Windows Analysis Report
ZPMC SCADA Setup v4.0.12737.zip

Overview

General Information

Sample name: ZPMC SCADA Setup v4.0.12737.zip
Analysis ID: 1544383
MD5: 8cec6cab7e45958bdda97ddc8bd32d9a
SHA1: dde365ea81f5dbde959633932a406bd57a3fd42d
SHA256: e4892a88830b8ff7b8ce8f702573ac331c814a1a7f7a9535f63ca83c53afb716
Infos:

Detection

Score: 48
Range: 0 - 100
Whitelisted: false
Confidence: 100%

Signatures

.NET source code contains potential unpacker
Modifies existing user documents (likely ransomware behavior)
Checks for available system drives (often done to infect USB drives)
Contains functionality to call native functions
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to check if a debugger is running (OutputDebugString,GetLastError)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to detect virtual machines (SGDT)
Contains functionality to detect virtual machines (SLDT)
Contains functionality to detect virtual machines (STR)
Contains functionality to dynamically determine API calls
Contains functionality to query CPU information (cpuid)
Contains functionality to query locales information (e.g. system language)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates or modifies windows services
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops certificate files (DER)
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
May infect USB drives
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains strange resources
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Tries to resolve domain names, but no domain seems valid (expired dropper behavior)
Uses code obfuscation techniques (call, push, ret)

Classification

Source: Binary string: "ZSNETE~2.PDB|zsNet.ElementBase.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l%ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: lEFZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Rcw.SdAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdbB source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~1.PDB|ZiSCADACLR.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdb\L source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FmtTxt.pdb) source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: !TCPCOM~1.PDB|TCPCommunication.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Language.pdbgoD source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: t.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.DefStruct.pdbC source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: APPSER~1.PDB|AppServerBase.pdbTM source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl TCPDAS~1.PDB|TcpDaSvrWrapper.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsEventService.pdbJ+qiCyZvjnbf6NgG2PLaTivvNsVWVtqaQl+5WdtiswQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZISCAD~3.PDB|ziSCADAStudio.pdbo source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: APPSER~1.PDB|AppServerBase.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\Formulate.pdbbdNJ9XO409VVoHQY2NaV3Oy48oXLvow8yyNGoUKb/Mw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Formulate.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l$ZSNETE~4.PDB|zsNet.EmtProperties.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l!ZSNETW~1.PDB|zsNet.WinFormsUI.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: NTCPMSG.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETB~1.PDB|zsNet.BaseClass.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HFacility.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: 6HZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAcsData.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsScada.Studio.Net.pdbg source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsAlmSvrAcs.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: .MZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCDaServWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l(ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\RunVBA.pdblTuhanUuBisWShxr799s8NkcZIcdTkIipcCxzkr4MmA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: atl80.i386.pdb source: ATL80.dll1.10.dr, ATL80.dll.10.dr, ATL80.dll0.10.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\AlarmServerCLR.pdb/Gq5O0+zk9sH+OZtYIpx1x/HLxXWkG9jwmb4MAIL5TA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ALARMS~2.PDB|AlarmServerCLR.pdb\L source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb M6 source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/CApi.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CApi.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l PROFIN~1.PDB|ProfiNetWrapper.pdb=Ita source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\UserControlBase.pdbzA4caz228yaAXsMa51+Jut2jqvnePUJQY8OI1mLNVlA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.WinFormsUI.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~2.PDB|ziSCADAServer.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ZCompEx.pdbYM+r8mUJr7CX9xMpIbOgiyNQ8xznIYL0BpfxMO7Stqg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\ziSCADAView.pdbYJ/ZWsSsjwcJlA2nR3jUS7OpEyarnnIeZDM0ZeBRW6g= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: DATAAC~2.PDB|DataAcsData.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~3.PDB|ziSCADAStudio.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: lPData.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdbOM source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSUASV~1.PDB|zsUASvrAcs.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HQUERY~1.PDB|HQueryFacility.pdbTM source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.BaseClass.pdb source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZCompEx.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\HFacility.pdbpFcaEXMM/XHbFS/YZ5JICdPt42tRLQKTeAOfa1jE7bA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PrjMan.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSALAR~1.PDB|zsAlarmService.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZiSCADACLR.pdb source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: NTCPMSG.pdbh source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.WinFormsUI.pdbi source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ziSCADAServer.pdbgVX6gmJpvf9H2sh93w886ZAXiy6mPON9AYfy7Jz3oHA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/NTCPMSG.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl!TCPCOM~1.PDB|TCPCommunication.pdbD source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RCW.ServerAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCDaServWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl(ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdbJ source: setup.exe, 00000012.00000003.2397425178.00000000059C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.Element.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WndMan.pdbdbbo_ source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RUNCSH~1.PDB|RunCSharp.pdb* source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: DZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/NTCPMSG.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/UserControlBase.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: Windows\winsxs\73t3z6j5.7agmfc80u.dll.pdb source: 7zG.exe, 0000000A.00000003.1972580949.000002239274A000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 3GZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAccess.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: MBZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WData.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.EmtProperties.pdb+i4oWQrULpuIq2T4TVcOBvHCmoT4ab4tmMH5jm/YKJA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: PROFIN~1.PDB|ProfiNetWrapper.pdb` source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HQueryFacility.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\ziSCADAStudio.pdbGHAjeWSJJcvSIYR5Vu2jV8LtSX0Yu9ezGS9U7joxKOA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RCW.ServerAPI.dllcation.pdb1i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl USERCO~1.PDB|UserControlBase.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: WndMan.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CWSDA~1.PDB|Rcw.SdAPI.pdb-; source: setup.exe, 00000012.00000002.2452182848.0000000001426000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HFacility.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: Language.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +`ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FmtTxt.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSNETD~1.PDB|zsNet.DefHelp.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FmtTxt.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: WData.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Old Dll/TCPCommunication.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: !ZSNETE~3.PDB|zsNet.ElementRes.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.Element.pdb3G73e+u5ywYmbKPiw+oatyW4KBQBlrG+zi3J6ZqammA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ViewClient_WPF.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZIP.pdb source: setup.exe, 00000012.00000003.2407110679.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2402174868.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: \VCMS3.0\SCADA a\Source\Src\API\Rcw.ServerAPI\obj\Release\Rcw.ServerAPI.pdbXDnD `D_CorDllMainmscoree.dll source: Rcw.ServerAPI.dll.10.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\Old Dll\TCPCommunication.pdb+renYCyyxeBD17JekMQ35RybL1om2tnfvcd5gpBeiWg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerCLR.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.DefStruct.pdbXPvfZisQncM3jvRcRa2HWDFG795X/F9RD7mOOrJSNVQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +Pl#ZSSCAD~1.PDB|zsScada.Studio.Net.pdbX source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb3 source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsUASvrAcs.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HFACIL~1.PDB|HFacility.pdbH source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l#OPCUAD~1.PDB|OPCUADaServWrapper.pdb source: setup.exe, 00000012.00000003.2073363822.000000000149D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\DataAcsData.pdbPTAMqTfcuARhovw8iXOa0w572DtBU5bVNVkYxTqBQ7Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PData.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ALARMS~2.PDB|AlarmServerCLR.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~4.PDB|ziSCADAView.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: s.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsServerHost.pdbQDq+M91uG67t/KKC1j0QYAD4391dsz5GeH7DDXCH5eA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: l USERCO~1.PDB|UserControlBase.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETB~1.PDB|zsNet.BaseClass.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl%ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdbV source: setup.exe, 00000012.00000003.2397425178.00000000059C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsAlarmService.pdbNl3QEY4Zzk7S8xQABFrQJoYNlSjB9kSr5S0Z5gCOtPA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +Pl!TCPCOM~1.PDB|TCPCommunication.pdb source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HQUERY~1.PDB|HQueryFacility.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msvcr80.i386.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223932AA000.00000004.00000020.00020000.00000000.sdmp, msvcr80.dll0.10.dr
Source: Binary string: ZSEVEN~1.PDB|zsEventService.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RCWSDA~1.PDB|Rcw.SdAPI.pdb6 source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\RCW.ServerAPI.pdbhVIZNbk7BHBi/sOgaWDgtrmJrawqcwMGntCJv1eoADQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +PlZGTag.pdba source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WData.pdbdll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunCSharp.pdb{o0 source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~1.PDB|ZiSCADACLR.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 2KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZISCAD~3.PDB|ziSCADAStudio.pdbLr source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4\objfre_wlh_x86\i386\Rockey4.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: GZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HDefStruct.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\OPCUADaServWrapper.pdbisgSc9OgGwW5q8YGr8NbplAset5LpDpXNDTb5exyt5Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ALARMS~1.PDB|AlarmServerAPI.pdb0 source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ALARMS~1.PDB|AlarmServerAPI.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\OPCUABrowse.pdbEpWKBLLKng8L1Z2hD+sBEA7sXeMuJawBU5s4IdgVEig= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: Windows\winsxs\vxgs54we.kj4\.pdbat source: 7zG.exe, 0000000A.00000003.1972809065.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975193758.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1972651086.0000022392737000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!ZSNETW~1.PDB|zsNet.WinFormsUI.pdb( source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZiSCADACLR.pdb// source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunCSharp.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdbaL source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +PlWData.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAServer.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETD~2.PDB|zsNet.DefStruct.pdb source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: #OPCUAD~1.PDB|OPCUADaServWrapper.pdb/ source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\NTCPMSG.pdb+qbZtaSkqgRcLB6bBZIBDQUJkg6oTeqUkjDmukv0PDQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: $ZSNETE~4.PDB|zsNet.EmtProperties.pdbg source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\EventServerAPI.pdbywZs/mcSkSP7IEHxIrHlyyxHFpcP1u1C3q3ONqykC0w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAcsData.pdbl.dll source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSALAR~1.PDB|zsAlarmService.pdb6 source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.DefStruct.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsServerHost.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 7BZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PData.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Data/Lib_D3/Crane.Xt.pdb.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!OPCDAS~1.PDB|OPCDaServWrapper.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ViewClient_WPF.pdb[ source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb{ source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 5JZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RCW.ServerAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: RCWSDA~1.PDB|Rcw.SdAPI.pdb$T source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUABrowse.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\rockeynt\objfre_w2k_x86\i386\rockeynt.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223935F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2473155026.000000000656A000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: L.OZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUADaServWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\Language.pdbpSxGErW/ehL/cJe7dz/PAg7+Rir/s3VlJooESBZ0RMg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: @EZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Language.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.ViewClient_WPF.pdb5Nc+GNw6xsin/aC2vxRJiG3ueNAszlwk3cV+m6Biyug= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZSEVEN~1.PDB|zsEventService.pdbpr source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl%ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdb source: setup.exe, 00000012.00000002.2500922986.0000000006997000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403207427.0000000006997000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ElementRes.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 7FZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunCSharp.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsScada.Studio.Net.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/TcpDaSvrWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: WndMan.pdb1 source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAView.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CoreAPI.pdb3 source: setup.exe, 00000012.00000002.2468744199.00000000059F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: EVENTS~1.PDB|EventServerAPI.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ZGTag.pdb1nDOpP2UNJGYCH45/5DEe6GucGydAu1rBU2he5a6YoA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: L3FZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Formulate.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: RunVBA.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ,0CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunVBA.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: -UZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Old Dll/TCPCommunication.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: CoreAPI.pdb/ source: setup.exe, 00000012.00000003.2397425178.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\Extend Dll\ProfiNet\ProfiNetWrapper.pdbSGqcu7bNm+yWW7wP0eLfvsjEREPP6odqYTcaWtwnNtQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: \VCMS3.0\SCADA a\Source\Src\API\Rcw.ServerAPI\obj\Release\Rcw.ServerAPI.pdb source: Rcw.ServerAPI.dll.10.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunVBA.pdbvoK source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\Redist\Language Independent\i386\ISSetup.pdb source: setup.exe, 00000012.00000002.2510020399.000000006CA06000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsAlmSvrAcs.pdb2awxTeEDHVYlsXpLWyKiz2mzq4nZm1MoWw9W7FMbyEA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\zsTrendAcs.pdbI+G7FfrUnOluYmYpbrbEnb4qiqR4WrNepkpF6Ev4JzQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: TCPDAS~1.PDB|TcpDaSvrWrapper.pdbl source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l1CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DaAPIU.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FuncAPI.pdbl>j' source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\CoreAPI.pdbZsrngPsrAYw3dnALGcwBhnneFAw7yX3hZPIBa0BAF1w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\HDefStruct.pdbCzX7CmJo3nndAcSKDd6IiwVm52t3gaZEeLL/fmDtX1w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: %ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l TCPDAS~1.PDB|TcpDaSvrWrapper.pdbd source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/UserControlBase.pdbll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: PrjMan.pdbS source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +AZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CApi.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSTREN~1.PDB|zsTrendAcs.pdb4m source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: h:\nt.obj.x86fre\base\wcp\tools\msmcustomaction\objfre\i386\msmcustomaction.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006210000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: CApi.pdb% source: setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.DefHelp.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsAlarmService.pdbn.batll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: lWData.pdb source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.VCMS3ScreenEditor.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\PrjMan.pdbrDOLbU8cc1ml83UeTt0+XikyAvG2OQD0cGh0VGQIpCw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Language.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: 2DZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CoreAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: PrjMan.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RunVBA.pdbO source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: cation.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\PData.pdbA4Wy9NlEX/Q+rrpRP1jkZFKRsinnbvbcZReHO5xRnmA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CoreAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsUASvrAcs.pdb+214c6Z/f1zI9gpI5wZUr2M2qiKtaS8ks4HHBwKvF8Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/EventServerAPI.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl"ZSNETE~2.PDB|zsNet.ElementBase.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsEventService.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: :LZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/UserControlBase.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUADaServWrapper.pdbQi source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HDefStruct.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZIP.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\DaAPIU.pdbm9rDqcA/83dViPdjMzeA6APZcL5pr7/EW4+Zs8bMbOg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: PrjMan.pdbP source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsEventService.pdb/=a} source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdbMZ source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/TcpDaSvrWrapper.pdbI.dll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: !OPCDAS~1.PDB|OPCDaServWrapper.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FuncAPI.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl(ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdb source: setup.exe, 00000012.00000002.2500922986.0000000006997000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403207427.0000000006997000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RunVBA.pdb- source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ALARMS~2.PDB|AlarmServerCLR.pdbJ source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdb M6 source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\rocknt\objfre\i386\Rockey4.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223935F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2473155026.000000000656A000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: USERCO~1.PDB|UserControlBase.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FmtTxt.pdb source: setup.exe, 00000012.00000002.2468744199.00000000059F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059FA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2397425178.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdbU source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: lZGTag.pdb] source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!ZSNETE~3.PDB|zsNet.ElementRes.pdb source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WData.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: CoreAPI.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!ZSNETW~1.PDB|zsNet.WinFormsUI.pdb{ source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETB~1.PDB|zsNet.BaseClass.pdbfr source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsTrendAcs.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSEVEN~1.PDB|zsEventService.pdb:M source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\RunCSharp.pdb/kBWtLYIdGFyw1TN8IvgppV+xPiyfiTKA37Fhqx8swA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: CApi.pdbc source: setup.exe, 00000012.00000003.2407110679.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000685B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: OPCUAB~1.PDB|OPCUABrowse.pdbL source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l ZSNETD~2.PDB|zsNet.DefStruct.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CApi.pdbW source: setup.exe, 00000012.00000003.2402174868.000000000685B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\Src\Runtime\InstallScript\ISBEW64\x64\Release\ISBEW64.pdb source: ISBEW64.exe, 00000015.00000000.2082773856.00007FF79E177000.00000002.00000001.01000000.0000000D.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/CoreAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: PData.pdbZ source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: DaAPIU.pdb source: setup.exe, 00000012.00000002.2468744199.00000000059F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059FA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2397425178.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 1CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PrjMan.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l!OPCDAS~1.PDB|OPCDaServWrapper.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\WndMan.pdbHt0juaJkP9RWSyjP6ddh2NCwzQ51QPDN153JGmQlw1w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsAlarmService.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HDefStruct.pdbtjy source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl$ZSNETE~4.PDB|zsNet.EmtProperties.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 7CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WndMan.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\enduser\objfre\i386\Rockey4Usb.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223935F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2473155026.000000000656A000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: l ZSNETB~1.PDB|zsNet.BaseClass.pdb~ source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\WData.pdbfw7DAyLwrZOpHKBugMNsn9PnzzKhy04OeGteCxLwodQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAccess.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: \UCDemo\obj\Release\UCDemo.pdb source: UCDemo.dll.10.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.VCMS3ScreenEditor.pdbXOGvZYk0vlYeKtgbpFxATqKl5hRdaVEcyNu4VWZabpg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\coinstall\objfre_wlh_x86\i386\Ry4CoInst.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: MFC80.i386.pdb source: mfc80.dll0.10.dr
Source: Binary string: EVENTS~1.PDB|EventServerAPI.pdb& source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETD~2.PDB|zsNet.DefStruct.pdb-r3 source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\FmtTxt.pdbV8acwzpmdLhyzCZzHlY1SdBfnAX2m51uBTX08ZaJIkw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdbi source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PrjMan.pdb$o source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAView.pdbResource/ii source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ElementBase.pdb source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.BaseClass.pdbSN7sf2B4S8hse3qg8x6TmaL+Bf/eSHmJZ5tJcuQ5j1Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Rcw.SdAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ,2KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/EventServerAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\Rcw.SdAPI.pdb40zK1l5r1IVdcrGQDHJ4iN46l4k8fYOzRIhRxxxnwzQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZGTag.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAcsData.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ,;JZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AppServerBase.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l!ZSNETE~3.PDB|zsNet.ElementRes.pdbsn source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: L0DZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FuncAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\FuncAPI.pdbWKZYnfZAIEWhGXdVyaiaSokHV5E7E7ZlmV6HYJegBtg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ,<KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerCLR.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZCompEx.pdbu source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSTREN~1.PDB|zsTrendAcs.pdbRT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAStudio.pdbb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l0KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HQueryFacility.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdbN source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: (ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: atl80.i386.pdbP source: ATL80.dll1.10.dr, ATL80.dll.10.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAStudio.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.ElementBase.pdbNiyjdKyX7a8HEC+YmrHhkuFzW3XVbkzXmkXmVaVVgJA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerCLR.pdb# source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: !ZSNETW~1.PDB|zsNet.WinFormsUI.pdbS source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.DefHelp.pdb0eWCDbSHO7JEy7YoXIT9P99O8c0y+5or4PYNh74/e7w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\ZiSCADACLR.pdbEmspR26nVl/p6CjI+Ca88ZYZx98nCs2x/urO4shrWkQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: APPSER~1.PDB|AppServerBase.pdb8 source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.EmtProperties.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZGTag.pdb& source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerAPI.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: HDEFST~1.PDB|HDefStruct.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ZIP.pdbq5sfofa+Y2MFs2iOa00t1HaHzOIN98Ot9vwlDkRrk7Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\TcpDaSvrWrapper.pdbCnburEURX1XwTB0aPCr0gFXIZmgod04xa4BG75GQF1A= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: Windows\winsxs\7z1v718o.6n8\mfc80.dllLib_Net/ImageList/Image_Symbol/history alarm.png.pdb source: 7zG.exe, 0000000A.00000003.1972906042.000002239270E000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975694409.0000022392729000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~1.PDB|ZiSCADACLR.pdbXT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RUNCSH~1.PDB|RunCSharp.pdbnT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.WinFormsUI.pdbZECxiRrmzu/5vdGi8uDFbC67nQJlgOV3eE2ny/2AE/A= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\CApi.pdbQp09apawCVncuo0Qwrqgb5Ol7evl+PVgV1vW4z5WqOQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WndMan.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZCompEx.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl#ZSSCAD~1.PDB|zsScada.Studio.Net.pdb source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\OPCDaServWrapper.pdbazo9K73ePJp5eaivAnbp6GfrzLa2jQv24ElpUYRYvQw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZISCAD~2.PDB|ziSCADAServer.pdby source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +PlPData.pdby source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: APPSER~1.PDB|AppServerBase.pdb{L source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Language.pdbg source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DaAPIU.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\AlarmServerAPI.pdb64kiymeQEXcIpRLov4R83UyJhdJQA+RO7a0jZkkoUxw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUABrowse.pdb;i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FORMUL~1.PDB|Formulate.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l#ZSSCAD~1.PDB|zsScada.Studio.Net.pdbko source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: /HZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUABrowse.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAServer.pdbb#i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSTREN~1.PDB|zsTrendAcs.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZGTag.pdb@oy source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\AppServerBase.pdbEvzWewnot2TPzs3oa7FUOhJptwLqpR1fenknJjugE4Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunVBA.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AppServerBase.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl#OPCUAD~1.PDB|OPCUADaServWrapper.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CApi.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSNETD~2.PDB|zsNet.DefStruct.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\setup.pdb source: setup.exe, 0000000E.00000000.2048637934.00000000000D5000.00000002.00000001.01000000.00000008.sdmp, setup.exe, 00000012.00000000.2057291118.0000000000435000.00000002.00000001.01000000.00000009.sdmp, setup.exe.10.dr, setup.exe.18.dr
Source: Binary string: FuncAPI.pdb3 source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl PROFIN~1.PDB|ProfiNetWrapper.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: OPCUAB~1.PDB|OPCUABrowse.pdb source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l!TCPCOM~1.PDB|TCPCommunication.pdbon source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FuncAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Data/Lib_D3/Chassis.Xs.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: DATAAC~1.PDB|DataAccess.pdb$ source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSALMS~1.PDB|zsAlmSvrAcs.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.ElementRes.pdb1X1+ibGSHroQM719tjh9nJh4Vp/tCeNtFrEy0BKyPRQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Old Dll/TCPCommunication.pdb]i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\DataAccess.pdbdIs9skEwDKWdooU/1ppvkiPmZwuv1nifzUBksCo/Axw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\HQueryFacility.pdbvCGtZRJsYo5tHe26INmz+mZvUFXFxWORVGbcsdk6TqQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +Pl!ZSNETE~3.PDB|zsNet.ElementRes.pdbp source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl TCPDAS~1.PDB|TcpDaSvrWrapper.pdbOM source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: #ZSSCAD~1.PDB|zsScada.Studio.Net.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUADaServWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: /LZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/TcpDaSvrWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: rp.pdb source: 7zG.exe, 0000000A.00000003.1972809065.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975193758.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1972651086.0000022392737000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb_k source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSUASV~1.PDB|zsUASvrAcs.pdbLT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l"ZSNETE~2.PDB|zsNet.ElementBase.pdb source: setup.exe, 00000012.00000003.2073363822.000000000149D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Language.pdb% source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsScada.Studio.Net.pdb3B5Byrv6F2DG8fm0vnIpBJ1G7CmgtAdoWL9GaUK5NhQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsUASvrAcs.pdb#o source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HQUERY~1.PDB|HQueryFacility.pdb{L source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: C:\Windows\System32\msiexec.exe File opened: z: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: x: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: v: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: t: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: r: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: p: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: n: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: l: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: j: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: h: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: f: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: b: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: y: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: w: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: u: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: s: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: q: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: o: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: m: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: k: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: i: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: g: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: e: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: c: Jump to behavior
Source: C:\Windows\System32\msiexec.exe File opened: a: Jump to behavior
Source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ZPMC SCADA Setup v4.0.12737/Autorun.inf
Source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: ZPMC SCADA Setup v4.0.12737/Autorun.infOal
Source: ZPMC SCADA Setup v4.0.12737.zip Binary or memory string: ZPMC SCADA Setup v4.0.12737/Autorun.inf[autorun]
Source: ZPMC SCADA Setup v4.0.12737.zip Binary or memory string: ZPMC SCADA Setup v4.0.12737/Autorun.inf[autorun]
Source: ZPMC SCADA Setup v4.0.12737.zip Binary or memory string: 'ZPMC SCADA Setup v4.0.12737/Autorun.inf[autorun]
Source: ZPMC SCADA Setup v4.0.12737.zip Binary or memory string: 'ZPMC SCADA Setup v4.0.12737/Autorun.inf[autorun]
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1003C60E __EH_prolog3_GS,FindFirstFileW, 18_2_1003C60E
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100B86D3 __EH_prolog3_GS,FindFirstFileW,lstrcmpW,lstrcmpW,FindNextFileW,RemoveDirectoryW,__CxxThrowException@8,DeleteFileW, 18_2_100B86D3
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin\Extend Dll\ProfiNet Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin\Extend Dll\View Resource Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin\Extend Dll Jump to behavior
Source: unknown DNS traffic detected: query: 206.23.85.13.in-addr.arpa replaycode: Name error (3)
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic DNS traffic detected: DNS query: 206.23.85.13.in-addr.arpa
Source: mfc80.dll0.10.dr String found in binary or memory: ftp://http://HTTP/1.0
Source: setup.exe, 00000012.00000003.2390078724.0000000004234000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://crl.thawte.com/Tha
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://crl.thawte.com/ThawteTimestampingCA.crl0
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://ocsp.thawte.com0
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://s1.symcb.com/pca3-g5.crl0
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://s2.symcb.com0
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://sv.symcb.com/sv.crl0a
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://sv.symcb.com/sv.crt0
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://sv.symcd.com0&
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://ts-aia.ws.symantec.com/tss-ca-g2.cer0
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://ts-crl.ws.symantec.com/tss-ca-g2.crl0(
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://ts-ocsp.ws.symantec.com07
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://www.flexerasoftware.com0
Source: setup.exe, 0000000E.00000000.2048637934.00000000000D5000.00000002.00000001.01000000.00000008.sdmp, setup.exe, 00000011.00000002.2073364727.00000000000D5000.00000002.00000001.01000000.00000008.sdmp, setup.exe, 00000012.00000002.2446987044.0000000000425000.00000002.00000001.01000000.00000009.sdmp, setup.exe, 00000012.00000000.2057291118.0000000000425000.00000002.00000001.01000000.00000009.sdmp, setup.exe.10.dr, setup.exe.18.dr String found in binary or memory: http://www.installshield.com/isetup/ProErrorCentral.asp?ErrorCode=%d
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://www.symauth.com/cps0(
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: http://www.symauth.com/rpa00
Source: setup.exe, 00000012.00000002.2452182848.00000000013FB000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2402174868.00000000068C1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2402174868.00000000068A1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.00000000068A2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403394781.0000000006954000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.00000000068C1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2401094319.0000000006950000.00000004.00000020.00020000.00000000.sdmp, String1033.txt.18.dr String found in binary or memory: http://www.zpmc.com
Source: setup.exe, 00000012.00000003.2402174868.00000000068A1000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.00000000068A2000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2395352507.0000000006877000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.00000000068A1000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.zpmc.comVERSON
Source: setup.exe, 00000012.00000003.2395352507.0000000006877000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://www.zpmc.comall
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: https://d.symcb.com/cps0%
Source: setup.exe, 00000012.00000002.2473155026.00000000062E0000.00000002.00000001.00040000.00000013.sdmp, setup.exe, 00000012.00000002.2473155026.00000000062B6000.00000002.00000001.00040000.00000013.sdmp, MSIC44.tmp.19.dr, MSI8A62.tmp.18.dr String found in binary or memory: https://d.symcb.com/rpa0
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\j4auwzcy.rsh\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Policies\i4auwzcy.rsh\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Manifests\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Policies\ed6uew4i.4ha\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Policies\m3oqdoe3.l2\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\vxgs54we.kj4\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Manifests\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\n3oqdoe3.l2\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Policies\u1sw1o0k.9hi\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\v1sw1o0k.9hi\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\73t3z6j5.7ag\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\fd6uew4i.4ha\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Manifests\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\b2rg91xw.1p4\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Policies\uxgs54we.kj4\8.0.50727.762.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303.cat Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\Manifests\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700.cat Jump to dropped file

Spam, unwanted Advertisements and Ransom Demands

barindex
Source: C:\Program Files\7-Zip\7zG.exe File deleted: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Data\Lib_D3\SkyboxTop.jpg Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File deleted: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Data\Lib_Net\ImageList\ImageList_1\pump1.jpg Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File deleted: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Data\Lib_Net\ImageList\ImageList_1\naozhong2.jpg Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File deleted: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Data\Lib_Net\ImageList\ImageList_1\truck2.jpg Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File deleted: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Data\Lib_Net\ImageList\ImageList_1\monitor.jpg Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100234D7 GetPropW,NtdllDefWindowProc_W, 18_2_100234D7
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1001C1DF NtdllDefWindowProc_W, 18_2_1001C1DF
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1001C207 NtdllDefWindowProc_W,GetSysColor, 18_2_1001C207
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1007C220 GetPropW,NtdllDefWindowProc_W,BeginPaint,BitBlt,EndPaint,CallWindowProcW,DeleteObject,DeleteDC,RemovePropW,SetWindowLongW,_memset,GetClassNameW,lstrcmpiW,GetWindowLongW,_memset,GetClassNameW,lstrcmpiW,SetBkMode,SetTextColor,lstrcmpiW,SetBkMode,SetTextColor,_memset,GetClassNameW,lstrcmpiW,SetBkMode,SetTextColor,GetStockObject, 18_2_1007C220
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1001C2D0 NtdllDefWindowProc_W, 18_2_1001C2D0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100222F6 GetWindowLongW,SetWindowLongW,NtdllDefWindowProc_W, 18_2_100222F6
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\420a40.msi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIBD6.tmp Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIC44.tmp Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55} Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI1221.tmp Jump to behavior
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI1520.tmp Jump to behavior
Source: C:\Windows\System32\msiexec.exe File deleted: C:\Windows\Installer\MSIBD6.tmp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070A7730 18_2_070A7730
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070B37B0 18_2_070B37B0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070A6910 18_2_070A6910
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1008D033 18_2_1008D033
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100B1124 18_2_100B1124
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100A535C 18_2_100A535C
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10045996 18_2_10045996
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100819A0 18_2_100819A0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100A5E68 18_2_100A5E68
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100A40CE 18_2_100A40CE
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1004C3B7 18_2_1004C3B7
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1009C407 18_2_1009C407
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10084490 18_2_10084490
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10064A20 18_2_10064A20
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: String function: 070A56E0 appears 40 times
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: String function: 1008BF00 appears 55 times
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: String function: 1008ABD5 appears 38 times
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: String function: 1008BECA appears 195 times
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: String function: 1008A218 appears 80 times
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: String function: 1008BE97 appears 174 times
Source: Rcw.ServerAPI.dll.10.dr Static PE information: Resource name: RT_VERSION type: MacBinary, comment length 97, char. code 0x69, total length 1711304448, Wed Mar 28 22:22:24 2040 INVALID date, modified Tue Feb 7 01:41:58 2040, creator ' ' "4"
Source: mfc80KOR.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80ESP.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80ITA.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80ENU.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80CHT.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80JPN.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80DEU.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80FRA.dll.10.dr Static PE information: No import functions for PE file found
Source: mfc80CHS.dll.10.dr Static PE information: No import functions for PE file found
Source: classification engine Classification label: mal48.rans.evad.winZIP@33/1053@1/0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1003DA79 GetLastError,FormatMessageW, 18_2_1003DA79
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1004A51B _memset,lstrcpyW,lstrcatW,GetDiskFreeSpaceExW,GetDiskFreeSpaceW, 18_2_1004A51B
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10060283 __EH_prolog3_GS,CreateToolhelp32Snapshot,GetLastError,Process32FirstW,Process32NextW,OpenProcess, 18_2_10060283
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1005E1FF __EH_prolog3_GS,GetModuleHandleW,GetProcAddress,LoadLibraryW,GetProcAddress,CoCreateInstance, 18_2_1005E1FF
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100452D3 __EH_prolog3,FindResourceW,LoadResource,LockResource,CreateDialogIndirectParamW,CreateDialogIndirectParamW, 18_2_100452D3
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737 Jump to behavior
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:876:120:WilError_03
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe File created: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9} Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe File read: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Setup.ini Jump to behavior
Source: C:\Windows\System32\rundll32.exe Key opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Windows\System32\rundll32.exe C:\Windows\System32\rundll32.exe C:\Windows\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -Embedding
Source: unknown Process created: C:\Program Files\7-Zip\7zG.exe "C:\Program Files\7-Zip\7zG.exe" x -o"C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\" -spe -an -ai#7zMap15170:110:7zEvent13957
Source: unknown Process created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe "C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe"
Source: unknown Process created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe "C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe"
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe /q"C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe" /tempdisk1folder"C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}" /IS_temp
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 77B4B6CB8D21758EFE216C05F17DCEE1 C
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{3C556304-8D46-41A1-A183-C63C96FA76B7}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{C68E9931-1A54-4D29-9A11-E2C1A6140D74}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{3C967A50-E90B-4AD5-B526-62683195C54F}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{EB53D73A-7D41-467E-AF22-FA743D2E5BD2}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{0B631758-29DD-4B8E-9A12-949F140ACCEC}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{58E35334-6736-4373-BC16-B19DB2B7F3E2}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{66BF646F-C6CD-4823-BD3A-BBBE0CE92580}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{5DB750C9-5B1D-4912-9BBB-735073942453}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{85F4BC9B-9F30-4363-AD6D-FD00E62E44B7}
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{D823CFD3-3D7A-4194-AD31-CD5AD6A26B55}
Source: unknown Process created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
Source: C:\Windows\System32\SrTasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F52714C42576362BF3928B61AE156682
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe /q"C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe" /tempdisk1folder"C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}" /IS_temp Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{3C556304-8D46-41A1-A183-C63C96FA76B7} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{C68E9931-1A54-4D29-9A11-E2C1A6140D74} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{3C967A50-E90B-4AD5-B526-62683195C54F} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{EB53D73A-7D41-467E-AF22-FA743D2E5BD2} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{0B631758-29DD-4B8E-9A12-949F140ACCEC} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{58E35334-6736-4373-BC16-B19DB2B7F3E2} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{66BF646F-C6CD-4823-BD3A-BBBE0CE92580} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{5DB750C9-5B1D-4912-9BBB-735073942453} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{85F4BC9B-9F30-4363-AD6D-FD00E62E44B7} Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe {EFB7539B-24F3-46B6-AF6E-3B021B51EFEF}:{D823CFD3-3D7A-4194-AD31-CD5AD6A26B55} Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding 77B4B6CB8D21758EFE216C05F17DCEE1 C Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding F52714C42576362BF3928B61AE156682 Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: msi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: msi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: tsappcmp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: riched32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: explorerframe.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: srclient.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: spp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: vssapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: vsstrace.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: sxproxy.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: srpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\System32\msiexec.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Section loaded: sxs.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: spp.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srclient.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ktmw32.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: wer.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: bcd.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: dsrole.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: msxml3.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vss_ps.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: wininet.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: iertutil.dll
Source: C:\Program Files\7-Zip\7zG.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56FDF344-FD6D-11d0-958A-006097C9A090}\InProcServer32 Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File written: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\0x0409.ini Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File opened: C:\Windows\SysWOW64\RICHED32.DLL Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: ZPMC SCADA Setup v4.0.12737.zip Static file information: File size 75435301 > 1048576
Source: Binary string: "ZSNETE~2.PDB|zsNet.ElementBase.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l%ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: lEFZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Rcw.SdAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdbB source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~1.PDB|ZiSCADACLR.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdb\L source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FmtTxt.pdb) source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: !TCPCOM~1.PDB|TCPCommunication.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Language.pdbgoD source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: t.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.DefStruct.pdbC source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: APPSER~1.PDB|AppServerBase.pdbTM source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl TCPDAS~1.PDB|TcpDaSvrWrapper.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsEventService.pdbJ+qiCyZvjnbf6NgG2PLaTivvNsVWVtqaQl+5WdtiswQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZISCAD~3.PDB|ziSCADAStudio.pdbo source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: APPSER~1.PDB|AppServerBase.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\Formulate.pdbbdNJ9XO409VVoHQY2NaV3Oy48oXLvow8yyNGoUKb/Mw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Formulate.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l$ZSNETE~4.PDB|zsNet.EmtProperties.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l!ZSNETW~1.PDB|zsNet.WinFormsUI.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: NTCPMSG.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETB~1.PDB|zsNet.BaseClass.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HFacility.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: 6HZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAcsData.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsScada.Studio.Net.pdbg source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsAlmSvrAcs.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: .MZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCDaServWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l(ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\RunVBA.pdblTuhanUuBisWShxr799s8NkcZIcdTkIipcCxzkr4MmA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: atl80.i386.pdb source: ATL80.dll1.10.dr, ATL80.dll.10.dr, ATL80.dll0.10.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\AlarmServerCLR.pdb/Gq5O0+zk9sH+OZtYIpx1x/HLxXWkG9jwmb4MAIL5TA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ALARMS~2.PDB|AlarmServerCLR.pdb\L source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb M6 source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/CApi.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CApi.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l PROFIN~1.PDB|ProfiNetWrapper.pdb=Ita source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\UserControlBase.pdbzA4caz228yaAXsMa51+Jut2jqvnePUJQY8OI1mLNVlA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.WinFormsUI.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~2.PDB|ziSCADAServer.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ZCompEx.pdbYM+r8mUJr7CX9xMpIbOgiyNQ8xznIYL0BpfxMO7Stqg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\ziSCADAView.pdbYJ/ZWsSsjwcJlA2nR3jUS7OpEyarnnIeZDM0ZeBRW6g= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: DATAAC~2.PDB|DataAcsData.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~3.PDB|ziSCADAStudio.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: lPData.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdbOM source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSUASV~1.PDB|zsUASvrAcs.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HQUERY~1.PDB|HQueryFacility.pdbTM source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.BaseClass.pdb source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZCompEx.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\HFacility.pdbpFcaEXMM/XHbFS/YZ5JICdPt42tRLQKTeAOfa1jE7bA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PrjMan.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSALAR~1.PDB|zsAlarmService.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZiSCADACLR.pdb source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: NTCPMSG.pdbh source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.WinFormsUI.pdbi source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ziSCADAServer.pdbgVX6gmJpvf9H2sh93w886ZAXiy6mPON9AYfy7Jz3oHA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/NTCPMSG.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl!TCPCOM~1.PDB|TCPCommunication.pdbD source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RCW.ServerAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCDaServWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl(ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdbJ source: setup.exe, 00000012.00000003.2397425178.00000000059C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.Element.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WndMan.pdbdbbo_ source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RUNCSH~1.PDB|RunCSharp.pdb* source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: DZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/NTCPMSG.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/UserControlBase.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: Windows\winsxs\73t3z6j5.7agmfc80u.dll.pdb source: 7zG.exe, 0000000A.00000003.1972580949.000002239274A000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 3GZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAccess.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: MBZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WData.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.EmtProperties.pdb+i4oWQrULpuIq2T4TVcOBvHCmoT4ab4tmMH5jm/YKJA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: PROFIN~1.PDB|ProfiNetWrapper.pdb` source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HQueryFacility.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\ziSCADAStudio.pdbGHAjeWSJJcvSIYR5Vu2jV8LtSX0Yu9ezGS9U7joxKOA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RCW.ServerAPI.dllcation.pdb1i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl USERCO~1.PDB|UserControlBase.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: WndMan.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CWSDA~1.PDB|Rcw.SdAPI.pdb-; source: setup.exe, 00000012.00000002.2452182848.0000000001426000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HFacility.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: Language.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +`ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FmtTxt.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSNETD~1.PDB|zsNet.DefHelp.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FmtTxt.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: WData.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Old Dll/TCPCommunication.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: !ZSNETE~3.PDB|zsNet.ElementRes.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.Element.pdb3G73e+u5ywYmbKPiw+oatyW4KBQBlrG+zi3J6ZqammA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ViewClient_WPF.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZIP.pdb source: setup.exe, 00000012.00000003.2407110679.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2402174868.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: \VCMS3.0\SCADA a\Source\Src\API\Rcw.ServerAPI\obj\Release\Rcw.ServerAPI.pdbXDnD `D_CorDllMainmscoree.dll source: Rcw.ServerAPI.dll.10.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\Old Dll\TCPCommunication.pdb+renYCyyxeBD17JekMQ35RybL1om2tnfvcd5gpBeiWg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerCLR.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.DefStruct.pdbXPvfZisQncM3jvRcRa2HWDFG795X/F9RD7mOOrJSNVQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +Pl#ZSSCAD~1.PDB|zsScada.Studio.Net.pdbX source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb3 source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsUASvrAcs.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HFACIL~1.PDB|HFacility.pdbH source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l#OPCUAD~1.PDB|OPCUADaServWrapper.pdb source: setup.exe, 00000012.00000003.2073363822.000000000149D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\DataAcsData.pdbPTAMqTfcuARhovw8iXOa0w572DtBU5bVNVkYxTqBQ7Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PData.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ALARMS~2.PDB|AlarmServerCLR.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~4.PDB|ziSCADAView.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: s.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsServerHost.pdbQDq+M91uG67t/KKC1j0QYAD4391dsz5GeH7DDXCH5eA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: l USERCO~1.PDB|UserControlBase.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETB~1.PDB|zsNet.BaseClass.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl%ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdbV source: setup.exe, 00000012.00000003.2397425178.00000000059C6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsAlarmService.pdbNl3QEY4Zzk7S8xQABFrQJoYNlSjB9kSr5S0Z5gCOtPA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +Pl!TCPCOM~1.PDB|TCPCommunication.pdb source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HQUERY~1.PDB|HQueryFacility.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: msvcr80.i386.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223932AA000.00000004.00000020.00020000.00000000.sdmp, msvcr80.dll0.10.dr
Source: Binary string: ZSEVEN~1.PDB|zsEventService.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RCWSDA~1.PDB|Rcw.SdAPI.pdb6 source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\RCW.ServerAPI.pdbhVIZNbk7BHBi/sOgaWDgtrmJrawqcwMGntCJv1eoADQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +PlZGTag.pdba source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WData.pdbdll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunCSharp.pdb{o0 source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~1.PDB|ZiSCADACLR.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 2KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZISCAD~3.PDB|ziSCADAStudio.pdbLr source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4\objfre_wlh_x86\i386\Rockey4.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: GZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HDefStruct.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\OPCUADaServWrapper.pdbisgSc9OgGwW5q8YGr8NbplAset5LpDpXNDTb5exyt5Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ALARMS~1.PDB|AlarmServerAPI.pdb0 source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ALARMS~1.PDB|AlarmServerAPI.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\OPCUABrowse.pdbEpWKBLLKng8L1Z2hD+sBEA7sXeMuJawBU5s4IdgVEig= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: Windows\winsxs\vxgs54we.kj4\.pdbat source: 7zG.exe, 0000000A.00000003.1972809065.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975193758.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1972651086.0000022392737000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!ZSNETW~1.PDB|zsNet.WinFormsUI.pdb( source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZiSCADACLR.pdb// source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunCSharp.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdbaL source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +PlWData.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAServer.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETD~2.PDB|zsNet.DefStruct.pdb source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: #OPCUAD~1.PDB|OPCUADaServWrapper.pdb/ source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\NTCPMSG.pdb+qbZtaSkqgRcLB6bBZIBDQUJkg6oTeqUkjDmukv0PDQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: $ZSNETE~4.PDB|zsNet.EmtProperties.pdbg source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\EventServerAPI.pdbywZs/mcSkSP7IEHxIrHlyyxHFpcP1u1C3q3ONqykC0w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAcsData.pdbl.dll source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSALAR~1.PDB|zsAlarmService.pdb6 source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.DefStruct.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsServerHost.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 7BZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PData.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Data/Lib_D3/Crane.Xt.pdb.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!OPCDAS~1.PDB|OPCDaServWrapper.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ViewClient_WPF.pdb[ source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSNETE~1.PDB|zsNet.Element.pdb{ source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 5JZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RCW.ServerAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: RCWSDA~1.PDB|Rcw.SdAPI.pdb$T source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUABrowse.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\rockeynt\objfre_w2k_x86\i386\rockeynt.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223935F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2473155026.000000000656A000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: L.OZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUADaServWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\Language.pdbpSxGErW/ehL/cJe7dz/PAg7+Rir/s3VlJooESBZ0RMg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: @EZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Language.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.ViewClient_WPF.pdb5Nc+GNw6xsin/aC2vxRJiG3ueNAszlwk3cV+m6Biyug= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZSEVEN~1.PDB|zsEventService.pdbpr source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl%ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdb source: setup.exe, 00000012.00000002.2500922986.0000000006997000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403207427.0000000006997000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ElementRes.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 7FZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunCSharp.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsScada.Studio.Net.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/TcpDaSvrWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: WndMan.pdb1 source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAView.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CoreAPI.pdb3 source: setup.exe, 00000012.00000002.2468744199.00000000059F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: EVENTS~1.PDB|EventServerAPI.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ZGTag.pdb1nDOpP2UNJGYCH45/5DEe6GucGydAu1rBU2he5a6YoA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: L3FZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Formulate.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: RunVBA.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ,0CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunVBA.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: -UZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Old Dll/TCPCommunication.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: CoreAPI.pdb/ source: setup.exe, 00000012.00000003.2397425178.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\Extend Dll\ProfiNet\ProfiNetWrapper.pdbSGqcu7bNm+yWW7wP0eLfvsjEREPP6odqYTcaWtwnNtQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: \VCMS3.0\SCADA a\Source\Src\API\Rcw.ServerAPI\obj\Release\Rcw.ServerAPI.pdb source: Rcw.ServerAPI.dll.10.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunVBA.pdbvoK source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\Redist\Language Independent\i386\ISSetup.pdb source: setup.exe, 00000012.00000002.2510020399.000000006CA06000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsAlmSvrAcs.pdb2awxTeEDHVYlsXpLWyKiz2mzq4nZm1MoWw9W7FMbyEA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\zsTrendAcs.pdbI+G7FfrUnOluYmYpbrbEnb4qiqR4WrNepkpF6Ev4JzQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: TCPDAS~1.PDB|TcpDaSvrWrapper.pdbl source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l1CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DaAPIU.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FuncAPI.pdbl>j' source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\CoreAPI.pdbZsrngPsrAYw3dnALGcwBhnneFAw7yX3hZPIBa0BAF1w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\HDefStruct.pdbCzX7CmJo3nndAcSKDd6IiwVm52t3gaZEeLL/fmDtX1w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: %ZSNETV~2.PDB|zsNet.ViewClient_WPF.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l TCPDAS~1.PDB|TcpDaSvrWrapper.pdbd source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/UserControlBase.pdbll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: PrjMan.pdbS source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +AZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CApi.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSTREN~1.PDB|zsTrendAcs.pdb4m source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: h:\nt.obj.x86fre\base\wcp\tools\msmcustomaction\objfre\i386\msmcustomaction.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006210000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: CApi.pdb% source: setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073645541.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.DefHelp.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsAlarmService.pdbn.batll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: lWData.pdb source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.VCMS3ScreenEditor.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\PrjMan.pdbrDOLbU8cc1ml83UeTt0+XikyAvG2OQD0cGh0VGQIpCw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Language.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: 2DZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CoreAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: PrjMan.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RunVBA.pdbO source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: cation.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\PData.pdbA4Wy9NlEX/Q+rrpRP1jkZFKRsinnbvbcZReHO5xRnmA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CoreAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\zsUASvrAcs.pdb+214c6Z/f1zI9gpI5wZUr2M2qiKtaS8ks4HHBwKvF8Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/EventServerAPI.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl"ZSNETE~2.PDB|zsNet.ElementBase.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsEventService.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: :LZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/UserControlBase.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUADaServWrapper.pdbQi source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HDefStruct.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZIP.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\DaAPIU.pdbm9rDqcA/83dViPdjMzeA6APZcL5pr7/EW4+Zs8bMbOg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: PrjMan.pdbP source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsEventService.pdb/=a} source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\Rockey4Drv\wdm\enduser\objfre\i386\RockUsb.pdbMZ source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/TcpDaSvrWrapper.pdbI.dll source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: !OPCDAS~1.PDB|OPCDaServWrapper.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FuncAPI.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl(ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdb source: setup.exe, 00000012.00000002.2500922986.0000000006997000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403207427.0000000006997000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RunVBA.pdb- source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ALARMS~2.PDB|AlarmServerCLR.pdbJ source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdb M6 source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\rocknt\objfre\i386\Rockey4.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223935F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2473155026.000000000656A000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: USERCO~1.PDB|UserControlBase.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FmtTxt.pdb source: setup.exe, 00000012.00000002.2468744199.00000000059F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059FA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2397425178.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdbU source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: lZGTag.pdb] source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!ZSNETE~3.PDB|zsNet.ElementRes.pdb source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WData.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: CoreAPI.pdb source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl!ZSNETW~1.PDB|zsNet.WinFormsUI.pdb{ source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETB~1.PDB|zsNet.BaseClass.pdbfr source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsTrendAcs.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSEVEN~1.PDB|zsEventService.pdb:M source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\RunCSharp.pdb/kBWtLYIdGFyw1TN8IvgppV+xPiyfiTKA37Fhqx8swA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: CApi.pdbc source: setup.exe, 00000012.00000003.2407110679.000000000685B000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000685B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: OPCUAB~1.PDB|OPCUABrowse.pdbL source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l ZSNETD~2.PDB|zsNet.DefStruct.pdb source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: CApi.pdbW source: setup.exe, 00000012.00000003.2402174868.000000000685B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\Src\Runtime\InstallScript\ISBEW64\x64\Release\ISBEW64.pdb source: ISBEW64.exe, 00000015.00000000.2082773856.00007FF79E177000.00000002.00000001.01000000.0000000D.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/CoreAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: PData.pdbZ source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: DaAPIU.pdb source: setup.exe, 00000012.00000002.2468744199.00000000059F9000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059FA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2397425178.00000000059FA000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 1CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PrjMan.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l!OPCDAS~1.PDB|OPCDaServWrapper.pdb source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\WndMan.pdbHt0juaJkP9RWSyjP6ddh2NCwzQ51QPDN153JGmQlw1w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsAlarmService.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HDefStruct.pdbtjy source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl$ZSNETE~4.PDB|zsNet.EmtProperties.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: 7CZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WndMan.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\enduser\objfre\i386\Rockey4Usb.pdb source: 7zG.exe, 0000000A.00000003.1961246630.00000223935F0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2473155026.000000000656A000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: l ZSNETB~1.PDB|zsNet.BaseClass.pdb~ source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\WData.pdbfw7DAyLwrZOpHKBugMNsn9PnzzKhy04OeGteCxLwodQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAccess.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: D:\myprogram\CVSProj\ePassSvr\rock_usb\RockeyCoinstall\objfre\i386\Ry4CoInst.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: \UCDemo\obj\Release\UCDemo.pdb source: UCDemo.dll.10.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.VCMS3ScreenEditor.pdbXOGvZYk0vlYeKtgbpFxATqKl5hRdaVEcyNu4VWZabpg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\coinstall\objfre_wlh_x86\i386\Ry4CoInst.pdb source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: MFC80.i386.pdb source: mfc80.dll0.10.dr
Source: Binary string: EVENTS~1.PDB|EventServerAPI.pdb& source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl ZSNETD~2.PDB|zsNet.DefStruct.pdb-r3 source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\FmtTxt.pdbV8acwzpmdLhyzCZzHlY1SdBfnAX2m51uBTX08ZaJIkw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: RCWSER~1.PDB|RCW.ServerAPI.pdbi source: setup.exe, 00000012.00000003.2073645541.0000000001461000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/PrjMan.pdb$o source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAView.pdbResource/ii source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.ElementBase.pdb source: 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.BaseClass.pdbSN7sf2B4S8hse3qg8x6TmaL+Bf/eSHmJZ5tJcuQ5j1Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Rcw.SdAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ,2KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/EventServerAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\Rcw.SdAPI.pdb40zK1l5r1IVdcrGQDHJ4iN46l4k8fYOzRIhRxxxnwzQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZGTag.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DataAcsData.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ,;JZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AppServerBase.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: l!ZSNETE~3.PDB|zsNet.ElementRes.pdbsn source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: L0DZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FuncAPI.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\FuncAPI.pdbWKZYnfZAIEWhGXdVyaiaSokHV5E7E7ZlmV6HYJegBtg= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ,<KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerCLR.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZCompEx.pdbu source: setup.exe, 00000012.00000003.2072971157.000000000145B000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSTREN~1.PDB|zsTrendAcs.pdbRT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAStudio.pdbb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l0KZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/HQueryFacility.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: e:\ft_code\drv_proj\drv_rockey4\src\32\vista\rockey4usb\objfre_wlh_x86\i386\Rockey4Usb.pdbN source: setup.exe, 00000012.00000002.2473155026.0000000006586000.00000002.00000001.00040000.00000013.sdmp
Source: Binary string: (ZSNETV~1.PDB|zsNet.VCMS3ScreenEditor.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSSERV~1.PDB|zsServerHost.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: atl80.i386.pdbP source: ATL80.dll1.10.dr, ATL80.dll.10.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAStudio.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.ElementBase.pdbNiyjdKyX7a8HEC+YmrHhkuFzW3XVbkzXmkXmVaVVgJA= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerCLR.pdb# source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: !ZSNETW~1.PDB|zsNet.WinFormsUI.pdbS source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.DefHelp.pdb0eWCDbSHO7JEy7YoXIT9P99O8c0y+5or4PYNh74/e7w= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\ZiSCADACLR.pdbEmspR26nVl/p6CjI+Ca88ZYZx98nCs2x/urO4shrWkQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: APPSER~1.PDB|AppServerBase.pdb8 source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsNet.EmtProperties.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZGTag.pdb& source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AlarmServerAPI.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: HDEFST~1.PDB|HDefStruct.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\ZIP.pdbq5sfofa+Y2MFs2iOa00t1HaHzOIN98Ot9vwlDkRrk7Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\TcpDaSvrWrapper.pdbCnburEURX1XwTB0aPCr0gFXIZmgod04xa4BG75GQF1A= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: Windows\winsxs\7z1v718o.6n8\mfc80.dllLib_Net/ImageList/Image_Symbol/history alarm.png.pdb source: 7zG.exe, 0000000A.00000003.1972906042.000002239270E000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975694409.0000022392729000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZISCAD~1.PDB|ZiSCADACLR.pdbXT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: RUNCSH~1.PDB|RunCSharp.pdbnT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.WinFormsUI.pdbZECxiRrmzu/5vdGi8uDFbC67nQJlgOV3eE2ny/2AE/A= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\CApi.pdbQp09apawCVncuo0Qwrqgb5Ol7evl+PVgV1vW4z5WqOQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/WndMan.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZCompEx.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl#ZSSCAD~1.PDB|zsScada.Studio.Net.pdb source: setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\OPCDaServWrapper.pdbazo9K73ePJp5eaivAnbp6GfrzLa2jQv24ElpUYRYvQw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZISCAD~2.PDB|ziSCADAServer.pdby source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +PlPData.pdby source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: APPSER~1.PDB|AppServerBase.pdb{L source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Language.pdbg source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/DaAPIU.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: program files\ZPMC\SCADA\Bin\AlarmServerAPI.pdb64kiymeQEXcIpRLov4R83UyJhdJQA+RO7a0jZkkoUxw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUABrowse.pdb;i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: FORMUL~1.PDB|Formulate.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l#ZSSCAD~1.PDB|zsScada.Studio.Net.pdbko source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: /HZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUABrowse.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ziSCADAServer.pdbb#i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSTREN~1.PDB|zsTrendAcs.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/ZGTag.pdb@oy source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\AppServerBase.pdbEvzWewnot2TPzs3oa7FUOhJptwLqpR1fenknJjugE4Q= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/RunVBA.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/AppServerBase.pdb source: 7zG.exe, 0000000A.00000003.1975989842.00000223926B1000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: +Pl#OPCUAD~1.PDB|OPCUADaServWrapper.pdb source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2403686348.00000000059C7000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/CApi.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZSNETD~2.PDB|zsNet.DefStruct.pdb source: setup.exe, 00000012.00000002.2462601860.0000000004180000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: C:\CodeBases\isdev\redist\Language Independent\i386\setup.pdb source: setup.exe, 0000000E.00000000.2048637934.00000000000D5000.00000002.00000001.01000000.00000008.sdmp, setup.exe, 00000012.00000000.2057291118.0000000000435000.00000002.00000001.01000000.00000009.sdmp, setup.exe.10.dr, setup.exe.18.dr
Source: Binary string: FuncAPI.pdb3 source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl PROFIN~1.PDB|ProfiNetWrapper.pdb source: setup.exe, 00000012.00000003.2402174868.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: OPCUAB~1.PDB|OPCUABrowse.pdb source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l!TCPCOM~1.PDB|TCPCommunication.pdbon source: setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/FuncAPI.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Data/Lib_D3/Chassis.Xs.pdb source: 7zG.exe, 0000000A.00000002.1978052133.00000223926C2000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1974975153.00000223926BE000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: DATAAC~1.PDB|DataAccess.pdb$ source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSALMS~1.PDB|zsAlmSvrAcs.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2073363822.000000000149F000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsNet.ElementRes.pdb1X1+ibGSHroQM719tjh9nJh4Vp/tCeNtFrEy0BKyPRQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/Old Dll/TCPCommunication.pdb]i source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\DataAccess.pdbdIs9skEwDKWdooU/1ppvkiPmZwuv1nifzUBksCo/Axw= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: program files\ZPMC\SCADA\Bin\HQueryFacility.pdbvCGtZRJsYo5tHe26INmz+mZvUFXFxWORVGbcsdk6TqQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: +Pl!ZSNETE~3.PDB|zsNet.ElementRes.pdbp source: setup.exe, 00000012.00000003.2401667791.000000000691D000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: +Pl TCPDAS~1.PDB|TcpDaSvrWrapper.pdbOM source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2494402472.000000000688C000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: #ZSSCAD~1.PDB|zsScada.Studio.Net.pdb source: setup.exe, 00000012.00000002.2452182848.0000000001480000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/OPCUADaServWrapper.pdb source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975880145.00000223926BB000.00000004.00000020.00020000.00000000.sdmp, ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: /LZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/TcpDaSvrWrapper.pdb source: ZPMC SCADA Setup v4.0.12737.zip
Source: Binary string: rp.pdb source: 7zG.exe, 0000000A.00000003.1972809065.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975193758.0000022392749000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1972651086.0000022392737000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: v4.0.12737/program files/ZPMC/SCADA/Bin/Extend Dll/ProfiNet/ProfiNetWrapper.pdb_k source: 7zG.exe, 0000000A.00000003.1975108571.00000223926B6000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: ZSUASV~1.PDB|zsUASvrAcs.pdbLT source: setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: l"ZSNETE~2.PDB|zsNet.ElementBase.pdb source: setup.exe, 00000012.00000003.2073363822.000000000149D000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072899743.0000000001497000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: Language.pdb% source: setup.exe, 00000012.00000003.2073527832.0000000001475000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2072971157.000000000146E000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: program files\ZPMC\SCADA\Bin\zsScada.Studio.Net.pdb3B5Byrv6F2DG8fm0vnIpBJ1G7CmgtAdoWL9GaUK5NhQ= source: SourceHash{DFC48024-1A7F-4AF4-A9BD-19E1C9DE7F55}.19.dr
Source: Binary string: ZPMC SCADA Setup v4.0.12737/program files/ZPMC/SCADA/Bin/zsUASvrAcs.pdb#o source: 7zG.exe, 0000000A.00000003.1975108571.00000223926BA000.00000004.00000020.00020000.00000000.sdmp, 7zG.exe, 0000000A.00000003.1975061029.00000223926B9000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: HQUERY~1.PDB|HQueryFacility.pdb{L source: setup.exe, 00000012.00000003.2407110679.000000000688C000.00000004.00000020.00020000.00000000.sdmp

Data Obfuscation

barindex
Source: CSAssemblyLoader.dll.10.dr, AssReflector.cs .Net Code: Load System.Reflection.Assembly.Load(byte[])
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070AA750 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress, 18_2_070AA750
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070AA720 push eax; ret 18_2_070AA74E
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10091A45 push ecx; ret 18_2_10091A58
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1008BE65 push ecx; ret 18_2_1008BE78
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\msvcm80.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\_isres_0x0409.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISRT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\DemoDotNet\Screen\Program\Rcw.ServerAPI.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\Ansi\ATL80.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIBD6.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80ENU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80ESP.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80KOR.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfcm80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\Demo\Server\AlarmServer\Program\CSProgram.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\_isuser_0x0409.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80FRA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80JPN.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfc80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80ITA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\b2rg91xw.1p4\msvcr80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\53t3z6j5.7ag\ATL80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80CHS.dll Jump to dropped file
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe File created: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\ISSetup.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\92rg91xw.1p4\msvcr80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80CHT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80FRA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfcm80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\DemoDotNet\Screen\Program\CSAssemblyLoader.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80ESP.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\msvcp80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\Demo\UC\UCDemo.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80DEU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80ENU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\msvcr80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80CHS.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80CHT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80DEU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80ESP.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80FRA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80ITA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\73t3z6j5.7ag\ATL80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\DemoDotNet\Screen\Program\CSProgram.dll Jump to dropped file
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe File created: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfc80.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISBEW64.exe Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfcm80.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIC44.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfc80u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\MSI8A92.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\MSI8A62.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80ENU.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\MSI89B5.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\b2rg91xw.1p4\msvcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfcm80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\ATL80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\92rg91xw.1p4\msvcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80JPN.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80KOR.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80ITA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80DEU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80KOR.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI1221.tmp Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe File created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\instdll.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80JPN.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfc80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\92rg91xw.1p4\msvcp80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80CHT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80CHS.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\Demo\Screen\Program\CSProgram.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe File created: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\b2rg91xw.1p4\msvcp80.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File created: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\setup.exe Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIBD6.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSI1221.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIC44.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Registry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore Jump to behavior
Source: C:\Windows\System32\SrTasks.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10041768 __EH_prolog3,LoadLibraryExW,IsIconic,ShowWindow, 18_2_10041768
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10045D87 GetModuleHandleW,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress, 18_2_10045D87
Source: C:\Windows\System32\rundll32.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100B53B0 sgdt fword ptr [ebp-08h] 18_2_100B53B0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100B53D0 sldt word ptr [ebp-08h] 18_2_100B53D0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100B5400 str word ptr [ebp-04h] 18_2_100B5400
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\_isres_0x0409.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\msvcm80.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\ISRT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\DemoDotNet\Screen\Program\Rcw.ServerAPI.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\Ansi\ATL80.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\MSIBD6.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80ESP.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80ENU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80KOR.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\Demo\Server\AlarmServer\Program\CSProgram.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfcm80u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\_isuser_0x0409.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80FRA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80JPN.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfc80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80ITA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\b2rg91xw.1p4\msvcr80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\53t3z6j5.7ag\ATL80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80CHS.dll Jump to dropped file
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\ISSetup.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80CHT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80FRA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\92rg91xw.1p4\msvcr80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfcm80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\DemoDotNet\Screen\Program\CSAssemblyLoader.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80ESP.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\msvcp80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\Demo\UC\UCDemo.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80DEU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80ENU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\msvcr80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80CHS.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80CHT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80DEU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80ESP.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80ITA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80FRA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\73t3z6j5.7ag\ATL80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\DemoDotNet\Screen\Program\CSProgram.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfc80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfcm80.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\MSIC44.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\7z1v718o.6n8\mfc80u.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI8A92.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI8A62.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80ENU.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\MSI89B5.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\b2rg91xw.1p4\msvcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfcm80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\ATL80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\92rg91xw.1p4\msvcm80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80JPN.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80KOR.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80ITA.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80DEU.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\refn04mk.ve6\mfc80KOR.dll Jump to dropped file
Source: C:\Windows\SysWOW64\msiexec.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{E696D1CF-59A2-4CC2-896D-A4083751C8A0}\instdll.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\MSI1221.tmp Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\pefn04mk.ve6\mfc80JPN.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\5z1v718o.6n8\mfc80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80u.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\92rg91xw.1p4\msvcp80.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80CHT.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\system32\mfc80CHS.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\User\Demo\Screen\Program\CSProgram.dll Jump to dropped file
Source: C:\Program Files\7-Zip\7zG.exe Dropped PE file which has not been started: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\Windows\winsxs\b2rg91xw.1p4\msvcp80.dll Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe API coverage: 4.9 %
Source: C:\Windows\System32\SrTasks.exe TID: 5076 Thread sleep time: -110000s >= -30000s
Source: C:\Windows\System32\SrTasks.exe Last function: Thread delayed
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File Volume queried: C:\Users\user\AppData\Local\Temp FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe File Volume queried: C:\Windows FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_1003C60E __EH_prolog3_GS,FindFirstFileW, 18_2_1003C60E
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100B86D3 __EH_prolog3_GS,FindFirstFileW,lstrcmpW,lstrcmpW,FindNextFileW,RemoveDirectoryW,__CxxThrowException@8,DeleteFileW, 18_2_100B86D3
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10064701 GetModuleHandleW,GetProcAddress,GetSystemInfo,GetNativeSystemInfo, 18_2_10064701
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin\Extend Dll\ProfiNet Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin\Extend Dll\View Resource Jump to behavior
Source: C:\Program Files\7-Zip\7zG.exe File opened: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\program files\ZPMC\SCADA\Bin\Extend Dll Jump to behavior
Source: SrTasks.exe, 00000022.00000003.2442781701.000002463890A000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963
Source: setup.exe, setup.exe, 00000012.00000002.2505511701.0000000010101000.00000040.00000001.01000000.0000000E.sdmp Binary or memory string: _GetVirtualMachineType
Source: setup.exe, 00000012.00000003.2391093452.0000000005A36000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0_GetVirtualMachineType
Source: SrTasks.exe, 00000022.00000003.2409334323.0000024638907000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \Device\HarddiskVolume1\??\Volume{ad6cc5d8-f1a9-4873-be33-91b2f05e9306}\??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\Device\CdRom0\??\Volume{a33c736e-61ca-11ee-8c18-806e6f6e6963}\DosDevices\D:w
Source: setup.exe, 00000012.00000003.2390078724.0000000004234000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2399754573.0000000004234000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachineWindowPowerI*
Source: setup.exe, setup.exe, 00000012.00000002.2505511701.0000000010101000.00000040.00000001.01000000.0000000E.sdmp, setup.exe, 00000012.00000002.2494402472.0000000006800000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: _IsVirtualMachine
Source: setup.exe, 00000012.00000003.2391093452.0000000005A36000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachine=%ldSu
Source: setup.exe, 00000012.00000002.2505511701.0000000010101000.00000040.00000001.01000000.0000000E.sdmp Binary or memory string: AddIconCallDLLFnComponentViewCreateWindowComponentViewDestroyComponentViewRefreshComponentViewSelectAllComponentViewSetInfoComponentViewSetInfoExCreateFolderDeleteFolderDeleteIconEnableHourGlassEnumFoldersItemsGetCPUTypeGetFontSubGetHandleGetPortsGetSelectedItemStateIsEmptyIsNTAdminIsOSTypeNTIsObjectIsPowerUserLangLoadStringMessageBeepPPathCompactPathPixelPathCrackUrlPathGetDirPathGetDrivePathGetFilePathGetFileExtPathGetFileNamePathGetLongFromShortPathGetPathPathIsValidSyntaxQueryIconReadArrayPropertyReadBoolPropertyReadNumberPropertyReplaceIconShowFolderTextSubSubstituteVerGetFileVersionWriteArrayPropertyWriteBoolPropertyWriteNumberPropertyWriteStringProperty_AppSearch_BrowseForFolder_CCPSearch_CHARArrayToWCHARArray_CalculateAndAddFileCost_CleanupInet_CloseFile_CmdGetHwndDlg_CmdGetMsg_CmdGetParam1_CmdGetParam2_CoGetObject_CompareDWORD_ComponentAddItem_ComponentCompareSizeRequired_ComponentError_ComponentErrorInfo_ComponentFileEnum_ComponentFileInfo_ComponentFilterLanguage_ComponentFilterOS_ComponentGetCost_ComponentGetCostEx_ComponentGetData_ComponentGetItemSize_ComponentGetTotalCost_ComponentGetTotalCostEx_ComponentInitialize_ComponentIsItemSelected_ComponentListItems_ComponentLoadTarget_ComponentMoveData_ComponentPatch_ComponentReinstall_ComponentRemoveAll_ComponentRemoveAllInLogOnly_ComponentSaveTarget_ComponentSelectItem_ComponentSelectNew_ComponentSetData_ComponentSetupTypeEnum_ComponentSetupTypeGetData_ComponentSetupTypeSet_ComponentTotalSize_ComponentTransferData_ComponentUpdate_ComponentValidate_ComponentViewCreate_ComponentViewQueryInfo_CopyBytes_CreateDir_CreateObject_CreateRegistrySet_CreateShellObjects_CtrlGetNotificationCode_CtrlGetParentWindowHelper_CtrlGetSubCommand_CtrlGetUrlForLinkClicked_CtrlSetHtmlContent_CtrlSetMLERichText_DIFxDriverPackageGetPath_DIFxDriverPackageInstall_DIFxDriverPackagePreinstall_DIFxDriverPackageUninstall_DefineDialog_DeleteCHARArray_DialogSetFont_DisableBranding_DisableStatus_Divide_DoInstall_DoSprintf_DotNetCoCreateObject_DotNetUnloadAppDomain_EnableDialogCache_EnablePrevDialog_EnableSkins_EnableStatus_EnableWow64FsRedirection_EndDialog_ExistsDir_ExistsDisk_ExistsFile_ExitInstall_FeatureAddCost_FeatureAddUninstallCost_FeatureGetCost_FeatureInitialize_FeatureSpendCost_FeatureSpendUninstallCost_FileCopy_FloatingPointOperation_GenerateFileMD5SignatureHex_GetByte_GetCurrentDialogName_GetDiskInfo_GetDiskSpaceEx_GetDiskSpaceExEx_GetFont_GetGlobalFlags_GetGlobalMemorySize_GetInetFileSize_GetInetFileTime_GetLine_GetLineSize_GetObject_GetObjectByIndex_GetObjectCount_GetProcessorInfo_GetRunningChildProcess_GetRunningChildProcessEx_GetRunningChildProcessEx2_GetSelectedTreeComponent_GetStandardLangId_GetSupportDir_GetSystemDpi_GetTrueTypeFontFileInfo_GetVirtualMachineType_InetEndofTransfer_InetGetLastError_InetGetNextDisk_InitInstall_IsFontTypefaceNameAvailable_IsInAdminGroup_IsLangSupported_IsSkinLoaded_IsVirtualMachine_IsWindowsME_IsWow64_KillProcesses_ListAddItem_ListAddString_ListCount_ListCreate_ListCurrentIte
Source: setup.exe, 00000012.00000003.2391093452.0000000005A36000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2390078724.0000000004234000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2399754573.0000000004234000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0bIsVirtualMachine
Source: setup.exe, 00000012.00000003.2391093452.0000000005A36000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: 0_IsVirtualMachineu
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe API call chain: ExitProcess graph end node
Source: C:\Windows\System32\msiexec.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100959E2 _memset,IsDebuggerPresent, 18_2_100959E2
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100A2FF8 RtlEncodePointer,RtlEncodePointer,LoadLibraryExW,GetLastError,LoadLibraryW,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,GetProcAddress,RtlEncodePointer,IsDebuggerPresent,OutputDebugStringW,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer,RtlDecodePointer, 18_2_100A2FF8
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070AA750 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress, 18_2_070AA750
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100522A9 mov esi, dword ptr fs:[00000030h] 18_2_100522A9
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100521D0 GetProcessHeap,RtlAllocateHeap,RtlInterlockedPopEntrySList,RtlInterlockedPopEntrySList,VirtualAlloc,RaiseException,RtlInterlockedPopEntrySList,VirtualFree,RtlInterlockedPushEntrySList, 18_2_100521D0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_10092707 SetUnhandledExceptionFilter,UnhandledExceptionFilter, 18_2_10092707
Source: C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe Process created: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe /q"C:\Users\user\Desktop\ZPMC SCADA Setup v4.0.12737\setup.exe" /tempdisk1folder"C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}" /IS_temp Jump to behavior
Source: setup.exe, 00000012.00000000.2057291118.0000000000425000.00000002.00000001.01000000.00000009.sdmp Binary or memory string: <Shell_TrayWnd0x0409
Source: setup.exe, 00000012.00000002.2511374840.000000006CA73000.00000002.00000001.01000000.0000000B.sdmp, setup.exe, 00000012.00000002.2491949919.0000000006630000.00000002.00000001.00040000.0000000B.sdmp Binary or memory string: ?OPTYPE_PROGMAN_FIELDSWWW
Source: setup.exe, 00000012.00000002.2472742914.0000000005D10000.00000004.00000800.00040000.00000012.sdmp Binary or memory string: OPTYPE_PROGMAN
Source: setup.exe, 00000012.00000003.2391093452.00000000059C0000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2468744199.00000000059EB000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMANaa>t>U
Source: setup.exe, 00000012.00000002.2468744199.00000000059E8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2391093452.00000000059C0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMANt.
Source: setup.exe, 0000000E.00000000.2048637934.00000000000D5000.00000002.00000001.01000000.00000008.sdmp Binary or memory string: Shell_TrayWnd0x0409
Source: setup.exe, 00000012.00000003.2397425178.00000000059EA000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000002.2468744199.00000000059E8000.00000004.00000020.00020000.00000000.sdmp, setup.exe, 00000012.00000003.2391093452.00000000059C0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OPTYPE_PROGMAN
Source: setup.exe, 00000012.00000002.2510020399.000000006CA06000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: lISLOG_VERSION_INFO..\..\..\Shared\LogServices2\LogDB.cppOPTYPE_PROGMANISLOGDB_USER_PROPERTIEST
Source: setup.exe.10.dr, setup.exe.18.dr Binary or memory string: AShell_TrayWnd0x0409
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_100B5450 cpuid 18_2_100B5450
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoA,IsValidCodePage,IsValidLocale, 18_2_070B0380
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: EnumSystemLocalesA, 18_2_070B0BA0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: EnumSystemLocalesA, 18_2_070B0A00
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: EnumSystemLocalesA, 18_2_070B0610
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoW,GetLocaleInfoA,GetLocaleInfoA,GetLocaleInfoW,GetLocaleInfoW,WideCharToMultiByte,WideCharToMultiByte, 18_2_070B3E50
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoA, 18_2_070B0EA0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoW,GetLocaleInfoA,GetLocaleInfoW,GetLocaleInfoA,GetLocaleInfoA,MultiByteToWideChar,MultiByteToWideChar, 18_2_070B3CB0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: _TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_TranslateName,_GetLocaleNameFromLangCountry,_GetLocaleNameFromLanguage,_GetLocaleNameFromDefault,IsValidCodePage,_wcschr,_wcschr,__itow_s,__invoke_watson,GetLocaleInfoW, 18_2_100A1A52
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: EnumSystemLocalesEx,EnumSystemLocalesW, 18_2_100A2787
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoEx,GetLocaleInfoW, 18_2_100A280D
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoW, 18_2_100A1C14
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: EnumSystemLocalesW, 18_2_100A1CC2
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: _GetPrimaryLen,EnumSystemLocalesW, 18_2_100A1D1E
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: _GetPrimaryLen,EnumSystemLocalesW, 18_2_100A1D9B
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoW,GetLocaleInfoW,__wcsnicmp,GetLocaleInfoW, 18_2_100A1E1E
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoW, 18_2_100A2011
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: _wcscmp,_wcscmp,GetLocaleInfoW,GetLocaleInfoW,GetACP, 18_2_100A2139
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: GetLocaleInfoW,_GetPrimaryLen, 18_2_100A21E6
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: _memset,_TranslateName,_TranslateName,_GetLcidFromCountry,GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,__itow_s, 18_2_100A22BA
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070B33D0 GetTimeZoneInformation,WideCharToMultiByte,WideCharToMultiByte,__malloc_dbg, 18_2_070B33D0
Source: C:\Users\user\AppData\Local\Temp\{550D56F5-BA13-447E-836D-F7C9187A59A9}\setup.exe Code function: 18_2_070A1040 GetVersion,GetCommandLineA, 18_2_070A1040
No contacted IP infos