Windows Analysis Report
plotdemo.exe

Overview

General Information

Sample name: plotdemo.exe
Analysis ID: 1531073
MD5: fbce37d191eb18a9b005539336aea939
SHA1: 37588e9f8796a0480638a4ff00d305dbdb472146
SHA256: 60f39e5220113596f51c5eabca7d6f81c603487971d58b7df9b8dbc093edbfae
Infos:

Detection

Score: 36
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Drops HTML or HTM files to system directories
Sets file extension default program settings to executables
Checks for available system drives (often done to infect USB drives)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a DirectInput object (often for capturing keystrokes)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Potential key logger detected (key state polling based)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Source: plotdemo.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\readme.rtf Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\README.TXT Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\README.rtf Jump to behavior
Source: Binary string: pscript5.pdb source: PSCRIPT5.DLL.7.dr, PSCRIPT5.DLL0.2.dr
Source: Binary string: f:\InstPost\Release\InstPost.pdb source: InstPost.exe, 00000007.00000002.1968290163.0000000000428000.00000002.00000001.01000000.00000006.sdmp, InstPost.exe, 00000007.00000000.1956464551.0000000000428000.00000002.00000001.01000000.00000006.sdmp
Source: Binary string: pscript5.pdbH source: PSCRIPT5.DLL.7.dr
Source: Binary string: MicrosoftWindowsGdiPlus-10100-gdiplus.pdb source: GdiPlus.dll.2.dr
Source: C:\Windows\System32\msiexec.exe File opened: z: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: x: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: v: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: t: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: r: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: p: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: n: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: l: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: j: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: h: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: f: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: b: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: y: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: w: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: u: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: s: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: q: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: o: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: m: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: k: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: i: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: g: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: e: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: c: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: a: Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0041744C CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 0_2_0041744C
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\Temp\_is8C78\0x0409.ini Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\Temp\_is8C78\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\Temp\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\ Jump to behavior
Source: ALIGN.PS.2.dr, WRFONT.PS.2.dr, FONT2PCL.PS.2.dr, GS_RES.PS.2.dr, PDF_FONT.PS.2.dr, GS_EPSF.PS.2.dr, WFTOPFA.PS.2.dr, GS_DPS.PS.2.dr, GS_LGO_E.PS.2.dr, GS_CCFNT.PS.2.dr, MARKHINT.PS.2.dr, GS_KANJI.PS.2.dr, GS_LL3.PS.2.dr, UNPROT.PS.2.dr, GS_WL5_E.PS.2.dr, GS_FRSD.PS.2.dr, GS_ICC.PS.2.dr, GS_DPNXT.PS.2.dr, MARKPATH.PS.2.dr, PPHS.PS.2.dr, PDF_BASE.PS.2.dr String found in binary or memory: http://www.artifex.com/licensing/
Source: ALIGN.PS.2.dr, WRFONT.PS.2.dr, FONT2PCL.PS.2.dr, GS_RES.PS.2.dr, PDF_FONT.PS.2.dr, GS_EPSF.PS.2.dr, WFTOPFA.PS.2.dr, GS_DPS.PS.2.dr, GS_LGO_E.PS.2.dr, GS_CCFNT.PS.2.dr, MARKHINT.PS.2.dr, GS_KANJI.PS.2.dr, GS_LL3.PS.2.dr, UNPROT.PS.2.dr, GS_WL5_E.PS.2.dr, GS_FRSD.PS.2.dr, GS_ICC.PS.2.dr, GS_DPNXT.PS.2.dr, MARKPATH.PS.2.dr, PPHS.PS.2.dr, PDF_BASE.PS.2.dr String found in binary or memory: http://www.ghostscript.com/licensing/.
Source: PDF_SEC.PS.2.dr String found in binary or memory: http://www.ozemail.com.au/%7Egeoffk/pdfencrypt/
Source: GdiPlus.dll.2.dr Binary or memory string: DirectDrawCreateEx memstr_52bd2abf-e
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0040D4FC GetKeyState,GetKeyState,GetKeyState,GetKeyState,SendMessageA, 7_2_0040D4FC
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00416579 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 0_2_00416579
Source: C:\Users\user\Desktop\plotdemo.exe File created: C:\Windows\Downloaded Installations Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File created: C:\Windows\Downloaded Installations\{96644CA9-8EA3-446B-8568-6E1624759883} Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File created: C:\Windows\Downloaded Installations\{96644CA9-8EA3-446B-8568-6E1624759883}\PSI-Plot Ver 10.5 Working Demo.msi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\5ee891.msi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{CF7D8275-38F3-42CF-AF3D-29B1BF918926} Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIED35.tmp Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\PSIPLOT.INI Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926} Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\ARPPRODUCTICON.exe Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut1_E57AF06D4375496697A2B3227B8F52A3.EXE Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut3_B94EC0BE542B4F308679E8D52BAD769F.htm Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut6_B94EC0BE542B4F308679E8D52BAD769F.exe Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut7_B94EC0BE542B4F308679E8D52BAD769F.PDF Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\5ee893.msi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\5ee893.msi Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\system32\spool\drivers\x64\3\PSIPSCRP.PPD Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\system32\spool\DRIVERS\x64\PSIPSCRP.PPD Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\system32\spool\DRIVERS\x64\PS5UI.DLL Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\system32\spool\DRIVERS\x64\PSCRIPT5.DLL Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\system32\spool\DRIVERS\x64\PSCRIPT.HLP Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\system32\spool\DRIVERS\x64\PSCRIPT.NTF Jump to behavior
Source: C:\Windows\System32\msiexec.exe File deleted: C:\Windows\Installer\5ee893.msi Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00421150 0_2_00421150
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_004263C6 0_2_004263C6
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00407797 0_2_00407797
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0040ECDE 7_2_0040ECDE
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00426021 7_2_00426021
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_004250A0 7_2_004250A0
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00416960 7_2_00416960
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_004249E0 7_2_004249E0
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00416AF6 7_2_00416AF6
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00421332 7_2_00421332
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00417BC9 7_2_00417BC9
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0041739D 7_2_0041739D
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0042449E 7_2_0042449E
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00419F47 7_2_00419F47
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00423F5C 7_2_00423F5C
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00416FC9 7_2_00416FC9
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0041DFFE 7_2_0041DFFE
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_004177A9 7_2_004177A9
Source: C:\Users\user\Desktop\plotdemo.exe Code function: String function: 0041C340 appears 129 times
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: String function: 00415DFE appears 68 times
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: String function: 00416904 appears 47 times
Source: PSCRIPT5.DLL.2.dr Static PE information: Resource name: RT_RCDATA type: DOS executable (COM, 0x8C-variant)
Source: PS5UI.DLL.2.dr Static PE information: Resource name: RT_RCDATA type: DOS executable (COM, 0x8C-variant)
Source: PS5UI.DLL.2.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: PSCRIPT5.DLL0.2.dr Static PE information: Resource name: RT_RCDATA type: DOS executable (COM, 0x8C-variant)
Source: PSCRIPT5.DLL0.2.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: PS5UI.DLL0.2.dr Static PE information: Resource name: RT_RCDATA type: DOS executable (COM, 0x8C-variant)
Source: PS5UI.DLL.7.dr Static PE information: Resource name: RT_RCDATA type: DOS executable (COM, 0x8C-variant)
Source: PSCRIPT5.DLL.7.dr Static PE information: Resource name: RT_RCDATA type: DOS executable (COM, 0x8C-variant)
Source: plotdemo.exe, 00000000.00000000.1667542232.0000000000438000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenamesetup.exe vs plotdemo.exe
Source: plotdemo.exe Binary or memory string: OriginalFilenamesetup.exe vs plotdemo.exe
Source: plotdemo.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: sus36.winEXE@8/327@0/0
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00416579 GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueA,AdjustTokenPrivileges,ExitWindowsEx, 0_2_00416579
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00415C4F LoadLibraryA,GetProcAddress,lstrcpyA,GetDiskFreeSpaceExA,GetDiskFreeSpaceA,FreeLibrary, 0_2_00415C4F
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00408489 CoCreateInstance,wsprintfA,StringFromCLSID,SysAllocString,CoTaskMemFree,lstrlenW,lstrlenW,wsprintfA,RegOpenKeyExA,RegOpenKeyExA,RegOpenKeyExA,RegQueryValueExA,CoCreateGuid,lstrcatA,StringFromCLSID,SysAllocString,CoTaskMemFree,lstrlenW,lstrcatA,CreateProcessA,SysFreeString,lstrlenW,wsprintfA,WaitForInputIdle,CloseHandle,CloseHandle,CloseHandle,Sleep,CreateItemMoniker,GetRunningObjectTable,SysFreeString,RegCloseKey,RegCloseKey,RegCloseKey,SysFreeString, 0_2_00408489
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00408223 FindResourceA,SizeofResource,LoadResource,LockResource, 0_2_00408223
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Users\Public\Desktop\PSI-Plot Working Demo.lnk Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File created: C:\Users\user\AppData\Local\Temp\~8C68.tmp Jump to behavior
Source: plotdemo.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\plotdemo.exe File read: C:\Users\user\AppData\Local\Temp\_is8C78\Setup.INI Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File read: C:\Users\user\Desktop\plotdemo.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\plotdemo.exe "C:\Users\user\Desktop\plotdemo.exe"
Source: C:\Users\user\Desktop\plotdemo.exe Process created: C:\Windows\SysWOW64\msiexec.exe MSIEXEC.EXE /i "C:\Windows\Downloaded Installations\{96644CA9-8EA3-446B-8568-6E1624759883}\PSI-Plot Ver 10.5 Working Demo.msi" SETUPEXEDIR="C:\Users\user\Desktop"
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 8C8A1754951F47B4EB3715E07FE2E622 C
Source: C:\Windows\System32\msiexec.exe Process created: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe "C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe"
Source: C:\Users\user\Desktop\plotdemo.exe Process created: C:\Windows\SysWOW64\msiexec.exe MSIEXEC.EXE /i "C:\Windows\Downloaded Installations\{96644CA9-8EA3-446B-8568-6E1624759883}\PSI-Plot Ver 10.5 Working Demo.msi" SETUPEXEDIR="C:\Users\user\Desktop" Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 8C8A1754951F47B4EB3715E07FE2E622 C Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process created: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe "C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe" Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: srpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: tsappcmp.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msihnd.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: srclient.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: spp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: vssapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: vsstrace.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Section loaded: textshaping.dll Jump to behavior
Source: psiplot.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.EXE
Source: Readme.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\PSI\PSIPLOT\readme.htm
Source: TUTORIAL.lnk.2.dr LNK file: ..\..\..\..\..\..\Program Files (x86)\PSI\PSIPLOT\TUTORIAL.PDF
Source: PSI-Plot Working Demo.lnk.2.dr LNK file: ..\..\..\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.EXE
Source: C:\Users\user\Desktop\plotdemo.exe File written: C:\Users\user\AppData\Local\Temp\_is8C78\Setup.INI Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Automated click: Next >
Source: C:\Windows\SysWOW64\msiexec.exe Automated click: Next >
Source: C:\Windows\SysWOW64\msiexec.exe Automated click: Next >
Source: C:\Windows\SysWOW64\msiexec.exe Automated click: Next >
Source: C:\Windows\SysWOW64\msiexec.exe Automated click: Install
Source: Window Recorder Window detected: More than 3 window changes detected
Source: plotdemo.exe Static file information: File size 21190666 > 1048576
Source: Binary string: pscript5.pdb source: PSCRIPT5.DLL.7.dr, PSCRIPT5.DLL0.2.dr
Source: Binary string: f:\InstPost\Release\InstPost.pdb source: InstPost.exe, 00000007.00000002.1968290163.0000000000428000.00000002.00000001.01000000.00000006.sdmp, InstPost.exe, 00000007.00000000.1956464551.0000000000428000.00000002.00000001.01000000.00000006.sdmp
Source: Binary string: pscript5.pdbH source: PSCRIPT5.DLL.7.dr
Source: Binary string: MicrosoftWindowsGdiPlus-10100-gdiplus.pdb source: GdiPlus.dll.2.dr
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0040E3D8 __EH_prolog,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary, 0_2_0040E3D8
Source: gdiplus.dll.2.dr Static PE information: section name: Shared
Source: GdiPlus.dll.2.dr Static PE information: section name: Shared
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0041C340 push eax; ret 0_2_0041C35E
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0041C310 push eax; ret 0_2_0041C33E
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0041CA5C push 880041CAh; retf 0041h 0_2_0041CA61
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00416949 push ecx; ret 7_2_0041695C
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00415E9D push ecx; ret 7_2_00415EB0
Source: gdiplus.dll.2.dr Static PE information: section name: .text entropy: 6.8196811563189135
Source: GdiPlus.dll.2.dr Static PE information: section name: .text entropy: 6.825071221107194

Persistence and Installation Behavior

barindex
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut3_B94EC0BE542B4F308679E8D52BAD769F.htm Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT5.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT.DRV Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSDLL32.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PS5UI.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Jump to dropped file
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\System32\spool\drivers\x64\PS5UI.DLL Jump to dropped file
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\ICONLIB.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSMON.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.EXE Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut3_B94EC0BE542B4F308679E8D52BAD769F.htm Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PS5UI.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\gdiplus.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PSCRIPT5.DLL Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe File created: C:\Users\user\AppData\Local\Temp\MSIA4B2.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut7_B94EC0BE542B4F308679E8D52BAD769F.PDF Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\GdiPlus.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSWIN32C.EXE Jump to dropped file
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\System32\spool\drivers\x64\PS5UI.DLL Jump to dropped file
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe File created: C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut3_B94EC0BE542B4F308679E8D52BAD769F.htm Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut7_B94EC0BE542B4F308679E8D52BAD769F.PDF Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT.DRV Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut3_B94EC0BE542B4F308679E8D52BAD769F.htm Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut7_B94EC0BE542B4F308679E8D52BAD769F.PDF Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\readme.rtf Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\README.TXT Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Program Files (x86)\PSI\PSIPLOT\README.rtf Jump to behavior

Boot Survival

barindex
Source: C:\Windows\System32\msiexec.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIData\shell\open\command C:\Program Files (x86)\PSI\PSIPLOT\psiplot.exe %1 Jump to behavior
Source: C:\Windows\System32\msiexec.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIGraph.PSIPlot.8\shell\open\command C:\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.EXE %1 Jump to behavior
Source: C:\Windows\System32\msiexec.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIReport\shell\open\command C:\Program Files (x86)\PSI\PSIPLOT\psiplot.exe %1 Jump to behavior
Source: C:\Windows\System32\msiexec.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PSIProject\shell\open\command C:\Program Files (x86)\PSI\PSIPLOT\psiplot.exe %1 Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot\psiplot.lnk Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot\Readme.lnk Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PSI-Plot\TUTORIAL.lnk Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_004011E0 IsIconic,SendMessageA,GetSystemMetrics,GetSystemMetrics,GetSystemMetrics,GetClientRect,DrawIcon,PostMessageA, 7_2_004011E0
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0040ADDE MonitorFromWindow,IsIconic,GetWindowPlacement,GetWindowRect, 7_2_0040ADDE
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00417252 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 0_2_00417252
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOGPFAULTERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT5.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSCRIPT.DRV Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSDLL32.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PS5UI.DLL Jump to dropped file
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Dropped PE file which has not been started: C:\Windows\System32\spool\drivers\x64\PS5UI.DLL Jump to dropped file
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Dropped PE file which has not been started: C:\Windows\System32\spool\drivers\x64\PSCRIPT5.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\ICONLIB.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PSMON.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\PSIPLOT.EXE Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut3_B94EC0BE542B4F308679E8D52BAD769F.htm Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\PS5UI.DLL Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\gdiplus.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\POSTSCRP\WinEx\PSCRIPT5.DLL Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSIA4B2.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\{CF7D8275-38F3-42CF-AF3D-29B1BF918926}\NewShortcut7_B94EC0BE542B4F308679E8D52BAD769F.PDF Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\GPLGS\GSWIN32C.EXE Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Program Files (x86)\PSI\PSIPLOT\GdiPlus.dll Jump to dropped file
Source: C:\Users\user\Desktop\plotdemo.exe File Volume queried: C:\Users\user\AppData\Local\Temp FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0041744C CreateEventA,GetProcAddress,SearchPathA,GetModuleFileNameA,FindFirstFileA,VirtualProtect,VirtualQuery,VirtualProtect,VirtualProtect,FindClose,FindClose, 0_2_0041744C
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00411E38 GetVersionExA,GetSystemInfo, 0_2_00411E38
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\Temp\_is8C78\0x0409.ini Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\Temp\_is8C78\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\Temp\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\Local\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\AppData\ Jump to behavior
Source: C:\Users\user\Desktop\plotdemo.exe File opened: C:\Users\user\ Jump to behavior
Source: GS_RES.PS.2.dr Binary or memory string: (END CATEGORY) VMDEBUG
Source: GS_RES.PS.2.dr Binary or memory string: (END MISC) VMDEBUG
Source: GS_RES.PS.2.dr Binary or memory string: (END GENERIC) VMDEBUG
Source: GS_RES.PS.2.dr Binary or memory string: (END FIXED) VMDEBUG
Source: GS_RES.PS.2.dr Binary or memory string: (BEGIN RESOURCES) VMDEBUG
Source: GS_RES.PS.2.dr Binary or memory string: (END ENCODING) VMDEBUG
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe API call chain: ExitProcess graph end node
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe API call chain: ExitProcess graph end node
Source: C:\Windows\System32\msiexec.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_004195B5 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 7_2_004195B5
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0040E3D8 __EH_prolog,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary, 0_2_0040E3D8
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00402C48 GetFileSize,GetProcessHeap,GetProcessHeap,RtlAllocateHeap,ReadFile,GetProcessHeap,HeapFree,GetProcessHeap,HeapFree, 0_2_00402C48
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00421C4C SetUnhandledExceptionFilter, 0_2_00421C4C
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_00421C3A SetUnhandledExceptionFilter, 0_2_00421C3A
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0041F842 _raise,_memset,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 7_2_0041F842
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0041AABB SetUnhandledExceptionFilter, 7_2_0041AABB
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_004195B5 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 7_2_004195B5
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00414E70 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 7_2_00414E70
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0041664E GetCurrentThread,OpenThreadToken,GetLastError,GetLastError,GetCurrentProcess,OpenProcessToken,GetLastError,GetTokenInformation,GetTokenInformation,GetLastError,GetTokenInformation,AllocateAndInitializeSid,EqualSid,FreeSid, 0_2_0041664E
Source: plotdemo.exe Binary or memory string: Shell_TrayWnd
Source: plotdemo.exe Binary or memory string: %s SetupLogFileNameSoftware\InstallShield\ISWI\7.0\SetupExeLogShell_TrayWndArialCancel%x,ALLCANCELDescriptionMSlovenianBasquedefault%#04xTitle.iniNoSuppressRebootKeyDotNetOptionalInstallIfSilentDotNetOptionalSETUPEXEDIRCertKeyISScript.MsiCacheFolderCacheRootLocationTypeScriptVerSuppressWrongOSSuppressReboot dotnetredistSp2.exelangpack.exeMicrosoft(R) .NET FrameworkJ#CmdLine/jscmd:\"""/q:a /C:\"J#Version/jsharpver:DotNetLangPacks /langs: /coreui:DotNetLangPackCmd /langcmd:"/c:\"\" /q:a" DotNetFxCmd" /c:" /ver: /q:a /l%d /q:a /c:"install /q"vjredist.exeDotNetCoreSetupUILang1033dotnetredist.exedotnetfx.exeInstallerLocationSoftware\Microsoft\Windows\CurrentVersion\Installer1.01.1J#OptionalJ#InstallOptionIfSilentISSCHEDULEREBOOT=1 ISSCHEDULEREBOOT=1ISScript10.Msiinstmsi30.exeRunAsLaunchingUser]
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_00421F05 cpuid 7_2_00421F05
Source: C:\Users\user\Desktop\plotdemo.exe Code function: GetLocaleInfoA, 0_2_004167D1
Source: C:\Users\user\Desktop\plotdemo.exe Code function: GetLocaleInfoA,TranslateCharsetInfo, 0_2_00416774
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: _strcpy_s,GetLocaleInfoA,__snprintf_s,LoadLibraryA, 7_2_00407DFE
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: GetThreadLocale,GetLocaleInfoA,GetACP, 7_2_0042641C
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: GetLocaleInfoA, 7_2_00423D63
Source: C:\Windows\SysWOW64\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Program Files (x86)\PSI\PSIPLOT\InstPost.exe Code function: 7_2_0041B36D GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter, 7_2_0041B36D
Source: C:\Users\user\Desktop\plotdemo.exe Code function: 0_2_0041DB0C EntryPoint,GetVersion,GetCommandLineA,GetStartupInfoA,GetModuleHandleA, 0_2_0041DB0C
No contacted IP infos