreateEventW, QueryPerformanceFrequency, GetTempFileNameW, CopyFileW, GetTickCount, GetExitCodeThread, CreateThread, FindResourceW, GlobalUnlock, GlobalLock, SizeofResource, LockResource, LoadResource, lstrcpyW, GetWindowsDirectoryW, SetErrorMode, GetTempPathW, FlushInstructionCache, ExpandEnvironmentStringsW, lstrcpynW, GetModuleFileNameW, GetProcessHeap, HeapFree, HeapAlloc, WriteFile, SetFilePointer, ReadFile, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, CloseHandle, GetFileSize, CreateFileW, SetLastError, GetLastError, LoadLibraryA, GetSystemDirectoryA, GetProcAddress, GetModuleHandleW, TlsGetValue, TlsAlloc, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStringTypeW, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, GetCurrentThreadId, HeapSize, AreFileApisANSI, GetModuleHandleExW, GetStdHandle, EncodePointer
USER32.dllCreateWindowExW, SetTimer, KillTimer, LoadCursorW, RegisterClassW, DefWindowProcW, PostMessageW, DispatchMessageW, TranslateMessage, GetMessageW, PostQuitMessage, GetSysColorBrush, CharPrevW, SendDlgItemMessageW, wvsprintfW, LoadImageW, CreateDialogParamW, MoveWindow, SetCursor, GetWindow, GetDlgItemTextW, SetFocus, EnableWindow, SetForegroundWindow, SetActiveWindow, SetDlgItemTextW, IsDialogMessageW, FindWindowW, SubtractRect, IntersectRect, SetRect, FillRect, GetSysColor, GetWindowRect, GetDC, GetSystemMetrics, GetDlgCtrlID, CreateDialogIndirectParamW, DestroyWindow, IsWindow, SendMessageW, MessageBoxW, CharNextW, WaitForInputIdle, SetWindowLongW, GetWindowLongW, GetClientRect, EndPaint, BeginPaint, ReleaseDC, ExitWindowsEx, CharUpperW, GetWindowDC, SetWindowPos, SetWindowTextW, GetDlgItem, EndDialog, DialogBoxIndirectParamW, ShowWindow, GetDesktopWindow, MsgWaitForMultipleObjects, PeekMessageW, wsprintfW, LoadIconW
GDI32.dllUnrealizeObject, CreateHalftonePalette, GetDIBColorTable, SelectPalette, RealizePalette, GetSystemPaletteEntries, CreatePalette, CreateFontW, GetObjectW, SetTextColor, SetBkMode, GetDeviceCaps, CreateSolidBrush, CreateFontIndirectW, SetStretchBltMode, StretchBlt, SelectObject, DeleteDC, CreateDIBitmap, CreateCompatibleDC, BitBlt, DeleteObject, GetStockObject, TranslateCharsetInfo
ADVAPI32.dllCryptCreateHash, CryptSignHashW, GetTokenInformation, FreeSid, EqualSid, AllocateAndInitializeSid, OpenThreadToken, OpenProcessToken, SetEntriesInAclW, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, CreateWellKnownSid, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteKeyW, RegSetValueExW, RegEnumValueW, RegCreateKeyExW, RegDeleteValueW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, AdjustTokenPrivileges, LookupPrivilegeValueW, RegOverridePredefKey, RegCreateKeyW, RegEnumKeyW, RegOpenKeyW, CryptAcquireContextW, CryptReleaseContext, CryptDeriveKey, CryptDestroyKey, CryptSetHashParam, CryptGetHashParam, CryptExportKey, CryptImportKey, CryptDestroyHash, CryptHashData, CryptVerifySignatureW
SHELL32.dllSHGetMalloc, SHGetFolderPathW, SHBrowseForFolderW, ShellExecuteW, CommandLineToArgvW, SHGetSpecialFolderLocation, ShellExecuteExW, SHGetPathFromIDListW
ole32.dllCoCreateInstance, StringFromGUID2, CoCreateGuid, CreateItemMoniker, GetRunningObjectTable, CLSIDFromProgID, CoTaskMemAlloc, CoTaskMemRealloc, ProgIDFromCLSID, CoTaskMemFree, CoUninitialize, CoInitializeSecurity, CoInitialize
OLEAUT32.dllRegisterTypeLib, UnRegisterTypeLib, SetErrorInfo, LoadTypeLib, CreateErrorInfo, SysAllocStringLen, SysFreeString, SysReAllocStringLen, SysStringLen, SysAllocString, SysStringByteLen, SysAllocStringByteLen, VarBstrCat, VarBstrFromDate, VariantClear, VariantChangeType, GetErrorInfo, VarUI4FromStr, SystemTimeToVariantTime
RPCRT4.dllRpcStringFreeW, UuidCreate, UuidToStringW, UuidFromStringW
Language of compilation systemCountry where language is spokenMap
EnglishUnited States