Windows Analysis Report
PSI-CONF_Setup_v2.76.exe

Overview

General Information

Sample name: PSI-CONF_Setup_v2.76.exe
Analysis ID: 1528774
MD5: 4bf5ec6ea419625fd7fbc9d7df84b5f4
SHA1: 4f530013dcc3d2393abb006ca66834f558036c89
SHA256: 9162049d459e334a9721e7e770bf2e1e64d60ebccfbf43d727e8975db6c9df00
Infos:

Detection

Score: 24
Range: 0 - 100
Whitelisted: false
Confidence: 0%

Compliance

Score: 47
Range: 0 - 100

Signatures

Installs new ROOT certificates
Sigma detected: Dot net compiler compiles file from suspicious location
Adds / modifies Windows certificates
Allocates memory with a write watch (potentially for evading sandboxes)
Compiles C# or VB.Net code
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates driver files
Creates files inside the driver directory
Creates files inside the system directory
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops certificate files (DER)
Drops files with a non-matching file extension (content does not match file extension)
Enables driver privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found potential string decryption / allocating functions
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Sleep loop found (likely to delay execution)
Stores files to the Windows start menu directory
Stores large binary data to the registry
Uses 32bit PE files
Uses cacls to modify the permissions of files
Uses code obfuscation techniques (call, push, ret)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)

Classification

Compliance

barindex
Source: PSI-CONF_Setup_v2.76.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\ProgramData\Phoenix Contact\PSIConfSoftware\SetupLog.txt Jump to behavior
Source: PSI-CONF_Setup_v2.76.exe Static PE information: certificate valid
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe File opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dll
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData Jump to behavior
Source: irsetup.exe, 00000002.00000002.2847956855.0000000004D09000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2826847095.0000000004CFA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.indigorose.com
Source: irsetup.exe, 00000002.00000002.2847956855.0000000004D09000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2826847095.0000000004CFA000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.indigorose.comERROR:
Source: irsetup.exe, 00000002.00000003.2826640586.00000000044A5000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2826600914.00000000044B9000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2837708313.000000000441E000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2840976065.0000000004426000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2826509562.0000000004753000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2842645729.000000000442D000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2828366742.0000000004453000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2837620517.0000000004406000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2828456225.0000000004466000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2841318428.0000000004426000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2841359508.0000000004429000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.phoenixcontact.com/
Source: irsetup.exe, 00000002.00000003.2841085831.0000000004474000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2828743366.000000000446C000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2828671762.0000000004468000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2828415199.000000000445D000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2828366742.0000000004453000.00000004.00000020.00020000.00000000.sdmp, irsetup.exe, 00000002.00000003.2828456225.0000000004466000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.phoenixcontact.com/EditField)_0
Source: irsetup.exe, 00000002.00000003.2825182735.00000000052F0000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: https://select.phoenixcontact.com/phoenix/dwl/dwl01.jsp?from=psiconf&file=
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\SET152A.tmp Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\SET18A5.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\slabvcp.cat Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\slabvcp.cat (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\slabvcp.cat Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x64\silabenm.sys Jump to behavior
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Windows\INF\oem0.PNF Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Windows\INF\oem1.PNF Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Windows\INF\oem3.PNF Jump to behavior
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\FileRepository\slabvcp.inf_amd64_d5d1b7de54203434 Jump to behavior
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\FileRepository\slabvcp.inf_amd64_d5d1b7de54203434\x64 Jump to behavior
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\drvstore.tmp Jump to behavior
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\inf\oem4.inf Jump to behavior
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe File created: C:\Windows\assembly\Desktop.ini
Source: C:\Windows\System32\drvinst.exe File deleted: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET17E6.tmp Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_0040525A 0_2_0040525A
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00403FB0 0_2_00403FB0
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ADE22 2_3_006ADE22
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006ABBEA 2_3_006ABBEA
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: 12_2_00007FF848F62825 12_2_00007FF848F62825
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: 12_2_00007FF848F73B3E 12_2_00007FF848F73B3E
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: 12_2_00007FF848F6F35C 12_2_00007FF848F6F35C
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: 12_2_00007FF848F72FBD 12_2_00007FF848F72FBD
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: 12_2_00007FF848F62953 12_2_00007FF848F62953
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: 12_2_00007FF848F6D6E9 12_2_00007FF848F6D6E9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process token adjusted: Load Driver Jump to behavior
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: String function: 00007FF848F65810 appears 39 times
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Code function: String function: 00007FF848F64E70 appears 37 times
Source: irsetup.exe.0.dr Static PE information: Resource name: RT_CURSOR type: DOS executable (COM, 0x8C-variant)
Source: irsetup.exe.0.dr Static PE information: Resource name: RT_DIALOG type: COM executable for DOS
Source: irsetup.exe.0.dr Static PE information: Resource name: RT_STRING type: DOS executable (COM, 0x8C-variant)
Source: Phoenix Contact VCPInstaller.exe.2.dr Static PE information: Resource name: EXE type: PE32 executable (GUI) Intel 80386, for MS Windows
Source: WdfCoInstaller01009.dll.2.dr Static PE information: Resource name: RT_RCDATA type: Microsoft Cabinet archive data, many, 1639755 bytes, 2 files, at 0x44 +A "Microsoft Kernel-Mode Driver Framework Install-v1.9-Win2k-WinXP-Win2k3.exe" +A "Microsoft Kernel-Mode Driver Framework Install-v1.9-Vista.msu", flags 0x4, ID 12343, number 1, extra bytes 20 in head, 51 datablocks, 0x1503 compression
Source: PSI-CONF_Setup_v2.76.exe, 00000000.00000002.2849394316.000000000040E000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenamesuf80_launch.exe2 vs PSI-CONF_Setup_v2.76.exe
Source: PSI-CONF_Setup_v2.76.exe, 00000000.00000002.2849863551.00000000006F6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesuf80_rt.exeT vs PSI-CONF_Setup_v2.76.exe
Source: PSI-CONF_Setup_v2.76.exe, 00000000.00000002.2849935303.0000000002130000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesuf80_launch.exe2 vs PSI-CONF_Setup_v2.76.exe
Source: PSI-CONF_Setup_v2.76.exe, 00000000.00000003.2848630429.00000000006F5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesuf80_rt.exeT vs PSI-CONF_Setup_v2.76.exe
Source: PSI-CONF_Setup_v2.76.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: irsetup.exe.0.dr Static PE information: Section: UPX1 ZLIB complexity 0.9887366134129213
Source: WdfCoInstaller01009.dll.2.dr Static PE information: Section: .rsrc ZLIB complexity 0.9985629322738576
Source: ICSharpCode.SharpZipLib.dll.2.dr, InflaterInputBuffer.cs Cryptographic APIs: 'TransformBlock'
Source: ICSharpCode.SharpZipLib.dll.2.dr, DeflaterOutputStream.cs Cryptographic APIs: 'TransformBlock'
Source: ICSharpCode.SharpZipLib.dll.2.dr, ZipAESTransform.cs Cryptographic APIs: 'TransformBlock'
Source: classification engine Classification label: sus24.expl.evad.winEXE@18/192@0/0
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_004018EE lstrlenA,GetCurrentDirectoryA,_memset,GetTempPathA,lstrlenA,lstrlenA,lstrcpyA,lstrlenA,lstrcatA,wsprintfA,wsprintfA,wsprintfA,DeleteFileA,DeleteFileA,RemoveDirectoryA,wsprintfA,wsprintfA,DeleteFileA,RemoveDirectoryA,GetFileAttributesA,CreateDirectoryA,CreateDirectoryA,lstrcpyA,lstrcpyA,SetCurrentDirectoryA,SetCurrentDirectoryA,lstrcpyA,CreateDirectoryA,SetCurrentDirectoryA,lstrcpyA,lstrlenA,lstrcatA,lstrcpyA,lstrcpyA,lstrcatA,GetDiskFreeSpaceA,lstrcpyA,SetCurrentDirectoryA, 0_2_004018EE
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\Public\Desktop\PSI-CONF.lnk Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3808:120:WilError_03
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Mutant created: NULL
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Mutant created: \Sessions\1\BaseNamedObjects\PSI-CONF
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6056:120:WilError_03
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0 Jump to behavior
Source: Yara match File source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\Firmware\Telit\Xfp1.9.exe, type: DROPPED
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Command line argument: /~DBG 0_2_0040121E
Source: PSI-CONF_Setup_v2.76.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe File read: C:\Users\user\Desktop\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{c7f7ce19-85e2-2b4e-af72-83044df6dea6} Global\{7407c8d9-0d94-0b41-8543-eb54da946896} C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.inf C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe File read: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe "C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe"
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Process created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe "C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:666146 "__IRAFN:C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-2246122658-3693405117-2476756634-1003"
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe "C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe"
Source: unknown Process created: C:\Windows\System32\drvinst.exe DrvInst.exe "4" "0" "C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\slabvcp.inf" "9" "4f7b0f4b7" "0000000000000148" "WinSta0\Default" "0000000000000168" "208" "C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0"
Source: C:\Windows\System32\drvinst.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{c7f7ce19-85e2-2b4e-af72-83044df6dea6} Global\{7407c8d9-0d94-0b41-8543-eb54da946896} C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.inf C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\System32\icacls.exe" "C:\ProgramData\Phoenix Contact\PSIConfSoftware" /grant *S-1-1-0:(OI)M /T
Source: C:\Windows\SysWOW64\icacls.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe "C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe"
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\rqco3gp6.cmdline"
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RESF17E.tmp" "c:\Users\user\AppData\Local\Temp\CSCF17D.tmp"
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Process created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe "C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:666146 "__IRAFN:C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-2246122658-3693405117-2476756634-1003" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe "C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\System32\icacls.exe" "C:\ProgramData\Phoenix Contact\PSIConfSoftware" /grant *S-1-1-0:(OI)M /T Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe "C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe" Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{c7f7ce19-85e2-2b4e-af72-83044df6dea6} Global\{7407c8d9-0d94-0b41-8543-eb54da946896} C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.inf C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat Jump to behavior
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\rqco3gp6.cmdline"
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RESF17E.tmp" "c:\Users\user\AppData\Local\Temp\CSCF17D.tmp"
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: oledlg.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: edputil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: slc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: spinf.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: devrtl.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: drvstore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: devobj.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: devrtl.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: drvstore.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: cryptnet.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: slc.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: sppc.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: pnpui.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: dui70.dll Jump to behavior
Source: C:\Windows\System32\drvinst.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\icacls.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: mscoree.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: apphelp.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: version.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: windows.storage.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: wldp.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: profapi.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: msasn1.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: riched20.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: usp10.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: msls31.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: cryptsp.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: rsaenh.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: cryptbase.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: gpapi.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: cryptnet.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: iphlpapi.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: winnsi.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: uxtheme.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: shfolder.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: windowscodecs.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: textinputframework.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: ntmarta.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: coremessaging.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: wintypes.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: dwrite.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: textshaping.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: riched20.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: usp10.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Section loaded: msls31.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Section loaded: mscoree.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Section loaded: cscomp.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Section loaded: version.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Section loaded: cryptsp.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Section loaded: rsaenh.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Section loaded: cryptbase.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe Section loaded: cryptsp.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe Section loaded: rsaenh.dll
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File written: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\setup.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Automated click: Next
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Automated click: Next >
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Automated click: Install
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Automated click: OK
Source: C:\Windows\System32\rundll32.exe Automated click: Install
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: Next
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: Next
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: Next
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: Next
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: Next
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: Next
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: Next
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Automated click: I accept the terms in the license agreement
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Window detected: Number of UI elements: 11
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe File opened: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorrc.dll
Source: PSI-CONF_Setup_v2.76.exe Static PE information: certificate valid
Source: PSI-CONF_Setup_v2.76.exe Static file information: File size 46190112 > 1048576
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe File opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dll
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\rqco3gp6.cmdline"
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\rqco3gp6.cmdline"
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00407054 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,__invoke_watson,GetProcAddress,GetProcAddress,__invoke_watson, 0_2_00407054
Source: silabenm.sys.2.dr Static PE information: section name: PAGESENM
Source: silabser.sys.2.dr Static PE information: section name: PAGESRP0
Source: silabser.sys.2.dr Static PE information: section name: PAGESER
Source: silabenm.sys0.2.dr Static PE information: section name: PAGESENM
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00403F99 push ecx; ret 0_2_00403FAC
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Code function: 2_3_006AB520 pushad ; ret 2_3_006ABBE9
Source: initial sample Static PE information: section name: UPX0
Source: initial sample Static PE information: section name: UPX1

Persistence and Installation Behavior

barindex
Source: C:\Windows\System32\drvinst.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\BE36A4562FB2EE05DBB3D32323ADF445084ED656 Blob Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\de\PCID2708517.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\de\PCID2702878.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\PCID2313669.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\uninstall.exe Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe File created: C:\Users\user\AppData\Local\Temp\rqco3gp6.dll Jump to dropped file
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\Firmware\Telit\Xfp1.9.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\PCID2901540.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\zh-CHS\PCID2702863.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x64\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\PCID1081818.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\PCID2901541_HG.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x64\silabenm.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\IRZip.lmd Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x86\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\ru\PCID2901541.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\de\PCID2702184.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\PhoenixResourceManager.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\silabenm.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x86\silabenm.sys Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET17E6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x64\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\PCID2313656.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\PCID2313559.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\zh-CHS\PCID2313656.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\zh-CHS\PCID2901541.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\PCID2313449.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\de\PCID2901540.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x86\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x86\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\zh-CHS\PCID2313449.resources.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\silabser.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\BugReportGenerator\ICSharpCode.SharpZipLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\SET14FA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\zh-CHS\PCID2313669.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x64\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x64\silabenm.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\PhoenixResourceManager.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\de\PCID2313559.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\de\PCID2901541.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\SET14D9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\BugReportGenerator\de\BugReportCreator.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\PCID2708517.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x64\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF AutoUpdate.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\de\PSI-CONF.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\SET14EA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\de\PCID2313106.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PhoenixResourceManager.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\zh-CHS\PCID2702878.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\PCID2313643.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\Firmware\Device\psiprog-1.57.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\PCID2702863.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET1845.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\zh-CHS\PCID2708517.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\de\PCID2313643.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\zh-CHS\PCID2313643.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\zh-CHS\PCID2313106.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\zh-CHS\PCID2901540.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\ru\PCID2702863.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\zh-CHS\PCID2313559.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\zh-CHS\PCID2702184.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\de\PCID2702863.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\ru\PSI-CONF.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\de\PCID2313449.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\PCID2313106.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x86\silabenm.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Uninstall\IRZip.lmd Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x86\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\GetActiveProxy.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\PCID2904909.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\ICSharpCode.SharpZipLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\silabenm.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\PCID2901541.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\zh-CHS\PCID2904909.resources.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET1865.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\de\PCID2313656.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\silabser.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\zh-CHS\PCID2313533.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\de\PCID2313669.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\PCID2702184.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\PCID2313533.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\BugReportGenerator\BugReportCreator.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\PCID2702878.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\de\PCID2313533.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\DriverUninstaller.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\zh-CHS\PSI-CONF.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe File created: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\WdfCoinstaller01009.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\de\PCID2904909.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\de\PCID1081818.resources.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\WdfCoinstaller01009.dll (copy) Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET1845.tmp Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\silabenm.sys (copy) Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET17E6.tmp Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET1865.tmp Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\silabser.sys (copy) Jump to dropped file
Source: C:\Windows\System32\drvinst.exe File created: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\WdfCoinstaller01009.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\IRZip.lmd Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Uninstall\IRZip.lmd Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\ProgramData\Phoenix Contact\PSIConfSoftware\SetupLog.txt Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phoenix Contact\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phoenix Contact\PSI-CONF\ Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phoenix Contact\PSI-CONF\PSI-CONF.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phoenix Contact\PSI-CONF\PSI-CONF Update Client.lnk Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Phoenix Contact\PSI-CONF\Uninstall PSI-CONF.lnk Jump to behavior
Source: C:\Windows\System32\drvinst.exe Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\4EB6D578499B1CCF5F581EAD56BE3D9B6744A5E5 Blob Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\System32\icacls.exe" "C:\ProgramData\Phoenix Contact\PSIConfSoftware" /grant *S-1-1-0:(OI)M /T
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\drvinst.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Memory allocated: 1A10000 memory reserve | memory write watch
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Memory allocated: 3A10000 memory reserve | memory write watch
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Memory allocated: 1BA10000 memory commit | memory reserve | memory write watch
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Window / User API: threadDelayed 1087 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\de\PCID2708517.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\de\PCID2702878.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\PCID2313669.dll Jump to dropped file
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\rqco3gp6.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\zh-CHS\PCID2702863.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\Firmware\Telit\Xfp1.9.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\PCID2901540.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x64\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\PCID1081818.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\PCID2901541_HG.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x64\silabenm.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\IRZip.lmd Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x86\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\ru\PCID2901541.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\de\PCID2702184.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\PhoenixResourceManager.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\silabenm.sys (copy) Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET17E6.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x86\silabenm.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x64\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\PCID2313656.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\PCID2313559.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\zh-CHS\PCID2313656.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\zh-CHS\PCID2901541.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\PCID2313449.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\de\PCID2901540.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x86\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x86\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\zh-CHS\PCID2313449.resources.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\silabser.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\BugReportGenerator\ICSharpCode.SharpZipLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\SET14FA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\zh-CHS\PCID2313669.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x64\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x64\silabenm.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\PhoenixResourceManager.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\de\PCID2313559.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\de\PCID2901541.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\SET14D9.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\BugReportGenerator\de\BugReportCreator.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\PCID2708517.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF AutoUpdate.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\de\PSI-CONF.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\SET14EA.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\x64\WdfCoInstaller01009.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\de\PCID2313106.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\zh-CHS\PCID2702878.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PhoenixResourceManager.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\PCID2313643.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\Firmware\Device\psiprog-1.57.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\PCID2702863.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET1845.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\zh-CHS\PCID2708517.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\de\PCID2313643.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\zh-CHS\PCID2313643.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\zh-CHS\PCID2313106.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\zh-CHS\PCID2901540.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\zh-CHS\PCID2313559.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\ru\PCID2702863.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\zh-CHS\PCID2702184.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\de\PCID2702863.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\ru\PSI-CONF.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\de\PCID2313449.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\PCID2313106.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x86\silabenm.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Uninstall\IRZip.lmd Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\x86\silabser.sys Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\GetActiveProxy.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\PCID2904909.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\ICSharpCode.SharpZipLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\silabenm.sys (copy) Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\SET1865.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\PCID2901541.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\zh-CHS\PCID2904909.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\de\PCID2313656.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\silabser.sys (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\zh-CHS\PCID2313533.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\de\PCID2313669.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\PCID2702184.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\PCID2313533.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\BugReportGenerator\BugReportCreator.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\PCID2702878.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\de\PCID2313533.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\Drivers\USB to UART Interface\DriverUninstaller.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\Phoenix Contact VCPInstaller.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{86984c43-8b67-194b-9c7f-ab018d349ed2}\x64\WdfCoinstaller01009.dll (copy) Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\zh-CHS\PSI-CONF.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\de\PCID2904909.resources.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\ModbusLib.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Dropped PE file which has not been started: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\de\PCID1081818.resources.dll Jump to dropped file
Source: C:\Windows\System32\drvinst.exe Dropped PE file which has not been started: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\x64\WdfCoinstaller01009.dll (copy) Jump to dropped file
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Thread sleep count: Count: 1087 delay: -10 Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe File opened: C:\Users\user\AppData Jump to behavior
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2308880687.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563ommonProgramFiles = "%CommonProgramFiles
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300308294.00000000029E1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321398589.00000000027C6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322455462.00000000027C6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DeviceDesc = "Microsoft Hyper-V SCSI Controller"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2298463203.0000000002781000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Activation.DeviceDesc = "Microsoft Hyper-V Activation Component"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: AddReg=VmIcShutdown.HW.AddReg
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVS
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2297697663.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563=
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324784219.000000000282D000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2299975086.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323438455.000000000282C000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322273255.000000000282C000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2306767874.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DeviceDesc = "Microsoft Hyper-V Fibre Channel HBA"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2266698107.0000000000565000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ; ConnectX-4 Hyper-V VF
Source: irsetup.exe, 00000002.00000003.2510425719.00000000006A4000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcShutdown.NT.HW]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: netvsc_eth.DeviceDesc = "Microsoft Hyper-V Ethernet Network Adapter"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2299975086.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Heartbeat.DeviceDesc = "Microsoft Hyper-V Heartbeat"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2299975086.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301023666.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Shutdown.DeviceDesc = "Microsoft Hyper-V Guest Shutdown"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2266698107.0000000000565000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ; ConnectX-4 non Hyper-V VF
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289874462.00000000029B1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324727014.00000000027A0000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2292021624.00000000029DC000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321398589.00000000027C6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VMBusHid.DeviceDesc = "Microsoft Hyper-V Input"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: %VSS.DeviceDesc% = VmIcVss, vmbus\{2450ee40-33bf-4fbd-892e-9fb06e9214cf}
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: netvsc_mbb_gsm.DeviceDesc = "Microsoft Hyper-V GSM MBB Network Adapter"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HyperVNetworkAdapterName = "Hyper-V Network Adapter Name"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2290813674.00000000027E2000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2282968382.00000000027DB000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ; Hyper-V Network Adapter Name
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322425727.0000000000507000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcVss.NT]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2308880687.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563b
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309686444.00000000027F6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300308294.00000000029E1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2316477527.00000000027F5000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2280765136.0000000000525000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322425727.0000000000507000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DynMemVsc.DeviceDesc = "Microsoft Hyper-V Dynamic Memory"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcHeartbeat.NT]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323611546.00000000027B2000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301023666.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322455462.00000000027AB000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: TimeSync.DeviceDesc = "Microsoft Hyper-V Time Synchronization"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2308880687.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563Y
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323611546.00000000027B2000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2298463203.0000000002781000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2306767874.00000000027DA000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2299975086.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301023666.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322455462.00000000027AB000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V Integration Components"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2259785251.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2279239071.0000000002831000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: GenericScsiVmLun = "Hyper-V LUN"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2298463203.0000000002781000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: VSS.DeviceDesc = "Microsoft Hyper-V Volume Shadow Copy"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcHeartbeat.NT.HW]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: AddReg=VmIcHeartbeat.HW.AddReg
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300308294.00000000029E1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289874462.00000000029B1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2292021624.00000000029DC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ; Hyper-V Synthetic Video driver.
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2308880687.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563w
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: AddReg=VmIcVss.HW.AddReg
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2320101206.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321656088.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: c = "Microsoft Hyper-V Activation Component"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323679118.0000000002802000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301077541.00000000027F6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2271536312.0000000000533000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2280765136.0000000000525000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2302146162.00000000027E5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ; INF file for installing the Hyper-V crashdump driver.
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321398589.00000000027C6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: id.DeviceDesc = "Microsoft Hyper-V Input"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcHeartbeat.NT.Services]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2306767874.00000000027DA000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: GuestInterface.DeviceDesc = "Microsoft Hyper-V Guest Service Interface"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcShutdown.HW.AddReg]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2320101206.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321656088.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{152fbe4b-c7ad-4f68-bada-a4fcc1464f6c}",,0x0,"Microsoft-Windows-Hyper-V-Netvsc"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2280765136.0000000000525000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: F file for installing the Hyper-V crashdump driver.
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2298463203.0000000002781000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Rdv.DeviceDesc = "Microsoft Hyper-V Remote Desktop Virtualization"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: %Heartbeat.DeviceDesc% = VmIcHeartbeat, vmbus\{57164f39-9115-4e78-ab55-382f3bd5422d}
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcHeartbeat.HW.AddReg]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcShutdown.NT.Services]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcShutdown.NT]
Source: PSI-CONF_Setup_v2.76.exe, 00000000.00000002.2849725983.00000000006BA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: _VMware_80n
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300308294.00000000029E1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321398589.00000000027C6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322455462.00000000027C6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId = "Microsoft Hyper-V SCSI Controller Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289874462.00000000029B1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324727014.00000000027A0000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2292021624.00000000029DC000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321398589.00000000027C6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V Input Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2290813674.00000000027E2000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2282968382.00000000027DB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HyperVNetworkAdapterName = "Hyper-V Network Adapter N%m
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324784219.000000000282D000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2299975086.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323438455.000000000282C000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322273255.000000000282C000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2306767874.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DeviceDesc_NULL = "Microsoft Hyper-V Fibre Channel HBA (not supported)"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcVss.NT.HW]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2298463203.0000000002781000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2320101206.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321656088.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: RdpD.DeviceDesc = "Microsoft Hyper-V Remote Desktop Data Channel"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2290813674.00000000027E2000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2282968382.00000000027DB000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: netvsc_ppp.DeviceDesc = "Microsoft Hyper-V VPN Network Adapter"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2282968382.00000000027DB000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2320101206.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321656088.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{152fbe4b-c7ad-4f68-bada-a4fcc1464f6c}\ChannelReferences\1",,0x0,"Microsoft-Windows-Hyper-V-NETVSC/Diagnostic"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V Network Adapter Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2308880687.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563x
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323679118.0000000002802000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301077541.00000000027F6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2271536312.0000000000533000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2280765136.0000000000525000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2302146162.00000000027E5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HvCrash.DeviceDesc = "Microsoft Hyper-V Crashdump Driver"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2298463203.0000000002781000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2320101206.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321656088.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: RdpC.DeviceDesc = "Microsoft Hyper-V Remote Desktop Control Channel"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: %Shutdown.DeviceDesc% = VmIcShutdown, vmbus\{b6650ff7-33bc-4840-8048-e0676786f393}
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301023666.000000000050B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Desc = "Microsoft Hyper-V Guest Service Interface"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000584000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2305972251.0000000002A70000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ; This is the INF file for installing the Hyper-V S3 Cap driver
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcVss.HW.AddReg]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: [VmIcVss.NT.Services]
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324684756.00000000027E3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HyperKbd.DeviceDesc = "Microsoft Hyper-V Virtual Keyboard"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300308294.00000000029E1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289874462.00000000029B1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2292021624.00000000029DC000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321398589.00000000027C6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322455462.00000000027C6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: SynthVid.DeviceDesc = "Microsoft Hyper-V Video"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: netvsc.DeviceDesc = "Microsoft Hyper-V Network Adapter"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVSC/Diagnostic","OwningPublisher",0x0,"{152fbe4b-c7ad-4f68-bada-a4fcc1464f6c}"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2297697663.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVSC/Diagnostic","ChannelAccess",0x0,"O:BAG:SYD:(A;;0x2;;;S-1-15-2-1)(A;;0xf0007;;;SY)(A;;0x7;;;BA)(A;;0x7;;;SO)(A;;0x3;;;IU)(A;;0x3;;;SU)(A;;0x3;;;S-1-5-3)(A;;0x3;;;S-1-5-33)(A;;0x1;;;S-1-5-32-573)"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324684756.00000000027E3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ; INF file for installing Hyper-V keyboard driver
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2308880687.000000000059C000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: @SYSTEM:vmci.inf_amd64_68ed49469341f563
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKR, Ndi\Interfaces, FilterMediaTypes,,"ethernet, wlan, ppip, vmnetextension"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVSC/Diagnostic","Isolation",0x00010001,0
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300308294.00000000029E1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289874462.00000000029B1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2292021624.00000000029DC000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321398589.00000000027C6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322455462.00000000027C6000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V Video Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324784219.000000000282D000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2299975086.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323438455.000000000282C000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322273255.000000000282C000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2306767874.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId = "Microsoft Hyper-V Fibre Channel HBA Installation Disk #1"
Source: irsetup.exe, 00000002.00000003.2510425719.00000000006A4000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323679118.0000000002802000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301077541.00000000027F6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2271536312.0000000000533000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2280765136.0000000000525000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2302146162.00000000027E5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V Crash Dump Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVSC/Diagnostic","Enabled",0x00010001,0
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2323611546.00000000027B2000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2289335943.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2301023666.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322455462.00000000027AB000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309945969.00000000027AA000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2275114474.0000000002780000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2291543255.0000000002B12000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: KvpExchange.DeviceDesc = "Microsoft Hyper-V Data Exchange"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2320101206.0000000002B86000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2321656088.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: "SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NE
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: t Hyper-V Virtual Keyboard"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2309686444.00000000027F6000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300308294.00000000029E1000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2316477527.00000000027F5000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2280765136.0000000000525000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2322425727.0000000000507000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V Dynamic Memory Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324727014.00000000027A0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: sc = "Microsoft Hyper-V Input"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000584000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2305972251.0000000002A70000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: S3CapDevice.DeviceDesc = "Microsoft Hyper-V S3 Cap"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2295813192.0000000002789000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000584000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2305972251.0000000002A70000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V S3 Cap Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: netvsc_wifi.DeviceDesc = "Microsoft Hyper-V WiFi Network Adapter"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETV
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324684756.00000000027E3000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: DiskId1 = "Microsoft Hyper-V Virtual Keyboard Installation Disk #1"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2300142790.0000000000555000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324403544.0000000002B12000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2307830794.0000000002B86000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: netvsc_mbb_cdma.DeviceDesc = "Microsoft Hyper-V CDMA MBB Network Adapter"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2298463203.0000000002781000.00000004.00000020.00020000.00000000.sdmp, Phoenix Contact VCPInstaller.exe, 00000003.00000003.2324727014.0000000002781000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: rrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVS
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2316477527.00000000027F5000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKR, Ndi\Interfaces,FilterMediaTypes,,"vmnetextension"
Source: Phoenix Contact VCPInstaller.exe, 00000003.00000003.2260352505.000000000050B000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: HKLM,"SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Channels\Microsoft-Windows-Hyper-V-NETVSC/Diagnostic","Type",0x00010001,2
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00407054 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,__invoke_watson,GetProcAddress,GetProcAddress,__invoke_watson, 0_2_00407054
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00402E99 GetStartupInfoA,GetProcessHeap,GetProcessHeap,HeapAlloc,_fast_error_exit,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,_fast_error_exit,_fast_error_exit,__RTC_Initialize,__ioinit,__amsg_exit,GetCommandLineA,___crtGetEnvironmentStringsA,__setargv,__amsg_exit,__setenvp,__amsg_exit,__cinit,__amsg_exit,__wincmdln, 0_2_00402E99
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00405859 SetUnhandledExceptionFilter, 0_2_00405859
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00401000 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_00401000
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00407303 _raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_00407303
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_0040110A _memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_0040110A
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Memory allocated: page read and write | page guard
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Process created: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe "C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe" __IRAOFF:666146 "__IRAFN:C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe" "__IRCT:0" "__IRTSS:0" "__IRSID:S-1-5-21-2246122658-3693405117-2476756634-1003" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Process created: C:\Windows\SysWOW64\icacls.exe "C:\Windows\System32\icacls.exe" "C:\ProgramData\Phoenix Contact\PSIConfSoftware" /grant *S-1-1-0:(OI)M /T Jump to behavior
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe "C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\user\AppData\Local\Temp\rqco3gp6.cmdline"
Source: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe Process created: C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe C:\Windows\Microsoft.NET\Framework64\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\user\AppData\Local\Temp\RESF17E.tmp" "c:\Users\user\AppData\Local\Temp\CSCF17D.tmp"
Source: C:\Windows\System32\drvinst.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe c:\windows\system32\pnpui.dll,installsecuritypromptrundllw 20 global\{c7f7ce19-85e2-2b4e-af72-83044df6dea6} global\{7407c8d9-0d94-0b41-8543-eb54da946896} c:\windows\system32\driverstore\temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.inf c:\windows\system32\driverstore\temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat
Source: C:\Windows\System32\drvinst.exe Process created: C:\Windows\System32\rundll32.exe rundll32.exe c:\windows\system32\pnpui.dll,installsecuritypromptrundllw 20 global\{c7f7ce19-85e2-2b4e-af72-83044df6dea6} global\{7407c8d9-0d94-0b41-8543-eb54da946896} c:\windows\system32\driverstore\temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.inf c:\windows\system32\driverstore\temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat Jump to behavior
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_0040605D cpuid 0_2_0040605D
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: GetLocaleInfoA, 0_2_0040783D
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\_ir_sf_temp_0\irsetup.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\drvinst.exe Queries volume information: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat VolumeInformation Jump to behavior
Source: C:\Windows\System32\drvinst.exe Queries volume information: C:\Windows\System32\DriverStore\Temp\{2980290e-e66e-1341-aacb-9a72a3cc8330}\slabvcp.cat VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\PCID1081818.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID1081818\PCID1081818.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\PCID2313106.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313106\PCID2313106.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\PCID2313449.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313449\PCID2313449.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\PCID2313533.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313533\PCID2313533.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\PCID2313559.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313559\PCID2313559.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\PCID2313643.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313643\PCID2313643.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\PCID2313656.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313656\PCID2313656.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\PCID2313669.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2313669\PCID2313669.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\PCID2702184.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702184\PCID2702184.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\PCID2702863.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702863\PCID2702863.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\PCID2702878.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2702878\PCID2702878.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\PCID2708517.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2708517\PCID2708517.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901540\PCID2901540.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\PCID2901541.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2901541\PCID2901541.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\Devices\PCID2904909\PCID2904909.dll VolumeInformation
Source: C:\Program Files (x86)\Phoenix Contact\PSI-CONF\PSI-CONF.exe Queries volume information: C:\Windows\Fonts\micross.ttf VolumeInformation
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00405F79 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter, 0_2_00405F79
Source: C:\Users\user\Desktop\PSI-CONF_Setup_v2.76.exe Code function: 0_2_00402E99 GetStartupInfoA,GetProcessHeap,GetProcessHeap,HeapAlloc,_fast_error_exit,GetVersionExA,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree,_fast_error_exit,_fast_error_exit,__RTC_Initialize,__ioinit,__amsg_exit,GetCommandLineA,___crtGetEnvironmentStringsA,__setargv,__amsg_exit,__setenvp,__amsg_exit,__cinit,__amsg_exit,__wincmdln, 0_2_00402E99
Source: C:\Windows\System32\drvinst.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
Source: C:\Windows\System32\drvinst.exe Registry key created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\46B8D8F38741CD4E839F1F6B874F58B0A87C1937 Blob Jump to behavior
No contacted IP infos