Windows Analysis Report
PandoraFMS_One_Agent_Windows-lts.x86_64.exe

Overview

General Information

Sample name: PandoraFMS_One_Agent_Windows-lts.x86_64.exe
Analysis ID: 1543756
MD5: 850a59f9c158b9d953ee6a75f55f7f8a
SHA1: 00112195c957667f320fa4565966827a8570c168
SHA256: 324f914c6e630516c2d2565cbd0b63e33eb6dc171f26aeaadf4f920636b16dc0
Infos:

Detection

Score: 32
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Compliance

Score: 34
Range: 0 - 100

Signatures

Multi AV Scanner detection for dropped file
Disables security and backup related services
Found API chain indicative of debugger detection
Potential context-aware VBS script found (checks for environment specific values)
Uses schtasks.exe or at.exe to add and modify task schedules
Abnormal high CPU Usage
Contains functionality for read data from the clipboard
Contains functionality to dynamically determine API calls
Contains functionality to shutdown / reboot the system
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
EXE planting / hijacking vulnerabilities found
Found dropped PE file which has not been started or loaded
PE file contains an invalid checksum
PE file contains more sections than normal
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Stores files to the Windows start menu directory
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Uses net.exe to stop services

Classification

AV Detection

barindex
Source: C:\Program Files\pandora_agent\util\pandora_hardening.exe ReversingLabs: Detection: 13%
Source: PandoraAgent.exe, 00000008.00000002.1898706731.0000000000736000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: -----BEGIN PUBLIC KEY----- memstr_17e0a04a-e
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe EXE: schtasks.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe EXE: cmd.exe Jump to behavior

Compliance

barindex
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe EXE: schtasks.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe EXE: cmd.exe Jump to behavior
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Window detected: < &BackI &AgreeCancelPandoraFMS v7.0 PandoraFMS v7.0License AgreementPlease review the license terms before installing Pandora FMS Agent 7.0NG.777.1.Press Page Down to see the rest of the agreement.License and terms of use Pandora FMSReview: May 2024General contract conditionsThese general conditions of PandoraFMS (the "Conditions") regulate the terms in which Pandora FMS gives intuitu personae to the Client the use of the PandoraFMS Pandora ITSM or Pandora RC application and of the contracted components as well as the terms in which the support services and the other applicable conditions will be provided. The license of use is fully valid regardless of the services contracted and is an essential part of the contract signed between the parties together with the order or purchase order (if any) and the commercial proposal (all of them together the Contract).These Terms and Conditions are binding to the Client and all entities and persons acting on the Client's behalf or in collaboration with the Client whether they be employees associates collaborators partners suppliers or any other (hereinafter the Associates). Particularly it is understood that all references made to the Client reach and bind the Associates to whom the Client must inform of the content of these conditions and for whose compliance and non-compliance they shall be jointly and severally liable.By the simple installation or acceptance of the installation and by the simple use of the application the Client declares to have read understood and accepted all the Terms of these Conditions. It also declares that it has sufficient power of attorney to be bound by its representation.1. Ownership of PandoraFMS its components and the application documentationPandora FMS Pandora ITSM and Pandora RC are the exclusive property of Pandora FMS SLU ("Pandora FMS"); an entity that manages and coordinates its development as a collective work and that holds all the moral exploitation and remunerative rights over it also exclusively. Pandora FMS hereby grants the Client a license to use the application (the executable binaries the expressly agreed upon source codes the related components provided with the software the application programming interfaces and the other associated media) and grants the Client no rights of reproduction distribution public communication or transformation of the application beyond those strictly necessary for the use intended in the commercial offer.The application manuals and all related material including the material used for their development (in any format) are protected by the same intellectual property rights as the application itself and the current license of use extends to them. Pandora FMS hereby grants the Client no rights of reproduction public communication and distribution of these materials beyond those strictly necessary to learn how to use the application. Any transformation (including translation into any language) of the aid and development materials
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\temp Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\temp\pandora_agent_nsis.conf Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\collections Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\ref Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\help Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key\id_dsa Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key\id_dsa.pub Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key\PUT_SSH_KEYS_HERE Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\LICENSE_EN.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\LICENSE_ES.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\config.tmp.conf Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\pandora.ico Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\PandoraAgent.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\README.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\delete_at_job.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\install_service_restart.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\start_pandora_agent.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\edit_config_file.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\stop_pandora_agent.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cmp.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\curl.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\curl-ca-bundle.crt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cut.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\date.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\df.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\df_percent.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\expr.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\gawk.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\getreg.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\getsnmp.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\grep.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\grep_log.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\head.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\logevent_log4x.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ls.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\md5.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\agentname.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\autodiscover.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_agent_exec.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\AGENTX-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-EVENT-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-EXPRESSION-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-NSLOOKUP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-PING-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-SCHEDULE-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-SCRIPT-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-TRACEROUTE-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\EtherLike-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\HCNUM-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\HOST-RESOURCES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\HOST-RESOURCES-TYPES.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANA-ADDRESS-FAMILY-NUMBERS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANA-LANGUAGE-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANA-RTPROTO-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANAifType-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\ianalist Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IF-INVERTED-STACK-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IF-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\INET-ADDRESS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IP-FORWARD-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-ICMP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-TCP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-UDP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\LM-SENSORS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\Makefile.in Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\Makefile.mib Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\makehtml.pl Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\mibfetch Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\MTA-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-AGENT-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-EXAMPLES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-EXTEND-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-MONITOR-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-SYSTEM-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NETWORK-SERVICES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\nodemap Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NOTIFICATION-LOG-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\README.mibs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RFC-1215.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RFC1155-SMI.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RFC1213-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\rfclist Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\rfcmibs.diff Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RMON-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\smistrip Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SMUX-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-COMMUNITY-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-FRAMEWORK-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-MPD-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-NOTIFICATION-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-PROXY-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-TARGET-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-USER-BASED-SM-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-USM-AES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-USM-DH-OBJECTS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-VIEW-BASED-ACM-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-CONF.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-SMI.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-TM.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\TCP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\TRANSPORT-ADDRESS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\TUNNEL-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DEMO-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DEMO-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DISKIO-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DISKIO-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DLMOD-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DLMOD-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFILTER-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFILTER-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFWACC-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFWACC-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-SNMP-MIB-OLD.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-SNMP-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-SNMP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UDP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_revent.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_update.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ps.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\du_percent.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\puttygen.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\snmpget.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\sort.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tail.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tentacle_client.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tentacle_server.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tr.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\unzip.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\wc.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cpuinfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\moboinfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\diskdrives.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cdromdrives.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\videocardinfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ifaces.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\monitors.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\printers.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\software_installed.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\raminfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\userslogged.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\productkey.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\productID.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\architecture.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\domain.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\osversion.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\df_percent_used.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mem_percent_used.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\network.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\route_parser.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\omnishell_client.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_hardening.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_security_win.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_security_win.conf Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ShortElev.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\PandoraFMS_Agent.url Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\uninst.exe Jump to behavior
Source: C:\Program Files\pandora_agent\PandoraAgent.exe Directory created: C:\Program Files\pandora_agent\pandora_agent.log Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\LICENSE_EN.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\LICENSE_ES.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\README.txt Jump to behavior
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe Static PE information: certificate valid
Source: Binary string: c:\projects\md5\Release\md5.pdb source: md5.exe.0.dr
Source: Binary string: C:\data\buildbot-pdk-slave\pdk-grover\build\src\PerlApp\src\paperl512.pdb source: pandora_revent.exe.0.dr
Source: Binary string: .Pdb'L source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe
Source: Binary string: .PdB] source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00407F13 FindFirstFileA,FindClose, 0_2_00407F13
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_004083A8 DeleteFileA,DeleteFileA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 0_2_004083A8
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_0040342B FindFirstFileA, 0_2_0040342B
Source: curl.exe.0.dr String found in binary or memory: Usage: curl [options...] <url>
Source: curl.exe.0.dr String found in binary or memory: E@Usage: curl [options...] <url>Options: (H) means HTTP/HTTPS only, (F) means FTP only --anyauth Pick "any" authentication method (H) -a, --append Append to target file when uploading (F/SFTP) --basic Use HTTP Basic Authentication (H) --cacert FILE CA certificate to verify peer against (SSL) --capath DIR CA directory to verify peer against (SSL) -E, --cert CERT[:PASSWD] Client certificate file and password (SSL) --cert-type TYPE Certificate file type (DER/PEM/ENG) (SSL) --ciphers LIST SSL ciphers to use (SSL) --compressed Request compressed response (using deflate or gzip) -K, --config FILE Specify which config file to read --connect-timeout SECONDS Maximum time allowed for connection -C, --continue-at OFFSET Resumed transfer offset -b, --cookie STRING/FILE String or file to read cookies from (H) -c, --cookie-jar FILE Write cookies to this file after operation (H) --create-dirs Create necessary local directory hierarchy --crlf Convert LF to CRLF in upload --crlfile FILE Get a CRL list in PEM format from the given file -d, --data DATA HTTP POST data (H) --data-ascii DATA HTTP POST ASCII data (H) --data-binary DATA HTTP POST binary data (H) --data-urlencode DATA HTTP POST data url encoded (H) --delegation STRING GSS-API delegation permission --digest Use HTTP Digest Authentication (H) --disable-eprt Inhibit using EPRT or LPRT (F) --disable-epsv Inhibit using EPSV (F) -D, --dump-header FILE Write the headers to this file --egd-file FILE EGD socket path for random data (SSL) --engine ENGINGE Crypto engine (SSL). "--engine list" for list -f, --fail Fail silently (no output at all) on HTTP errors (H) -F, --form CONTENT Specify HTTP multipart POST data (H) --form-string STRING Specify HTTP multipart POST data (H) --ftp-account DATA Account data string (F) --ftp-alternative-to-user COMMAND String to replace "USER [name]" (F) --ftp-create-dirs Create the remote dirs if not present (F) --ftp-method [MULTICWD/NOCWD/SINGLECWD] Control CWD usage (F) --ftp-pasv Use PASV/EPSV instead of PORT (F) -P, --ftp-port ADR Use PORT with given address instead of PASV (F) --ftp-skip-pasv-ip Skip the IP address for PASV (F)
Source: curl.exe.0.dr String found in binary or memory: http://curl.haxx.se/P
Source: curl.exe.0.dr String found in binary or memory: http://curl.haxx.se/docs/copyright.htmlD
Source: PandoraAgent.exe, 00000008.00000002.1898706731.0000000000736000.00000002.00000001.01000000.0000000B.sdmp, PandoraAgent.exe, 0000001B.00000000.1928109476.0000000000736000.00000002.00000001.01000000.0000000B.sdmp, curl.exe.0.dr, PandoraAgent.exe.0.dr String found in binary or memory: http://curl.haxx.se/docs/http-cookies.html
Source: curl.exe.0.dr String found in binary or memory: http://curl.haxx.se/docs/sslcerts.html
Source: curl.exe.0.dr String found in binary or memory: http://curl.haxx.se/libcurl/c/curl_easy_setopt.html
Source: curl.exe.0.dr String found in binary or memory: http://https://-.://%s%s%s/%sall
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe, uninst.exe.0.dr String found in binary or memory: http://nsis.sf.net/NSIS_Error
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe, uninst.exe.0.dr String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: config.tmp.conf.0.dr, pandora_agent_nsis.conf.0.dr String found in binary or memory: http://pandorafms.org
Source: md5.exe.0.dr String found in binary or memory: http://www.fourmilab.ch/
Source: config.tmp.conf.0.dr, pandora_agent_nsis.conf.0.dr String found in binary or memory: http://www.google.com
Source: INET-ADDRESS-MIB.txt.0.dr String found in binary or memory: http://www.iana.org/
Source: IP-MIB.txt.0.dr String found in binary or memory: http://www.iana.org/assignments/icmp-parameters
Source: IP-MIB.txt.0.dr String found in binary or memory: http://www.iana.org/assignments/icmpv6-parameters
Source: AGENTX-MIB.txt.0.dr String found in binary or memory: http://www.ietf.org/html.charters/agentx-charter.html
Source: TCP-MIB.txt.0.dr, IP-FORWARD-MIB.txt.0.dr String found in binary or memory: http://www.ietf.org/html.charters/ipv6-charter.html
Source: unzip.exe.0.dr String found in binary or memory: http://www.info-zip.org/UnZip.htmlDVarFileInfo$
Source: unzip.exe.0.dr String found in binary or memory: http://www.info-zip.org/zip-bug.html;
Source: PandoraAgent.exe, 00000008.00000000.1897515760.000000000079D000.00000002.00000001.01000000.0000000B.sdmp, PandoraAgent.exe, 0000001B.00000002.4162596872.000000000079D000.00000002.00000001.01000000.0000000B.sdmp, PandoraAgent.exe.0.dr String found in binary or memory: http://www.openssl.org/support/faq.html
Source: PandoraAgent.exe, 00000008.00000000.1897515760.000000000079D000.00000002.00000001.01000000.0000000B.sdmp, PandoraAgent.exe, 0000001B.00000002.4162596872.000000000079D000.00000002.00000001.01000000.0000000B.sdmp, PandoraAgent.exe.0.dr String found in binary or memory: http://www.openssl.org/support/faq.htmlRAND
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe, 00000000.00000002.4162559671.00000000007EE000.00000004.00000020.00020000.00000000.sdmp, PandoraFMS_Agent.url.0.dr String found in binary or memory: http://www.pandorafms.com
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe, 00000000.00000002.4163286809.0000000003963000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.pandorafms.com.
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe, 00000000.00000002.4162559671.00000000007EE000.00000004.00000020.00020000.00000000.sdmp, LICENSE_EN.txt.0.dr, LICENSE_ES.txt.0.dr String found in binary or memory: https://support.pandorafms.com/
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00406EFB GetDlgItem,GetClientRect,GetSystemMetrics,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SendMessageA,SetDlgItemTextA,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,SendMessageA,SendMessageA,SendMessageA,GetDlgItem,CreateThread,CloseHandle,ShowWindow,ShowWindow,ShowWindow,ShowWindow,SendMessageA,CreatePopupMenu,AppendMenuA,GetWindowRect,TrackPopupMenu,SendMessageA,OpenClipboard,EmptyClipboard,GlobalAlloc,GlobalLock,SendMessageA,SendMessageA,GlobalUnlock,SetClipboardData,CloseClipboard, 0_2_00406EFB
Source: C:\Program Files\pandora_agent\PandoraAgent.exe Process Stats: CPU usage > 49%
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 EntryPoint,SetErrorMode,GetVersion,lstrlenA,InitCommonControls,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,DeleteFileA,DeleteFileA,GetWindowsDirectoryA,DeleteFileA,DeleteFileA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,DeleteFileA,DeleteFileA,OleUninitialize,GetCurrentProcess,ExitWindowsEx,ExitProcess, 0_2_00404167
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00408D2E 0_2_00408D2E
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_6E5C4710 0_2_6E5C4710
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_6E5C22B5 0_2_6E5C22B5
Source: Joe Sandbox View Dropped File: C:\Program Files\pandora_agent\util\ShortElev.exe D8CB74994754E0FE701F842651AD5EA4F54B41C0450ECFD511E2B7A8C761847E
Source: PandoraAgent.exe.0.dr Static PE information: Number of sections : 18 > 10
Source: ShortElev.exe.0.dr Static PE information: Number of sections : 16 > 10
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, DEBUG_STRIPPED
Source: grep_log.exe.0.dr Static PE information: Section: .rsrc ZLIB complexity 0.9979870854591837
Source: route_parser.exe.0.dr Static PE information: Section: .rsrc ZLIB complexity 0.9976158993089234
Source: classification engine Classification label: sus32.evad.winEXE@39/174@0/0
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405A34 GetDlgItem,SetWindowTextA,SetDlgItemTextA,SetDlgItemTextA,SHAutoComplete,SHBrowseForFolderA,CoTaskMemFree,lstrcmpiA,GetDiskFreeSpaceExA,GetDiskFreeSpaceA,MulDiv, 0_2_00405A34
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00402988 CoCreateInstance,MultiByteToWideChar, 0_2_00402988
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu.lnk Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7708:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7992:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \BaseNamedObjects\Local\SM0:8148:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7924:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8096:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7836:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:8044:120:WilError_03
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7468:120:WilError_03
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Local\Temp\nsnBCF3.tmp Jump to behavior
Source: unknown Process created: C:\Windows\System32\cmd.exe C:\Windows\SYSTEM32\cmd.exe /c ""C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat""
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_ALIGN_1BYTES, IMAGE_SCN_ALIGN_2BYTES, IMAGE_SCN_ALIGN_4BYTES, IMAGE_SCN_ALIGN_16BYTES, IMAGE_SCN_ALIGN_32BYTES, IMAGE_SCN_ALIGN_64BYTES, IMAGE_SCN_ALIGN_256BYTES, IMAGE_SCN_ALIGN_512BYTES, IMAGE_SCN_ALIGN_1024BYTES, IMAGE_SCN_ALIGN_4096BYTES, IMAGE_SCN_ALIGN_8192BYTES, IMAGE_SCN_ALIGN_MASK, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: PandoraAgent.exe, 00000008.00000002.1898706731.0000000000736000.00000002.00000001.01000000.0000000B.sdmp, PandoraAgent.exe, 0000001B.00000000.1928109476.0000000000736000.00000002.00000001.01000000.0000000B.sdmp, PandoraAgent.exe.0.dr Binary or memory string: SELECT Name, PathName, State FROM Win32_Service.PathName;
Source: PandoraAgent.exe String found in binary or memory: -startinfo
Source: PandoraAgent.exe String found in binary or memory: -StartupInfo
Source: PandoraAgent.exe String found in binary or memory: -address
Source: PandoraAgent.exe String found in binary or memory: -startinfo
Source: PandoraAgent.exe String found in binary or memory: -StartupInfo
Source: PandoraAgent.exe String found in binary or memory: -address
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File read: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe "C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe"
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\net.exe net stop pandoraFMSagent
Source: C:\Windows\SysWOW64\net.exe Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c PandoraAgent.exe --install
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Program Files\pandora_agent\PandoraAgent.exe PandoraAgent.exe --install
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /Create /TN pandora_agent_restart /TR "\"C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat\"" /SC DAILY /ST 00:00:00 /F /RU SYSTEM
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /Change /TN pandora_agent_restart /TR "\"C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat\""
Source: C:\Windows\SysWOW64\schtasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Program Files\pandora_agent\util\ShortElev.exe "C:\Program Files\pandora_agent\util\ShortElev.exe" "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\Edit Config File.lnk"
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Program Files\pandora_agent\util\ShortElev.exe "C:\Program Files\pandora_agent\util\ShortElev.exe" "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\PandoraFMS_Agent_start.lnk"
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Program Files\pandora_agent\util\ShortElev.exe "C:\Program Files\pandora_agent\util\ShortElev.exe" "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\PandoraFMS_Agent_stop.lnk"
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\cmd.exe C:\Windows\SYSTEM32\cmd.exe /c ""C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat""
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net stop PandoraFMSAgent
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop PandoraFMSAgent
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net start PandoraFMSAgent
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start PandoraFMSAgent
Source: unknown Process created: C:\Program Files\pandora_agent\PandoraAgent.exe "C:\Program Files\pandora_agent\PandoraAgent.exe"
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c PandoraAgent.exe --install Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /Create /TN pandora_agent_restart /TR "\"C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat\"" /SC DAILY /ST 00:00:00 /F /RU SYSTEM Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /Change /TN pandora_agent_restart /TR "\"C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat\"" Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Program Files\pandora_agent\util\ShortElev.exe "C:\Program Files\pandora_agent\util\ShortElev.exe" "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\Edit Config File.lnk" Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Program Files\pandora_agent\util\ShortElev.exe "C:\Program Files\pandora_agent\util\ShortElev.exe" "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\PandoraFMS_Agent_start.lnk" Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Program Files\pandora_agent\util\ShortElev.exe "C:\Program Files\pandora_agent\util\ShortElev.exe" "C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\PandoraFMS_Agent_stop.lnk" Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\net.exe net stop pandoraFMSagent Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 stop pandoraFMSagent Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Program Files\pandora_agent\PandoraAgent.exe PandoraAgent.exe --install Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net stop PandoraFMSAgent Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net start PandoraFMSAgent Jump to behavior
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop PandoraFMSAgent Jump to behavior
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start PandoraFMSAgent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: oleacc.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\SysWOW64\net1.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\net1.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\SysWOW64\net1.exe Section loaded: dsrole.dll Jump to behavior
Source: C:\Windows\SysWOW64\net1.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\SysWOW64\net1.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\SysWOW64\net1.exe Section loaded: logoncli.dll Jump to behavior
Source: C:\Windows\SysWOW64\net1.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files\pandora_agent\PandoraAgent.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: taskschd.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Section loaded: xmllite.dll Jump to behavior
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\cmd.exe Section loaded: cmdext.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: dsrole.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: logoncli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\net.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: dsrole.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: logoncli.dll Jump to behavior
Source: C:\Windows\System32\net1.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: Start Menu.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\pandora_agent\README.txt
Source: Start Pandora Agent.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\Program Files\pandora_agent\scripts\start_pandora_agent.bat
Source: Stop Pandora Agent.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\Program Files\pandora_agent\scripts\stop_pandora_agent.bat
Source: Website.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\pandora_agent\PandoraFMS_Agent.url
Source: Uninstall.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\pandora_agent\uninst.exe
Source: Edit Config File.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\pandora_agent\scripts\edit_config_file.bat
Source: PandoraFMS_Agent_start.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\pandora_agent\scripts\start_pandora_agent.bat
Source: PandoraFMS_Agent_stop.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\pandora_agent\scripts\stop_pandora_agent.bat
Source: README.lnk.0.dr LNK file: ..\..\..\..\..\..\Program Files\pandora_agent\README.txt
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: I Agree
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Install
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: Next >
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Automated click: OK
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Window detected: < &BackI &AgreeCancelPandoraFMS v7.0 PandoraFMS v7.0License AgreementPlease review the license terms before installing Pandora FMS Agent 7.0NG.777.1.Press Page Down to see the rest of the agreement.License and terms of use Pandora FMSReview: May 2024General contract conditionsThese general conditions of PandoraFMS (the "Conditions") regulate the terms in which Pandora FMS gives intuitu personae to the Client the use of the PandoraFMS Pandora ITSM or Pandora RC application and of the contracted components as well as the terms in which the support services and the other applicable conditions will be provided. The license of use is fully valid regardless of the services contracted and is an essential part of the contract signed between the parties together with the order or purchase order (if any) and the commercial proposal (all of them together the Contract).These Terms and Conditions are binding to the Client and all entities and persons acting on the Client's behalf or in collaboration with the Client whether they be employees associates collaborators partners suppliers or any other (hereinafter the Associates). Particularly it is understood that all references made to the Client reach and bind the Associates to whom the Client must inform of the content of these conditions and for whose compliance and non-compliance they shall be jointly and severally liable.By the simple installation or acceptance of the installation and by the simple use of the application the Client declares to have read understood and accepted all the Terms of these Conditions. It also declares that it has sufficient power of attorney to be bound by its representation.1. Ownership of PandoraFMS its components and the application documentationPandora FMS Pandora ITSM and Pandora RC are the exclusive property of Pandora FMS SLU ("Pandora FMS"); an entity that manages and coordinates its development as a collective work and that holds all the moral exploitation and remunerative rights over it also exclusively. Pandora FMS hereby grants the Client a license to use the application (the executable binaries the expressly agreed upon source codes the related components provided with the software the application programming interfaces and the other associated media) and grants the Client no rights of reproduction distribution public communication or transformation of the application beyond those strictly necessary for the use intended in the commercial offer.The application manuals and all related material including the material used for their development (in any format) are protected by the same intellectual property rights as the application itself and the current license of use extends to them. Pandora FMS hereby grants the Client no rights of reproduction public communication and distribution of these materials beyond those strictly necessary to learn how to use the application. Any transformation (including translation into any language) of the aid and development materials
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\temp Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\temp\pandora_agent_nsis.conf Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\collections Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\ref Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\help Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key\id_dsa Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key\id_dsa.pub Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\key\PUT_SSH_KEYS_HERE Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\LICENSE_EN.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\LICENSE_ES.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\config.tmp.conf Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\pandora.ico Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\PandoraAgent.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\README.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\delete_at_job.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\install_service_restart.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\start_pandora_agent.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\edit_config_file.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\scripts\stop_pandora_agent.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cmp.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\curl.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\curl-ca-bundle.crt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cut.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\date.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\df.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\df_percent.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\expr.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\gawk.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\getreg.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\getsnmp.bat Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\grep.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\grep_log.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\head.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\logevent_log4x.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ls.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\md5.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\agentname.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\autodiscover.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_agent_exec.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\AGENTX-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-EVENT-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-EXPRESSION-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-NSLOOKUP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-PING-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-SCHEDULE-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-SCRIPT-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\DISMAN-TRACEROUTE-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\EtherLike-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\HCNUM-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\HOST-RESOURCES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\HOST-RESOURCES-TYPES.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANA-ADDRESS-FAMILY-NUMBERS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANA-LANGUAGE-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANA-RTPROTO-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IANAifType-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\ianalist Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IF-INVERTED-STACK-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IF-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\INET-ADDRESS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IP-FORWARD-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-ICMP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-TCP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\IPV6-UDP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\LM-SENSORS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\Makefile.in Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\Makefile.mib Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\makehtml.pl Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\mibfetch Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\MTA-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-AGENT-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-EXAMPLES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-EXTEND-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-MONITOR-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-SYSTEM-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NET-SNMP-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NETWORK-SERVICES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\nodemap Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\NOTIFICATION-LOG-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\README.mibs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RFC-1215.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RFC1155-SMI.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RFC1213-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\rfclist Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\rfcmibs.diff Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\RMON-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\smistrip Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SMUX-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-COMMUNITY-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-FRAMEWORK-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-MPD-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-NOTIFICATION-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-PROXY-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-TARGET-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-USER-BASED-SM-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-USM-AES-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-USM-DH-OBJECTS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMP-VIEW-BASED-ACM-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-CONF.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-SMI.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-TC.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\SNMPv2-TM.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\TCP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\TRANSPORT-ADDRESS-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\TUNNEL-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DEMO-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DEMO-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DISKIO-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DISKIO-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DLMOD-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-DLMOD-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFILTER-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFILTER-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFWACC-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-IPFWACC-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-SNMP-MIB-OLD.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-SNMP-MIB.inc Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UCD-SNMP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mibs\UDP-MIB.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_revent.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_update.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ps.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\du_percent.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\puttygen.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\snmpget.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\sort.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tail.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tentacle_client.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tentacle_server.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\tr.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\unzip.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\wc.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cpuinfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\moboinfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\diskdrives.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\cdromdrives.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\videocardinfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ifaces.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\monitors.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\printers.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\software_installed.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\raminfo.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\userslogged.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\productkey.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\productID.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\architecture.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\domain.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\osversion.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\df_percent_used.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\mem_percent_used.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\network.vbs Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\route_parser.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\omnishell_client.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_hardening.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_security_win.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\pandora_security_win.conf Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\util\ShortElev.exe Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\PandoraFMS_Agent.url Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Directory created: C:\Program Files\pandora_agent\uninst.exe Jump to behavior
Source: C:\Program Files\pandora_agent\PandoraAgent.exe Directory created: C:\Program Files\pandora_agent\pandora_agent.log Jump to behavior
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe Static PE information: certificate valid
Source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe Static file information: File size 62120984 > 1048576
Source: Binary string: c:\projects\md5\Release\md5.pdb source: md5.exe.0.dr
Source: Binary string: C:\data\buildbot-pdk-slave\pdk-grover\build\src\PerlApp\src\paperl512.pdb source: pandora_revent.exe.0.dr
Source: Binary string: .Pdb'L source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe
Source: Binary string: .PdB] source: PandoraFMS_One_Agent_Windows-lts.x86_64.exe
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_6E5C22B5 lstrcpyA,GlobalAlloc,GlobalFree,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GetModuleHandleA,LoadLibraryA,GetProcAddress,GetProcAddress,lstrcatA,GetProcAddress,lstrcpyA,GlobalFree, 0_2_6E5C22B5
Source: expr.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x56b2
Source: puttygen.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x2f1b4
Source: tr.exe.0.dr Static PE information: real checksum: 0x0 should be: 0xdb79
Source: ls.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x1bafa
Source: cut.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x5f11
Source: head.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x14301
Source: uninst.exe.0.dr Static PE information: real checksum: 0x3b4b43a should be: 0x40336
Source: gawk.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x3c909
Source: cmp.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x2de4
Source: md5.exe.0.dr Static PE information: real checksum: 0x0 should be: 0xcd6f
Source: snmpget.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x483f9
Source: sort.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x13795
Source: grep.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x1acfd
Source: wc.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x122f4
Source: date.exe.0.dr Static PE information: real checksum: 0x0 should be: 0xf68d
Source: tail.exe.0.dr Static PE information: real checksum: 0x0 should be: 0x18175
Source: PandoraAgent.exe.0.dr Static PE information: section name: .xdata
Source: PandoraAgent.exe.0.dr Static PE information: section name: /4
Source: PandoraAgent.exe.0.dr Static PE information: section name: /19
Source: PandoraAgent.exe.0.dr Static PE information: section name: /31
Source: PandoraAgent.exe.0.dr Static PE information: section name: /45
Source: PandoraAgent.exe.0.dr Static PE information: section name: /57
Source: PandoraAgent.exe.0.dr Static PE information: section name: /70
Source: PandoraAgent.exe.0.dr Static PE information: section name: /81
Source: PandoraAgent.exe.0.dr Static PE information: section name: /92
Source: getreg.exe.0.dr Static PE information: section name: .xdata
Source: autodiscover.exe.0.dr Static PE information: section name: _RDATA
Source: omnishell_client.exe.0.dr Static PE information: section name: .xdata
Source: ShortElev.exe.0.dr Static PE information: section name: /4
Source: ShortElev.exe.0.dr Static PE information: section name: /14
Source: ShortElev.exe.0.dr Static PE information: section name: /29
Source: ShortElev.exe.0.dr Static PE information: section name: /41
Source: ShortElev.exe.0.dr Static PE information: section name: /55
Source: ShortElev.exe.0.dr Static PE information: section name: /67
Source: ShortElev.exe.0.dr Static PE information: section name: /80
Source: ShortElev.exe.0.dr Static PE information: section name: /91
Source: ShortElev.exe.0.dr Static PE information: section name: /102
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00403141 push edx; mov dword ptr [esp], eax 0_2_00403156
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00407F4B push ebx; mov dword ptr [esp], 00434A80h 0_2_00407F68
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00407F4B push eax; mov dword ptr [esp], 00434A80h 0_2_00407FE0
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00402E4B push ebx; mov dword ptr [esp], 00413040h 0_2_00402EF6
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_0040194E push ecx; mov dword ptr [esp], eax 0_2_0040195B
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00401860 push eax; mov dword ptr [esp], ebx 0_2_0040192D
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00403164 push edi; mov dword ptr [esp], eax 0_2_00403177
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push ecx; mov dword ptr [esp], ebx 0_2_004041BB
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push ebx; mov dword ptr [esp], 0000000Bh 0_2_004041D8
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push eax; mov dword ptr [esp], 00000000h 0_2_00404263
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push edx; mov dword ptr [esp], eax 0_2_004042A0
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push eax; mov dword ptr [esp], ebx 0_2_00404382
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push eax; mov dword ptr [esp], 00440400h 0_2_004044D8
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push ecx; mov dword ptr [esp], 00431860h 0_2_0040454D
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push eax; mov dword ptr [esp], 00431860h 0_2_004045B2
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 push ebx; mov dword ptr [esp], 00000002h 0_2_0040462A
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00401B06 push edx; mov dword ptr [esp], eax 0_2_00401B53
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00401B06 push edi; mov dword ptr [esp], 00412840h 0_2_00401B6A
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00402613 push ecx; mov dword ptr [esp], ebx 0_2_00402634
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405A34 push esi; mov dword ptr [esp], ebx 0_2_00405A71
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405A34 push eax; mov dword ptr [esp], 0000000Ah 0_2_00405B27
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405A34 push ecx; mov dword ptr [esp], ebx 0_2_00405BF4
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405A34 push eax; mov dword ptr [esp], ebx 0_2_00405CA8
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405A34 push ecx; mov dword ptr [esp], 00000001h 0_2_00405CCD
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405A34 push ebx; mov dword ptr [esp], 004324C0h 0_2_00405CF4
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_0040183B push ecx; mov dword ptr [esp], eax 0_2_0040184E
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_004040CC push eax; mov dword ptr [esp], 00440400h 0_2_004040DF
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_004040CC push eax; mov dword ptr [esp], 00440400h 0_2_00404101
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404DDD push eax; mov dword ptr [esp], 00000405h 0_2_00405305
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405EED push eax; mov dword ptr [esp], ebx 0_2_00406093
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00405EED push ebx; mov dword ptr [esp], 0043F400h 0_2_004060AE
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\cmp.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\tentacle_client.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\route_parser.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\gawk.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\tentacle_server.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\pandora_update.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\grep_log.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\pandora_revent.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\expr.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\snmpget.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\autodiscover.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\getreg.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Local\Temp\nsiBE5B.tmp\nsDialogs.dll Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Local\Temp\nsiBE5B.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\tr.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\wc.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Local\Temp\nsiBE5B.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\cut.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\puttygen.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\omnishell_client.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\pandora_hardening.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\sort.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\date.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\PandoraAgent.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\tail.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\grep.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\unzip.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\pandora_agent_exec.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\head.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\md5.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\curl.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\ShortElev.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\pandora_security_win.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\util\ls.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\LICENSE_EN.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\LICENSE_ES.txt Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Program Files\pandora_agent\README.txt Jump to behavior

Boot Survival

barindex
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\schtasks.exe schtasks /Create /TN pandora_agent_restart /TR "\"C:\Program Files\pandora_agent\scripts\restart_pandora_agent.bat\"" /SC DAILY /ST 00:00:00 /F /RU SYSTEM
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Start Pandora Agent.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Stop Pandora Agent.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1 Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\Website.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\Uninstall.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\Edit Config File.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\PandoraFMS_Agent_start.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\PandoraFMS_Agent_stop.lnk Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PandoraFMS_Agent_v7.0NG.777.1\README.lnk Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\net.exe net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\SysWOW64\schtasks.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\conhost.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\cmd.exe Process information set: NOOPENFILEERRORBOX Jump to behavior

Malware Analysis System Evasion

barindex
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped file: Wscript.StdOut.WriteLine "<data><![CDATA[" & mobo.manufacturer & ";" & mobo.model & ";" & mobo.OEMStringArray(0) & "]]></data>" Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped file: Wscript.StdOut.WriteLine "<data><![CDATA[" & data.osarchitecture & "]]></data>" Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\tentacle_client.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\route_parser.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\cmp.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\gawk.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\tentacle_server.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\pandora_update.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\grep_log.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\expr.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\pandora_revent.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\snmpget.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\autodiscover.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\getreg.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsiBE5B.tmp\nsDialogs.dll Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsiBE5B.tmp\LangDLL.dll Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\tr.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\wc.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\cut.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nsiBE5B.tmp\System.dll Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\puttygen.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\pandora_hardening.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\omnishell_client.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\sort.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\date.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\tail.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\grep.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\unzip.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\pandora_agent_exec.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\head.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\md5.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\curl.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\pandora_security_win.exe Jump to dropped file
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Dropped PE file which has not been started: C:\Program Files\pandora_agent\util\ls.exe Jump to dropped file
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\conhost.exe Last function: Thread delayed
Source: C:\Windows\System32\net1.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File Volume queried: C:\Program Files FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe File Volume queried: C:\Program Files FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00407F13 FindFirstFileA,FindClose, 0_2_00407F13
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_004083A8 DeleteFileA,DeleteFileA,lstrlenA,FindFirstFileA,DeleteFileA,FindNextFileA,FindClose,RemoveDirectoryA, 0_2_004083A8
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_0040342B FindFirstFileA, 0_2_0040342B
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe API call chain: ExitProcess graph end node

Anti Debugging

barindex
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Debugger detection routine: QueryPerformanceCounter, DebugActiveProcess, DecisionNodes, ExitProcess or Sleep
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_6E5C22B5 lstrcpyA,GlobalAlloc,GlobalFree,lstrcpyA,GlobalFree,GlobalFree,GlobalFree,GlobalFree,GetModuleHandleA,LoadLibraryA,GetProcAddress,GetProcAddress,lstrcatA,GetProcAddress,lstrcpyA,GlobalFree, 0_2_6E5C22B5
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00DB1BCC CreateControl,GetProcessHeap,GetProcessHeap,HeapAlloc,GetProcessHeap,GetProcessHeap,HeapReAlloc,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,lstrcmpiA,CreateWindowExA,SetPropA,SendMessageA,SendMessageA,SendMessageA,SetWindowLongA,GetProcessHeap,HeapFree, 0_2_00DB1BCC
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_6E5C3AB0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 0_2_6E5C3AB0
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_6E5C3AAC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 0_2_6E5C3AAC
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Code function: 15_2_00401179 Sleep,Sleep,SetUnhandledExceptionFilter,_acmdln,malloc,strlen,malloc,memcpy,__initenv,_cexit,_amsg_exit,_initterm,GetStartupInfoA,_initterm,exit, 15_2_00401179
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Code function: 15_2_004021C0 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_004021C0
Source: C:\Program Files\pandora_agent\util\ShortElev.exe Code function: 15_2_004021BC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,abort, 15_2_004021BC
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Windows\SysWOW64\net.exe net stop pandoraFMSagent Jump to behavior
Source: C:\Windows\SysWOW64\net.exe Process created: C:\Windows\SysWOW64\net1.exe C:\Windows\system32\net1 stop pandoraFMSagent Jump to behavior
Source: C:\Windows\SysWOW64\cmd.exe Process created: C:\Program Files\pandora_agent\PandoraAgent.exe PandoraAgent.exe --install Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net stop PandoraFMSAgent Jump to behavior
Source: C:\Windows\System32\cmd.exe Process created: C:\Windows\System32\net.exe net start PandoraFMSAgent Jump to behavior
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 stop PandoraFMSAgent Jump to behavior
Source: C:\Windows\System32\net.exe Process created: C:\Windows\System32\net1.exe C:\Windows\system32\net1 start PandoraFMSAgent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_6E5C3A00 GetSystemTimeAsFileTime,GetCurrentProcessId,GetCurrentThreadId,GetTickCount,QueryPerformanceCounter, 0_2_6E5C3A00
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Code function: 0_2_00404167 EntryPoint,SetErrorMode,GetVersion,lstrlenA,InitCommonControls,OleInitialize,SHGetFileInfoA,GetCommandLineA,GetModuleHandleA,CharNextA,GetTempPathA,DeleteFileA,DeleteFileA,GetWindowsDirectoryA,DeleteFileA,DeleteFileA,lstrcmpiA,SetCurrentDirectoryA,DeleteFileA,CopyFileA,CloseHandle,DeleteFileA,DeleteFileA,OleUninitialize,GetCurrentProcess,ExitWindowsEx,ExitProcess, 0_2_00404167

Lowering of HIPS / PFW / Operating System Security Settings

barindex
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
Source: C:\Users\user\Desktop\PandoraFMS_One_Agent_Windows-lts.x86_64.exe Process created: C:\Windows\SysWOW64\cmd.exe cmd.exe /c net stop pandoraFMSagent Jump to behavior
No contacted IP infos