Click to jump to signature section
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\rocknt\objfre\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdbU source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\enduser\objfre\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdbN source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\coinstall\objfre_wlh_x86\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: h:\nt.obj.x86fre\base\wcp\tools\msmcustomaction\objfre\i386\msmcustomaction.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4\objfre_wlh_x86\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\rockeynt\objfre_w2k_x86\i386\rockeynt.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdbMZ source: SCADA 4.0.12.737.msi |
Source: C:\Windows\System32\msiexec.exe | File opened: z: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: x: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: v: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: t: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: r: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: p: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: n: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: l: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: j: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: h: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: f: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: b: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: y: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: w: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: u: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: s: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: q: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: o: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: m: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: k: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: i: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: g: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: e: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: c: | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | File opened: a: | Jump to behavior |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://ocsp.thawte.com0 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://s2.symcb.com0 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://sv.symcb.com/sv.crl0a |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://sv.symcb.com/sv.crt0 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://sv.symcd.com0& |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0( |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://ts-ocsp.ws.symantec.com07 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://www.flexerasoftware.com0 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://www.symauth.com/cps0( |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: http://www.symauth.com/rpa00 |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: https://d.symcb.com/cps0% |
Source: SCADA 4.0.12.737.msi | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilename_IsIcoRes.exe< vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameSetAllUsers.dll< vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameSFHelper.dll vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameRockey4.sys vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameRockey4USB.sys vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameRockeynt.sys vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameRockUsb.sysR vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameR4CoInst.dll vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary or memory string: OriginalFilenameInstDll.dll vs SCADA 4.0.12.737.msi |
Source: SCADA 4.0.12.737.msi | Binary string: \Device\ROCKEYUSB |
Source: SCADA 4.0.12.737.msi | Binary string: \Device\USBHUB0U |
Source: SCADA 4.0.12.737.msi | Binary string: \Device\Dongle0TestBusySupport\Parameters\DosDevices\ROCKEYNT |
Source: SCADA 4.0.12.737.msi | Binary string: \Device\Dongle0U |
Source: SCADA 4.0.12.737.msi | Binary string: \DosDevices\ROCKEY9X\Device\Dongle0 |
Source: SCADA 4.0.12.737.msi | Binary string: D@B\Device\ROCKEYUSB\DosDevices\ROCKEYUSBU |
Source: SCADA 4.0.12.737.msi | Binary string: \Device\ROCKEYUSB%s%03dU |
Source: SCADA 4.0.12.737.msi | Binary string: \Device\ROCKEYUSB\DosDevices\ROCKEYNTTestBusySupport\Parameters\Device\Dongle0 |
Source: SCADA 4.0.12.737.msi | Binary string: \Device\RootHubU |
Source: SCADA 4.0.12.737.msi | Binary string: \DosDevices\ROCKEYNT\Device\Dongle0 |
Source: SCADA 4.0.12.737.msi | Binary string: P`0PEnum\USBSystem\CurrentControlSet\Services\vxd\Rockey9xSupportTestBusyDisablePort1DisablePort2DisablePort3\Device\ROCKEYUSBU |
Source: SCADA 4.0.12.737.msi | Binary string: P@RockUsb for NT 4.0\Device\ROCKEYUSB\DosDevices\ROCKEYUSBU |
Source: classification engine | Classification label: clean2.winMSI@2/1@0/0 |
Source: C:\Windows\System32\msiexec.exe | File created: C:\Users\user\AppData\Local\Temp\MSI46ae6.LOG | Jump to behavior |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\SCADA 4.0.12.737.msi" |
Source: unknown | Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: srpapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: propsys.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: wkscli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mscoree.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sspicli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msihnd.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: pcacli.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: aclayers.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: sfc_os.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: msi.dll | Jump to behavior |
Source: C:\Windows\System32\msiexec.exe | Section loaded: tsappcmp.dll | Jump to behavior |
Source: SCADA 4.0.12.737.msi | Static file information: File size 3905024 > 1048576 |
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\rocknt\objfre\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdbU source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\enduser\objfre\i386\Rockey4Usb.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdbN source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\coinstall\objfre_wlh_x86\i386\Ry4CoInst.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: h:\nt.obj.x86fre\base\wcp\tools\msmcustomaction\objfre\i386\msmcustomaction.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4\objfre_wlh_x86\i386\Rockey4.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\rockeynt\objfre_w2k_x86\i386\rockeynt.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdb source: SCADA 4.0.12.737.msi |
Source: | Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdbMZ source: SCADA 4.0.12.737.msi |
Source: C:\Windows\System32\msiexec.exe | Process information set: NOOPENFILEERRORBOX | Jump to behavior |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Windows\System32\msiexec.exe | File Volume queried: C:\ FullSizeInformation | Jump to behavior |
Source: all processes | Thread injection, dropped files, key value created, disk infection and DNS query: no activity detected |
Source: C:\Windows\System32\msiexec.exe | Queries volume information: C:\ VolumeInformation | Jump to behavior |