Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\rocknt\objfre\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdbU source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\enduser\objfre\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdbN source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\coinstall\objfre_wlh_x86\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: h:\nt.obj.x86fre\base\wcp\tools\msmcustomaction\objfre\i386\msmcustomaction.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4\objfre_wlh_x86\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\rockeynt\objfre_w2k_x86\i386\rockeynt.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdbMZ source: SCADA 4.0.12.737.msi |
Source: C:\Windows\System32\msiexec.exe |
File opened: z: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: x: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: v: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: t: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: r: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: p: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: n: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: l: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: j: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: h: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: f: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: b: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: y: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: w: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: u: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: s: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: q: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: o: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: m: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: k: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: i: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: g: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: e: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: c: |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
File opened: a: |
Jump to behavior |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://ocsp.thawte.com0 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://s2.symcb.com0 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://sv.symcb.com/sv.crl0a |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://sv.symcb.com/sv.crt0 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://sv.symcd.com0& |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://www.flexerasoftware.com0 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://www.symauth.com/cps0( |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: http://www.symauth.com/rpa00 |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: https://d.symcb.com/cps0% |
Source: SCADA 4.0.12.737.msi |
String found in binary or memory: https://d.symcb.com/rpa0 |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilename_IsIcoRes.exe< vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameSetAllUsers.dll< vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameSFHelper.dll vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameRockey4.sys vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameRockey4USB.sys vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameRockeynt.sys vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameRockUsb.sysR vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameR4CoInst.dll vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary or memory string: OriginalFilenameInstDll.dll vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi |
Binary string: \Device\ROCKEYUSB |
Source: SCADA 4.0.12.737.msi |
Binary string: \Device\USBHUB0U |
Source: SCADA 4.0.12.737.msi |
Binary string: \Device\Dongle0TestBusySupport\Parameters\DosDevices\ROCKEYNT |
Source: SCADA 4.0.12.737.msi |
Binary string: \Device\Dongle0U |
Source: SCADA 4.0.12.737.msi |
Binary string: \DosDevices\ROCKEY9X\Device\Dongle0 |
Source: SCADA 4.0.12.737.msi |
Binary string: D@B\Device\ROCKEYUSB\DosDevices\ROCKEYUSBU |
Source: SCADA 4.0.12.737.msi |
Binary string: \Device\ROCKEYUSB%s%03dU |
Source: SCADA 4.0.12.737.msi |
Binary string: \Device\ROCKEYUSB\DosDevices\ROCKEYNTTestBusySupport\Parameters\Device\Dongle0 |
Source: SCADA 4.0.12.737.msi |
Binary string: \Device\RootHubU |
Source: SCADA 4.0.12.737.msi |
Binary string: \DosDevices\ROCKEYNT\Device\Dongle0 |
Source: SCADA 4.0.12.737.msi |
Binary string: P`0PEnum\USBSystem\CurrentControlSet\Services\vxd\Rockey9xSupportTestBusyDisablePort1DisablePort2DisablePort3\Device\ROCKEYUSBU |
Source: SCADA 4.0.12.737.msi |
Binary string: P@RockUsb for NT 4.0\Device\ROCKEYUSB\DosDevices\ROCKEYUSBU |
Source: classification engine |
Classification label: clean2.winMSI@2/1@0/0 |
Source: C:\Windows\System32\msiexec.exe |
File created: C:\Users\user\AppData\Local\Temp\MSI46ae6.LOG |
Jump to behavior |
Source: unknown |
Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\SCADA 4.0.12.737.msi" |
Source: unknown |
Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: aclayers.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: msi.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: srpapi.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: tsappcmp.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: uxtheme.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: textinputframework.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: coreuicomponents.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: coremessaging.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: ntmarta.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: wintypes.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: windows.storage.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: wldp.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: propsys.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: textshaping.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: netapi32.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: wkscli.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: netutils.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: version.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: mscoree.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: profapi.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: sspicli.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: msihnd.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: pcacli.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: mpr.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: apphelp.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: aclayers.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: sfc.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: sfc_os.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: kernel.appcore.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: msi.dll |
Jump to behavior |
Source: C:\Windows\System32\msiexec.exe |
Section loaded: tsappcmp.dll |
Jump to behavior |
Source: SCADA 4.0.12.737.msi |
Static file information: File size 3905024 > 1048576 |
Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\rocknt\objfre\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdbU source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\enduser\objfre\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdbN source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\coinstall\objfre_wlh_x86\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: h:\nt.obj.x86fre\base\wcp\tools\msmcustomaction\objfre\i386\msmcustomaction.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4\objfre_wlh_x86\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\rockeynt\objfre_w2k_x86\i386\rockeynt.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdb source: SCADA 4.0.12.737.msi |
Source: |
Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdbMZ source: SCADA 4.0.12.737.msi |
Source: C:\Windows\System32\msiexec.exe |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Windows\System32\msiexec.exe |
File Volume queried: C:\ FullSizeInformation |
Jump to behavior |
Source: all processes |
Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Windows\System32\msiexec.exe |
Queries volume information: C:\ VolumeInformation |
Jump to behavior |