Windows Analysis Report
nitro_pro14.exe

Overview

General Information

Sample name: nitro_pro14.exe
Analysis ID: 1533060
MD5: 957c08652837223a7876d64f5f93f232
SHA1: 22cb448ac6bd4fc47a1889aa2643f0bd91e9c7ff
SHA256: 071dcd0fb10975eea48df1f75b3c6ecaec30c901fc7639ad8e60b99c231ee223
Infos:

Detection

Score: 25
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Potentially malicious time measurement code found
Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check the parent process ID (often done to detect debuggers and analysis systems)
Contains functionality to communicate with device drivers
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
JA3 SSL client fingerprint seen in connection with other malware
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)

Classification

Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000DBCDD DecryptFileW, 0_2_000DBCDD
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000DBAC2 DecryptFileW,DecryptFileW, 0_2_000DBAC2
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_00104B6F CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError, 0_2_00104B6F
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A7BCDD DecryptFileW, 1_2_00A7BCDD
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A7BAC2 DecryptFileW,DecryptFileW, 1_2_00A7BAC2
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00AA4B6F CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError, 1_2_00AA4B6F
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4578D0 MultiByteToWideChar,MultiByteToWideChar,CryptAcquireContextW,CryptReleaseContext,GetLastError, 1_2_6A4578D0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A459330 MultiByteToWideChar,MultiByteToWideChar,GetLastError,CryptAcquireContextW,CryptGetProvParam,GetLastError,CryptReleaseContext,CryptGetProvParam,GetLastError,CryptReleaseContext, 1_2_6A459330
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A458500 CryptAcquireContextW,GetLastError,CryptGetUserKey,CryptReleaseContext, 1_2_6A458500
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A40F590 CryptQueryObject,CryptMsgGetParam,CryptMsgGetParam,CertFindCertificateInStore,_invalid_parameter_noinfo_noreturn, 1_2_6A40F590
Source: nitro_pro14.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: nitro_pro14.exe Static PE information: certificate valid
Source: unknown HTTPS traffic detected: 104.16.123.109:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: nitro_pro14.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\build\nitroapp\vs2022-windows32\src\installer\bootstrapper\bootstrapper_dll\obj\Win32\Release\NitroBA.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000003.1700798161.0000000000ECE000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000002.2951735153.0000000006642000.00000002.00000001.01000000.0000000B.sdmp, nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp, NitroBA.dll.1.dr
Source: Binary string: C:\build\nitroapp\vs2022-windows32\src\installer\bootstrapper\page_transitions\obj\Win32\Release\PageTransitions.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2952860245.0000000006DF2000.00000002.00000001.01000000.0000000E.sdmp, PageTransitions.dll.1.dr
Source: Binary string: ?\C:\Windows\dll\NitroBA.pdb source: nitro_pro14.exe, 00000001.00000002.2951818300.00000000067A0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Windows\NitroBA.pdbpdboBA.pdb source: nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\burn.pdb source: nitro_pro14.exe, nitro_pro14.exe.0.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\obj\ship\x86\core\BootstrapperCore.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951384555.0000000006202000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.1.dr
Source: Binary string: \??\C:\Windows\NitroBA.pdbw source: nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\burn.pdb4 source: nitro_pro14.exe, nitro_pro14.exe.0.dr
Source: Binary string: C:\build\nitroapp\vs2022-windows32\src\installer\bootstrapper\page_transitions\obj\Win32\Release\PageTransitions.pdbd\~\ p\_CorDllMainmscoree.dll source: nitro_pro14.exe, 00000001.00000002.2952860245.0000000006DF2000.00000002.00000001.01000000.0000000E.sdmp, PageTransitions.dll.1.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: Binary string: \??\C:\Windows\NitroBA.pdb source: nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\agent\_work\35\s\wix\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdbP source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: Binary string: C:\build\nitroapp\vs2022-windows32\bin\Release\metrics.pdb source: nitro_pro14.exe, 00000001.00000002.2956167840.000000006A4EA000.00000002.00000001.01000000.0000000D.sdmp, metrics.dll.1.dr
Source: Binary string: C:\Users\lbugn\Documents\MVVMLight\GalaSoft.MvvmLight\GalaSoft.MvvmLight (NET4)\obj\Release\GalaSoft.MvvmLight.pdb source: nitro_pro14.exe, 00000001.00000002.2951653958.0000000006632000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\mbahost.pdb source: nitro_pro14.exe, 00000001.00000002.2956422927.000000006CC08000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.1.dr
Source: Binary string: C:\Users\lbugn\Documents\MVVMLight\GalaSoft.MvvmLight\GalaSoft.MvvmLight (NET4)\obj\Release\GalaSoft.MvvmLight.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951653958.0000000006632000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.1.dr
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C3B2C FindFirstFileW,FindClose, 0_2_000C3B2C
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000FC1FF FindFirstFileExW,FindNextFileW,FindClose,FindClose, 0_2_000FC1FF
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C1700 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,FindClose, 0_2_000C1700
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000DB76B FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 0_2_000DB76B
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A63B2C FindFirstFileW,FindClose, 1_2_00A63B2C
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9C1FF FindFirstFileExW,FindNextFileW,FindClose,FindClose, 1_2_00A9C1FF
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A61700 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,FindClose, 1_2_00A61700
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A7B76B FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 1_2_00A7B76B
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4D48E0 _errno,malloc,_errno,memset,MultiByteToWideChar,GetLastError,MultiByteToWideChar,MultiByteToWideChar,free,_errno,FindFirstFileW,free,_errno,_errno,FindNextFileW,WideCharToMultiByte,_errno, 1_2_6A4D48E0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4E175D ___std_fs_close_handle@4,FindFirstFileExW,GetLastError, 1_2_6A4E175D
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4E1794 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx,___std_fs_close_handle@4, 1_2_6A4E1794
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 4x nop then movd mm0, dword ptr [edx] 1_2_6A38CFF0
Source: Joe Sandbox View JA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: desktop.gonitro.com
Source: unknown HTTP traffic detected: POST /v14.29.1.0/events HTTP/1.1Content-type: application/jsonUser-Agent: Nitro 14.29.1.0Host: desktop.gonitro.comContent-Length: 334Connection: Keep-AliveCache-Control: no-cache
Source: nitro_pro14.exe String found in binary or memory: http://appsyndication.org/2006/appsyn
Source: nitro_pro14.exe, nitro_pro14.exe.0.dr String found in binary or memory: http://appsyndication.org/2006/appsynapplicationc:
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertCSRSA4096RootG5.crt0E
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA2.crt0
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://crl.globalsign.com/codesigningrootr45.crl0U
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://crl.globalsign.com/gsgccr45evcodesignca2020.crl0
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl3.digicert.com/DigiCertCSRSA4096RootG5.crl0
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0F
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA2.crl0=
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://ocsp.digicert.com0A
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://ocsp.digicert.com0C
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://ocsp.digicert.com0O
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, mbapreq.dll.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, mbahost.dll.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://ocsp.digicert.com0X
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://ocsp.globalsign.com/codesigningrootr450F
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://ocsp.globalsign.com/gsgccr45evcodesignca20200U
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://secure.globalsign.com/cacert/codesigningrootr45.crt0A
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: http://secure.globalsign.com/cacert/gsgccr45evcodesignca2020.crt0?
Source: nitro_pro14.exe String found in binary or memory: http://wixtoolset.org/
Source: nitro_pro14.exe, 00000001.00000002.2951384555.0000000006202000.00000002.00000001.01000000.0000000A.sdmp, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
Source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951384555.0000000006202000.00000002.00000001.01000000.0000000A.sdmp, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://wixtoolset.org/news/
Source: nitro_pro14.exe, Microsoft.Deployment.WindowsInstaller.dll.1.dr String found in binary or memory: http://wixtoolset.org/releases/
Source: nitro_pro14.exe, 00000001.00000002.2951384555.0000000006202000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.1.dr String found in binary or memory: http://wixtoolset.org/releases/SCreating
Source: mbapreq.thm.1.dr String found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010
Source: nitro_pro14.exe String found in binary or memory: http://wixtoolset.org/telemetry/v
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: http://www.digicert.com/CPS0
Source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951653958.0000000006632000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr String found in binary or memory: http://www.galasoft.ch
Source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951653958.0000000006632000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr String found in binary or memory: http://www.galasoft.ch/s/dialogmessage.
Source: nitro_pro14.exe, 00000001.00000002.2951653958.0000000006632000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr String found in binary or memory: http://www.galasoft.ch4
Source: nitro_pro14.exe, 00000001.00000002.2951681502.000000000663A000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr String found in binary or memory: http://www.galasoft.chN
Source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2950609083.0000000004101000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.gonitro.com/
Source: nitro_pro14.exe, 00000001.00000002.2951735153.0000000006642000.00000002.00000001.01000000.0000000B.sdmp, NitroBA.dll.1.dr String found in binary or memory: http://www.gonitro.com///support/privacy-policy
Source: nitro_pro14.exe, 00000001.00000002.2950609083.0000000004526000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.gonitro.com/en/support/privacy-po
Source: nitro_pro14.exe, 00000001.00000002.2950609083.0000000004526000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.gonitro.com/en/support/privacy-policy
Source: nitro_pro14.exe, 00000001.00000002.2950609083.0000000004526000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.gonitro.com/en/support/privacy-policy09
Source: nitro_pro14.exe, 00000001.00000002.2950609083.0000000004101000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.gonitro.com/en/support/privacy-policyx
Source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951735153.0000000006642000.00000002.00000001.01000000.0000000B.sdmp, nitro_pro14.exe, 00000001.00000002.2950609083.0000000004101000.00000004.00000800.00020000.00000000.sdmp, NitroBA.dll.1.dr String found in binary or memory: http://www.gonitro.com/services/linkredirector.aspx?lr_loc=
Source: nitro_pro14.exe, 00000001.00000002.2950609083.0000000004101000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://www.gonitro.com/services/linkredirector.aspx?lr_loc=en&lr_src=retail&lr_prod=Professional&lr_
Source: nitro_pro14.exe String found in binary or memory: http://www.google.com
Source: nitro_pro14.exe, 00000001.00000002.2951735153.0000000006642000.00000002.00000001.01000000.0000000B.sdmp, NitroBA.dll.1.dr String found in binary or memory: http://www.google.com)WPD
Source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2956167840.000000006A4EA000.00000002.00000001.01000000.0000000D.sdmp, metrics.dll.1.dr String found in binary or memory: https://desktop.gonitro.com
Source: nitro_pro14.exe, 00000001.00000002.2951818300.00000000067DF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://desktop.gonitro.com/
Source: nitro_pro14.exe, 00000001.00000002.2951818300.00000000067DF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://desktop.gonitro.com/M
Source: nitro_pro14.exe, 00000001.00000002.2951818300.00000000067DF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://desktop.gonitro.com/v14.29.1.0/events
Source: nitro_pro14.exe, 00000001.00000002.2951818300.00000000067DF000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://desktop.gonitro.com/v14.29.1.0/events=
Source: nitro_pro14.exe, 00000001.00000002.2956167840.000000006A4EA000.00000002.00000001.01000000.0000000D.sdmp, metrics.dll.1.dr String found in binary or memory: https://desktop.gonitro.comhttps://desktop.gonitrodev.commetrics.use_dev_servert
Source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2956167840.000000006A4EA000.00000002.00000001.01000000.0000000D.sdmp, metrics.dll.1.dr String found in binary or memory: https://desktop.gonitrodev.com
Source: nitro_pro14.exe, 00000000.00000003.1689742811.0000000000E90000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000000.00000003.1689862045.0000000000E90000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000000.00000002.2947590094.0000000000E90000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://downloads.gonitro.com/professional_14.29.1.0/en
Source: nitro_pro14.exe, 00000000.00000003.1689742811.0000000000E98000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000000.00000003.1689862045.0000000000E98000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000000.00000002.2947590094.0000000000E90000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000000.00000002.2948280651.0000000003400000.00000004.00000800.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000002.2947992871.0000000000E2F000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000003.1696687450.0000000000E36000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000002.2950438684.00000000033F0000.00000004.00000800.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000003.1696687450.0000000000E08000.00000004.00000020.00020000.00000000.sdmp, BootstrapperApplicationData.xml.1.dr String found in binary or memory: https://downloads.gonitro.com/professional_14.29.1.0/en/retail/nitro_pro14_ba_x64.msi
Source: nitro_pro14.exe, 00000000.00000003.1689742811.0000000000E90000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000000.00000003.1689862045.0000000000E90000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000000.00000002.2947590094.0000000000E90000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://go.micro
Source: nitro_pro14.exe, 00000001.00000003.1696687450.0000000000E2F000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://go.microI
Source: mbapreq.dll.1.dr, mbahost.dll.1.dr, Microsoft.Deployment.WindowsInstaller.dll.1.dr, BootstrapperCore.dll.1.dr String found in binary or memory: https://wixtoolset.org/
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: https://www.globalsign.com/repository/0
Source: nitro_pro14.exe, NitroBA.resources.dll0.1.dr, NitroBA.resources.dll2.1.dr, GalaSoft.MvvmLight.dll.1.dr, nitro_pro14.exe.0.dr, NitroBA.resources.dll3.1.dr, metrics.dll.1.dr, NitroBA.resources.dll.1.dr, PageTransitions.dll.1.dr, NitroBA.dll.1.dr, NitroBA.resources.dll1.1.dr String found in binary or memory: https://www.gonitro.com
Source: unknown Network traffic detected: HTTP traffic on port 443 -> 49732
Source: unknown Network traffic detected: HTTP traffic on port 49732 -> 443
Source: unknown HTTPS traffic detected: 104.16.123.109:443 -> 192.168.2.4:49732 version: TLS 1.2
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A40C340: MultiByteToWideChar,memset,MultiByteToWideChar,_invalid_parameter_noinfo_noreturn,DeviceIoControl,CloseHandle,std::_Xregex_error,fwrite,_errno, 1_2_6A40C340
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F712E 0_2_000F712E
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F21D9 0_2_000F21D9
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F24A0 0_2_000F24A0
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F74BC 0_2_000F74BC
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000FA703 0_2_000FA703
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F275B 0_2_000F275B
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000FEAE0 0_2_000FEAE0
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F1BBD 0_2_000F1BBD
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000E5CCD 0_2_000E5CCD
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000EDD78 0_2_000EDD78
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F1F2F 0_2_000F1F2F
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000FEF68 0_2_000FEF68
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C7FA9 0_2_000C7FA9
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_00103FCA 0_2_00103FCA
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A921D9 1_2_00A921D9
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9712E 1_2_00A9712E
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A924A0 1_2_00A924A0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A974BC 1_2_00A974BC
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9A703 1_2_00A9A703
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9275B 1_2_00A9275B
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9EAE0 1_2_00A9EAE0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A91BBD 1_2_00A91BBD
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A85CCD 1_2_00A85CCD
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A8DD78 1_2_00A8DD78
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A67FA9 1_2_00A67FA9
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00AA3FCA 1_2_00AA3FCA
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A91F2F 1_2_00A91F2F
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9EF68 1_2_00A9EF68
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_06642050 1_2_06642050
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_06647AC3 1_2_06647AC3
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_0664CD43 1_2_0664CD43
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_0664CD29 1_2_0664CD29
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_06DF2050 1_2_06DF2050
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A412EC0 1_2_6A412EC0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A415460 1_2_6A415460
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A383A9D 1_2_6A383A9D
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3B6AD0 1_2_6A3B6AD0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3E2B10 1_2_6A3E2B10
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A46FB00 1_2_6A46FB00
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4708C0 1_2_6A4708C0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3EC8B0 1_2_6A3EC8B0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3E1880 1_2_6A3E1880
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A424940 1_2_6A424940
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D2970 1_2_6A3D2970
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3F1950 1_2_6A3F1950
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A40EE50 1_2_6A40EE50
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A40BED0 1_2_6A40BED0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A409EA0 1_2_6A409EA0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D2F20 1_2_6A3D2F20
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A38DF40 1_2_6A38DF40
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A42AC10 1_2_6A42AC10
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3EBC80 1_2_6A3EBC80
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A41CDE0 1_2_6A41CDE0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3EC210 1_2_6A3EC210
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A42B220 1_2_6A42B220
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D7250 1_2_6A3D7250
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A426290 1_2_6A426290
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3F72D0 1_2_6A3F72D0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4423A0 1_2_6A4423A0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A381000 1_2_6A381000
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D50A0 1_2_6A3D50A0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D40C0 1_2_6A3D40C0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A423120 1_2_6A423120
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A415630 1_2_6A415630
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A42A6F0 1_2_6A42A6F0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D6720 1_2_6A3D6720
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D9710 1_2_6A3D9710
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A43F700 1_2_6A43F700
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A46F430 1_2_6A46F430
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4194D0 1_2_6A4194D0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D6480 1_2_6A3D6480
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3B6540 1_2_6A3B6540
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A422580 1_2_6A422580
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A46E590 1_2_6A46E590
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A3D35E0 1_2_6A3D35E0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBF9E1C 1_2_6CBF9E1C
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CC00738 1_2_6CC00738
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBF9A8E 1_2_6CBF9A8E
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CC002B0 1_2_6CC002B0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CC063CE 1_2_6CC063CE
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBFC3AC 1_2_6CBFC3AC
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_06648703 1_2_06648703
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_06647E1C 1_2_06647E1C
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 00AA534A appears 683 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 6A3E7AD0 appears 108 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 6A3E31A0 appears 87 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 00A613B3 appears 501 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 6A4E0A30 appears 50 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 6CBF4460 appears 34 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 00AA78B5 appears 79 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 6A42DE20 appears 55 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 00A629F6 appears 54 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 00AA5831 appears 34 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 00A90AC0 appears 33 times
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: String function: 6A400440 appears 48 times
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: String function: 000F0AC0 appears 33 times
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: String function: 001078B5 appears 79 times
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: String function: 000C29F6 appears 54 times
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: String function: 00105831 appears 34 times
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: String function: 000C13B3 appears 501 times
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: String function: 0010534A appears 683 times
Source: nitro_pro14.exe Binary or memory string: OriginalFilename vs nitro_pro14.exe
Source: nitro_pro14.exe, 00000001.00000002.2947992871.0000000000DE8000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameclr.dllT vs nitro_pro14.exe
Source: nitro_pro14.exe, 00000001.00000002.2952860245.0000000006DF2000.00000002.00000001.01000000.0000000E.sdmp Binary or memory string: OriginalFilenamePageTransitions.dll@ vs nitro_pro14.exe
Source: nitro_pro14.exe, 00000001.00000002.2951681502.000000000663A000.00000002.00000001.01000000.0000000C.sdmp Binary or memory string: OriginalFilenameGalaSoft.MvvmLight.dllF vs nitro_pro14.exe
Source: nitro_pro14.exe, 00000001.00000002.2951735153.0000000006642000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: OriginalFilenameNitroBA.dll< vs nitro_pro14.exe
Source: nitro_pro14.exe, 00000001.00000002.2956473751.000000006CC12000.00000002.00000001.01000000.00000007.sdmp Binary or memory string: OriginalFilenamembahost.dll\ vs nitro_pro14.exe
Source: nitro_pro14.exe, 00000001.00000002.2951420115.0000000006214000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: OriginalFilenameBootstrapperCore.dll\ vs nitro_pro14.exe
Source: nitro_pro14.exe, 00000001.00000002.2956329196.000000006A565000.00000002.00000001.01000000.0000000D.sdmp Binary or memory string: OriginalFilenamemetrics< vs nitro_pro14.exe
Source: nitro_pro14.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: classification engine Classification label: sus25.evad.winEXE@3/51@1/1
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C2A4C FormatMessageW,GetLastError,LocalFree, 0_2_000C2A4C
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C62C2 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 0_2_000C62C2
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A662C2 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 1_2_00A662C2
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A414060 CreateToolhelp32Snapshot,CloseHandle,_CxxThrowException,GetCurrentProcessId,Thread32First,GetLastError,Thread32Next, 1_2_6A414060
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_00107615 GetModuleHandleA,GetLastError,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CoCreateInstance,ExitProcess, 0_2_00107615
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000E864A ChangeServiceConfigW,GetLastError, 0_2_000E864A
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Users\user\AppData\Roaming\Nitro Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Mutant created: NULL
Source: C:\Users\user\Desktop\nitro_pro14.exe File created: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\ Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: cabinet.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: msi.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: version.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: wininet.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: comres.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: clbcatq.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: msasn1.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: crypt32.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: feclient.dll 0_2_000C10E1
Source: C:\Users\user\Desktop\nitro_pro14.exe Command line argument: cabinet.dll 0_2_000C10E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: cabinet.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: msi.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: version.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: wininet.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: comres.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: clbcatq.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: msasn1.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: crypt32.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: feclient.dll 1_2_00A610E1
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Command line argument: cabinet.dll 1_2_00A610E1
Source: nitro_pro14.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\nitro_pro14.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: nitro_pro14.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: nitro_pro14.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: nitro_pro14.exe String found in binary or memory: resources/nitro-installer-convert.png
Source: nitro_pro14.exe String found in binary or memory: resources/nitro-installer-devices.png
Source: nitro_pro14.exe String found in binary or memory: resources/nitro-installer-customer-logos.png
Source: nitro_pro14.exe String found in binary or memory: resources/nitro-installer-edit.png
Source: nitro_pro14.exe String found in binary or memory: resources/nitro-installer-sign.png
Source: nitro_pro14.exe String found in binary or memory: resources/nitro-installer-office-scene.png
Source: nitro_pro14.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: C:\Users\user\Desktop\nitro_pro14.exe File read: C:\Users\user\Desktop\nitro_pro14.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\nitro_pro14.exe "C:\Users\user\Desktop\nitro_pro14.exe"
Source: C:\Users\user\Desktop\nitro_pro14.exe Process created: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe "C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe" -burn.clean.room="C:\Users\user\Desktop\nitro_pro14.exe" -burn.filehandle.attached=652 -burn.filehandle.self=680
Source: C:\Users\user\Desktop\nitro_pro14.exe Process created: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe "C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe" -burn.clean.room="C:\Users\user\Desktop\nitro_pro14.exe" -burn.filehandle.attached=652 -burn.filehandle.self=680 Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: msi.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: msvcp140_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: msvcp140.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: msvcp140_atomic_wait.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: mfc140u.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: concrt140.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: vcruntime140.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: schannel.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: mskeyprotect.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dpapi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: gpapi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: ncryptsslp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: windowscodecs.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: msctfui.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: nitro_pro14.exe Static PE information: certificate valid
Source: nitro_pro14.exe Static file information: File size 2457960 > 1048576
Source: nitro_pro14.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: nitro_pro14.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: nitro_pro14.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: nitro_pro14.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: nitro_pro14.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: nitro_pro14.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: nitro_pro14.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: nitro_pro14.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\build\nitroapp\vs2022-windows32\src\installer\bootstrapper\bootstrapper_dll\obj\Win32\Release\NitroBA.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000003.1700798161.0000000000ECE000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000002.2951735153.0000000006642000.00000002.00000001.01000000.0000000B.sdmp, nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp, NitroBA.dll.1.dr
Source: Binary string: C:\build\nitroapp\vs2022-windows32\src\installer\bootstrapper\page_transitions\obj\Win32\Release\PageTransitions.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2952860245.0000000006DF2000.00000002.00000001.01000000.0000000E.sdmp, PageTransitions.dll.1.dr
Source: Binary string: ?\C:\Windows\dll\NitroBA.pdb source: nitro_pro14.exe, 00000001.00000002.2951818300.00000000067A0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\Windows\NitroBA.pdbpdboBA.pdb source: nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\burn.pdb source: nitro_pro14.exe, nitro_pro14.exe.0.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\obj\ship\x86\core\BootstrapperCore.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951384555.0000000006202000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.1.dr
Source: Binary string: \??\C:\Windows\NitroBA.pdbw source: nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\burn.pdb4 source: nitro_pro14.exe, nitro_pro14.exe.0.dr
Source: Binary string: C:\build\nitroapp\vs2022-windows32\src\installer\bootstrapper\page_transitions\obj\Win32\Release\PageTransitions.pdbd\~\ p\_CorDllMainmscoree.dll source: nitro_pro14.exe, 00000001.00000002.2952860245.0000000006DF2000.00000002.00000001.01000000.0000000E.sdmp, PageTransitions.dll.1.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: Binary string: \??\C:\Windows\NitroBA.pdb source: nitro_pro14.exe, 00000001.00000003.1700853682.0000000000EA5000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\agent\_work\35\s\wix\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdbP source: Microsoft.Deployment.WindowsInstaller.dll.1.dr
Source: Binary string: C:\build\nitroapp\vs2022-windows32\bin\Release\metrics.pdb source: nitro_pro14.exe, 00000001.00000002.2956167840.000000006A4EA000.00000002.00000001.01000000.0000000D.sdmp, metrics.dll.1.dr
Source: Binary string: C:\Users\lbugn\Documents\MVVMLight\GalaSoft.MvvmLight\GalaSoft.MvvmLight (NET4)\obj\Release\GalaSoft.MvvmLight.pdb source: nitro_pro14.exe, 00000001.00000002.2951653958.0000000006632000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\mbahost.pdb source: nitro_pro14.exe, 00000001.00000002.2956422927.000000006CC08000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.1.dr
Source: Binary string: C:\Users\lbugn\Documents\MVVMLight\GalaSoft.MvvmLight\GalaSoft.MvvmLight (NET4)\obj\Release\GalaSoft.MvvmLight.pdb source: nitro_pro14.exe, nitro_pro14.exe, 00000001.00000002.2951653958.0000000006632000.00000002.00000001.01000000.0000000C.sdmp, GalaSoft.MvvmLight.dll.1.dr
Source: Binary string: C:\agent\_work\35\s\wix\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.1.dr
Source: nitro_pro14.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: nitro_pro14.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: nitro_pro14.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: nitro_pro14.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: nitro_pro14.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: nitro_pro14.exe Static PE information: section name: .wixburn
Source: nitro_pro14.exe.0.dr Static PE information: section name: .wixburn
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F0B06 push ecx; ret 0_2_000F0B19
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_0010CCD3 push ecx; ret 0_2_0010CCE6
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A90B06 push ecx; ret 1_2_00A90B19
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00AACCD3 push ecx; ret 1_2_00AACCE6
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_06635B25 push es; ret 1_2_06635B2A
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4E0E28 push ecx; ret 1_2_6A4E0E3B
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A382C10 push 89084589h; iretd 1_2_6A382C15
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBF44A6 push ecx; ret 1_2_6CBF44B9
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CC06AE3 push ecx; ret 1_2_6CC06AF6
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_031A6590 pushad ; iretd 1_2_031A6591
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_031A7590 push es; ret 1_2_031A75A0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_031AD5F0 push E8717814h; iretd 1_2_031AD5F5
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_031AB440 push esp; retf 1_2_031AB449
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_031A6B15 pushfd ; iretd 1_2_031A6B19
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_031AAF4B pushad ; iretd 1_2_031AAF59
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_031AAF7B pushfd ; iretd 1_2_031AAF89
Source: NitroBA.dll.1.dr Static PE information: section name: .text entropy: 7.17009385214746
Source: metrics.dll.1.dr Static PE information: section name: .text entropy: 6.950457755326262
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\de\NitroBA.resources.dll Jump to dropped file
Source: C:\Users\user\Desktop\nitro_pro14.exe File created: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\fr\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\PageTransitions.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\it\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\nl\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\es\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\mbahost.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\metrics.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\GalaSoft.MvvmLight.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\NitroBA.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\de\NitroBA.resources.dll Jump to dropped file
Source: C:\Users\user\Desktop\nitro_pro14.exe File created: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\fr\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\PageTransitions.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\it\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\nl\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\es\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\mbahost.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\metrics.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\GalaSoft.MvvmLight.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe File created: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\NitroBA.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Memory allocated: 2DF0000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Memory allocated: 4100000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Memory allocated: 32F0000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A381A90 rdtsc 1_2_6A381A90
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A414060 CreateToolhelp32Snapshot,CloseHandle,_CxxThrowException,GetCurrentProcessId,Thread32First,GetLastError,Thread32Next, 1_2_6A414060
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Window / User API: threadDelayed 405 Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\de\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\fr\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\PageTransitions.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\it\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\nl\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\es\NitroBA.resources.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\mbahost.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\metrics.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\GalaSoft.MvvmLight.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Dropped PE file which has not been started: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\NitroBA.dll Jump to dropped file
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\nitro_pro14.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\nitro_pro14.exe API coverage: 9.1 %
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_00104FD0 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 0010506Bh 0_2_00104FD0
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_00104FD0 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 00105064h 0_2_00104FD0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00AA4FD0 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 00AA506Bh 1_2_00AA4FD0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00AA4FD0 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 00AA5064h 1_2_00AA4FD0
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C3B2C FindFirstFileW,FindClose, 0_2_000C3B2C
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000FC1FF FindFirstFileExW,FindNextFileW,FindClose,FindClose, 0_2_000FC1FF
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C1700 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,FindClose, 0_2_000C1700
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000DB76B FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 0_2_000DB76B
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A63B2C FindFirstFileW,FindClose, 1_2_00A63B2C
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9C1FF FindFirstFileExW,FindNextFileW,FindClose,FindClose, 1_2_00A9C1FF
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A61700 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,FindClose, 1_2_00A61700
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A7B76B FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 1_2_00A7B76B
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4D48E0 _errno,malloc,_errno,memset,MultiByteToWideChar,GetLastError,MultiByteToWideChar,MultiByteToWideChar,free,_errno,FindFirstFileW,free,_errno,_errno,FindNextFileW,WideCharToMultiByte,_errno, 1_2_6A4D48E0
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4E175D ___std_fs_close_handle@4,FindFirstFileExW,GetLastError, 1_2_6A4E175D
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4E1794 GetFileAttributesExW,GetLastError,FindFirstFileW,GetLastError,FindClose,___std_fs_open_handle@16,GetFileInformationByHandleEx,GetLastError,GetFileInformationByHandleEx,GetFileInformationByHandleEx,___std_fs_close_handle@4, 1_2_6A4E1794
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000EFB9C VirtualQuery,GetSystemInfo, 0_2_000EFB9C
Source: nitro_pro14.exe, 00000001.00000003.2197325293.0000000006819000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000002.2951818300.00000000067DF000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000002.2951818300.0000000006819000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: nitro_pro14.exe, 00000001.00000003.2197325293.0000000006819000.00000004.00000020.00020000.00000000.sdmp, nitro_pro14.exe, 00000001.00000002.2951818300.0000000006819000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAWen-GBnqZ
Source: C:\Users\user\Desktop\nitro_pro14.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\nitro_pro14.exe API call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe API call chain: ExitProcess graph end node

Anti Debugging

barindex
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A381A90 1_2_6A381A90
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A381B00 1_2_6A381B00
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A381A90 rdtsc 1_2_6A381A90
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F84A7 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_000F84A7
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A414060 CreateToolhelp32Snapshot,CloseHandle,_CxxThrowException,GetCurrentProcessId,Thread32First,GetLastError,Thread32Next, 1_2_6A414060
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F9808 mov ecx, dword ptr fs:[00000030h] 0_2_000F9808
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000FCF2C mov eax, dword ptr fs:[00000030h] 0_2_000FCF2C
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A99808 mov ecx, dword ptr fs:[00000030h] 1_2_00A99808
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A9CF2C mov eax, dword ptr fs:[00000030h] 1_2_00A9CF2C
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBFDCB7 mov eax, dword ptr fs:[00000030h] 1_2_6CBFDCB7
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBFB3F1 mov ecx, dword ptr fs:[00000030h] 1_2_6CBFB3F1
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C50E9 GetProcessHeap,RtlAllocateHeap, 0_2_000C50E9
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F03A9 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 0_2_000F03A9
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F84A7 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_000F84A7
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F0874 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 0_2_000F0874
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F0A07 SetUnhandledExceptionFilter, 0_2_000F0A07
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A903A9 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 1_2_00A903A9
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A984A7 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_00A984A7
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A90874 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_00A90874
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_00A90A07 SetUnhandledExceptionFilter, 1_2_00A90A07
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4E0B10 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 1_2_6A4E0B10
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6A4E0F75 IsProcessorFeaturePresent,memset,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_6A4E0F75
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBF44BC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 1_2_6CBF44BC
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBFAC7C IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_6CBFAC7C
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: 1_2_6CBF42E6 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_6CBF42E6
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Process created: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe "C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe" -burn.clean.room="C:\Users\user\Desktop\nitro_pro14.exe" -burn.filehandle.attached=652 -burn.filehandle.self=680 Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_00105CFE InitializeSecurityDescriptor,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,CreateWellKnownSid,GetLastError,SetEntriesInAclA,SetSecurityDescriptorOwner,GetLastError,SetSecurityDescriptorGroup,GetLastError,SetSecurityDescriptorDacl,GetLastError,CoInitializeSecurity,LocalFree, 0_2_00105CFE
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_0010801A AllocateAndInitializeSid,CheckTokenMembership, 0_2_0010801A
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000F0C37 cpuid 0_2_000F0C37
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Code function: GetLocaleInfoEx,FormatMessageA, 1_2_6A4E14CD
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\BootstrapperCore.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\NitroBA.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\GalaSoft.MvvmLight.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Users\user\AppData\Roaming\Nitro\PDF Pro\14 VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Temp\{6E12AC3B-4BC0-4764-A2BD-1C246CC66772}\.ba\PageTransitions.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Queries volume information: C:\Windows\Fonts\segoeuil.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000D6BA2 ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,GetLastError,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree, 0_2_000D6BA2
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_001092A6 GetSystemTimeAsFileTime, 0_2_001092A6
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C7E8C GetUserNameW,GetLastError, 0_2_000C7E8C
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_0010BDED GetTimeZoneInformation,SystemTimeToTzSpecificLocalTime, 0_2_0010BDED
Source: C:\Users\user\Desktop\nitro_pro14.exe Code function: 0_2_000C6E5B GetModuleHandleW,CoInitializeEx,GetVersionExW,GetLastError,CoUninitialize, 0_2_000C6E5B
Source: C:\Windows\Temp\{FF9FB498-690B-42AD-8947-9DAF033FB533}\.cr\nitro_pro14.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs