Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
RadProCalculator3.26_64BSetup.exe

Overview

General Information

Sample name:RadProCalculator3.26_64BSetup.exe
Analysis ID:1524334
MD5:db2df493ed3ef51a0731e67c41c81eb1
SHA1:483f3fdba4fd84b2739a19f90a17d9c08f0559eb
SHA256:4b526c198671dbe6351021935b780a9ce582a891b1ca0eddc1b170fa762b8661
Infos:

Detection

Score:12
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

Found potential equation exploit (CVE-2017-11882)
Creates a DirectInput object (often for capturing keystrokes)
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Sigma detected: Use NTFS Short Name in Command Line
Uses 32bit PE files

Classification

  • System is w10x64
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
    SourceRuleDescriptionAuthorStrings
    00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmpJoeSecurity_DelphiSystemParamCountDetected Delphi use of System.ParamCount()Joe Security
      Source: Process startedAuthor: frack113, Nasreddine Bencherchali (Nextron Systems): Data: Command: .\RadProCalculator3.26_64BSetup.exe /m="C:\Users\user\Desktop\RADPRO~1.EXE" /k="", CommandLine: .\RadProCalculator3.26_64BSetup.exe /m="C:\Users\user\Desktop\RADPRO~1.EXE" /k="", CommandLine|base64offset|contains: , Image: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe, NewProcessName: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe, OriginalFileName: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe, ParentCommandLine: "C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe", ParentImage: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe, ParentProcessId: 3984, ParentProcessName: RadProCalculator3.26_64BSetup.exe, ProcessCommandLine: .\RadProCalculator3.26_64BSetup.exe /m="C:\Users\user\Desktop\RADPRO~1.EXE" /k="", ProcessId: 4872, ProcessName: RadProCalculator3.26_64BSetup.exe
      No Suricata rule has matched

      Click to jump to signature section

      Show All Signature Results

      Exploits

      barindex
      Source: Static RTF information: Object: 0 Offset: 000016F2h
      Source: Static RTF information: Object: 1 Offset: 00004C0Ah
      Source: Static RTF information: Object: 2 Offset: 0000811Dh
      Source: RadProCalculator3.26_64BSetup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\D1E532D5\242A76C8\RadPro License.rtfJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia1\license.rtfJump to behavior
      Source: Binary string: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\1E27FC18\242A76C8\adProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3432860988.000000000075C000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198152344.0000000000756000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\USERS\RAY\DOCUMENTS\VISUAL STUDIO 2008\PROJECTS\RADPROCALCULATOR64BIT\BIN\RADPROCALCULATOR.PDB source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp
      Source: Binary string: gacutil.pdb, AH/@ source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209757364.000000000060C000.00000002.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: 242A76C8\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.00000000024CC000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, mia.tmp.2.dr, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: gacutil.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209757364.000000000060C000.00000002.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: aC:\Users\Ray\Documents\Visual Studio 2008\Projects\RadProCalculator64Bit\bin\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp
      Source: Binary string: u/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2208829416.00000000009AB000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3433082676.00000000009AF000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2208941075.00000000009AD000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\1E27FC18\42A76C8\adProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3432860988.000000000075C000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198152344.0000000000756000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: MicrosoftWindowsGdiPlus-1.0.2600.1355-gdiplus.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003CC1000.00000004.00000020.00020000.00000000.sdmp, gdiplus.dll.0.dr
      Source: Binary string: data/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdbvD source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2208740632.00000000009AB000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198233127.00000000009AB000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2207629927.00000000009AB000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Users\Ray\Documents\Visual Studio 2008\Projects\RadProCalculator64Bit\bin\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp, mia.tmp.2.dr, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: aC:\USERS\RAY\DOCUMENTS\VISUAL STUDIO 2008\PROJECTS\RADPROCALCULATOR64BIT\BIN\RADPROCALCULATOR.PDB source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp
      Source: Binary string: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\884935FF\42A76C8\RadProCalculator.pdbll source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3432860988.000000000075C000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198152344.0000000000756000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Users\Ray\Documents\Visual Studio 2008\Projects\RadProCalculator64Bit\obj\Debug\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator.exe.0.dr
      Source: Binary string: data/RadProCalculator3.26_64BSetup.msiRadProCalculator3.26_64BSetup.msisetup.bmpdata/OFFLINE/5779DC17/242A76C8/RadProCalculator.exe.manifestdata/OFFLINE/9DCC724B/242A76C8/RadProCalculator.xmldata/OFFLINE/2635807C/242A76C8/Rad Pro Settings-DONT DELETE.txtdata/OFFLINE/ABF56A8A/C6DB425E/Rad Pro Settings-DONT DELETE.txtdata/OFFLINE/4D693B19/242A76C8/Settings.txtdata/OFFLINE/1E89F593/242A76C8/file.docdata/OFFLINE/B2FB7337/242A76C8/ShieldingandBuildup.docdata/OFFLINE/DA2F022C/242A76C8/Contact Rad Pro Calculator.rtfdata/OFFLINE/6E19DDB9/242A76C8/Notice of Disclaimer Rad Pro Calculator.rtfdata/OFFLINE/884935FF/242A76C8/Rad Pro Calculator References.rtfdata/OFFLINE/D1E532D5/242A76C8/RadPro License.rtfdata/OFFLINE/353EFE74/242A76C8/Uranium.rtfdata/OFFLINE/EF8B86D1/242A76C8/Help for Rad Pro Calculator.pdfdata/OFFLINE/1C1753FF/242A76C8/Rad Pro Calculator References.pdfdata/OFFLINE/1E27FC18/242A76C8/ShieldingandBuildup.pdfdata/OFFLINE/764C6FA8/242A76C8/RadProCalculator.exeRadProCalculator3.26_64BSetup.exedata/OFFLINE/28D15CAF/242A76C8/AxInterop.ComCtl2.dlldata/OFFLINE/F699690B/242A76C8/AxInterop.ComctlLib.dlldata/gdiplus.dlldata/OFFLINE/F10E7C53/242A76C8/Interop.ComCtl2.dlldata/OFFLINE/DEFF21C9/242A76C8/Interop.ComctlLib.dlldata/OFFLINE/F3319620/242A76C8/Interop.Microsoft.Office.Core.dlldata/OFFLINE/9B25A4E7/242A76C8/Interop.Microsoft.Office.Interop.Excel.dlldata/OFFLINE/489D2344/242A76C8/Interop.VBIDE.dlldata/mMSI.dll/mMSIExec.dllmia.libdata/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdbdata/OFFLINE/A6542D7A/242A76C8/RadProCalculator.applicationRadProCalculator3.26_64BSetup.resdata/{0AD26D48-644B-4268-AAB1-C0C6839EEBCB}data/OFFLINE/F699690B/242A76C8data/OFFLINE/F699690Bdata/OFFLINE/F3319620/242A76C8data/OFFLINE/F3319620data/OFFLINE/F10E7C53/242A76C8data/OFFLINE/F10E7C53data/OFFLINE/EF8B86D1/242A76C8data/OFFLINE/EF8B86D1data/OFFLINE/DEFF21C9/242A76C8data/OFFLINE/DEFF21C9data/OFFLINE/DA2F022C/242A76C8data/OFFLINE/DA2F022Cdata/OFFLINE/D1E532D5/242A76C8data/OFFLINE/D1E532D5data/OFFLINE/B2FB7337/242A76C8data/OFFLINE/B2FB7337data/OFFLINE/B00CA824/242A76C8data/OFFLINE/B00CA824data/OFFLINE/ABF56A8A/C6DB425Edata/OFFLINE/ABF56A8Adata/OFFLINE/A6542D7A/242A76C8data/OFFLINE/A6542D7Adata/OFFLINE/9DCC724B/242A76C8data/OFFLINE/9DCC724Bdata/OFFLINE/9B25A4E7/242A76C8data/OFFLINE/9B25A4E7data/OFFLINE/884935FF/242A76C8data/OFFLINE/884935FFdata/OFFLINE/764C6FA8/242A76C8data/OFFLINE/764C6FA8data/OFFLINE/6E19DDB9/242A76C8data/OFFLINE/6E19DDB9data/OFFLINE/5779DC17/242A76C8data/OFFLINE/5779DC17data/OFFLINE/4D693B19/242A76C8data/OFFLINE/4D693B19data/OFFLINE/489D2344/242A76C8data/OFFLINE/489D2344data/OFFLINE/353EFE74/242A76C8data/OFFLINE/353EFE74data/OFFLINE/28D15CAF/242A76C8data/OFFLINE/28D15CAFdata/OFFLINE/2635807C/242A76C8data/OFFLINE/2635807Cdata/OFFLINE/1E89F593/242A76C8data/OFFLINE/1E89F593data/OFFLINE/1E27FC18/242A76C8data/OFFLINE/1E27FC18data/OFFLINE/1C1753FF/242A76C8data/OFFLINE/1C1753FFdata/OFFLINEdata/mMSI.dll source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.218
      Source: Binary string: op.Excel.dlldata/OFFLINE/489D2344/242A76C8/Interop.VBIDE.dlldata/mMSI.dll/mMSIExec.dllmia.libdata/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdbdata/OFFLINE/A6542D7A/242A76C8/RadProCalcul source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3433056568.00000000009A0000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Documents and Settings\K-ballo\Mis documentos\Visual Studio 2008\Projects\ahadmin_wrapper\ReleaseDLL\ahadmin_wrapper.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209757364.000000000060C000.00000002.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppDataJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.iniJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\userJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
      Source: ShieldingandBuildup.doc.0.drString found in binary or memory: http://hps.org/publicinformation/ate/faqs/gammaandexposure.html
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.pdf.0.dr, Rad Pro Calculator References.pdf.0.dr, Help for Rad Pro Calculator.pdf.0.drString found in binary or memory: http://hps.org/publicinformation/ate/faqs/gammaandexposure.html)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.doc.0.drString found in binary or memory: http://hps.org/publicinformation/ate/faqs/gammaandexposure.htmlyX
      Source: Rad Pro Calculator References.rtf.0.drString found in binary or memory: http://ie.lbl.gov/toi.html
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Rad Pro Calculator References.pdf.0.drString found in binary or memory: http://ie.lbl.gov/toi.html)/S/URI
      Source: ShieldingandBuildup.doc.0.drString found in binary or memory: http://physics.nist.gov/PhysRefData/XrayMassCoef/tab3.html
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.pdf.0.drString found in binary or memory: http://physics.nist.gov/PhysRefData/XrayMassCoef/tab3.html)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.doc.0.drString found in binary or memory: http://physics.nist.gov/PhysRefData/XrayMassCoef/tab3.htmla
      Source: ShieldingandBuildup.doc.0.drString found in binary or memory: http://physics.nist.gov/PhysRefData/XrayMassCoef/tab4.html
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.pdf.0.drString found in binary or memory: http://physics.nist.gov/PhysRefData/XrayMassCoef/tab4.html)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Rad Pro Calculator References.rtf.0.drString found in binary or memory: http://physics.nist.gov/xaamdi
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.drString found in binary or memory: http://www.InstallAware.com/
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.drString found in binary or memory: http://www.InstallAware.com/open
      Source: ShieldingandBuildup.doc.0.drString found in binary or memory: http://www.ans.org/store/vi-240180
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.pdf.0.drString found in binary or memory: http://www.ans.org/store/vi-240180)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drString found in binary or memory: http://www.epa.gov/radiation/marssim/docs/revision1_August_2002corrections/chapter6.pdf)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drString found in binary or memory: http://www.epa.gov/radiation/marssim/obtain.html)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe.0.drString found in binary or memory: http://www.installaware.com/
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.drString found in binary or memory: http://www.installaware.com/InstallAware
      Source: RadProCalculator3.26_64BSetup.exe, RadProCalculator3.26_64BSetup.exe.0.drString found in binary or memory: http://www.installaware.comz
      Source: Rad Pro Calculator References.rtf.0.drString found in binary or memory: http://www.pacificrad.com/pages/publications.html
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Rad Pro Calculator References.pdf.0.drString found in binary or memory: http://www.pacificrad.com/pages/publications.html)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drString found in binary or memory: http://www.radiationsoftware.com/mshield.html)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.00000000024CC000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, mia.tmp.2.dr, RadProCalculator3.26_64BSetup.exe.0.drString found in binary or memory: http://www.radprocalculator.com/
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drString found in binary or memory: http://www.radprocalculator.com/Request.aspx)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator.exe.0.drString found in binary or memory: http://www.radprocalculator.com/Request.aspxGmailto:support
      Source: Contact Rad Pro Calculator.rtf.0.drString found in binary or memory: http://www.radprocalculator.com/request.aspx
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drString found in binary or memory: http://www.wmginc.com/Software/MegaShield/megashield.htm)/S/URI
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003CC1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: DirectDrawCreateExmemstr_68406ce3-7
      Source: RadProCalculator3.26_64BSetup.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
      Source: RadProCalculator3.26_64BSetup.exe.0.drStatic PE information: Resource name: RT_RCDATA type: PE32 executable (console) Intel 80386, for MS Windows
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003E6C000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameInterop.Microsoft.Office.Core.dll|. vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003E38000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameInterop.ComctlLib.dll vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003EA1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameInterop.Microsoft.Office.Interop.Excel.dll|- vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003EA1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameInterop.VBIDE.dll|- vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003EA1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename7z.exe, vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003CA7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameAxInterop.ComctlLib.dll4 vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameRadProCalculator.exeP vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamegacutil.exeT vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameAxInterop.ComCtl2.dll4 vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003CC1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamegdiplusj% vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003CC1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameInterop.ComCtl2.dll vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3434996427.0000000010069000.00000002.00000001.01000000.00000005.sdmpBinary or memory string: OriginalFilename7z.exe, vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenamegacutil.exeT vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2214055378.000000007FDC0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilename7z.exe, vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209757364.000000000060C000.00000002.00000001.01000000.00000004.sdmpBinary or memory string: OriginalFilenamegacutil.exeT vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exe.0.drBinary or memory string: OriginalFilenamegacutil.exeT vs RadProCalculator3.26_64BSetup.exe
      Source: RadProCalculator3.26_64BSetup.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003EA1000.00000004.00000020.00020000.00000000.sdmp, Interop.VBIDE.dll.0.drBinary or memory string: VBIDE.VBProjectClass)
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003EA1000.00000004.00000020.00020000.00000000.sdmp, Interop.VBIDE.dll.0.drBinary or memory string: VBIDE.VBProjectsClass)
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003EA1000.00000004.00000020.00020000.00000000.sdmp, Interop.VBIDE.dll.0.drBinary or memory string: VBIDE.VBProjectClass
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003EA1000.00000004.00000020.00020000.00000000.sdmp, Interop.VBIDE.dll.0.drBinary or memory string: VBIDE.VBProjectsClass
      Source: classification engineClassification label: clean12.expl.winEXE@3/73@0/0
      Source: ShieldingandBuildup.pdf.0.drInitial sample: http://physics.nist.gov/physrefdata/xraymasscoef/tab3.html
      Source: ShieldingandBuildup.pdf.0.drInitial sample: http://physics.nist.gov/PhysRefData/XrayMassCoef/tab3.html
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.radprocalculator.com/Request.aspx
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.epa.gov/radiation/marssim/docs/revision1_August_2002corrections/chapter6.pdf
      Source: ShieldingandBuildup.pdf.0.drInitial sample: http://hps.org/publicinformation/ate/faqs/gammaandexposure.html
      Source: ShieldingandBuildup.pdf.0.drInitial sample: http://physics.nist.gov/PhysRefData/XrayMassCoef/tab4.html
      Source: ShieldingandBuildup.pdf.0.drInitial sample: http://physics.nist.gov/physrefdata/xraymasscoef/tab4.html
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.radiationsoftware.com/mshield.html
      Source: Rad Pro Calculator References.pdf.0.drInitial sample: http://www.pacificrad.com/pages/publications.html
      Source: Rad Pro Calculator References.pdf.0.drInitial sample: http://ie.lbl.gov/toi.html
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.wmginc.com/Software/MegaShield/megashield.htm
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.wmginc.com/software/megashield/megashield.htm
      Source: ShieldingandBuildup.pdf.0.drInitial sample: http://www.ans.org/store/vi-240180
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.epa.gov/radiation/marssim/obtain.html
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.epa.gov/radiation/marssim/docs/revision1_august_2002corrections/chapter6.pdf
      Source: Help for Rad Pro Calculator.pdf.0.drInitial sample: http://www.radprocalculator.com/request.aspx
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\PackageAwareJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmpJump to behavior
      Source: Yara matchFile source: 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, type: MEMORY
      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe, type: DROPPED
      Source: RadProCalculator3.26_64BSetup.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile read: C:\Users\desktop.iniJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile read: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeJump to behavior
      Source: unknownProcess created: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe "C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe"
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe .\RadProCalculator3.26_64BSetup.exe /m="C:\Users\user\Desktop\RADPRO~1.EXE" /k=""
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeProcess created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe .\RadProCalculator3.26_64BSetup.exe /m="C:\Users\user\Desktop\RADPRO~1.EXE" /k=""Jump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: explorerframe.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: textinputframework.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeSection loaded: textshaping.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: apphelp.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: version.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: mpr.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: winmm.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: uxtheme.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: olepro32.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: kernel.appcore.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: windows.storage.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: wldp.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: propsys.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: profapi.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: dwmapi.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: textshaping.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: textinputframework.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: coreuicomponents.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: ntmarta.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: coremessaging.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: wintypes.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: msi.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: explorerframe.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: riched32.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: riched20.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: usp10.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: msls31.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: dataexchange.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: d3d11.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: dcomp.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: dxgi.dllJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeSection loaded: twinapi.appcore.dllJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32Jump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeWindow found: window name: TButtonJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeAutomated click: Next >
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeAutomated click: I accept the license agreement
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeAutomated click: Next >
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Windows\SysWOW64\RICHED32.DLLJump to behavior
      Source: Window RecorderWindow detected: More than 3 window changes detected
      Source: RadProCalculator3.26_64BSetup.exeStatic file information: File size 3493085 > 1048576
      Source: Binary string: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\1E27FC18\242A76C8\adProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3432860988.000000000075C000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198152344.0000000000756000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\USERS\RAY\DOCUMENTS\VISUAL STUDIO 2008\PROJECTS\RADPROCALCULATOR64BIT\BIN\RADPROCALCULATOR.PDB source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp
      Source: Binary string: gacutil.pdb, AH/@ source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209757364.000000000060C000.00000002.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: 242A76C8\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.00000000024CC000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, mia.tmp.2.dr, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: gacutil.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209757364.000000000060C000.00000002.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: aC:\Users\Ray\Documents\Visual Studio 2008\Projects\RadProCalculator64Bit\bin\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp
      Source: Binary string: u/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2208829416.00000000009AB000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3433082676.00000000009AF000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2208941075.00000000009AD000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\1E27FC18\42A76C8\adProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3432860988.000000000075C000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198152344.0000000000756000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: MicrosoftWindowsGdiPlus-1.0.2600.1355-gdiplus.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003CC1000.00000004.00000020.00020000.00000000.sdmp, gdiplus.dll.0.dr
      Source: Binary string: data/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdbvD source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2208740632.00000000009AB000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198233127.00000000009AB000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2207629927.00000000009AB000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Users\Ray\Documents\Visual Studio 2008\Projects\RadProCalculator64Bit\bin\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp, mia.tmp.2.dr, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: Binary string: aC:\USERS\RAY\DOCUMENTS\VISUAL STUDIO 2008\PROJECTS\RADPROCALCULATOR64BIT\BIN\RADPROCALCULATOR.PDB source: RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.0000000002458000.00000004.00001000.00020000.00000000.sdmp
      Source: Binary string: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\884935FF\42A76C8\RadProCalculator.pdbll source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3432860988.000000000075C000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198152344.0000000000756000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Users\Ray\Documents\Visual Studio 2008\Projects\RadProCalculator64Bit\obj\Debug\RadProCalculator.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator.exe.0.dr
      Source: Binary string: data/RadProCalculator3.26_64BSetup.msiRadProCalculator3.26_64BSetup.msisetup.bmpdata/OFFLINE/5779DC17/242A76C8/RadProCalculator.exe.manifestdata/OFFLINE/9DCC724B/242A76C8/RadProCalculator.xmldata/OFFLINE/2635807C/242A76C8/Rad Pro Settings-DONT DELETE.txtdata/OFFLINE/ABF56A8A/C6DB425E/Rad Pro Settings-DONT DELETE.txtdata/OFFLINE/4D693B19/242A76C8/Settings.txtdata/OFFLINE/1E89F593/242A76C8/file.docdata/OFFLINE/B2FB7337/242A76C8/ShieldingandBuildup.docdata/OFFLINE/DA2F022C/242A76C8/Contact Rad Pro Calculator.rtfdata/OFFLINE/6E19DDB9/242A76C8/Notice of Disclaimer Rad Pro Calculator.rtfdata/OFFLINE/884935FF/242A76C8/Rad Pro Calculator References.rtfdata/OFFLINE/D1E532D5/242A76C8/RadPro License.rtfdata/OFFLINE/353EFE74/242A76C8/Uranium.rtfdata/OFFLINE/EF8B86D1/242A76C8/Help for Rad Pro Calculator.pdfdata/OFFLINE/1C1753FF/242A76C8/Rad Pro Calculator References.pdfdata/OFFLINE/1E27FC18/242A76C8/ShieldingandBuildup.pdfdata/OFFLINE/764C6FA8/242A76C8/RadProCalculator.exeRadProCalculator3.26_64BSetup.exedata/OFFLINE/28D15CAF/242A76C8/AxInterop.ComCtl2.dlldata/OFFLINE/F699690B/242A76C8/AxInterop.ComctlLib.dlldata/gdiplus.dlldata/OFFLINE/F10E7C53/242A76C8/Interop.ComCtl2.dlldata/OFFLINE/DEFF21C9/242A76C8/Interop.ComctlLib.dlldata/OFFLINE/F3319620/242A76C8/Interop.Microsoft.Office.Core.dlldata/OFFLINE/9B25A4E7/242A76C8/Interop.Microsoft.Office.Interop.Excel.dlldata/OFFLINE/489D2344/242A76C8/Interop.VBIDE.dlldata/mMSI.dll/mMSIExec.dllmia.libdata/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdbdata/OFFLINE/A6542D7A/242A76C8/RadProCalculator.applicationRadProCalculator3.26_64BSetup.resdata/{0AD26D48-644B-4268-AAB1-C0C6839EEBCB}data/OFFLINE/F699690B/242A76C8data/OFFLINE/F699690Bdata/OFFLINE/F3319620/242A76C8data/OFFLINE/F3319620data/OFFLINE/F10E7C53/242A76C8data/OFFLINE/F10E7C53data/OFFLINE/EF8B86D1/242A76C8data/OFFLINE/EF8B86D1data/OFFLINE/DEFF21C9/242A76C8data/OFFLINE/DEFF21C9data/OFFLINE/DA2F022C/242A76C8data/OFFLINE/DA2F022Cdata/OFFLINE/D1E532D5/242A76C8data/OFFLINE/D1E532D5data/OFFLINE/B2FB7337/242A76C8data/OFFLINE/B2FB7337data/OFFLINE/B00CA824/242A76C8data/OFFLINE/B00CA824data/OFFLINE/ABF56A8A/C6DB425Edata/OFFLINE/ABF56A8Adata/OFFLINE/A6542D7A/242A76C8data/OFFLINE/A6542D7Adata/OFFLINE/9DCC724B/242A76C8data/OFFLINE/9DCC724Bdata/OFFLINE/9B25A4E7/242A76C8data/OFFLINE/9B25A4E7data/OFFLINE/884935FF/242A76C8data/OFFLINE/884935FFdata/OFFLINE/764C6FA8/242A76C8data/OFFLINE/764C6FA8data/OFFLINE/6E19DDB9/242A76C8data/OFFLINE/6E19DDB9data/OFFLINE/5779DC17/242A76C8data/OFFLINE/5779DC17data/OFFLINE/4D693B19/242A76C8data/OFFLINE/4D693B19data/OFFLINE/489D2344/242A76C8data/OFFLINE/489D2344data/OFFLINE/353EFE74/242A76C8data/OFFLINE/353EFE74data/OFFLINE/28D15CAF/242A76C8data/OFFLINE/28D15CAFdata/OFFLINE/2635807C/242A76C8data/OFFLINE/2635807Cdata/OFFLINE/1E89F593/242A76C8data/OFFLINE/1E89F593data/OFFLINE/1E27FC18/242A76C8data/OFFLINE/1E27FC18data/OFFLINE/1C1753FF/242A76C8data/OFFLINE/1C1753FFdata/OFFLINEdata/mMSI.dll source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.218
      Source: Binary string: op.Excel.dlldata/OFFLINE/489D2344/242A76C8/Interop.VBIDE.dlldata/mMSI.dll/mMSIExec.dllmia.libdata/OFFLINE/B00CA824/242A76C8/RadProCalculator.pdbdata/OFFLINE/A6542D7A/242A76C8/RadProCalcul source: RadProCalculator3.26_64BSetup.exe, 00000000.00000002.3433056568.00000000009A0000.00000004.00000020.00020000.00000000.sdmp
      Source: Binary string: C:\Documents and Settings\K-ballo\Mis documentos\Visual Studio 2008\Projects\ahadmin_wrapper\ReleaseDLL\ahadmin_wrapper.pdb source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209757364.000000000060C000.00000002.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.dr
      Source: RadProCalculator3.26_64BSetup.exe.0.drStatic PE information: real checksum: 0x0 should be: 0x299dfc
      Source: AxInterop.ComctlLib.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x23494
      Source: RadProCalculator3.26_64BSetup.exeStatic PE information: real checksum: 0x2df62 should be: 0x35d76e
      Source: RadProCalculator.exe.0.drStatic PE information: real checksum: 0x0 should be: 0x176d87
      Source: Interop.Microsoft.Office.Core.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x42fac
      Source: AxInterop.ComCtl2.dll.0.drStatic PE information: real checksum: 0x0 should be: 0xd5a5
      Source: Interop.Microsoft.Office.Interop.Excel.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x13827f
      Source: Interop.ComctlLib.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x42505
      Source: Interop.ComCtl2.dll.0.drStatic PE information: real checksum: 0x0 should be: 0xe761
      Source: gdiplus.dll.0.drStatic PE information: section name: Shared
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\764C6FA8\242A76C8\RadProCalculator.exeJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\mMSI.dll\mMSIExec.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F3319620\242A76C8\Interop.Microsoft.Office.Core.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\28D15CAF\242A76C8\AxInterop.ComCtl2.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F10E7C53\242A76C8\Interop.ComCtl2.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\DEFF21C9\242A76C8\Interop.ComctlLib.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\gdiplus.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F699690B\242A76C8\AxInterop.ComctlLib.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\9B25A4E7\242A76C8\Interop.Microsoft.Office.Interop.Excel.dllJump to dropped file
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia1\mMSIExec.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\489D2344\242A76C8\Interop.VBIDE.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\mia.libJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\mia.libJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\D1E532D5\242A76C8\RadPro License.rtfJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile created: C:\Users\user\AppData\Local\Temp\mia1\license.rtfJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\764C6FA8\242A76C8\RadProCalculator.exeJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\mMSI.dll\mMSIExec.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F3319620\242A76C8\Interop.Microsoft.Office.Core.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\28D15CAF\242A76C8\AxInterop.ComCtl2.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F10E7C53\242A76C8\Interop.ComCtl2.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\DEFF21C9\242A76C8\Interop.ComctlLib.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\gdiplus.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F699690B\242A76C8\AxInterop.ComctlLib.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\9B25A4E7\242A76C8\Interop.Microsoft.Office.Interop.Excel.dllJump to dropped file
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia1\mMSIExec.dllJump to dropped file
      Source: C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\489D2344\242A76C8\Interop.VBIDE.dllJump to dropped file
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppDataJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.iniJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\userJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\Roaming\Microsoft\WindowsJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\RoamingJump to behavior
      Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exeFile opened: C:\Users\user\AppData\Roaming\MicrosoftJump to behavior
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmpBinary or memory string: Shell_TrayWnd
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmpBinary or memory string: Progman
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmpBinary or memory string: Progmanadvapi32.dllCreateProcessWithTokenW
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmpBinary or memory string: ProgmanU
      Source: RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmpBinary or memory string: Shell_TrayWndU
      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
      Gather Victim Identity InformationAcquire Infrastructure1
      Spearphishing Link
      1
      Exploitation for Client Execution
      1
      DLL Side-Loading
      2
      Process Injection
      11
      Masquerading
      1
      Input Capture
      1
      Process Discovery
      Remote Services1
      Input Capture
      Data ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
      CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
      DLL Side-Loading
      2
      Process Injection
      LSASS Memory2
      File and Directory Discovery
      Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
      DLL Side-Loading
      Security Account Manager1
      System Information Discovery
      SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
      Hide Legend

      Legend:

      • Process
      • Signature
      • Created File
      • DNS/IP Info
      • Is Dropped
      • Is Windows Process
      • Number of created Registry Values
      • Number of created Files
      • Visual Basic
      • Delphi
      • Java
      • .Net C# or VB.NET
      • C, C++ or other language
      • Is malicious
      • Internet

      This section contains all screenshots as thumbnails, including those not shown in the slideshow.


      windows-stand
      SourceDetectionScannerLabelLink
      RadProCalculator3.26_64BSetup.exe7%ReversingLabs
      SourceDetectionScannerLabelLink
      C:\Users\user\AppData\Local\Temp\mia1\mMSIExec.dll7%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe7%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\28D15CAF\242A76C8\AxInterop.ComCtl2.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\489D2344\242A76C8\Interop.VBIDE.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\764C6FA8\242A76C8\RadProCalculator.exe0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\9B25A4E7\242A76C8\Interop.Microsoft.Office.Interop.Excel.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\DEFF21C9\242A76C8\Interop.ComctlLib.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F10E7C53\242A76C8\Interop.ComCtl2.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F3319620\242A76C8\Interop.Microsoft.Office.Core.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\OFFLINE\F699690B\242A76C8\AxInterop.ComctlLib.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\gdiplus.dll0%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\data\mMSI.dll\mMSIExec.dll7%ReversingLabs
      C:\Users\user\AppData\Local\Temp\mia400B.tmp\mia.lib0%ReversingLabs
      No Antivirus matches
      No Antivirus matches
      No Antivirus matches
      No contacted domains info
      NameSourceMaliciousAntivirus DetectionReputation
      http://ie.lbl.gov/toi.html)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Rad Pro Calculator References.pdf.0.drfalse
        unknown
        http://physics.nist.gov/PhysRefData/XrayMassCoef/tab3.htmlShieldingandBuildup.doc.0.drfalse
          unknown
          http://www.epa.gov/radiation/marssim/obtain.html)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drfalse
            unknown
            http://www.pacificrad.com/pages/publications.html)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Rad Pro Calculator References.pdf.0.drfalse
              unknown
              http://www.installaware.comzRadProCalculator3.26_64BSetup.exe, RadProCalculator3.26_64BSetup.exe.0.drfalse
                unknown
                http://www.radprocalculator.com/Request.aspxGmailto:supportRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator.exe.0.drfalse
                  unknown
                  http://www.InstallAware.com/openRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.drfalse
                    unknown
                    http://www.radprocalculator.com/RadProCalculator3.26_64BSetup.exe, 00000002.00000002.3433296326.00000000024CC000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, mia.tmp.2.dr, RadProCalculator3.26_64BSetup.exe.0.drfalse
                      unknown
                      http://www.epa.gov/radiation/marssim/docs/revision1_August_2002corrections/chapter6.pdf)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drfalse
                        unknown
                        http://www.ans.org/store/vi-240180ShieldingandBuildup.doc.0.drfalse
                          unknown
                          http://www.installaware.com/RadProCalculator3.26_64BSetup.exe.0.drfalse
                            unknown
                            http://physics.nist.gov/xaamdiRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Rad Pro Calculator References.rtf.0.drfalse
                              unknown
                              http://www.radprocalculator.com/request.aspxContact Rad Pro Calculator.rtf.0.drfalse
                                unknown
                                http://physics.nist.gov/PhysRefData/XrayMassCoef/tab4.htmlShieldingandBuildup.doc.0.drfalse
                                  unknown
                                  http://www.wmginc.com/Software/MegaShield/megashield.htm)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drfalse
                                    unknown
                                    http://www.ans.org/store/vi-240180)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.pdf.0.drfalse
                                      unknown
                                      http://www.pacificrad.com/pages/publications.htmlRad Pro Calculator References.rtf.0.drfalse
                                        unknown
                                        http://www.installaware.com/InstallAwareRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.drfalse
                                          unknown
                                          http://ie.lbl.gov/toi.htmlRad Pro Calculator References.rtf.0.drfalse
                                            unknown
                                            http://www.InstallAware.com/RadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.0000000003A24000.00000004.00000020.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000003.2215926342.000000007FBB0000.00000004.00001000.00020000.00000000.sdmp, RadProCalculator3.26_64BSetup.exe, 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, RadProCalculator3.26_64BSetup.exe.0.drfalse
                                              unknown
                                              http://physics.nist.gov/PhysRefData/XrayMassCoef/tab3.htmlaRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.doc.0.drfalse
                                                unknown
                                                http://physics.nist.gov/PhysRefData/XrayMassCoef/tab4.html)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.pdf.0.drfalse
                                                  unknown
                                                  http://www.radprocalculator.com/Request.aspx)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drfalse
                                                    unknown
                                                    http://physics.nist.gov/PhysRefData/XrayMassCoef/tab3.html)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, ShieldingandBuildup.pdf.0.drfalse
                                                      unknown
                                                      http://www.radiationsoftware.com/mshield.html)/S/URIRadProCalculator3.26_64BSetup.exe, 00000000.00000003.2198576039.000000000372F000.00000004.00000020.00020000.00000000.sdmp, Help for Rad Pro Calculator.pdf.0.drfalse
                                                        unknown
                                                        No contacted IP infos
                                                        Joe Sandbox version:41.0.0 Charoite
                                                        Analysis ID:1524334
                                                        Start date and time:2024-10-02 17:33:35 +02:00
                                                        Joe Sandbox product:CloudBasic
                                                        Overall analysis duration:0h 6m 4s
                                                        Hypervisor based Inspection enabled:false
                                                        Report type:full
                                                        Cookbook file name:default.jbs
                                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                        Number of analysed new started processes analysed:5
                                                        Number of new started drivers analysed:0
                                                        Number of existing processes analysed:0
                                                        Number of existing drivers analysed:0
                                                        Number of injected processes analysed:0
                                                        Technologies:
                                                        • EGA enabled
                                                        • AMSI enabled
                                                        Analysis Mode:default
                                                        Analysis stop reason:Timeout
                                                        Sample name:RadProCalculator3.26_64BSetup.exe
                                                        Detection:CLEAN
                                                        Classification:clean12.expl.winEXE@3/73@0/0
                                                        Cookbook Comments:
                                                        • Found application associated with file extension: .exe
                                                        • Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe
                                                        • Excluded domains from analysis (whitelisted): client.wns.windows.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                        • Report size getting too big, too many NtOpenKeyEx calls found.
                                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                                        • VT rate limit hit for: RadProCalculator3.26_64BSetup.exe
                                                        TimeTypeDescription
                                                        11:34:56API Interceptor62x Sleep call for process: RadProCalculator3.26_64BSetup.exe modified
                                                        No context
                                                        No context
                                                        No context
                                                        No context
                                                        No context
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):153172
                                                        Entropy (8bit):4.653133657313636
                                                        Encrypted:false
                                                        SSDEEP:3072:V5ULyLagqz5QAJrtw+ZE9QMl6MU827IJi35ky:6
                                                        MD5:B2443D27BC6393A08F7F1ECFCC70A6FE
                                                        SHA1:6CA5FEE66B636C28E9E68DA71F77A67633147650
                                                        SHA-256:B07763A11636BCBECEF5976D8E1D2E6EC811E5C2BFDECB75152F99A81EC13F7E
                                                        SHA-512:09B5C68CDEFA107D28EF1288EE3E35BE2F7BEC5F64798A47BFD1E625F1A937DA0583D09B07A1FF6C92DBDB7868F7B01E408B09AD55B9DA3D5EE027DED1CB75E5
                                                        Malicious:false
                                                        Reputation:moderate, very likely benign file
                                                        Preview:Please install the common controls update from Microsoft before attempting to install this product...Setup resource not found..Setup resource decompression failure..Setup database not found..Runtime error in install: ..bytes..KB..MB..Attempting to get value of undefined variable ..Attempting to set value of undefined variable ..Copying: ..Unable to copy installation data to local folders..Downloading Web Media: ..Unable to download installation data from the web..Extracting Web Media: ..Unable to extract installation data downloaded from the web..Please locate your original setup sources to continue operation..Original setup sources required to complete operation, sources not found..General setup failure..Runtime error in setup script:..% complete..bytes received..InstallAware Wizard..InstallAware is preparing the InstallAware Wizard which will install this application. Please wait...Retry Download?..Downloading of installation data from the web has failed. Would you like to try again?
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with very long lines (343), with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):51127
                                                        Entropy (8bit):5.4987913081775845
                                                        Encrypted:false
                                                        SSDEEP:384:65at8RYu5sUvRBFGg2LxyMut2RWVwqXSLsKuMxBN/MrCL+0INq9:eYgZLoyMcFCkzqRMDra
                                                        MD5:5557EBDA30BCB25D1F331AE87BED6490
                                                        SHA1:F1B323F90B682DE1BF5D60C27FF407A20B60BA2E
                                                        SHA-256:A55A2D59D92B56590BFFEEDB13126447A11A3D4A08D6D25102DDD7EA288FF49C
                                                        SHA-512:F82D140F0E54F61453B0EAECD1991B6362892A2E2AAE8241D9F749A8F160A52F837162334EA6EB4A83A2D412767AB9B16DB24E7AE48067D16EC32FE1C46EF4C0
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:Comment..Comment..Code Folding Region..Comment..Get System Settings..If..MessageBox..Terminate Install..End..Comment..Code Folding Region..Comment..Code Folding Region..Comment..Code Folding Region..Comment..Set Variable..Set Variable..Comment..If..Set Variable..Set Variable..End..Comment..Code Folding Region..Comment..Code Folding Region..Comment..If..Display Dialog..If..Terminate Install..End..Display Dialog..Comment..If..Set Variable..Set Variable..(Un)Install MSI Setup..If..MessageBox..Terminate Install..End..If..MessageBox..If..Reboot and Resume..Else..Terminate Install..End..End..Set Variable..End..Comment..Hide Dialog..End..Code Folding Region..Comment..Code Folding Region..Comment..Code Folding Region..Comment..Get System Settings..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..If..Set Variable..End..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..Get Folder Location..Code Folding Regi
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Revision Number: {FBE2F65D-00D5-4F6D-9B60-35D3C6EDD74F}, Number of Words: 0, Number of Pages: 200, Template: Intel;1033, Title: Rad Pro Calculator, Subject: Rad Pro Calculator Installation, Keywords: Installer, MSI, Database, Author: Rad Pro Calculator Software Development, Comments: All rights reserved, Name of Creating Application: InstallAware, Security: 0
                                                        Category:dropped
                                                        Size (bytes):284160
                                                        Entropy (8bit):6.2627372614826795
                                                        Encrypted:false
                                                        SSDEEP:3072:nTnl5XMOjH4fUBHkjyhbmz5OyV9WxCIqcyzUDWgaxZiUSGJh/Ck375V5JbeaKpXO:nrl5dH4fUBE2hbObiqs+iJlQ5kFY6
                                                        MD5:36A8A56388C62892278CAEC56CD3901A
                                                        SHA1:15ED810612130320D77ECE0189E4412D86010461
                                                        SHA-256:3C30BCE0980D4E4246C43740412F0520CFD1A10C8CD9C959D18719EE5C762B81
                                                        SHA-512:3E476791022EEA1FD72610D25705F919CEFFEBA9E1AC83AADFE1CC15E4979022E28E5CD088923ABC0DAE1542213A190E52E5BE61A4815A8B0D5E1F826EFC7A37
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................%.......................................................................(...............................V........... ...!..."...#...$...&.......'...p...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...W...]...X...Y...Z...[...\.......^..._...`...t...b...c...d...e...n...g...h...i...j...k...l...m...a...o.......q...r...s...u...v...w...x...y...z...|...
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG image data, JFIF standard 1.02, resolution (DPI), density 1440x1440, segment length 16, Exif Standard: [TIFF image data, big-endian, direntries=7, orientation=upper-left, xresolution=98, yresolution=106, resolutionunit=2, software=Adobe Photoshop CS3 Windows, datetime=2007:08:18 19:15:58], baseline, precision 8, 465x281, components 3
                                                        Category:dropped
                                                        Size (bytes):56510
                                                        Entropy (8bit):7.815732828419113
                                                        Encrypted:false
                                                        SSDEEP:1536:5wF4wF7KPoV+/JcdlorKEVna+vJUHypB0:5040mE9orXDuH/
                                                        MD5:41041792003EEEE589C49ABD038E5839
                                                        SHA1:910AE3A55B7595FD3791EAC7B333E04209CE60B0
                                                        SHA-256:AE5CEFE95282CB7D3CA939C9F86DAF3E79F5FDC49B265ECF27DA3713F05CF4CD
                                                        SHA-512:1DDAA1B076827DE33EDE145EC119160D69A218E5285D4CE3A7BB3D67866EEBABE129F771323CD0BA9D9D8AFF9CD50672DA7A9CC2CF154460E9D28471E0DCC9D8
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:......JFIF..............Exif..MM.*.............................b...........j.(...........1.........r.2...........i...................'......'.Adobe Photoshop CS3 Windows.2007:08:18 19:15:58...................................................................................&.(.........................................H.......H..........JFIF.....H.H......Adobe_CM......Adobe.d.................................................................................................................................................a...."................?..........................................................................3......!.1.AQa."q.2.....B#$.R.b34r..C.%.S...cs5....&D.TdE.t6..U.e...u..F'...............Vfv........7GWgw........................5.....!1..AQaq"..2.....B#.R..3$b.r..CS.cs4.%......&5..D.T..dEU6te....u..F...............Vfv........'7GWgw.................?.....l,W.e?..6>..;~.7;......u...a...TC....6...P>......t..?.j...2..H..W^.1.o.,q.dY...FImM.o.U.......(...W_....J.......
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):160754
                                                        Entropy (8bit):3.7383281464814453
                                                        Encrypted:false
                                                        SSDEEP:768:r3aEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0gmTqYT6qd6qG6:r3a5EW7a5tGCwhwGYAh4HHGya5tn46
                                                        MD5:36B36D2992301AC3FBB6835150C39E7D
                                                        SHA1:0FA51F0FE6762C9339C0F2DF20CE6CF0041273FF
                                                        SHA-256:2EDD6E512440854484F433416ADCCC10FFB197911B27EB4EF321C86FB46E1C93
                                                        SHA-512:F2E674EA55BB9CAFAC82006EC9392292E44A56B2195080494C2566ADB52F71D4223C48345B565FBACE93C9158A884AE7FD7B064C2A71E43306123835C6D987ED
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..s..TPF0.TfrmDesign.frmDesign.Left.C..Top.s.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc.
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):160722
                                                        Entropy (8bit):3.737411366052792
                                                        Encrypted:false
                                                        SSDEEP:768:LCaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0gmTqYT6qd6qG6:LCa5EW7a5tGCwhwGYAh4HHGya5tn46
                                                        MD5:2CBC715B7AADBB83D413B8A2C73F7157
                                                        SHA1:30941B6D3E95F2DCE9593105AE7A4924E86CD094
                                                        SHA-256:F3BD8506934DFFF9F0C3DE24DC62040243FFF36F278B8CA82C8E26F82E076BCB
                                                        SHA-512:BD440C1C074F69667AF9FA51DDEF1AE0B0604A70C670F575AC8F765F16D01B19313B85788A72A9CC690466D3627AD4128C0E7A3C3A54021097D21591800042EE
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..s..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):160516
                                                        Entropy (8bit):3.730591461526072
                                                        Encrypted:false
                                                        SSDEEP:768:anaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qHCTqcu:ana5EW7a5tGCwhwGYAh4HHGya5tBH
                                                        MD5:C80E4EF8DD310E82F3DB13F7325EE261
                                                        SHA1:C2D7B751F25D81F964F6F91B95194DF1C4527067
                                                        SHA-256:B5E346F44B649857D1DD413D4A1978BB34CB82A3F98F36897281ED17147455EC
                                                        SHA-512:76297F3D6E229398D2A71F35AFB87384BCCE9A67D4C5F024AC8AC09F69FB34221BF9F1DC5592C2656448843F7D1D75C8317E60C3ED7884751406CE66757F911D
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..r..TPF0.TfrmDesign.frmDesign.Left.N..Top.|.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc.
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):110
                                                        Entropy (8bit):4.415603550315235
                                                        Encrypted:false
                                                        SSDEEP:3:ajKaxAHGdRFRzuFRAdRLOEpe7J0vKaxAHGdRFMLYFRAdRLOEpe8vn:aPx6KjRqMtrkeTx6KjMLYMtrk8v
                                                        MD5:80BE29BB2D9F9C01812B66541932DC04
                                                        SHA1:0A0AF42AC5AC2F1813FCF570178EE17DA21AB700
                                                        SHA-256:5A06BF977E74C946F9562A14FEC7E46FA1551754FACCA9DBC1ECD531EE28E456
                                                        SHA-512:CD4B1005C0B762190048AF606B30F2D00D5B35FC3ABD094057F2AB95CE58E571AE3347FFD938E35ED1D958B072862A2AE756C9BFF4507B02138905F65409E76B
                                                        Malicious:false
                                                        Preview:IF (FolderText.Text = ) THEN Next.Enabled := False;..IF (FolderText.Text <> ) THEN Next.Enabled := True;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):159900
                                                        Entropy (8bit):3.7155214139715844
                                                        Encrypted:false
                                                        SSDEEP:768:IlaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0bpTqBTqATqcN:Ila5EW7a5tGCwhwGYAh4HHGya5tbS
                                                        MD5:92C1192151FB785823C8707B2D762D41
                                                        SHA1:D8C87C034BC473E4857EAC1EA1B0C56A687466C0
                                                        SHA-256:4C444FBADD4BA023CB2FF88E3EFC22F133E6DC791DB47BCCEE5DFC08834EC8DD
                                                        SHA-512:5F32FD1FFDFF8439491F10743989CB2E424045673DD241FDC3E63C9C1CA54EA3D78D85AE5C8918A7A01B99C1B7C484A566A1B1DF4A67DD6D32CE48D4638C7727
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..p..TPF0.TfrmDesign.frmDesign.Left....Top.z.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc.
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):1561
                                                        Entropy (8bit):5.018115004625162
                                                        Encrypted:false
                                                        SSDEEP:24:UuikSi+nfi0ZiFuEai/pZSruicvSi+pipUivuNsIi/pEaiDatfi/pTvSgREii/pH:U5ExAGVPbu1ZRMfkf3faWYt
                                                        MD5:2FE4E500443ECB1E27A767BEE9A18C63
                                                        SHA1:887A5789CDAC46BEA2829870DF02AD6B87A92270
                                                        SHA-256:6492FEB41031C64C70FA8FABAABCCDE4846F9438B017D152C68C4B356C6A167A
                                                        SHA-512:9475EB0E7509493A23DEA491CFA0A9A1DB0D339C216F1E38512DF18A74D80C69B6C8CE9C10131047227FFA3E979D5D6F144748569CFD9209C47977D770D94DD4
                                                        Malicious:false
                                                        Preview:IF (checkSuccess.Caption = COMPLETE) THEN textComplete.Visible := True;..IF (checkSuccess.Caption = REBOOT) THEN textReboot.Visible := True;..IF (checkSuccess.Caption = CANCEL) THEN textCancelled.Visible := True;..IF (checkSuccess.Caption = ERROR) THEN textError.Visible := True;..IF (checkSuccess.Caption = COMPLETE) THEN RunNow.Visible := True;..IF (checkRemove.Caption = TRUE) THEN textRemove.Visible := True;..IF (checkSuccess.Caption = REBOOT) THEN RebootNow.Visible := True;..IF (checkSuccess.Caption <> COMPLETE) THEN textComplete.Visible := False;..IF (checkSuccess.Caption <> REBOOT) THEN textReboot.Visible := False;..IF (checkSuccess.Caption <> CANCEL) THEN textCancelled.Visible := False;..IF (checkSuccess.Caption <> ERROR) THEN textError.Visible := False;..IF (checkSuccess.Caption <> COMPLETE) THEN RunNow.Visible := False;..IF (checkRemove.Caption <> TRUE) THEN textRemove.Visible := False;..IF (checkRemove.Caption = TRUE) THEN textComplete.Visible := Fal
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:RIFF (little-endian) data, AVI, 107 x 31, 10.00 fps, video:
                                                        Category:dropped
                                                        Size (bytes):103424
                                                        Entropy (8bit):2.6025793031989863
                                                        Encrypted:false
                                                        SSDEEP:96:D5qqqqqqqqqqwrrrKKrrrKgUUUKnUUUKmZ6UUUKoUUUKdUUUKxrrrKdrrrKqqqqO:HrtG6vxiF/xP
                                                        MD5:718C1569EA402531E0C285D7F2F00B54
                                                        SHA1:010B39EEB4CA2AA82D4FF3B5C0AE1F615FAA090D
                                                        SHA-256:CB0ECC02BA073771704AD7406B8C385B0722AF56FEE7B1CC7EFA130119BB74E5
                                                        SHA-512:F09B35695B8341A0A58DC8E56346D07781020F04508F5EA52997880A0C663796204159997898F7E26AB1D77E84C204412385D07F1DAA56281B124A88E112CD90
                                                        Malicious:false
                                                        Preview:RIFF8...AVI LIST....hdrlavih8.......h.......................<'..k.......................LISTt...strlstrh8...vidsmsvc................d...........<'...'..........k...strf(...(...k...................................JUNK................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:MS Windows icon resource - 2 icons, 16x16, 32x32
                                                        Category:dropped
                                                        Size (bytes):3638
                                                        Entropy (8bit):4.834312953493427
                                                        Encrypted:false
                                                        SSDEEP:48:OgYXF4NNlICT9MPF+SAzffklVyczcI8W09I/fiCymGR+Evk3+JatFNTa:OgWKnl79SF+bzcVLQDBW/figDEM3WmQ
                                                        MD5:8C88256F49888097BC7EC2F23588F7AF
                                                        SHA1:4BD103041C2B1401C082D978C7CF00A53E7D1710
                                                        SHA-256:B10E31E4BBDAA407458E0F2B6F6072B33B1EAF59926011BF6B07949D271B86CA
                                                        SHA-512:A13A41EE51587C59EAAB3F55158EE1BFF4FD9986AC279C2DE62120779ABE819716B0A5BE66BC72C9ADB50A06911C6413F6E594ABB1424ADFAEE360EEC7C2E410
                                                        Malicious:false
                                                        Preview:..............h...&... ..............(....... ...........@........................................;..:....4..4...._..Z....... ...n............)..K....p..D............"..........#....C..c...................T........0.......C..."...d...k..4...*.......)...q.......!...R................................2.......&..}...........3...j...................}............................b..............:...q...................................~...~...........................................................}.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:HTML document, ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):459
                                                        Entropy (8bit):5.401860265427165
                                                        Encrypted:false
                                                        SSDEEP:12:hnMEwuiuX4w4vy4Wh96Qclfhqb8RHVM/IhMGvMmcGu:hMNmMvy4WvspqwRUI/Umq
                                                        MD5:F72F3965BAE0BFACDE8050F75CABFBA8
                                                        SHA1:8C9D2BCE6AEABDFADC94A1339ED8E90A316F95D5
                                                        SHA-256:9B8419BD36800A491B1143803C1B070DAA2D16EECEA0A194646066336E921E16
                                                        SHA-512:C2425600298070566DF86DCEF23B014922F84C71D2125DA36C6869F51EC2B59AD8657498A9A2D69F02F779B76BB1921B23E645F8DDE611F32500FC7B54CD10EB
                                                        Malicious:false
                                                        Preview:<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">..<html xmlns="http://www.w3.org/1999/xhtml">..<head>..<meta http-equiv="Content-Type" content="text/html; charset=utf-8" />..<title>Untitled Document</title>..<style type="text/css">.. ..body {...background-color: #000000;..}..-->..</style></head>....<body>..<img src="RadProSplash.jpg" width="465" height="281" />..</body>..</html>..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                        Category:dropped
                                                        Size (bytes):7520
                                                        Entropy (8bit):5.0048786924553825
                                                        Encrypted:false
                                                        SSDEEP:96:r3Du7xf0S9ntkCgbihHjm6nv+FwZU0gElcTJkJWA6EB:rqd97kCrHjJnpuClXB6EB
                                                        MD5:E9B2694D7C93EEF275ADDB7424E74583
                                                        SHA1:D1A72FA83587015D14612EC8CA8D646C5C79C8EC
                                                        SHA-256:B71F02B1A0E66BA16ED490FF0897D532810B3D47788A8005BF7040D32695171B
                                                        SHA-512:5EA6E43D01CB90013F01CB0BDEE5C9AE06024807C27F53B181628624A0729414A31B85B02F2995FDF5EC9B0F7B8431898E47BBC3694BE6C0446D7B1678D4AFFE
                                                        Malicious:false
                                                        Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f37\fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Verdana;}{\f258\froman\fcharset238\fprq2 Times New Roman CE;}..{\f259\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f261\froman\fcharset161\fprq2 Times New Roman Greek;}{\f262\froman\fcharset162\fprq2 Times New Roman Tur;}{\f263\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}..{\f264\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f265\froman\fcharset186\fprq2 Times New Roman Baltic;}{\f266\froman\fcharset163\fprq2 Times New Roman (Vietnamese);}{\f628\fswiss\fcharset238\fprq2 Verdana CE;}..{\f629\fswiss\fcharset204\fprq2 Verdana Cyr;}{\f631\fswiss\fcharset161\fprq2 Verdana Greek;}{\f632\fswiss\fcharset162\fprq2 Verdana Tur;}{\f635\fswiss\fcharset186\fprq2 Verdana Baltic;}{\f636\fswiss\fcharset163\fpr
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158637
                                                        Entropy (8bit):3.6621886201865914
                                                        Encrypted:false
                                                        SSDEEP:768:MKaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIGl:MKa5EW7a5tGCwhwGYAh4HHGya5tFm
                                                        MD5:8111DC166660F7A7BF715DBF2C72FB03
                                                        SHA1:2D675818B40B90BCE3F85DD4637543C675262DDF
                                                        SHA-256:C243387182FB7318620288890664022902E0C60D771A1D5F24AD49813DAA7064
                                                        SHA-512:FCD34F75BEED13E322C2737A967226F94CFBBBA8E3097247BAEDDC8C0DC59124D8202BAB72C8F4271E63A7E56B19D78889CA6AB0FB740FBFAA839E9CFB4E059A
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..k..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):130
                                                        Entropy (8bit):4.652234735705968
                                                        Encrypted:false
                                                        SSDEEP:3:ap7GrL97R2tuFRAdRLOEpe8vi7GrL97VuFRAdRLOEpe7Jv:aF8KuMtrk84IuMtrkt
                                                        MD5:3A94EA05F8B5537CB505D0B6D762AECB
                                                        SHA1:48E63C97A60933E2D8F9858DF9634693F1120CC5
                                                        SHA-256:9F362C44CC4959EFC8279413F8CB6526454A72DD6DC37BC26C0C2CA9458961D4
                                                        SHA-512:34B4E57CB6D3BF895E2D474A98991423B2FAC1BFFA28C016A1ACBD2B9DFEF31EEA0ED563D114928BF86B96C92C954086A5665B44E6CA36F41075AE2E04898E8E
                                                        Malicious:false
                                                        Preview:IF (LicenseAccept.Checked = True) THEN Next.Enabled := True;..IF (LicenseAccept.Checked = False) THEN Next.Enabled := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158861
                                                        Entropy (8bit):3.670267666283049
                                                        Encrypted:false
                                                        SSDEEP:768:x5aEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIGu:x5a5EW7a5tGCwhwGYAh4HHGya5tFb
                                                        MD5:40E18219890851CDA51668327851E544
                                                        SHA1:6C48797A42AE6B1CC405A444ACC143868EE82C46
                                                        SHA-256:9AE291A14D36C0633F8633DFA54FB410E755158D7BD5D5F87DAC5E5920DFCCF6
                                                        SHA-512:FE1BBFF8AA4319A0ED998ECAB764227EF486DDA0E53F45D07A55E9CD1A295B05275DCABCDA51E27E64897AD488AD04B7F0F16B0E68D94EE552961620C9DBE7AF
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0.yl..TPF0.TfrmDesign.frmDesign.Left....Top...HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc.
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):260
                                                        Entropy (8bit):4.672977372753125
                                                        Encrypted:false
                                                        SSDEEP:6:aF8KuMtrk8suMtrk84IuMtrkeBKuMtrkt:g2MtgMMtgdpMtgAMtgt
                                                        MD5:57C518A3F3AADBF3804AA202D6E52C0F
                                                        SHA1:4DA9645BDB2662478F7799DCCB3371C03577B4F1
                                                        SHA-256:C1E5E51D99CAF4A4CB98767831D27328B915905CD932D169EA5B55EB38355EC6
                                                        SHA-512:B595DC56296CC0338D29DE642BB497182F132E832071FFC296DD6A6A3E8A3A5CA0CEAAED37B824714A1E461BC688A606BE44545E368A633D49A0D447777025BB
                                                        Malicious:false
                                                        Preview:IF (LicenseAccept.Checked = True) THEN Next.Enabled := True;..IF (LicenseReject.Checked = False) THEN Next.Enabled := True;..IF (LicenseAccept.Checked = False) THEN Next.Enabled := False;..IF (LicenseReject.Checked = True) THEN Next.Enabled := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158700
                                                        Entropy (8bit):3.6643756131838185
                                                        Encrypted:false
                                                        SSDEEP:768:hIaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIGBc:hIa5EW7a5tGCwhwGYAh4HHGya5tFSc
                                                        MD5:253AF27AE24B42EE720860ED964EC1C0
                                                        SHA1:76554D0718CC71D200C43A68CB08031AF4F727F5
                                                        SHA-256:A8859448F2F990A3AF8DF90D3D9F6713B533E7003F18C02F55240821D4E29418
                                                        SHA-512:32504B0DAE76D539275D86FEFBD01E9772722ECAF546F82E54CCBB5CE73F49840CB0C356FF3E259CE21DC06709EEC10FACB8747DDC73B220B50A21F6FB5FCEDB
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..k..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):128
                                                        Entropy (8bit):4.604885794192715
                                                        Encrypted:false
                                                        SSDEEP:3:apu4R6dRFx5lxMFFxYFRAdRLOEpe8viu4R6dRFsdxMFFxYFRAdRLOEpe7Jv:ah2jxq/xYMtrk8+2jsg/xYMtrkt
                                                        MD5:C8723DC60FD1A2A054A495F85A2953C7
                                                        SHA1:6182237EA6E6A6DF3B4893F5F8831964A3AC7C75
                                                        SHA-256:9ECB43F171020A2677E84BB4E20F3A0D579DF74C3DB46F4C640949FEB3135E87
                                                        SHA-512:2BAB5A7AD2FBBC26DA2B0177DC6C001DB072385ABE89B74A0B46C12B616D09D27D7F4011E3D4B36E0C7CCA2AD26A40638A1D6D5744BD915AAE561454CC6F866E
                                                        Malicious:false
                                                        Preview:IF (LicenseText.Text = I ACCEPT) THEN Next.Enabled := True;..IF (LicenseText.Text <> I ACCEPT) THEN Next.Enabled := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):438272
                                                        Entropy (8bit):6.605226720005331
                                                        Encrypted:false
                                                        SSDEEP:6144:Wo3rpaDTVMXwQ4zB9lSZ48AeP9QrhDLHyc24FfCyVzKjsRZa8tTpMc1bq3gRvNc:WnDTmXwQg648/9e5HlFayVEOZBtVMlY
                                                        MD5:598EA39BF501C22D63AA44F2F9FF940D
                                                        SHA1:C3B69AFAD05429768CA3744E2C895EAF3A373644
                                                        SHA-256:844CB5C399364519B619E00876C45381F34A24292D2BAE10AB48082DCA4F35E0
                                                        SHA-512:7FBD686CAE04BFCF33CC6694ECF199B64B696660A4E42C8898266A159937DE47A3FD1A46CAEEA6CA304EDD444F2153CC16F33E45C7685225CE989407B341F4F0
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 7%
                                                        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...(..I..........................................@..........................@..........................................N....P...).......:......................._...................................................W..p............................text............................... ..`.itext..P........................... ..`.data...4...........................@....bss....TN...............................idata...)...P...*..................@....edata..N...........................@..@.rdata..............................@..@.reloc..._.......`..................@..B.rsrc....:.......:...v..............@..@.............@......................@..@................................................................................................
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):177645
                                                        Entropy (8bit):3.815150921062852
                                                        Encrypted:false
                                                        SSDEEP:768:SoaEilpj+WWaEiltTMtskowhwG1S79AQoM1HaeBiLtaEilM2W0i6qK6qO6qIGE6:Soa5EWWa5tGCwhwGYAh4HHGta5tFA
                                                        MD5:BCEB5F5780C690B15894DE1F339D27CD
                                                        SHA1:4066CAFF886E266EA577FFA737698762C64F1966
                                                        SHA-256:83CF33DDBDEE50653A7B36E377ECE56DAC5E9AAFDCA9F52B0F2771A57B5FA06A
                                                        SHA-512:9D20A899D5B2335D302C792AFBD9E4287B61CAB8E21EF1B12EA2F2ED7515BA085AC6869448D4F2C23AA13414727332EBB79342EFA23F58916F363AC26B631577
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0....TPF0.TfrmDesign.frmDesign.Left.*..Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158783
                                                        Entropy (8bit):3.6673299836270483
                                                        Encrypted:false
                                                        SSDEEP:768:r6aEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIGo:r6a5EW7a5tGCwhwGYAh4HHGya5tFH
                                                        MD5:D14F071573AA625FAB4E91D84E024A92
                                                        SHA1:165BC7579A8BC31C5E9A4B33A8766EE7483FD658
                                                        SHA-256:7CF426EC7B6D871806096DE5B39571BE8DADB45AF2888B2974373748CB589255
                                                        SHA-512:3FE7077599E1AE77C4BB4E59BF5CC33C68E32007F59D2244606709A83928CFAF764AEF802F781001B18D3482681A3FC65CB403B99513F0B3931EBD2FE3659F46
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0.+l..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):370
                                                        Entropy (8bit):4.959095954912026
                                                        Encrypted:false
                                                        SSDEEP:6:aG1uSLF2du6szW4Rl1Ac2duJRl1Ow0Ld2du4LRl1uSLju6szWAK1Ow0Lru4FK1AC:qITMDIb6UIJTc6S6jO
                                                        MD5:D8BA1E1B3F547F94CB059C8ACEC89297
                                                        SHA1:71A5043CA3BF89FECA070431985C232E28940AAB
                                                        SHA-256:62EE20B127F44C2D91BBCC9A232689DD3F1BC3359E606257BF3B115D4CBBDD2C
                                                        SHA-512:5DA1E4DEB8518CD7AF202E7169F181683C74A83F62D98A36DEB45A03E14F384410633017D16CCBB6E216904F40AC782D7BE97940EACAB7D60B2D54CB7DBAEDC9
                                                        Malicious:false
                                                        Preview:IF (checkWINST.Caption <> TRUE) THEN WINST.Visible := True;..IF (checkJS.Caption <> TRUE) THEN JS.Visible := True;..IF (checkDotNET.Caption <> TRUE) THEN dotNET.Visible := True;..IF (checkWINST.Caption = TRUE) THEN WINST.Visible := False;..IF (checkDotNET.Caption = TRUE) THEN dotNET.Visible := False;..IF (checkJS.Caption = TRUE) THEN JS.Visible := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):159046
                                                        Entropy (8bit):3.68127879127009
                                                        Encrypted:false
                                                        SSDEEP:768:9NaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qD/TqATqcj:9Na5EW7a5tGCwhwGYAh4HHGya5tiD
                                                        MD5:513544FD9E89B1CEF46081ED1174C40C
                                                        SHA1:AD0920D4750A58754CAE967A8016C1AFBF3B27EF
                                                        SHA-256:32E30EAF1DF2610B48E793B87A0BF40AFC0ABD0ECF2249AE8E0475F0DEE79084
                                                        SHA-512:89651FE85CDAAD57A20D1AECADC19A7978B6D33AB784DDBACADD2F81FEE1D38CAC2DFC1603190E530FF6C0B3EDFF74AC0F58C76B94D86CD927B35AA75E3BADA0
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0.2m..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):292
                                                        Entropy (8bit):4.740550563860751
                                                        Encrypted:false
                                                        SSDEEP:6:a3jF2duukAiRcjjuukTDoRcjF2duukTDQTjjuukAh:csIrqar1sIroarg
                                                        MD5:86B3EBFBD934B66842048F0AA241E5C5
                                                        SHA1:F770786C29D12D8C33B975EF2BAAD6D59A90F7CF
                                                        SHA-256:4AEDBF26E568E62B47517E91FBCC818A5B95BD7FDB8A7DC5B826C0BD194077A6
                                                        SHA-512:FE37AD98EC8DE62CE6E6A46E284450BBE19B7D8EB8C7B3B81BD06BA22EEBA487C2CEE8C3B37CD84FEAA09F8F39BDF532371B57FCCC7788A2F54EDA3390E58FD3
                                                        Malicious:false
                                                        Preview:IF (TestRemove.Caption <> TRUE) THEN CaptionInstall.Visible := True;..IF (TestRemove.Caption = TRUE) THEN CaptionUninstall.Visible := True;..IF (TestRemove.Caption <> TRUE) THEN CaptionUninstall.Visible := False;..IF (TestRemove.Caption = TRUE) THEN CaptionInstall.Visible := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158764
                                                        Entropy (8bit):3.6648395593983847
                                                        Encrypted:false
                                                        SSDEEP:768:ceaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIz2:cea5EW7a5tGCwhwGYAh4HHGya5tF6
                                                        MD5:F365BBBBD84B66CE88203D6DFE74AEC9
                                                        SHA1:842D65794803CF09F6107CC76078A372CF71AE64
                                                        SHA-256:C0B2F75475AAD76C5536065EE51B97F2DF9566C823529318FED398ED6F621AC7
                                                        SHA-512:1171D3E4CF63625B143A7E0240280BCE73F93EB0850F72456471B3AEDA9E668C7387724DD4C6AA1CE76605E09B2B6AE139B17BDCE22578090F6CD8AEDAD41AC6
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..l..TPF0.TfrmDesign.frmDesign.Left.M..Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color..clWhite.Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158388
                                                        Entropy (8bit):3.652882984962139
                                                        Encrypted:false
                                                        SSDEEP:768:SEaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qnGx6qU:SEa5EW7a5tGCwhwGYAh4HHGya5thL
                                                        MD5:7E0A4074BBD7E70189B8CA2DAEF0A1A2
                                                        SHA1:B35C28DF0C9DE76978B3834C2E26346DEF3226A3
                                                        SHA-256:AD1AD22FE2E03D2B04A3A8541B93C324D6CA04503B718FC42B9392138BFFD46B
                                                        SHA-512:17A7B56290FB321CE5EAA88821D58C0A703A1F0B736E9D97E952B73DC994109B2F81713774BAA6B5A310A1FB241748DA49F8A14BD0687CF3AC5FB8A2ECB3A10D
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..j..TPF0.TfrmDesign.frmDesign.Left.:..Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158682
                                                        Entropy (8bit):3.663803043201259
                                                        Encrypted:false
                                                        SSDEEP:768:7saEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIGH:7sa5EW7a5tGCwhwGYAh4HHGya5tFa
                                                        MD5:BE6663C9080A4256A896458D1759C906
                                                        SHA1:7E8873A3FEE0B4B6004FF0CCF8D2A2DEE34AE9A6
                                                        SHA-256:A20FB27048C62CAC81EE218CE6024F9C4C8C3A22111A4EAB27CF923D2BD63013
                                                        SHA-512:AD299469ECDC031D814023E952D45FEF6A083BB324169F437493BCF5AB3F3BC41F48133AFEBF6716B2D4667F6E528B8CFFDB92F6495BD57D83B25523FF1FCC60
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..k..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):218
                                                        Entropy (8bit):4.635426120490109
                                                        Encrypted:false
                                                        SSDEEP:6:awbBiLYMtrk8TVMLYMtrk8TbB7qMtrke8VRqMtrkt:7VGYMtgIWYMtgIVmMtgpWMtgt
                                                        MD5:188D78E86F52BF3F82BC567339268E81
                                                        SHA1:949ED916F5A813020D40C068EE24E010701B73F6
                                                        SHA-256:4E5EE72B6F00571F0CEB8F8C51519E68B4B597E7DC4E4BD7BFF0CC38807EBEF8
                                                        SHA-512:7876002FEB629D9E8DADE3B04321EE8796B979D36B7199CC99B8A8D402C599DCFC970FDD2B7287FC921814F1EADF374E915D66C170075DE3B372C40A7D68FC6A
                                                        Malicious:false
                                                        Preview:IF (UserName.Text <> ) THEN Next.Enabled := True;..IF (UserCompany.Text <> ) THEN Next.Enabled := True;..IF (UserName.Text = ) THEN Next.Enabled := False;..IF (UserCompany.Text = ) THEN Next.Enabled := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):159299
                                                        Entropy (8bit):3.6863122637284245
                                                        Encrypted:false
                                                        SSDEEP:768:R/TaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIGw:R/Ta5EW7a5tGCwhwGYAh4HHGya5tFX
                                                        MD5:E365CA34F84487F72048CA7AB751A3EC
                                                        SHA1:2435E0F8171EBF4FE8F972C9B574B376B6AEC82E
                                                        SHA-256:8F4CB90C918BCD027D061389AC9A0FA0C4F60C5D99514BDED30D17204266D6FC
                                                        SHA-512:883B32F3CDB4A57B63C82FD55E67D2E43F38DD6439F887D74D3008D979AF7451F141B2D4BC7DAD8AD1E9F4CEAED406AFCD3F85A451F027764E91A0A447868CF7
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0./n..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):708
                                                        Entropy (8bit):4.634738153762559
                                                        Encrypted:false
                                                        SSDEEP:12:7VGYMtgIWYMtgpYMtgUYMtgHYMtgyYMtggGYMtgFMtghMtgiMtgTMtgZmMtgpVm+:7VfwPi9ALofNpKbBmxVmxWF
                                                        MD5:696AAF75D0FDE1C9A32F6E0FA2748793
                                                        SHA1:5437593B04AE8AB9A0C10AD98081498544C8B8B2
                                                        SHA-256:3CFFFC761E1CB8ABBD1E2AE768498F81C98477BD32593A4B1E2689D664B9EE0A
                                                        SHA-512:E393B331A5D6DFBD879F06C0D12F11D06C84CB55ACAE88FAEBA1E515D4ED6BB86C0D9EBC373414B64BC236FB224692F2E8CD224148B1BD500795A847C1067163
                                                        Malicious:false
                                                        Preview:IF (UserName.Text <> ) THEN Next.Enabled := True;..IF (UserCompany.Text <> ) THEN Next.Enabled := True;..IF (Key1.Text <> ) THEN Next.Enabled := True;..IF (Key2.Text <> ) THEN Next.Enabled := True;..IF (Key3.Text <> ) THEN Next.Enabled := True;..IF (Key4.Text <> ) THEN Next.Enabled := True;..IF (Key5.Text <> ) THEN Next.Enabled := True;..IF (Key1.Text = ) THEN Next.Enabled := False;..IF (Key2.Text = ) THEN Next.Enabled := False;..IF (Key3.Text = ) THEN Next.Enabled := False;..IF (Key4.Text = ) THEN Next.Enabled := False;..IF (Key5.Text = ) THEN Next.Enabled := False;..IF (UserName.Text = ) THEN Next.Enabled := False;..IF (UserCompany.Text = ) THEN Next.Enabled := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):177735
                                                        Entropy (8bit):3.7883642019096055
                                                        Encrypted:false
                                                        SSDEEP:768:12aEilpj+WWaEiltTMtskowhwG1S79AQoM1HaeBiLtaEilM2W0i6qK6qtsCTqg:12a5EWWa5tGCwhwGYAh4HHGta5t08
                                                        MD5:EBFAECDFF92F6819546DB62FC5C9B22F
                                                        SHA1:961D99DA692AC7DC6FD27C98FBBFFE8A982A8FC4
                                                        SHA-256:4EDB51A94FDD9745BFAB896CAE73524DB4DDAB1004012C5DD9454338161B28E1
                                                        SHA-512:A127CF3C718A5127A37E898223881355102CDC7CEC885D9EE5300EE2631B34CE5E414064C7EF82ACADDE754435B6D85D5D936C3FC28D2D53C50532744276327E
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0.3...TPF0.TfrmDesign.frmDesign.Left.j..Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158566
                                                        Entropy (8bit):3.662744601376867
                                                        Encrypted:false
                                                        SSDEEP:768:XsaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qHCTqcK:Xsa5EW7a5tGCwhwGYAh4HHGya5tBp
                                                        MD5:6243D37F86BB70FD391BCBF820C2F9A1
                                                        SHA1:71F6E389216A12D756CCEEDE47435EC74639EFE9
                                                        SHA-256:461336E5D740E8FF4AF2ED2A076F5B77CA5544567087E7F2DBFBA1B8A788B649
                                                        SHA-512:ACE2C0E1FE4E746DC001A5055D80D490D3DD6AEC70B57A13B3232861717386CB5FF657BF6534332CD5C4F6CEEBC7B61E060B8C6F0DFA5C4FD0DCC1319925A98F
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0.Rk..TPF0.TfrmDesign.frmDesign.Left.B..Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):159133
                                                        Entropy (8bit):3.6831764396491127
                                                        Encrypted:false
                                                        SSDEEP:768:aIaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qHCTqcq:aIa5EW7a5tGCwhwGYAh4HHGya5tBP
                                                        MD5:261F5DCF6EB5ADDD7F8FB129D4DC6250
                                                        SHA1:C381AD6890084DB21043382847900A9FDAFAE99E
                                                        SHA-256:458E43CFDF8173B2ACAC69472D998CE4517D3B52209D7C4569D835C688C6B68D
                                                        SHA-512:D5CD6AA1EDE36F5211468F5E318596084CFAA4DD0BABBEC9C705FE5B5E25BA1D2E2E1BBA392B6D66EC6017AFB387657CBFC2951305E192D3E7C71B39F68A4546
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..m..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):228
                                                        Entropy (8bit):4.823487220355037
                                                        Encrypted:false
                                                        SSDEEP:6:aoqLYMtrk8LTqMtrkegurusdrHE8Pud2dusdrHEt:jOYMtgQeMtg1dsdrHEUxIsdrHEt
                                                        MD5:8ED569EB90D7EC0791C65F696B85AA4B
                                                        SHA1:AA48F7BD2BA3A2F5DD63D25DA56A1039A18E7FB0
                                                        SHA-256:ABF9F1E255935EC3BA966B8CDA6D129F93F28F43F8C805523B4846769C90F788
                                                        SHA-512:3BDBBDF37199E6FEB281867FFDE480782905E0C24DB729DBF78D6FA0D92A363AA0CABBE20303E06D1327A24C3142F0EF72F8B0AF1ED268652DB301407A4F5926
                                                        Malicious:false
                                                        Preview:IF (MenuGroup.Text <> ) THEN Next.Enabled := True;..IF (MenuGroup.Text = ) THEN Next.Enabled := False;..IF (ISNT.Caption = TRUE) THEN AllUsers.Enabled := True;..IF (ISNT.Caption <> TRUE) THEN AllUsers.Enabled := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:MS Windows icon resource - 2 icons, 16x16, 32x32
                                                        Category:dropped
                                                        Size (bytes):3638
                                                        Entropy (8bit):4.834312953493427
                                                        Encrypted:false
                                                        SSDEEP:48:OgYXF4NNlICT9MPF+SAzffklVyczcI8W09I/fiCymGR+Evk3+JatFNTa:OgWKnl79SF+bzcVLQDBW/figDEM3WmQ
                                                        MD5:8C88256F49888097BC7EC2F23588F7AF
                                                        SHA1:4BD103041C2B1401C082D978C7CF00A53E7D1710
                                                        SHA-256:B10E31E4BBDAA407458E0F2B6F6072B33B1EAF59926011BF6B07949D271B86CA
                                                        SHA-512:A13A41EE51587C59EAAB3F55158EE1BFF4FD9986AC279C2DE62120779ABE819716B0A5BE66BC72C9ADB50A06911C6413F6E594ABB1424ADFAEE360EEC7C2E410
                                                        Malicious:false
                                                        Preview:..............h...&... ..............(....... ...........@........................................;..:....4..4...._..Z....... ...n............)..K....p..D............"..........#....C..c...................T........0.......C..."...d...k..4...*.......)...q.......!...R................................2.......&..}...........3...j...................}............................b..............:...q...................................~...~...........................................................}.........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158515
                                                        Entropy (8bit):3.6575564720278413
                                                        Encrypted:false
                                                        SSDEEP:768:GSaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qIGhF:GSa5EW7a5tGCwhwGYAh4HHGya5tF8
                                                        MD5:FC47C1ACA6BDB1155907F12416CF1458
                                                        SHA1:2859472F98D29C2B81933DA36156E3DD93B29EC9
                                                        SHA-256:C7A08415D1387A7028D510E53D967689D7A84845FB3FD29B75791D4A65BF9724
                                                        SHA-512:53E995C422069EA49CD5557AAF0C0536C572D7AE152EACCFA2D3F68C8DA4D99A7870CED76B64B11A7F50EB73F26F62EF1DB4EF401206158A7CE03889E27CD315
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..k..TPF0.TfrmDesign.frmDesign.Left....Top....HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):260
                                                        Entropy (8bit):4.672977372753125
                                                        Encrypted:false
                                                        SSDEEP:6:aF8KuMtrk8suMtrk84IuMtrkeBKuMtrkt:g2MtgMMtgdpMtgAMtgt
                                                        MD5:57C518A3F3AADBF3804AA202D6E52C0F
                                                        SHA1:4DA9645BDB2662478F7799DCCB3371C03577B4F1
                                                        SHA-256:C1E5E51D99CAF4A4CB98767831D27328B915905CD932D169EA5B55EB38355EC6
                                                        SHA-512:B595DC56296CC0338D29DE642BB497182F132E832071FFC296DD6A6A3E8A3A5CA0CEAAED37B824714A1E461BC688A606BE44545E368A633D49A0D447777025BB
                                                        Malicious:false
                                                        Preview:IF (LicenseAccept.Checked = True) THEN Next.Enabled := True;..IF (LicenseReject.Checked = False) THEN Next.Enabled := True;..IF (LicenseAccept.Checked = False) THEN Next.Enabled := False;..IF (LicenseReject.Checked = True) THEN Next.Enabled := False;..
                                                        Process:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        File Type:JPEG XL codestream
                                                        Category:dropped
                                                        Size (bytes):158239
                                                        Entropy (8bit):3.6101038553522367
                                                        Encrypted:false
                                                        SSDEEP:768:5SaEilpj+W7aEiltTMtskowhwG1S79AQoM1HaeBiLyaEilM2W0i6qK6qO6qb6qtH:5Sa5EW7a5tGCwhwGYAh4HHGya5tq
                                                        MD5:90E552A589F911110B23E2654ED43C83
                                                        SHA1:6B6B9F9CF0EA54F170983AF19A5B2CDAC746B368
                                                        SHA-256:8241051774B237983EAFB579F20303F1A4854320173190A15552ECF02768B32B
                                                        SHA-512:BE29DD996BA9CBFDC8B7F68BCB00EF51ADF166A944027F2AF3638E6192BAE252A63296CB0D1BBC9DEDC117A6341BCCD09B1E2D06B117C18BD1095EA48F4A4096
                                                        Malicious:false
                                                        Preview:...TFRMDESIGN.0..j..TPF0.TfrmDesign.frmDesign.Left....Top.w.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................KE>...}.qjb.wph.unf.yrj..|t.umc.
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):2706359
                                                        Entropy (8bit):6.451758829239219
                                                        Encrypted:false
                                                        SSDEEP:49152:lhTcNLdFYSfSSAvNQPFt1/wCfbTNmLCuCs+z6wlreEP0+8U7:7MTYQ0FI11bTwLCoE6AeEJ
                                                        MD5:C82B11E5425B91A31672CEEC8E0F37A0
                                                        SHA1:795CD8777D6FA087BC5DBC2D1A725EB09AEDB59B
                                                        SHA-256:90D9A6A4876D315ABE1057C961ADB03E098F6EB772D55D5F36B61F4F3FE8B7BE
                                                        SHA-512:CD821398AAFE50160D4765B4ABEFD72834D92ECC4C28A1D8F9844BD96042362173291E6DB106A1011075FD6937C7229BF8A2AE3999A47490A164440B4DA25379
                                                        Malicious:false
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe, Author: Joe Security
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 7%
                                                        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L....B.I.................J...6......L<.......`....@.......................... +..................@...........................p...G.... .DY..........................................................................|}...............................text............................... ..`.itext...^.......`.................. ..`.data.......`.......N..............@....bss....Le...............................idata...G...p...H..................@....tls....4............(...................rdata...............(..............@..@.reloc...............*..............@..B.rsrc...DY.... ..Z...*..............@..@.............p+.......*.............@..@................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Revision Number: {FBE2F65D-00D5-4F6D-9B60-35D3C6EDD74F}, Number of Words: 0, Number of Pages: 200, Template: Intel;1033, Title: Rad Pro Calculator, Subject: Rad Pro Calculator Installation, Keywords: Installer, MSI, Database, Author: Rad Pro Calculator Software Development, Comments: All rights reserved, Name of Creating Application: InstallAware, Security: 0
                                                        Category:dropped
                                                        Size (bytes):284160
                                                        Entropy (8bit):6.2627372614826795
                                                        Encrypted:false
                                                        SSDEEP:3072:nTnl5XMOjH4fUBHkjyhbmz5OyV9WxCIqcyzUDWgaxZiUSGJh/Ck375V5JbeaKpXO:nrl5dH4fUBE2hbObiqs+iJlQ5kFY6
                                                        MD5:36A8A56388C62892278CAEC56CD3901A
                                                        SHA1:15ED810612130320D77ECE0189E4412D86010461
                                                        SHA-256:3C30BCE0980D4E4246C43740412F0520CFD1A10C8CD9C959D18719EE5C762B81
                                                        SHA-512:3E476791022EEA1FD72610D25705F919CEFFEBA9E1AC83AADFE1CC15E4979022E28E5CD088923ABC0DAE1542213A190E52E5BE61A4815A8B0D5E1F826EFC7A37
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................%.......................................................................(...............................V........... ...!..."...#...$...&.......'...p...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...W...]...X...Y...Z...[...\.......^..._...`...t...b...c...d...e...n...g...h...i...j...k...l...m...a...o.......q...r...s...u...v...w...x...y...z...|...
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:7-zip archive data, version 0.2
                                                        Category:dropped
                                                        Size (bytes):3679511
                                                        Entropy (8bit):4.462430533661214
                                                        Encrypted:false
                                                        SSDEEP:12288:TOLoXOLo3OLoZOLoSOLorOLoDOLoF4ZL7WOLoCOLoHOLoltcBOLozOLo1OLo9ZL5:btcjr3yFw08xJNzMd1A
                                                        MD5:6A8F181AA2AA2A1381BD2FFBF48ACE32
                                                        SHA1:7C401A005117E4F07DEC8AE8CA6EA5D5CB7707B5
                                                        SHA-256:C439BEDB2C952C415FBE3FC8D64EA26439434F001BCCD30A551FBCCDE4F3F009
                                                        SHA-512:60E60D0E657D6132BCA4721844C7364F8D1A9D79F11FD845613AD85FB0AFE972A1E036E803FA0039C55A1BD181ECA83ACAB3C85FDB148FEFD1C2765E8EDA8E2C
                                                        Malicious:false
                                                        Preview:7z..'....NQ!.$8.....%........Kt....TFRMDESIGN.0..s..TPF0.TfrmDesign.frmDesign.Left.C..Top.s.HelpType..htKeyword.HelpKeyword..passingvariables.BorderIcons..biSystemMenu.biMinimize..BorderStyle..bsSingle.Caption..$TITLE$.ClientHeight....ClientWidth....Color.Wai..Font.Charset..DEFAULT_CHARSET.Font.Color..clWindowText.Font.Height...Font.Name..Tahoma.Font.Style...OldCreateOrder..Position..poDesigned.PixelsPerInch.`.TextHeight....TImage.Image1.Left...Top...Width....Height.(.Picture.Data..n...TBitmap.n..BM.n......6...(.......'............j..................iaW.LF?...w.....o[O.OE>.pcX..si..tk.LFA.ocX.nbW.qeZ.pdY.sg\.th].NF?.ME>.{od.|qg.{pf..xn..uk..yo.skd.....OF=.wla.jaX.lcZ..|q.pg^.ne\.ri`..wm.vmd.tkb.xof..yp.}um.............uj^.vk_.ynb.lcY.jaW.ne[.pg].ri_.tka.jbY.iaX..{p.xoe.ld[.kcZ...t..~s..}r.|si.zqg.og^.nf].me\.rja.ph_..yo.umd.tlc.skb..}s.xpg.wof.vne.|tk.~vm......zq..xo......~u..|s.........................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PDF document, version 1.4, 2 pages
                                                        Category:dropped
                                                        Size (bytes):19946
                                                        Entropy (8bit):6.7913247794366525
                                                        Encrypted:false
                                                        SSDEEP:192:whvyorAI60xMN+RPKFjkRYsxfDcUC37XBYCp0nsAXXl6ST7OEvphTo3N+ASkX:woov6VYRPK2RhBW7KnFnbT71vpVApX
                                                        MD5:DEBDAA46FA9B6E10AED27DE24EE2ACA2
                                                        SHA1:689FEF6D3C38B7D9206351EF9CC327F14D8EB218
                                                        SHA-256:E32B2FABEE535F248EA0712399EE56644D51F366D7DD0E911FEBD5D6E4661399
                                                        SHA-512:91FA1173352BCE149BCD51AA5A8E2BD83E7EE51D2990799766C589F0A221F9B40E584810DADB81FE0DA6CBF76C24FBBA262938D4ED7315B910FB3926D2151962
                                                        Malicious:false
                                                        Preview:%PDF-1.4.%......57 0 obj.<</Linearized 1/L 19946/O 59/E 12273/N 2/T 18759/H [ 876 234]>>.endobj. ..xref..57 29..0000000016 00000 n..0000001277 00000 n..0000001550 00000 n..0000001857 00000 n..0000001903 00000 n..0000002055 00000 n..0000002206 00000 n..0000002360 00000 n..0000002513 00000 n..0000002868 00000 n..0000003405 00000 n..0000003440 00000 n..0000003664 00000 n..0000003741 00000 n..0000004440 00000 n..0000005106 00000 n..0000005764 00000 n..0000006442 00000 n..0000007111 00000 n..0000007763 00000 n..0000008412 00000 n..0000009031 00000 n..0000009113 00000 n..0000009172 00000 n..0000009268 00000 n..0000009350 00000 n..0000012043 00000 n..0000001110 00000 n..0000000876 00000 n..trailer..<</Size 86/Prev 18748/XRefStm 1110/Root 58 0 R/Info 8 0 R/ID[<1D958F9B8FD7BBC559347176370C0332><4F50F4A85B5DC14C8B0BCCEE769683E3>]>>..startxref..0..%%EOF.. ..85 0 obj.<</Length 141/C 145/Filter/FlateDecode/I 172/L 129/S 63>>stream..x.b```b``Ua`e``.....|.,`..a......Q.*......D..P..
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PDF document, version 1.4, 7 pages
                                                        Category:dropped
                                                        Size (bytes):87455
                                                        Entropy (8bit):7.511352220537533
                                                        Encrypted:false
                                                        SSDEEP:1536:NTQj5sse41FO+SwhKL3FE0A8j1vOACba3Vu7BI6ycCO:xWsa1FOxwhKCutCbsDm
                                                        MD5:B30499A30F109A5350C2DEE4FBAF4A80
                                                        SHA1:DC2BC48D58824BD2401D44A8A0E0A14EC33FA4B7
                                                        SHA-256:67B3B10AD95654D74943B9987FF8983076AC5366826B847863E8AC844AB20241
                                                        SHA-512:BBE7B55C21FFD69D1446FFE75320DB1979EA97FD5C00CDBEB87A3FB89D47C46239F3E3710B9FAB18EFA1F19BB196769B7ED2F887DBE0595E51E63C36D0F77C17
                                                        Malicious:false
                                                        Preview:%PDF-1.4.%......237 0 obj.<</Linearized 1/L 80772/O 239/E 21383/N 7/T 75984/H [ 953 357]>>.endobj. ..xref..237 32..0000000016 00000 n..0000001491 00000 n..0000001750 00000 n..0000002109 00000 n..0000002136 00000 n..0000002290 00000 n..0000002713 00000 n..0000003239 00000 n..0000003534 00000 n..0000003747 00000 n..0000003881 00000 n..0000003918 00000 n..0000004143 00000 n..0000004400 00000 n..0000004631 00000 n..0000004953 00000 n..0000005031 00000 n..0000005275 00000 n..0000006409 00000 n..0000007413 00000 n..0000008407 00000 n..0000009465 00000 n..0000010570 00000 n..0000011608 00000 n..0000012501 00000 n..0000013491 00000 n..0000016185 00000 n..0000020811 00000 n..0000021043 00000 n..0000021286 00000 n..0000001310 00000 n..0000000953 00000 n..trailer..<</Size 269/Prev 75972/XRefStm 1310/Root 238 0 R/Info 35 0 R/ID[<6D7C101A30A96D7E1618E15BC360ACC0><D6D8D4DCBEE58248BA1610F2767B1D08>]>>..startxref..0..%%EOF.. ..268 0 obj.<</Length 262/C 280/Filter/FlateDecod
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):24
                                                        Entropy (8bit):3.66829583405449
                                                        Encrypted:false
                                                        SSDEEP:3:xWv7P89qGyyn:xWDI0yn
                                                        MD5:3DE6078BED5FCFF5C7614765D3A8BF41
                                                        SHA1:89533A2734BC5BF9E8C13A99A87C71FFC905A277
                                                        SHA-256:CB8E500BF0C6496DCACB08B1C73D837AC2ABABCD3C3F53A27D8044B5C21BD6FB
                                                        SHA-512:804E917D148A39A81F652E7A921C07D5780F9817F06527B65FB746880CEDA6EA20B7CA13C00C463C3282F4DCD47796BBB63208198DDC2D53206571CFABA2F186
                                                        Malicious:false
                                                        Preview:Gloss..FS..Automatic....
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):33
                                                        Entropy (8bit):3.725916088924304
                                                        Encrypted:false
                                                        SSDEEP:3:fkkEK5qGykEK5qGy4:Fj50S504
                                                        MD5:7A2B7CDD27F7BEA214BED403D668AD85
                                                        SHA1:A33B230DEF0B11BDEABB74826947EB4634372D34
                                                        SHA-256:729FC4EB898C3B72A11B25FCB99ED273974727A2B7BD79CAD18E8444FF4F424F
                                                        SHA-512:E5E8723392E6B6424A04C05E747D380A5982048817FA381078646084CC22C6645D1E7E0096AA767A55BF12D8B4820F7F6192D012CDD0B3F246F6FF0899E0D17A
                                                        Malicious:false
                                                        Preview:Async..Automatic..Automatic..-1..
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):36864
                                                        Entropy (8bit):3.8165661949140977
                                                        Encrypted:false
                                                        SSDEEP:384:9jC3eTWyIFosDa/vlxt9tDrduf0VpNp18f511s:9jC3JoQAvlxt9tlu5f53s
                                                        MD5:4D3C78607BC9E755F6858908D60EEBFD
                                                        SHA1:F5BE2D60247144E7EED4FD134D639CC7474885F8
                                                        SHA-256:B2DEE51965E525ADAC259C3DB05502E2B39AE680ED5B932B43B892E93172D9F8
                                                        SHA-512:B8CFC165DBE088882611A4C9DA6375BAD618E8BC1D8A2D05DB8BE6F2FFF57CDA4F57AA5DEAE91D1799446318F49B86F92D499FB078896975E5D6F92F656ABE3F
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Q..J...........!.....`... ......^u... ........@.. ....................................@..................................u..K.................................................................................... ............... ..H............text...dU... ...`.................. ..`.rsrc................p..............@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                        Category:dropped
                                                        Size (bytes):46946
                                                        Entropy (8bit):3.3359468111006785
                                                        Encrypted:false
                                                        SSDEEP:384:JEsQs4DUp+W3Ntej26mgz10JUOWJgxqWvnOSc9bwBV7UBSIUW+ylWzSEgF0D3cFH:XQs4DUw3nIrxqd5+WlaSEzJT0gC5EoF
                                                        MD5:9685ACF73103944FE25865E415527B50
                                                        SHA1:EB2F9306C7BB1AF72D0A1A8EE8D04CE74407518E
                                                        SHA-256:B6B6A2A5F0E362B0C466A7DB0AF9561AB0A4B3EC306A67277E6F914CED338033
                                                        SHA-512:479FE196FEC940B9AEA0CF2686A098878DA10C9B059066906B3E237040AB9BC8A253166C263AF0CD435EE7B3B37DAD5EA0BA68D9891CF2DAB192597C1F7E1DB5
                                                        Malicious:false
                                                        Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f3\froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}..{\f37\fswiss\fcharset0\fprq2{\*\panose 00000000000000000000}Verdana;}{\f38\froman\fcharset238\fprq2 Times New Roman CE;}{\f39\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f41\froman\fcharset161\fprq2 Times New Roman Greek;}..{\f42\froman\fcharset162\fprq2 Times New Roman Tur;}{\f43\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}{\f44\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f45\froman\fcharset186\fprq2 Times New Roman Baltic;}..{\f46\froman\fcharset163\fprq2 Times New Roman (Vietnamese);}{\f408\fswiss\fcharset238\fprq2 Verdana CE;}{\f409\fswiss\fcharset204\fprq2 Verdana Cyr;}{\f411\fswiss\fcharset161\fprq2 Verdana Greek;}{\f412\fswiss\fcharset162\fprq2 Verdana Tur;}..{\f415\fswiss\fc
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):57344
                                                        Entropy (8bit):4.58838400562351
                                                        Encrypted:false
                                                        SSDEEP:768:+Vdd7DtJvhdoLHGOYGUT+iRgvLtVRSI5DeemzHTHfdy:+Vdd7JqDgJjRgvZjo8
                                                        MD5:19D28CA38BCA0524E3CE03DC06BC28F6
                                                        SHA1:183EE1BB6376C4C7D425ED84E62A0A149242F643
                                                        SHA-256:595029B4E4B93A71D3976FFED024B26A14D4842197B8BBA51E45F851E80BA603
                                                        SHA-512:18498308908DDB4DB57EB0ADBF1B8E5ADFA7F60E72C526B53BB601DCD190AE60D0B9E49F6CB1C394AF3DF3E76D235F3962B1969DD2289BB6A648F9826FCE75A0
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Q..J...........!......... ......>.... ........@.. ....................... ............@.....................................W.......`............................................................................ ............... ..H............text...D.... ...................... ..`.rsrc...`...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):33
                                                        Entropy (8bit):3.5330516047849017
                                                        Encrypted:false
                                                        SSDEEP:3:VRHUK5qGykEK5qGyCvn:7HT50S50Cv
                                                        MD5:C30127ECD70103C4C68316D4AC965072
                                                        SHA1:1AF143AD64EBFB3453B5861B5916EA79E8A2412A
                                                        SHA-256:4F159DA310F2847B4619EB9D2A535E8CF7491A68214CFEA0542E151C4E295335
                                                        SHA-512:4F5C34319886D765AC1B5F0D0F26EE526A119B3D414452C7E7927E886FC0855FF8929151B03B95774558C26F23037DBF14D49DDC626B847A4B99153EFF0071B6
                                                        Malicious:false
                                                        Preview:Tastic..Automatic..Automatic..0..
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (451), with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):9353
                                                        Entropy (8bit):5.162537937853746
                                                        Encrypted:false
                                                        SSDEEP:96:aPW241jhaSk18qT/1tYcAe3vyQkWkznkO22k4EskmjRPk4kmXukAkwlkcM8SkHD:aew84rYcAeQHzkO2nTb9m/VwW14HD
                                                        MD5:AB6AFB952049EFC33CD6A3B6736AB813
                                                        SHA1:22A40350E635806D08DEDD0DF720B0D90F61AE0F
                                                        SHA-256:DDD17A7CF4D2E6FB057239A80B6932E77FD276FB9704ED4AADCA23E8F9E7902A
                                                        SHA-512:F9F497AC9A34EB985D855D23C6698505DD2BD07568D1384E61DEBEA4FDE079FA2F50DC7E553B4CA1059C54C07AF847C977992A4F5F05F8D158560CA214DFFF52
                                                        Malicious:false
                                                        Preview:.<?xml version="1.0" encoding="utf-8"?>..<asmv1:assembly manifestVersion="1.0" xsi:schemaLocation="urn:schemas-microsoft-com:asm.v1 assembly.adaptive.xsd" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" xmlns="urn:schemas-microsoft-com:asm.v2" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns:co.v1="urn:schemas-microsoft-com:clickonce.v1">.. <asmv1:assemblyIdentity name="RadProCalculator.exe" version="3.0.4.0" publicKeyToken="0000000000000000" language="neutral" processorArchitecture="x86" type="win32" />.. <description asmv2:iconFile="transparent.ico" xmlns="urn:schemas-microsoft-com:asm.v1" />.. <application />.. <entryPoint>.. <assemblyIdentity name="RadProCalculator" version="2.0.3582.33751" language="neutral" processorArchitecture="x86" />.. <commandLine file="RadProCalculator.exe" parameters="" />.. </entryPoint>.. <t
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                        Category:dropped
                                                        Size (bytes):7530
                                                        Entropy (8bit):5.004268990470405
                                                        Encrypted:false
                                                        SSDEEP:96:r3Du7xf0SQntFNbihHjm6nv+FwVUHElcTJkJWA6EB:rqd9qFwHjJnpKklXB6EB
                                                        MD5:B26C9B2A0F2CAAE33934CBE7A43620AC
                                                        SHA1:8ED8D505FF3640B644D5AD738C2BCC4DAECA1E29
                                                        SHA-256:A817F32F7D7EC6A966CABA9D5094852EA2A2215E834C6A0E539FCFC022EEA0E8
                                                        SHA-512:7E07C121551B075034459B43A6B18F319C7971B78032D1A18E2CA75CDD09F273D0C1347338805A2F7BDD9CC04390BFC78875E12E997AD7A53A0643DB0B5A57AC
                                                        Malicious:false
                                                        Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f37\fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Verdana;}{\f258\froman\fcharset238\fprq2 Times New Roman CE;}..{\f259\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f261\froman\fcharset161\fprq2 Times New Roman Greek;}{\f262\froman\fcharset162\fprq2 Times New Roman Tur;}{\f263\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}..{\f264\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f265\froman\fcharset186\fprq2 Times New Roman Baltic;}{\f266\froman\fcharset163\fprq2 Times New Roman (Vietnamese);}{\f628\fswiss\fcharset238\fprq2 Verdana CE;}..{\f629\fswiss\fcharset204\fprq2 Verdana Cyr;}{\f631\fswiss\fcharset161\fprq2 Verdana Greek;}{\f632\fswiss\fcharset162\fprq2 Verdana Tur;}{\f635\fswiss\fcharset186\fprq2 Verdana Baltic;}{\f636\fswiss\fcharset163\fpr
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):1487872
                                                        Entropy (8bit):6.0333692770512695
                                                        Encrypted:false
                                                        SSDEEP:24576:6xpxRQj5iqaPI5EJPMZ5EJPMlzhqyE/FLCjHmRQj5iq6x3:6xpxRQj5iqaPI5EJPMZ5EJPMlzhqyE/z
                                                        MD5:C310ACA087B8EC58FF5DD4E371996EE7
                                                        SHA1:ED31BCCE307F115FEBA76DF09A46BE11F4C8B0E8
                                                        SHA-256:6DF34EBAF0D3F1021C1A38C47B45B5EEBF03712AF9C8CEBC1DEAD4EA3C81E0F1
                                                        SHA-512:E0725AE19AB6825E9E3978CB42ACF466BED57B16081812D75E86EDCED55AD14D1D1A83784990C2D79C88B66DE00B3A41B10B491CBE1FFADCA27AC73A2183CE44
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......J................................. ........@.. ....................... ............@.................................\...O.................................................................................... ............... ..H............text........ ...................... ..`.sdata..............................@....rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                        Category:dropped
                                                        Size (bytes):18126
                                                        Entropy (8bit):5.109763243900801
                                                        Encrypted:false
                                                        SSDEEP:384:PkLdTDn9FoIQn15b+nQBMxlQmsChQcrCz/4QhQGbQHQ0pdVjr7yY+TGENryZok:8JTDn9FoIQn15b+nQBMrQmRhQcrCz/4H
                                                        MD5:86353F4D9CD7544EA41157DEFBB1A5C2
                                                        SHA1:7BD6658A2E07E62382E1653BB8CED5C3FD74B86A
                                                        SHA-256:D913C560ABD241223783D8DD024F36CFC467F124BA761F6647A36DA14ADCD54C
                                                        SHA-512:E78BF661E1EFE27FD119D08986C0CD59ED7F5A94FB9B0308590BA26AF047D3382ACD7B7002AE63F0A0F8CE54169DD97436F424E8483CFA1455EF70F4E1441B73
                                                        Malicious:false
                                                        Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f37\fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Verdana;}{\f260\froman\fcharset238\fprq2 Times New Roman CE;}..{\f261\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f263\froman\fcharset161\fprq2 Times New Roman Greek;}{\f264\froman\fcharset162\fprq2 Times New Roman Tur;}{\f265\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}..{\f266\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f267\froman\fcharset186\fprq2 Times New Roman Baltic;}{\f268\froman\fcharset163\fprq2 Times New Roman (Vietnamese);}{\f630\fswiss\fcharset238\fprq2 Verdana CE;}..{\f631\fswiss\fcharset204\fprq2 Verdana Cyr;}{\f633\fswiss\fcharset161\fprq2 Verdana Greek;}{\f634\fswiss\fcharset162\fprq2 Verdana Tur;}{\f637\fswiss\fcharset186\fprq2 Verdana Baltic;}{\f638\fswiss\fcharset163\fpr
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):1273856
                                                        Entropy (8bit):5.565554258166864
                                                        Encrypted:false
                                                        SSDEEP:24576:RFyEB8ZXrGoIhyNnUTt7A9H4Vs+wVMKP4eMuET1a/2b/KdGe+fDh9Nc5CZKGMJAe:RFyEB8ZXrGoIhyNnUTt7A9H4Vs+wVMKd
                                                        MD5:BA8DF85FA959E65ABAF479D17F2D9669
                                                        SHA1:ED76117D7E3E8326A2D3C9F9E547E1017DE2AE38
                                                        SHA-256:BCD428CC0F2924711BD8536E6D69F6AFF292F573A07FAB2C18F60047B922BAF4
                                                        SHA-512:A3E540C5C2141F89D898DB249AF9D8E036C39EA8E163D6C4EE1EB8BAC66EBFEDA57B2E4BDBAD36A58C0B1772418D20CA389C1411BB86CE51346BA8E343784242
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..J...........!.....@... .......]... ...`....@.. ....................................@.................................8]..S....`............................................................................... ............... ..H............text....=... ...@.................. ..`.rsrc........`.......P..............@..@.reloc...............`..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):124
                                                        Entropy (8bit):4.607805868545925
                                                        Encrypted:false
                                                        SSDEEP:3:JLWMNHUz6Gbf/FZ4ovK9PBp1oFZqgGMaZTtgGM8Xbn:JiMV06Gbf/BK9Zp1teafgp8Xbn
                                                        MD5:D8E56217B56327343E193BC5138CB62C
                                                        SHA1:3CC70F75DA261102A6EF09D22400BE030D0C4084
                                                        SHA-256:58727BBFB115512B8659417375E0A096C20C0EABD1541FDBD04DC8FDE8F5584F
                                                        SHA-512:866BFC9AB9B7A164F873E07ED8D9E734B4F0C0EB9DBE5A1C6F11D0B601C7618C333C3623B7512EAB345C54B311D28844CD204CD5675A14793C1937EAA6BD178A
                                                        Malicious:false
                                                        Preview:.<?xml version="1.0"?>..<doc>..<assembly>..<name>..RadProCalculator..</name>..</assembly>..<members>....</members>..</doc>
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (497), with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):1601
                                                        Entropy (8bit):5.212138340599378
                                                        Encrypted:false
                                                        SSDEEP:48:3B9otZq1jw87sgazlbxikgXn6N0kkQdW3Tw:xWtZq1jszlbIHSkO
                                                        MD5:C4EC2DC6FFB60E09D9EA5E2EB98E22CF
                                                        SHA1:3451374CC5530708B00AC6A438D32612455B4208
                                                        SHA-256:BE3D2A1DE3C90F1E0C9323CEA95AE2A83908AAE0787A0232951C82871E3E6E69
                                                        SHA-512:0B44CA555CD9F56A2D46D33068E362F9F32C449EABC90117CEB84B49DF098967C455884AEA7A56F22983A2AE151EA547BEF97438DCF75BC0F325D1CEF9BC32AC
                                                        Malicious:false
                                                        Preview:.<?xml version="1.0" encoding="utf-8"?>..<asmv1:assembly xsi:schemaLocation="urn:schemas-microsoft-com:asm.v1 assembly.adaptive.xsd" manifestVersion="1.0" xmlns:asmv3="urn:schemas-microsoft-com:asm.v3" xmlns:dsig="http://www.w3.org/2000/09/xmldsig#" xmlns:co.v1="urn:schemas-microsoft-com:clickonce.v1" xmlns="urn:schemas-microsoft-com:asm.v2" xmlns:asmv1="urn:schemas-microsoft-com:asm.v1" xmlns:asmv2="urn:schemas-microsoft-com:asm.v2" xmlns:xrml="urn:mpeg:mpeg21:2003:01-REL-R-NS" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">.. <assemblyIdentity name="RadProCalculator.application" version="3.0.4.0" publicKeyToken="0000000000000000" language="neutral" processorArchitecture="x86" xmlns="urn:schemas-microsoft-com:asm.v1" />.. <description asmv2:publisher="Microsoft" asmv2:product="RadProCalculator" xmlns="urn:schemas-microsoft-com:asm.v1" />.. <deployment install="true" mapFileExtensions="true" />.. <dependency>.. <dependentAssembly dependencyType="install" codebase="RadPr
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):33
                                                        Entropy (8bit):3.725916088924304
                                                        Encrypted:false
                                                        SSDEEP:3:fkkEK5qGykEK5qGy4:Fj50S504
                                                        MD5:7A2B7CDD27F7BEA214BED403D668AD85
                                                        SHA1:A33B230DEF0B11BDEABB74826947EB4634372D34
                                                        SHA-256:729FC4EB898C3B72A11B25FCB99ED273974727A2B7BD79CAD18E8444FF4F424F
                                                        SHA-512:E5E8723392E6B6424A04C05E747D380A5982048817FA381078646084CC22C6645D1E7E0096AA767A55BF12D8B4820F7F6192D012CDD0B3F246F6FF0899E0D17A
                                                        Malicious:false
                                                        Preview:Async..Automatic..Automatic..-1..
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:MSVC program database ver 7.00, 512*1287 bytes
                                                        Category:dropped
                                                        Size (bytes):658944
                                                        Entropy (8bit):4.958716677664873
                                                        Encrypted:false
                                                        SSDEEP:6144:fCUGdqZ6DSmGbYez+bJO9A7rz0Xx24cAR82J5exZQQYXK13QVI89NTHo5u9tJ:fCLd5DSmoSjkx24ce5GQq3IIs+0
                                                        MD5:37AAE4439924CC2849271121740F9F6F
                                                        SHA1:2DB2CE7E0C618F143751419B47674D88D04ABA4E
                                                        SHA-256:F4A24D18AFCB543B736FAB0426091562075BF5CD2BB84D2994C9C04374AD4674
                                                        SHA-512:E051D2C57F53F971BC9887BC91D0D30FB3E10F7888D6845A77F309CCCEC78113CF17034682CE03F1349AEE2D6D8536C9D271F4D6881855D20B154FA5A1F39CF4
                                                        Malicious:false
                                                        Preview:Microsoft C/C++ MSF 7.00...DS...............P...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 5.1, Code page: 1252, Title: Basic Shielding Formula:, Author: Ray, Template: Normal.dot, Last Saved By: Ray, Revision Number: 24, Name of Creating Application: Microsoft Office Word, Total Editing Time: 10:33:00, Last Printed: Thu May 3 03:21:00 2007, Create Time/Date: Sat Jan 27 04:07:00 2007, Last Saved Time/Date: Sun Aug 5 23:41:00 2007, Number of Pages: 1, Number of Words: 1337, Number of Characters: 6958, Security: 0
                                                        Category:dropped
                                                        Size (bytes):94208
                                                        Entropy (8bit):6.095271828284225
                                                        Encrypted:false
                                                        SSDEEP:1536:7SOo+QxzweYvD2h1fD7vAkIfRj4vZJVzP3pByzJpXw:7LotxzPYvqLfD7vAk8NiNzhBy16
                                                        MD5:322F4603A4BB66C13FB1DCF464314891
                                                        SHA1:ED767EE3268386EC3A98ADE989F45CD028CA56AD
                                                        SHA-256:E39A82EAD6EDA485D54D60921CC593C40AC8503569E0DDD1AFD69E970C05729F
                                                        SHA-512:AD81D0399B3AA2C94E30089FFA91E850FD3D1E274B63CF7B2147D83CAF60B2A121C490E3049A700535792720C4DEFDDDA03C70E9BAFCAD3FE17B2C72EFB1C21B
                                                        Malicious:false
                                                        Preview:......................>.......................3...........5...............2...J..................................................................................................................................................................................................................................................................................................................................................................................................................................................#`.......................Q....bjbj...........................R..........g ................................................................................$.......$...$.......$.......$.......$.......$...4...........X.......@.......@.......@.......@...l.......,...X........(..\.......~...b ......b ......b ......b ......=!..>...{!.......!.......'.......'.......'.......'.......'.......'.......'..$....)..h...g,..f....(..Q...................$........#......................=!......=!....
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                        Category:dropped
                                                        Size (bytes):7520
                                                        Entropy (8bit):5.0048786924553825
                                                        Encrypted:false
                                                        SSDEEP:96:r3Du7xf0S9ntkCgbihHjm6nv+FwZU0gElcTJkJWA6EB:rqd97kCrHjJnpuClXB6EB
                                                        MD5:E9B2694D7C93EEF275ADDB7424E74583
                                                        SHA1:D1A72FA83587015D14612EC8CA8D646C5C79C8EC
                                                        SHA-256:B71F02B1A0E66BA16ED490FF0897D532810B3D47788A8005BF7040D32695171B
                                                        SHA-512:5EA6E43D01CB90013F01CB0BDEE5C9AE06024807C27F53B181628624A0729414A31B85B02F2995FDF5EC9B0F7B8431898E47BBC3694BE6C0446D7B1678D4AFFE
                                                        Malicious:false
                                                        Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f37\fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Verdana;}{\f258\froman\fcharset238\fprq2 Times New Roman CE;}..{\f259\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f261\froman\fcharset161\fprq2 Times New Roman Greek;}{\f262\froman\fcharset162\fprq2 Times New Roman Tur;}{\f263\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}..{\f264\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f265\froman\fcharset186\fprq2 Times New Roman Baltic;}{\f266\froman\fcharset163\fprq2 Times New Roman (Vietnamese);}{\f628\fswiss\fcharset238\fprq2 Verdana CE;}..{\f629\fswiss\fcharset204\fprq2 Verdana Cyr;}{\f631\fswiss\fcharset161\fprq2 Verdana Greek;}{\f632\fswiss\fcharset162\fprq2 Verdana Tur;}{\f635\fswiss\fcharset186\fprq2 Verdana Baltic;}{\f636\fswiss\fcharset163\fpr
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Rich Text Format data, version 1, ANSI, code page 1252, default middle east language ID 1025
                                                        Category:dropped
                                                        Size (bytes):6493
                                                        Entropy (8bit):5.040598158588747
                                                        Encrypted:false
                                                        SSDEEP:96:Gw6T7xfGS8aiQZwjm6nv+Fw20+TJcT7EMF0Ihy8fqQ:GxdT80ZwjJnp2+DN
                                                        MD5:D0E89EDAD44444D9E3B5625D15EFA27C
                                                        SHA1:CB880EACA1DA687BC695B912C66733743DC5C056
                                                        SHA-256:F4DB731F373361B92E0C9EA0F95DD23E439333E1414987B70B6B88F870D31E8E
                                                        SHA-512:BDFCA693520BFA9232B523BD6F7E96AC831400661F124875133C02FB152B5009D0B8BB6916CBF1D403C710EB12ACDC114A3B0D8EB403D0855D521DAD18D6AF3A
                                                        Malicious:false
                                                        Preview:{\rtf1\adeflang1025\ansi\ansicpg1252\uc1\adeff0\deff0\stshfdbch0\stshfloch0\stshfhich0\stshfbi0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f37\fswiss\fcharset0\fprq2{\*\panose 020b0604030504040204}Verdana;}{\f39\froman\fcharset238\fprq2 Times New Roman CE;}..{\f40\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f42\froman\fcharset161\fprq2 Times New Roman Greek;}{\f43\froman\fcharset162\fprq2 Times New Roman Tur;}{\f44\fbidi \froman\fcharset177\fprq2 Times New Roman (Hebrew);}..{\f45\fbidi \froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f46\froman\fcharset186\fprq2 Times New Roman Baltic;}{\f47\froman\fcharset163\fprq2 Times New Roman (Vietnamese);}{\f409\fswiss\fcharset238\fprq2 Verdana CE;}..{\f410\fswiss\fcharset204\fprq2 Verdana Cyr;}{\f412\fswiss\fcharset161\fprq2 Verdana Greek;}{\f413\fswiss\fcharset162\fprq2 Verdana Tur;}{\f416\fswiss\fcharset186\fprq2 Verdana Baltic;}{\f417\fswiss\fcharset163\fprq2 Verda
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):212992
                                                        Entropy (8bit):5.395602733383332
                                                        Encrypted:false
                                                        SSDEEP:6144:Pbmx8PaVQTOpk3iNPspKfwdujUBSnY1Wr8ZMPstK7YZmn8G1sDa5QneN5Kj0VOPs:Pbmx8PaVQTOpk3iNPspKfwdujUBSnY1k
                                                        MD5:B0C8FBE395F80BE28F1463338845EA93
                                                        SHA1:D70EEC447874E6E969839A80B165B5912081606A
                                                        SHA-256:8F421CB47471A7C44C569D1E8FE29ECB77C23D86130CE987F6E303143FC9FB69
                                                        SHA-512:1BAA385E90E418C257D9E53C5F8384220A2AB6C7B1FEC532362D35C06DA549395C2441C0067BFB389D6F95E5556E90E4D73789E6B7588955A9B47AA977B5B165
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...P..J...........!......... .......+... ...@....@.. ....................................@..................................+..O....@..x....................`....................................................... ............... ..H............text........ ...................... ..`.rsrc...x....@....... ..............@..@.reloc.......`.......0..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PDF document, version 1.4, 21 pages
                                                        Category:dropped
                                                        Size (bytes):570020
                                                        Entropy (8bit):7.87723276983166
                                                        Encrypted:false
                                                        SSDEEP:12288:TwSVsb3lwll4Jh+ubEhsrT9JE1hMAh6vim1/O4j2uadhdGJ:CNRAu39OH3hzJKavq
                                                        MD5:921FE687BEB5BF4AF19E2F389FEA2022
                                                        SHA1:06934D282A2D9B0BD28DD8CBC4CF607AABC1962F
                                                        SHA-256:02243786775BF1A3FEE3887BEE22848ECF6A0461F61ABE7BFC44C8947674D6DE
                                                        SHA-512:688DEA3E94A8743E7CF19B930E363BFDA34BFE4DA6FEB1CBE3E909999DC3D6759338C59A9B854C732223BD326DA0421E28498226E768C40B64FDA208424554B2
                                                        Malicious:false
                                                        Preview:%PDF-1.4.%......809 0 obj.<</Linearized 1/L 570020/O 811/E 4438/N 21/T 553792/H [ 529 798]>>.endobj. ..xref..809 11..0000000016 00000 n..0000001521 00000 n..0000001801 00000 n..0000002025 00000 n..0000002481 00000 n..0000003020 00000 n..0000003251 00000 n..0000003476 00000 n..0000003554 00000 n..0000001327 00000 n..0000000529 00000 n..trailer..<</Size 820/Prev 553780/XRefStm 1327/Root 810 0 R/Info 212 0 R/ID[<CFE96803BB510FB553C65C8ADDDB5AC8><4DF5951CC2F5174EA1B447E86B90BD86>]>>..startxref..0..%%EOF.. ..819 0 obj.<</Length 697/C 718/Filter/FlateDecode/I 803/L 702/O 686/S 507>>stream..x.b```b``~....... .....l...,..K..\.&i.1.e``...|>..l..r..).....%w.=.~g:4/...././n.)S.s...NY.3.`.....FM...1MV.......3.t.MRz..T...q..5..wxi..((..c.u.t.z&..;....YXx8.u..M9]~.`#..............b.....Ew$./...$$8........h....u<./..1q-.......(.CB.._V&2..y..CB...O>dd].GB.J|........m....c.w...W.....sw......ig........}..~....@...FA.. .`......@......:....].r.......@Y.......H..1P..Hh
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):49152
                                                        Entropy (8bit):4.149890775612605
                                                        Encrypted:false
                                                        SSDEEP:768:1DXSN0rmtIvCz+5EXiN47WRhmEZTAk6RXripnP3p1dOfDr93Ybks8:1DXSN0rmtIvCz+5EXiN47WR1PoH93YbQ
                                                        MD5:C21214AF49AD124EBC065F7118D05848
                                                        SHA1:4F5506DFC759E00358FE0B8F67AF7C9A19069003
                                                        SHA-256:1A8472F3C94A830DCDB672BFF010CB4D94B5C55BD7BA2BE9304408AA425ADA40
                                                        SHA-512:C7FD27A78DAAEB0F5A16ADE8C4A20A0F0DE3AE384DBC413E38CBD30CA0973E4CBFB6E1CD840501D0201F334CEEF52B858F32CD1875AB6136A9E1C66C4391F913
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...P..J...........!......... ......>.... ........@.. ....................................@....................................W.......h............................................................................ ............... ..H............text...D.... ...................... ..`.rsrc...h...........................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):217088
                                                        Entropy (8bit):5.846221870014408
                                                        Encrypted:false
                                                        SSDEEP:6144:6kq1KNxWzzoymd65COhbnDkJNccyjozy:6kq1KjWPoy2AxngJNccyjb
                                                        MD5:6D9CDD95ACCCC1B3F0CFB95381FDA450
                                                        SHA1:427665058FFE932D14236408541D73F30658F67D
                                                        SHA-256:7EF157BC3AE1DC486CEA6E1C684022BEC90A0C721ADA90B89A730D3E9E433382
                                                        SHA-512:F453F9A51188136209D08D297CA085F97B5DD0E1E3ABE953AF2BF71D81B34722C7E7AF0FF40542C9A98418BA6369ED1255B23F402E1DD772F74DEC79BF0120E5
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...,.@I...........!..... ... .......;... ...@....@.. ....................................@..................................;..S....@.......................`....................................................... ............... ..H............text........ ... .................. ..`.rsrc........@.......0..............@..@.reloc.......`.......@..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):106496
                                                        Entropy (8bit):5.214981875407206
                                                        Encrypted:false
                                                        SSDEEP:3072:3XU6AFl93857y85zaZMhMsRkaxE/GB0wlPuJ0w1+HqLryZgDmSzH4/aIbsdvkezL:FAHqaIb2kc
                                                        MD5:E88F556A1059294CE348A42C20F8787B
                                                        SHA1:E68B0943A7D0F04C2E7B6EF08EDB1D3F1CE5ED5F
                                                        SHA-256:B7BC33B9197DA46A074971ECEAA34130D72661CBE120BF0872144BAD269A4AA2
                                                        SHA-512:FB276EC28882F43242FA768EE74C7F2ECB2D1F5E9810EF16F91F10525A6FE5B5C30CBA3F7EDEC8F37BFC10AD1B1A64BA1B865A73865860F5085AEEA35720BCE7
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...R..J...........!.....p... ........... ........@.. ....................................@.....................................S.................................................................................... ............... ..H............text....g... ...p.................. ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Revision Number: {FBE2F65D-00D5-4F6D-9B60-35D3C6EDD74F}, Number of Words: 0, Number of Pages: 200, Template: Intel;1033, Title: Rad Pro Calculator, Subject: Rad Pro Calculator Installation, Keywords: Installer, MSI, Database, Author: Rad Pro Calculator Software Development, Comments: All rights reserved, Name of Creating Application: InstallAware, Security: 0
                                                        Category:dropped
                                                        Size (bytes):284160
                                                        Entropy (8bit):6.2627372614826795
                                                        Encrypted:false
                                                        SSDEEP:3072:nTnl5XMOjH4fUBHkjyhbmz5OyV9WxCIqcyzUDWgaxZiUSGJh/Ck375V5JbeaKpXO:nrl5dH4fUBE2hbObiqs+iJlQ5kFY6
                                                        MD5:36A8A56388C62892278CAEC56CD3901A
                                                        SHA1:15ED810612130320D77ECE0189E4412D86010461
                                                        SHA-256:3C30BCE0980D4E4246C43740412F0520CFD1A10C8CD9C959D18719EE5C762B81
                                                        SHA-512:3E476791022EEA1FD72610D25705F919CEFFEBA9E1AC83AADFE1CC15E4979022E28E5CD088923ABC0DAE1542213A190E52E5BE61A4815A8B0D5E1F826EFC7A37
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................%.......................................................................(...............................V........... ...!..."...#...$...&.......'...p...)...*...+...,...-......./...0...1...2...3...4...5...6...7...8...9...:...;...<...=...>...?...@...A...B...C...D...E...F...G...H...I...J...K...L...M...N...O...P...Q...R...S...T...U...W...]...X...Y...Z...[...\.......^..._...`...t...b...c...d...e...n...g...h...i...j...k...l...m...a...o.......q...r...s...u...v...w...x...y...z...|...
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):1638400
                                                        Entropy (8bit):6.78149956490533
                                                        Encrypted:false
                                                        SSDEEP:24576:swfBQEnwy6nJRXMuv4w6g59WUw1D8waHnnTNaINZw6jT1A8CllccjMszJxckYz1k:cznJqwXfWUwd8XnTNRJKNllaUz1
                                                        MD5:CC73464126D45EC55BF908E16505EC65
                                                        SHA1:394F7A932A5AE946B74CBAB149F83DC87F52FA47
                                                        SHA-256:7FE971893502163AC9B65A9BF7AEE779B55B1B1891D3C57D39428D8AEBCA63E6
                                                        SHA-512:E21230F1AF1D895DB8513385C2F54D9E17539C6C935117678844F2E4F88FB2200242C99D00AEB950460F420A54FFC5C4722D01D7113EF03F5D39B0650541414F
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......s...7o..7o..7o...L..<o..7o..en...L..$o...L...o...L..6o...L..6o...L..(n...L..6o..Rich7o..................PE..L....=>@...........!.........`.......Q.......`.....p................................C...................................CN......x....p...........................s..x...8...............................................0............................text............................... ..`.data...P...........................@...Shared.......`.......P..............@....rsrc........p... ...`..............@..@.reloc...s..........................@..B................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):438272
                                                        Entropy (8bit):6.605226720005331
                                                        Encrypted:false
                                                        SSDEEP:6144:Wo3rpaDTVMXwQ4zB9lSZ48AeP9QrhDLHyc24FfCyVzKjsRZa8tTpMc1bq3gRvNc:WnDTmXwQg648/9e5HlFayVEOZBtVMlY
                                                        MD5:598EA39BF501C22D63AA44F2F9FF940D
                                                        SHA1:C3B69AFAD05429768CA3744E2C895EAF3A373644
                                                        SHA-256:844CB5C399364519B619E00876C45381F34A24292D2BAE10AB48082DCA4F35E0
                                                        SHA-512:7FBD686CAE04BFCF33CC6694ECF199B64B696660A4E42C8898266A159937DE47A3FD1A46CAEEA6CA304EDD444F2153CC16F33E45C7685225CE989407B341F4F0
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 7%
                                                        Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L...(..I..........................................@..........................@..........................................N....P...).......:......................._...................................................W..p............................text............................... ..`.itext..P........................... ..`.data...4...........................@....bss....TN...............................idata...)...P...*..................@....edata..N...........................@..@.rdata..............................@..@.reloc..._.......`..................@..B.rsrc....:.......:...v..............@..@.............@......................@..@................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):575060
                                                        Entropy (8bit):6.5839257495060375
                                                        Encrypted:false
                                                        SSDEEP:12288:KJRXnclmcyiDnhImJTFUcUbAxC5w5Mohq:55/Fobg6i2
                                                        MD5:CBDCAC7234BBBE0682590957087668BA
                                                        SHA1:A72307C8FFF0115C9578394D4BD424C5C3CD3B5C
                                                        SHA-256:E42B865C76B5A2F5C96E5759C4EA6D492E1DB773F98C5F57B4B0CE1EA3C52498
                                                        SHA-512:717B44298E2165E187BDD5576E74222224EF178645F23E98AE56B53994E9453BBE3D65249EC1C6852D6DF8E7404DB5D5817EE8EA7C9F24919C211235592DD17D
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........y8..k..k..k_.wk..k_..k..k_.Hk...k+..k..k.Jk..kR.Jk..k..kh..k_.tk...k_.Kk..k=.Ik..k_.Mk..kRich..k........PE..L....'.I...........!.....`...................p......................................................................0...........d................................6.....................................@............p..$............................text....^.......`.................. ..`.rdata..;f...p...p...p..............@..@.data...@........0..................@....rsrc...............................@..@.reloc...K.......P... ..............@..B................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        File Type:PC bitmap, Windows 3.x format, 465 x 281 x 24, image size 392276, resolution 3780 x 3780 px/m, cbSize 392330, bits offset 54
                                                        Category:dropped
                                                        Size (bytes):392330
                                                        Entropy (8bit):7.656424249083946
                                                        Encrypted:false
                                                        SSDEEP:6144:42aZg33M4SjCSN5Ifq4uPONNWouEYT2vsId70blilvL/YerQaJeOAuhNc:ey3846DNuSJPbTEWes6wbli1L/Yeb0O0
                                                        MD5:74615FA4CAB1FDBBCB2FD34413ACDEED
                                                        SHA1:0AF2820C71BE3B4EE7F561E2FFEC992ACFFE4C5D
                                                        SHA-256:71D2CD4AE9700B73FD2B37BFDDFC6468C8C9652F95146C4F824F92A84ACFED31
                                                        SHA-512:6571683F92C9133854AE442BCDDCB368FA2F86355A7B9A96DA832E903F3BA01908B2D87444A645FA1A0C36108C492D43E096247627EF35DD91526FA5771D5318
                                                        Malicious:false
                                                        Preview:BM........6...(...................T...................l..Jr.'Xv.Ln$Su&Tx&Uy&Vy&Vy'Xz(Y|*[~+\.)Y~%V|"Qy Px"R{%U.+[./^.0_.,\.*Y./[.5^.6`.5_.7`.6]..Qq%Fc.9R.6M.*>."6........,..+..(..%..&..). 0."2.%6.'8.*=.-D.,I.&J. H. I.%K.*O..S.1W.2X.4Z.6Z.<`#Ad&Dg#Ad$Ae(Ej%Cg!?b.0R..=.%G.KpQp.Wy.Hl.8^y'Le!B]#A^$@[$AX.;N.6H.4D.7H.8J.8L.7N.4L.Rn<t.N..D..1i.&\. Qu#Qr*Ss+Qq*Pt%My%O.+S.7[.Gj.Oq.Jj.<Yr*E\"=U.3K.1K.-J.+I..N.4S.9V.:U.8P.4L.0D.,<..;.3@.7M.)M.9hEq.e..T..+{..F`#%D!.9 .L.;U.?X!Ia)Mf)Jf!B`.?_!Dd(Hh-Gg0Gf0If+Kf&Lg!Lh!Jh"Hh!Hg Hg.Gg.Hj.Jm Lp!Ou!Qw Qy Py$T.(X.)Y.&V.#R."Q.#Q.$R.)U.,Y.0\.2\.4^.4_.8c.=h.Bl.Hp.Hn.Gk.Ad.8[.-R}.Am.4c.$T. P..F..B..7..0..6.%F'5N%4H.'5..#..".*5+=N/DZ'=T.4G.#0.. ..................................................................................................................................................................................................................................................................................................................................
                                                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                        Entropy (8bit):7.9908648731397465
                                                        TrID:
                                                        • Win32 Executable (generic) a (10002005/4) 99.96%
                                                        • Generic Win/DOS Executable (2004/3) 0.02%
                                                        • DOS Executable Generic (2002/1) 0.02%
                                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                        File name:RadProCalculator3.26_64BSetup.exe
                                                        File size:3'493'085 bytes
                                                        MD5:db2df493ed3ef51a0731e67c41c81eb1
                                                        SHA1:483f3fdba4fd84b2739a19f90a17d9c08f0559eb
                                                        SHA256:4b526c198671dbe6351021935b780a9ce582a891b1ca0eddc1b170fa762b8661
                                                        SHA512:535696b88b4554d3de328f0cabd4bf3cb54531d522630ff6c70f725aad017f7017c98c9f6325e9a2d12ef4642b6047e7c4e5570ac578f2677a644a7b726c4b40
                                                        SSDEEP:98304:GwMLUKpE5qexu87zAaJJhM5cQ3WQRw+RRx/QGC0+:GwMLUKpMqexpzA6hK/vRL439
                                                        TLSH:84F5332132E9C977C1E56C71447BAAEEF3E7EF4148709AAB3F0C4E0D9B674244866346
                                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......F...................................I...............................................<...........................Rich...........
                                                        Icon Hash:2b3173694d4d070e
                                                        Entrypoint:0x412a70
                                                        Entrypoint Section:.text
                                                        Digitally signed:false
                                                        Imagebase:0x400000
                                                        Subsystem:windows gui
                                                        Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                                                        DLL Characteristics:
                                                        Time Stamp:0x49E64705 [Wed Apr 15 20:43:49 2009 UTC]
                                                        TLS Callbacks:
                                                        CLR (.Net) Version:
                                                        OS Version Major:4
                                                        OS Version Minor:0
                                                        File Version Major:4
                                                        File Version Minor:0
                                                        Subsystem Version Major:4
                                                        Subsystem Version Minor:0
                                                        Import Hash:29f777a4c1af9bae1c88e78b8844b0f5
                                                        Instruction
                                                        push 00000060h
                                                        push 0041A2B8h
                                                        call 00007F1C14865FB5h
                                                        mov edi, 00000094h
                                                        mov eax, edi
                                                        call 00007F1C1486741Dh
                                                        mov dword ptr [ebp-18h], esp
                                                        mov esi, esp
                                                        mov dword ptr [esi], edi
                                                        push esi
                                                        call dword ptr [0041A0E8h]
                                                        mov ecx, dword ptr [esi+10h]
                                                        mov dword ptr [00420D24h], ecx
                                                        mov eax, dword ptr [esi+04h]
                                                        mov dword ptr [00420D30h], eax
                                                        mov edx, dword ptr [esi+08h]
                                                        mov dword ptr [00420D34h], edx
                                                        mov esi, dword ptr [esi+0Ch]
                                                        and esi, 00007FFFh
                                                        mov dword ptr [00420D28h], esi
                                                        cmp ecx, 02h
                                                        je 00007F1C14865BFEh
                                                        or esi, 00008000h
                                                        mov dword ptr [00420D28h], esi
                                                        shl eax, 08h
                                                        add eax, edx
                                                        mov dword ptr [00420D2Ch], eax
                                                        xor esi, esi
                                                        push esi
                                                        mov edi, dword ptr [0041A1A8h]
                                                        call edi
                                                        cmp word ptr [eax], 5A4Dh
                                                        jne 00007F1C14865C11h
                                                        mov ecx, dword ptr [eax+3Ch]
                                                        add ecx, eax
                                                        cmp dword ptr [ecx], 00004550h
                                                        jne 00007F1C14865C04h
                                                        movzx eax, word ptr [ecx+18h]
                                                        cmp eax, 0000010Bh
                                                        je 00007F1C14865C11h
                                                        cmp eax, 0000020Bh
                                                        je 00007F1C14865BF7h
                                                        mov dword ptr [ebp-1Ch], esi
                                                        jmp 00007F1C14865C19h
                                                        cmp dword ptr [ecx+00000084h], 0Eh
                                                        jbe 00007F1C14865BE4h
                                                        xor eax, eax
                                                        cmp dword ptr [ecx+000000F8h], esi
                                                        jmp 00007F1C14865C00h
                                                        cmp dword ptr [ecx+74h], 0Eh
                                                        jbe 00007F1C14865BD4h
                                                        xor eax, eax
                                                        cmp dword ptr [ecx+000000E8h], esi
                                                        setne al
                                                        mov dword ptr [ebp-1Ch], eax
                                                        Programming Language:
                                                        • [C++] VS2003 (.NET) SP1 build 6030
                                                        • [ASM] VS2003 (.NET) SP1 build 6030
                                                        • [ C ] VS2003 (.NET) SP1 build 6030
                                                        • [RES] VS2003 (.NET) build 3077
                                                        • [LNK] VS2003 (.NET) SP1 build 6030
                                                        NameVirtual AddressVirtual Size Is in Section
                                                        IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_IMPORT0x1e4240x8c.rdata
                                                        IMAGE_DIRECTORY_ENTRY_RESOURCE0x270000x2a74.rsrc
                                                        IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x1bb680x40.rdata
                                                        IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_IAT0x1a0000x24c.rdata
                                                        IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                        IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                        NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                        .text0x10000x181850x1820071b46d394c5740a746aa1aab161d1467False0.592879695595855data6.547251516505409IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                        .rdata0x1a0000x50c20x520071800784eababe5a686eb5855811f01fFalse0.32779153963414637data4.702651421056667IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                        .data0x200000x69e00xc003f34c1f7a93ef3d77d489a6b770914a9False0.3173828125data3.090463631555638IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                        .rsrc0x270000x2a740x2c00988e030c6755d5b124d4de9e4c95f1bfFalse0.3552024147727273data4.423180008056004IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                        NameRVASizeTypeLanguageCountryZLIB Complexity
                                                        RT_ICON0x272940x568Device independent bitmap graphic, 16 x 32 x 8, image size 320EnglishUnited States0.4407514450867052
                                                        RT_ICON0x277fc0x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1152EnglishUnited States0.6832129963898917
                                                        RT_DIALOG0x280a40x1d8data0.5720338983050848
                                                        RT_DIALOG0x2827c0x1bedata0.5605381165919282
                                                        RT_STRING0x2843c0x210Matlab v4 mat-file (little endian) C, numeric, rows 0, columns 0EnglishUnited States0.4053030303030303
                                                        RT_STRING0x2864c0x2fedataEnglishUnited States0.42297650130548303
                                                        RT_STRING0x2894c0x106dataEnglishUnited States0.5152671755725191
                                                        RT_GROUP_ICON0x28a540x22dataEnglishUnited States0.9411764705882353
                                                        RT_VERSION0x28a780xb88dataEnglishUnited States0.1334688346883469
                                                        RT_MANIFEST0x296000x474XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.45
                                                        DLLImport
                                                        COMCTL32.dll
                                                        KERNEL32.dllWaitForSingleObject, SetEvent, ResetEvent, WaitForMultipleObjects, CompareStringA, GetLastError, WideCharToMultiByte, MultiByteToWideChar, CompareStringW, lstrlenA, LoadLibraryA, AreFileApisANSI, GetModuleFileNameA, GetModuleFileNameW, FormatMessageA, LocalFree, FormatMessageW, SetFileAttributesA, RemoveDirectoryA, SetCurrentDirectoryA, GetWindowsDirectoryA, SetFileAttributesW, RemoveDirectoryW, CreateDirectoryA, CreateDirectoryW, DeleteFileA, DeleteFileW, GetShortPathNameW, GetShortPathNameA, GetFullPathNameA, GetFullPathNameW, GetCurrentDirectoryA, GetTempPathA, GetTempFileNameA, FindClose, FindFirstFileA, SetLastError, FindFirstFileW, FindNextFileA, CreateThread, CreateFileA, CreateFileW, GetFileSize, SetFilePointer, ReadFile, SetFileTime, WriteFile, SetEndOfFile, CreateEventA, EnterCriticalSection, LeaveCriticalSection, Sleep, GetVersionExA, GetCommandLineW, CreateProcessA, GetExitCodeProcess, IsBadReadPtr, SetUnhandledExceptionFilter, RaiseException, GetSystemInfo, VirtualProtect, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, IsBadCodePtr, LCMapStringW, LCMapStringA, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetCPInfo, GetOEMCP, GetACP, VirtualQuery, InterlockedExchange, RtlUnwind, IsBadWritePtr, VirtualAlloc, VirtualFree, CloseHandle, DeleteCriticalSection, InitializeCriticalSection, HeapCreate, HeapDestroy, TlsGetValue, TlsSetValue, TlsFree, GetCurrentThreadId, TlsAlloc, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetStdHandle, HeapSize, GetCurrentProcess, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, HeapFree, HeapAlloc, HeapReAlloc, ExitProcess, GetProcAddress, TerminateProcess
                                                        USER32.dllPostMessageA, ShowWindow, DestroyWindow, KillTimer, SetTimer, SetDlgItemTextA, EndDialog, IsDlgButtonChecked, GetDlgItem, MessageBoxW, DialogBoxParamA, GetDesktopWindow, SetForegroundWindow, SetWindowLongA, SetWindowTextW, GetWindowTextA, GetWindowTextLengthA, SetWindowTextA, SendMessageA, LoadStringW, LoadStringA, CharPrevA, GetWindowLongA
                                                        ADVAPI32.dllRegCreateKeyExA, RegCloseKey, RegSetValueExA
                                                        ole32.dllCoCreateInstance, CoInitialize
                                                        OLEAUT32.dllVariantClear, SysAllocString, SysFreeString
                                                        Language of compilation systemCountry where language is spokenMap
                                                        EnglishUnited States
                                                        No network behavior found

                                                        Click to jump to process

                                                        Click to jump to process

                                                        Click to dive into process behavior distribution

                                                        Click to jump to process

                                                        Target ID:0
                                                        Start time:11:34:31
                                                        Start date:02/10/2024
                                                        Path:C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe
                                                        Wow64 process (32bit):true
                                                        Commandline:"C:\Users\user\Desktop\RadProCalculator3.26_64BSetup.exe"
                                                        Imagebase:0x400000
                                                        File size:3'493'085 bytes
                                                        MD5 hash:DB2DF493ED3EF51A0731E67C41C81EB1
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:low
                                                        Has exited:false

                                                        Target ID:2
                                                        Start time:11:34:34
                                                        Start date:02/10/2024
                                                        Path:C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe
                                                        Wow64 process (32bit):true
                                                        Commandline:.\RadProCalculator3.26_64BSetup.exe /m="C:\Users\user\Desktop\RADPRO~1.EXE" /k=""
                                                        Imagebase:0x400000
                                                        File size:2'706'359 bytes
                                                        MD5 hash:C82B11E5425B91A31672CEEC8E0F37A0
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:Borland Delphi
                                                        Yara matches:
                                                        • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: 00000002.00000000.2209437928.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Author: Joe Security
                                                        • Rule: JoeSecurity_DelphiSystemParamCount, Description: Detected Delphi use of System.ParamCount(), Source: C:\Users\user\AppData\Local\Temp\mia400B.tmp\RadProCalculator3.26_64BSetup.exe, Author: Joe Security
                                                        Antivirus matches:
                                                        • Detection: 7%, ReversingLabs
                                                        Reputation:low
                                                        Has exited:false

                                                        No disassembly