Click to jump to signature section
Source: WDSetup.EXE, 00000005.00000002.1986488473.000000006A322000.00000002.00000001.01000000.00000017.sdmp | Binary or memory string: -----BEGIN PUBLIC KEY----- | memstr_d3b9a20a-7 |
Source: INSTALL.EXE | Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE |
Source: C:\Users\user\AppData\Local\Temp\WD_171A.tmp\INSTALL.EXE | File created: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetupFontLicence.txt | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetup.EXE | File created: C:\Program Files (x86)\SIGA\INSTALL\WDSetupFontLicence.txt | Jump to behavior |
Source: INSTALL.EXE | Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: | Binary string: H:\source\source.YB\79749\Release_preinstall_9\WX\Desktop_x86_32\Release\SetupFTP.pdb source: INSTALL.EXE, 00000001.00000000.1154931373.00000000004C3000.00000002.00000001.01000000.00000006.sdmp |
Source: | Binary string: H:\source\source.PAD\91845\Release_wdobj_261\WX\Desktop_x86_32\Release\wd260obj.pdb' source: SIGA-ADMINISTRATION.exe, 0000000C.00000002.2287778764.0000000068801000.00000002.00000001.01000000.0000001C.sdmp |
Source: | Binary string: C:\source\source.SAM\58099\Release_WebKit_14_Source\PCS\PCSWebKitDLL\WX\Win32\Release\bin\wd260wk.pdbpR>d source: WDSetup.EXE, 00000005.00000003.1562198990.0000000008BFC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: H:\source\source.PAD\91845\Release_wdobj_261\WX\Desktop_x86_32\Release\wd260obj.pdb source: SIGA-ADMINISTRATION.exe, 0000000C.00000002.2287778764.0000000068801000.00000002.00000001.01000000.0000001C.sdmp |
Source: | Binary string: C:\source\source.SAM\58099\Release_WebKit_14_Source\PCS\PCSWebKitDLL\WX\Win32\Release\bin\wd260wk.pdb source: WDSetup.EXE, 00000005.00000003.1562198990.0000000008BFC000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: H:\source\source.SAM\79765\Release_wdexe_75\WX\Desktop_x86_32\Release\WDExe.pdbe source: WDSetup.EXE, 00000005.00000003.1570498209.0000000008F95000.00000004.00000020.00020000.00000000.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000000.1645869868.0000000000BB2000.00000002.00000001.01000000.00000018.sdmp |
Source: | Binary string: H:\source\source.MG\91382\Release_wdhf_263\WX\Desktop_x86_32\Release\wd260hf.pdb source: WDSetup.EXE, 00000005.00000002.2021980964.000000006AA1B000.00000002.00000001.01000000.00000015.sdmp |
Source: | Binary string: H:\source\source.GP\79788\Release_WDMetabase_7\wx\Desktop_x86_32\Release\WDMetabase.pdb source: INSTALL.EXE, 00000001.00000003.1260444365.00000000015FD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: c:\source\source.GF\92082\Release_wdhtml_7\WX\Desktop_x86_32\Release\WD260HTML.pdb source: WDSetup.EXE, 00000005.00000003.1552176753.0000000008BD9000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: H:\source\source.SAM\73975\Release_wdexe_75\WX\Desktop_x86_32\Release\WDExe.pdb source: WDSetup.EXE, 00000005.00000003.1271448834.00000000024E3000.00000004.00000020.00020000.00000000.sdmp, WDSetup.EXE, 00000005.00000000.1265854653.0000000000532000.00000002.00000001.01000000.0000000B.sdmp |
Source: | Binary string: H:\source\source.RR\79738\Release_wdtrs_35\WX\Desktop_x86_32\Release\wd260trs.pdb+ source: INSTALL.EXE, 00000001.00000003.1254506738.00000000015FD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: c:\source\source.YB\91875\Release_wdvm_59\wx\Desktop_x86_32\Release\wd260vm.PDB source: SIGA-ADMINISTRATION.exe, 0000000C.00000002.2424167458.0000000069CDC000.00000002.00000001.01000000.00000019.sdmp |
Source: | Binary string: L5jsuccessfulmalformedrequestinternalerrortrylatersigrequiredunauthorizedgoodunspecifiedkeyCompromisecACompromiseaffiliationChangedsupersededcessationOfOperationcertificateHoldremoveFromCRL(UNKNOWN)crypto\ocsp\ocsp_vfy.ccompiler: cl /Z7 /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 /WX -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_CPUID_OBJ -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DRC4_ASM -DMD5_ASM -DRMD160_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DECP_NISTZ256_ASM -DPOLY1305_ASMOpenSSL 1.1.1d 10 Sep 2019built on: Fri Oct 11 16:24:32 2019 UTCplatform: VC-WIN32OPENSSLDIR: "M:\Source.WX\WDCom\LibExternes\openssl\WX\WIN32\release"ENGINESDIR: "M:\Source.WX\WDCom\LibExternes\openssl\WX\WIN32\release\lib\engines-1_1"not available%lu:%s:%s:%d:%s source: WDSetup.EXE, 00000005.00000002.1986488473.000000006A322000.00000002.00000001.01000000.00000017.sdmp |
Source: | Binary string: H:\source\source.YV\80306\Release_wdautoex_9\WX\Desktop_x86_32\Release\WdAutoEx.pdb source: INSTALL.EXE, 00000000.00000000.1151554817.00000000006ED000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: H:\source\source.SAM\73975\Release_wdexe_75\WX\Desktop_x86_32\Release\WDExe.pdb[ source: WDSetup.EXE, 00000005.00000003.1271448834.00000000024E3000.00000004.00000020.00020000.00000000.sdmp, WDSetup.EXE, 00000005.00000000.1265854653.0000000000532000.00000002.00000001.01000000.0000000B.sdmp |
Source: | Binary string: H:\source\source.SAM\79765\Release_wdexe_75\WX\Desktop_x86_32\Release\WDExe.pdb source: WDSetup.EXE, 00000005.00000003.1570498209.0000000008F95000.00000004.00000020.00020000.00000000.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000000.1645869868.0000000000BB2000.00000002.00000001.01000000.00000018.sdmp |
Source: | Binary string: H:\source\source.GP\87613\Release_wdpnt_69\WX\Desktop_x86_32\Release\wd260pnt.pdb source: WDSetup.EXE, 00000005.00000002.2052440671.000000006B4FD000.00000002.00000001.01000000.00000011.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000002.2256481971.000000006830B000.00000002.00000001.01000000.0000001D.sdmp |
Source: | Binary string: compiler: cl /Z7 /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 /WX -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_CPUID_OBJ -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DRC4_ASM -DMD5_ASM -DRMD160_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DECP_NISTZ256_ASM -DPOLY1305_ASM source: WDSetup.EXE, 00000005.00000002.1986488473.000000006A322000.00000002.00000001.01000000.00000017.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000002.2195204845.0000000067183000.00000002.00000001.01000000.00000021.sdmp |
Source: | Binary string: H:\source\source.GP\91849\Release_wdmdl_37\WX\Desktop_x86_32\Release\wd260mdl.pdb source: WDSetup.EXE, 00000005.00000002.2038961916.000000006B073000.00000002.00000001.01000000.00000012.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000002.2208071294.00000000675AB000.00000002.00000001.01000000.00000020.sdmp |
Source: | Binary string: H:\source\source.YV\80306\Release_wdautoex_9\WX\Desktop_x86_32\Release\WdAutoEx.pdb: source: INSTALL.EXE, 00000000.00000000.1151554817.00000000006ED000.00000002.00000001.01000000.00000003.sdmp |
Source: | Binary string: gsuccessfulmalformedrequestinternalerrortrylatersigrequiredunauthorizedgoodunspecifiedkeyCompromisecACompromiseaffiliationChangedsupersededcessationOfOperationcertificateHoldremoveFromCRL(UNKNOWN)crypto\ocsp\ocsp_vfy.ccompiler: cl /Z7 /Fdossl_static.pdb /MT /Zl /Gs0 /GF /Gy /W3 /wd4090 /nologo /O2 /WX -DL_ENDIAN -DOPENSSL_PIC -DOPENSSL_CPUID_OBJ -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DOPENSSL_BN_ASM_MONT -DOPENSSL_BN_ASM_GF2m -DSHA1_ASM -DSHA256_ASM -DSHA512_ASM -DRC4_ASM -DMD5_ASM -DRMD160_ASM -DVPAES_ASM -DWHIRLPOOL_ASM -DGHASH_ASM -DECP_NISTZ256_ASM -DPOLY1305_ASMOpenSSL 1.1.1d 10 Sep 2019built on: Fri Oct 11 16:24:32 2019 UTCplatform: VC-WIN32OPENSSLDIR: "M:\Source.WX\WDCom\LibExternes\openssl\WX\WIN32\release"ENGINESDIR: "M:\Source.WX\WDCom\LibExternes\openssl\WX\WIN32\release\lib\engines-1_1"not available%lu:%s:%s:%d:%s source: SIGA-ADMINISTRATION.exe, 0000000C.00000002.2195204845.0000000067183000.00000002.00000001.01000000.00000021.sdmp |
Source: | Binary string: H:\source\source.DS\91575\Release_wdstd_81\WX\Desktop_x86_32\Release\wd260std.pdb source: SIGA-ADMINISTRATION.exe, 0000000C.00000002.2388162641.00000000697F1000.00000002.00000001.01000000.0000001A.sdmp |
Source: | Binary string: C:\source\source.DS\89287\Release_wdcom_89\WX\Desktop_x86_32\Release\wd260com.pdb source: WDSetup.EXE, 00000005.00000002.1986488473.000000006A322000.00000002.00000001.01000000.00000017.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000002.2195204845.0000000067246000.00000002.00000001.01000000.00000021.sdmp |
Source: | Binary string: H:\source\source.AP\91518\Release_wdxml_93\WX\Desktop_x86_32\Release\wd260xml.pdb source: WDSetup.EXE, 00000005.00000002.2004416457.000000006A71D000.00000002.00000001.01000000.00000016.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000002.2217506054.000000006787F000.00000002.00000001.01000000.0000001F.sdmp |
Source: | Binary string: H:\source\source.YB\79749\Release_preinstall_9\WX\Desktop_x86_32\Release\SetupFTP.pdb\ source: INSTALL.EXE, 00000001.00000000.1154931373.00000000004C3000.00000002.00000001.01000000.00000006.sdmp |
Source: | Binary string: C:\source\source.IC\79759\Release_wdpdf_23\WX\Desktop_x86_32\Release\wd260pdf.pdb source: WDSetup.EXE, 00000005.00000003.1554487092.0000000008BE6000.00000004.00000020.00020000.00000000.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000002.2233545225.00000000680DD000.00000002.00000001.01000000.0000001E.sdmp |
Source: | Binary string: C:\source\source.IC\79759\Release_wdpdf_23\WX\Desktop_x86_32\Release\wd260pdf.pdbc source: WDSetup.EXE, 00000005.00000003.1554487092.0000000008BE6000.00000004.00000020.00020000.00000000.sdmp, SIGA-ADMINISTRATION.exe, 0000000C.00000002.2233545225.00000000680DD000.00000002.00000001.01000000.0000001E.sdmp |
Source: | Binary string: H:\source\source.YV\79805\Release_wdrtf_25\WX\Desktop_x86_32\Release\wd260rtf.pdb source: WDSetup.EXE, 00000005.00000003.1541205718.0000000008BDE000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: H:\source\source.RR\79738\Release_wdtrs_35\WX\Desktop_x86_32\Release\wd260trs.pdb source: INSTALL.EXE, 00000001.00000003.1254506738.00000000015FD000.00000004.00000020.00020000.00000000.sdmp |
Source: | Binary string: H:\source\source.RR\80476\Release_wduni_27\Build\Desktop_x86_32\Release\wd260UNI.pdb source: WDSetup.EXE, 00000005.00000003.1393687929.0000000007F09000.00000004.00000020.00020000.00000000.sdmp |
Source: C:\Program Files (x86)\SIGA\SIGA-ADMINISTRATION.exe | Code function: 12_2_6741AB59 LoadLibraryW,GetProcAddress,GetFileInformationByHandle,GetLogicalDriveStringsW,GetVolumeInformationW, | 12_2_6741AB59 |
Source: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetup.EXE | File opened: C:\Users\user\AppData\Local\Temp\GAB4F22.tmp\GenFlat_Mailing.gif | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetup.EXE | File opened: C:\Users\user\AppData\Local\Temp\GAB4F22.tmp\GenFlat_Pict_BrwFirst_V_24_5.png | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetup.EXE | File opened: C:\Users\user\AppData\Local\Temp\GAB4F22.tmp\GenFlat_Pict_Add_16_5.png | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetup.EXE | File opened: C:\Users\user\AppData\Local\Temp\GAB4F22.tmp\GenFlat_Pict_Browse_16_5.png | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetup.EXE | File opened: C:\Users\user\AppData\Local\Temp\GAB4F22.tmp\GenFlat_Pict_Apply_16_5.png | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\WD1C79.tmp\WDSetup.EXE | File opened: C:\Users\user\AppData\Local\Temp\GAB4F22.tmp\GenFlat_MailingUS.gif | Jump to behavior |
Source: unknown | UDP traffic detected without corresponding DNS query: 1.1.1.1 |
Source: global traffic | HTTP traffic detected: HTTP/1.1 200 OKContent-Type: application/x-zip-compressedLast-Modified: Thu, 16 Jun 2022 23:23:49 GMTAccept-Ranges: bytesETag: "852f922d881d81:0"Server: Microsoft-IIS/8.0X-Powered-By: ASP.NETAccess-Control-Allow-Origin: *Access-Control-Allow-Headers: *Access-Control-Request-Method: *Date: Fri, 25 Oct 2024 20:13:12 GMTContent-Length: 30660388Data Raw: 50 4b 03 04 14 00 00 08 08 00 bb 9a d0 54 e9 06 7a f5 b0 2b 00 00 0c d1 01 00 09 00 00 00 49 4e 53 54 2e 57 58 46 00 ed 5d db 72 1c 37 92 c5 c3 be 78 23 f6 1f f8 e2 f1 4c 84 45 77 57 5f e9 31 3d 41 35 2f a2 cd db f0 22 cd c5 13 0c 8a a4 24 7a 24 92 66 93 b2 e5 89 f9 1e ff 96 df 76 34 1f b1 bb c8 4c a0 00 54 65 02 60 b7 b4 96 23 10 8c 26 59 00 12 c8 4c 24 32 51 07 55 d9 ff fb 3f 7f 55 4f d4 aa 5a 57 7f 53 ff a5 fe 53 1d a8 0b f5 5c 2d eb b2 3f e9 b2 b1 29 bb 52 a7 ba fc 5c dd ea cf b2 6e bd a9 76 d4 9a da 53 2b 58 bf a2 ae f5 cf 4b dd 62 59 b7 dd 54 1b ba e4 81 fe ac aa 6d 6c b9 a9 4b 0f d5 be 2e 39 d4 ff ef ea 12 a0 7a ac fb ba 51 53 4d 75 a5 2e 35 65 57 2d aa 8e fe 99 a8 13 ac df d6 e5 67 ba 8d df 7b 85 35 fb ba f4 5a f7 7e ae 9e e9 b2 2f 74 1f 37 9a 97 1b dd fe b9 fe 7d a2 5e 69 ce 2f 34 c5 b9 ae f9 52 7d 53 f3 e4 68 a1 fe 74 c6 1e 56 d4 9d d6 c3 95 ae fb 41 7f 4e 35 3d 94 92 9c cb f5 18 cf cd ff 7b ba b7 5b f5 42 4b 05 52 c2 68 1d 2c bf 54 5b ba e6 52 b7 bb 43 9d 76 b1 d4 2f fb ad 6e d9 55 bf d3 75 03 46 5f bb 9a bb 33 46 6b 8f 74 fd 14 f9 bb d1 ff 7d 87 3d 75 f5 0f 71 03 12 bf d4 2d 2f ea 5e b7 75 eb e7 9a f3 4b 9c db 1b dd e7 85 fe 6f 59 f7 07 b3 0d 65 0b ba bd 9d 81 53 94 86 38 80 f2 05 f5 56 5f bf d5 7f 5f 23 35 68 f0 0e 35 f7 52 97 02 ed b5 6e 75 a3 ff 4e 6b 9a 33 ad dd 0b fd 3f f1 79 83 3d 9e 6b aa 1b 6c 7d 65 fe bb d3 2d 80 fe 15 b6 83 ff 7e d6 9f 6f eb 7a e0 6e 41 b7 f9 04 e7 e8 d6 8c 34 d5 7f cf 90 e2 1a c7 bb 50 4f 71 16 fd 9e 5f 9a 7e af f4 e7 1c e5 5e f4 34 b1 62 24 b9 c5 5e 60 64 db 2a 4f 27 af 51 2b ff 46 c9 a0 dd 45 ad d9 1b 1c f1 1a 67 24 5f d2 45 fd ff 63 d4 0f 69 f5 5c fd 88 da 3c d1 25 c4 e9 02 ce f6 1d 8e 32 45 0e ae f0 ef 2b 5c 3f 17 da e6 42 1e a7 b5 f6 be c3 5e 6f 0d 7f a0 99 4f 04 b9 7c 0d 1d e0 78 d7 5a 1f b0 9e 0f b5 1f d8 a9 d7 f5 82 fa 5c 7f 56 50 da 7f e3 18 67 28 91 dc b3 af 09 49 03 76 4d 41 1d c8 6d 57 0b ad e5 09 f6 69 e7 88 d6 dc 0d 72 78 85 14 0f 35 cd a9 fa bb a6 bb ae 57 9f 5b 07 76 35 2f ab a1 a9 7b ac cb a1 47 f2 3d b6 b6 f2 34 70 8c eb 05 ac ee 04 e7 64 4d 5f 4d 0c b7 53 c3 c3 a1 ae 7b 5e 7b 02 eb 3f f2 bd e3 86 3a d2 57 ab 46 96 33 33 53 |