Click to jump to signature section
Source: Cleaning_Tool_for_Driver_Select1.17.exe | Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
Source: | Binary string: C:\work\Legacy_DriverSelect\DriverSelect\tango_setup\CleaningTool\OceCleaningTool\Release\CleaningTool.pdby source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004860000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr |
Source: | Binary string: C:\work\Legacy_DriverSelect\DriverSelect\tango_setup\CleaningTool\OceCleaningTool\Release\CleaningTool.pdb source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004860000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0 |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0 |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0 |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0 |
Source: DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0 |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0= |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://ocsp.digicert.com0 |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://ocsp.digicert.com0A |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://ocsp.digicert.com0C |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://ocsp.digicert.com0X |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr | String found in binary or memory: http://www.digicert.com/CPS0 |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004B70000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameCleaningToolH vs Cleaning_Tool_for_Driver_Select1.17.exe |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000002.1399345496.000000000043A000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFilename7z.sfx.exe, vs Cleaning_Tool_for_Driver_Select1.17.exe |
Source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFilenameCleaningToolH vs Cleaning_Tool_for_Driver_Select1.17.exe |
Source: Cleaning_Tool_for_Driver_Select1.17.exe | Binary or memory string: OriginalFilename7z.sfx.exe, vs Cleaning_Tool_for_Driver_Select1.17.exe |
Source: Cleaning_Tool_for_Driver_Select1.17.exe | Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, LARGE_ADDRESS_AWARE, 32BIT_MACHINE |
Source: classification engine | Classification label: clean2.winEXE@1/2@0/0 |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | File created: C:\Users\user\Desktop\DriverSelect_CleaningTool.pdf | Jump to behavior |
Source: Cleaning_Tool_for_Driver_Select1.17.exe | Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | File read: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: explorerframe.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32 | Jump to behavior |
Source: Cleaning_Tool_for_Driver_Select1.17.exe | Static file information: File size 3557750 > 1048576 |
Source: | Binary string: C:\work\Legacy_DriverSelect\DriverSelect\tango_setup\CleaningTool\OceCleaningTool\Release\CleaningTool.pdby source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004860000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr |
Source: | Binary string: C:\work\Legacy_DriverSelect\DriverSelect\tango_setup\CleaningTool\OceCleaningTool\Release\CleaningTool.pdb source: Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1397923680.00000000047F0000.00000004.00001000.00020000.00000000.sdmp, Cleaning_Tool_for_Driver_Select1.17.exe, 00000001.00000003.1398106012.0000000004860000.00000004.00001000.00020000.00000000.sdmp, DriverSelect_CleaningTool.exe.1.dr |
Source: Cleaning_Tool_for_Driver_Select1.17.exe | Static PE information: section name: .sxdata |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | File created: C:\Users\user\Desktop\DriverSelect_CleaningTool.exe | Jump to dropped file |
Source: C:\Users\user\Desktop\Cleaning_Tool_for_Driver_Select1.17.exe | Dropped PE file which has not been started: C:\Users\user\Desktop\DriverSelect_CleaningTool.exe | Jump to dropped file |