Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://crl.globalsign.com/ca/gstsacasha384g4.crl0 |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0 |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://crl.globalsign.com/root-r6.crl0G |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://ocsp.globalsign.com/ca/gstsacasha384g40C |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://ocsp2.globalsign.com/rootr606 |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0? |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: http://secure.globalsign.com/cacert/gstsacasha384g4.crt0 |
Source: TreeSizeFreeSetup.exe, 00000000.00000002.2445856607.0000000002865000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.exe, 00000000.00000003.1174941114.0000000002650000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003692000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2446477363.0000000003820000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: http://www.dk-soft.org/ |
Source: TreeSizeFreeSetup.exe, 00000000.00000002.2443195048.0000000002347000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.exe, 00000000.00000003.1174941114.0000000002650000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.000000000259E000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://customers.jam-software.de/survey.php |
Source: TreeSizeFreeSetup.exe, 00000000.00000002.2443195048.0000000002347000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.exe, 00000000.00000003.1174941114.0000000002650000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.000000000259E000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://jam-software.upvoty.com/TreeSize |
Source: TreeSizeFreeSetup.exe | String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: https://www.globalsign.com/repository/0 |
Source: TreeSizeFreeSetup.exe, 00000000.00000003.1176516486.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.exe, 00000000.00000003.1176145422.00000000029A0000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000000.1177818704.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: https://www.innosetup.com/ |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003620000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003692000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2447941370.0000000003A4C000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.com/TreeSize/editions.shtml |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003692000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.com/TreeSize/editions.shtml0ExplorerContextMenuItems |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003620000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2447941370.0000000003A4C000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.com/TreeSize/surumler.shtml |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003620000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.00000000025FD000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.com/company/help-us-translate.shtml?language=EN |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003692000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.00000000025F4000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.com/company/privacy.shtml |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003620000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.000000000263F000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.com/treesize/ |
Source: TreeSizeFreeSetup.exe, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: https://www.jam-software.com0 |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003692000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.de/TreeSize/editions.shtml |
Source: TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.0000000002540000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.de/TreeSize/editions.shtmlPqY |
Source: TreeSizeFreeSetup.tmp, 00000001.00000002.2447941370.0000000003A33000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003692000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.de/company/privacy.shtml |
Source: TreeSizeFreeSetup.exe, 00000000.00000002.2443195048.0000000002347000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.exe, 00000000.00000003.1174941114.0000000002650000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.000000000259E000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.de/freeware/?language= |
Source: TreeSizeFreeSetup.tmp, 00000001.00000003.1179395905.0000000003620000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000002.2444046973.000000000263F000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://www.jam-software.de/treesize/ |
Source: TreeSizeFreeSetup.exe, 00000000.00000003.1176516486.000000007FB50000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.exe, 00000000.00000003.1176145422.00000000029A0000.00000004.00001000.00020000.00000000.sdmp, TreeSizeFreeSetup.tmp, 00000001.00000000.1177818704.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TreeSizeFreeSetup.tmp.0.dr | String found in binary or memory: https://www.remobjects.com/ps |
Source: TreeSizeFreeSetup.exe, 00000000.00000002.2443195048.0000000002378000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFilenamekernel32j% vs TreeSizeFreeSetup.exe |
Source: TreeSizeFreeSetup.exe, 00000000.00000003.1176516486.000000007FB50000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFileName vs TreeSizeFreeSetup.exe |
Source: TreeSizeFreeSetup.exe, 00000000.00000000.1174462731.00000000004C6000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFileName vs TreeSizeFreeSetup.exe |
Source: TreeSizeFreeSetup.exe, 00000000.00000003.1176145422.00000000029A0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFileName vs TreeSizeFreeSetup.exe |
Source: TreeSizeFreeSetup.exe | Binary or memory string: OriginalFileName vs TreeSizeFreeSetup.exe |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: unknown | Process created: C:\Users\user\Desktop\TreeSizeFreeSetup.exe "C:\Users\user\Desktop\TreeSizeFreeSetup.exe" | |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Process created: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp "C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp" /SL5="$402BC,12766924,857088,C:\Users\user\Desktop\TreeSizeFreeSetup.exe" | |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Process created: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp "C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp" /SL5="$402BC,12766924,857088,C:\Users\user\Desktop\TreeSizeFreeSetup.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: mscms.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: userenv.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: coloradapterclient.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Section loaded: dwmapi.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TreeSizeFreeSetup.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-B6GD7.tmp\TreeSizeFreeSetup.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |