Windows Analysis Report
TlsPatcher-1.1.1.exe

Overview

General Information

Sample name: TlsPatcher-1.1.1.exe
Analysis ID: 1545112
MD5: fdeac4be6f9e9154d54956760c3f0f58
SHA1: b706a826fbfdf577e5806927d43fb7d9138093e6
SHA256: 7a16eee0bac29b88ad46a147dcad633860e81541538d91cc0e397b5d6b5986fe
Infos:

Detection

Score: 7
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Checks for available system drives (often done to infect USB drives)
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Creates or modifies windows services
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
Modifies existing windows services
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sigma detected: Wow6432Node CurrentVersion Autorun Keys Modification
Uses 32bit PE files

Classification

Source: TlsPatcher-1.1.1.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore SRInitDone
Source: C:\Windows\System32\msiexec.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{114CA666-974E-4CC7-BE0E-45C1F713825B}
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File created: C:\Users\user\AppData\Local\Temp\TLS_Patcher_v1.1.1_20241030011659_000_LevelUp.Integrations.TlsPatcher.Installer_1.1.1_x64.msi.log
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe File created: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.ba\license.rtf
Source: TlsPatcher-1.1.1.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: C:\Windows\System32\msiexec.exe File opened: z:
Source: C:\Windows\System32\msiexec.exe File opened: x:
Source: C:\Windows\System32\msiexec.exe File opened: v:
Source: C:\Windows\System32\msiexec.exe File opened: t:
Source: C:\Windows\System32\msiexec.exe File opened: r:
Source: C:\Windows\System32\msiexec.exe File opened: p:
Source: C:\Windows\System32\msiexec.exe File opened: n:
Source: C:\Windows\System32\msiexec.exe File opened: l:
Source: C:\Windows\System32\msiexec.exe File opened: j:
Source: C:\Windows\System32\msiexec.exe File opened: h:
Source: C:\Windows\System32\msiexec.exe File opened: f:
Source: C:\Windows\System32\msiexec.exe File opened: b:
Source: C:\Windows\System32\msiexec.exe File opened: y:
Source: C:\Windows\System32\msiexec.exe File opened: w:
Source: C:\Windows\System32\msiexec.exe File opened: u:
Source: C:\Windows\System32\msiexec.exe File opened: s:
Source: C:\Windows\System32\msiexec.exe File opened: q:
Source: C:\Windows\System32\msiexec.exe File opened: o:
Source: C:\Windows\System32\msiexec.exe File opened: m:
Source: C:\Windows\System32\msiexec.exe File opened: k:
Source: C:\Windows\System32\msiexec.exe File opened: i:
Source: C:\Windows\System32\msiexec.exe File opened: g:
Source: C:\Windows\System32\msiexec.exe File opened: e:
Source: C:\Windows\System32\msiexec.exe File opened: c:
Source: C:\Windows\System32\msiexec.exe File opened: a:
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\NULL
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\66c66c.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIC7C4.tmp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\inprogressinstallinfo.ipi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\SourceHash{114CA666-974E-4CC7-BE0E-45C1F713825B}
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIC852.tmp
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\66c66f.msi
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\66c66f.msi
Source: C:\Windows\System32\msiexec.exe File deleted: C:\Windows\Installer\MSIC7C4.tmp
Source: TlsPatcher-1.1.1.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: classification engine Classification label: clean7.winEXE@10/21@0/0
Source: C:\Windows\System32\conhost.exe Mutant created: \Sessions\1\BaseNamedObjects\Local\SM0:4720:120:WilError_03
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe File created: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\
Source: TlsPatcher-1.1.1.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe File read: C:\Windows\win.ini
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe File read: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe
Source: unknown Process created: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe "C:\Users\user\Desktop\TlsPatcher-1.1.1.exe"
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Process created: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe "C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe" -burn.clean.room="C:\Users\user\Desktop\TlsPatcher-1.1.1.exe" -burn.filehandle.attached=524 -burn.filehandle.self=520
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Process created: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe "C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe" -burn.clean.room="C:\Users\user\Desktop\TlsPatcher-1.1.1.exe" -burn.filehandle.attached=524 -burn.filehandle.self=520
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Process created: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe "C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe" -q -burn.elevated BurnPipe.{567FAD9A-84D5-4F0A-B05E-A60CC1098593} {A2E813C1-ACFD-4546-839C-313841CBE496} 6316
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Process created: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe "C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe" -q -burn.elevated BurnPipe.{567FAD9A-84D5-4F0A-B05E-A60CC1098593} {A2E813C1-ACFD-4546-839C-313841CBE496} 6316
Source: unknown Process created: C:\Windows\System32\SrTasks.exe C:\Windows\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:1
Source: C:\Windows\System32\SrTasks.exe Process created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: unknown Process created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding BCEF48201EFB427ED67C871BCA995DA8
Source: C:\Windows\System32\msiexec.exe Process created: C:\Windows\SysWOW64\msiexec.exe C:\Windows\syswow64\MsiExec.exe -Embedding BCEF48201EFB427ED67C871BCA995DA8
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: cryptbase.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: msi.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: cabinet.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: msxml3.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: windows.storage.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: wldp.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: profapi.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: feclient.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: iertutil.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: msi.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: cabinet.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: msxml3.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: feclient.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: msimg32.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: windowscodecs.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: explorerframe.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: riched20.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: usp10.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: msls31.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: textshaping.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: propsys.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: edputil.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: windows.staterepositoryps.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: appresolver.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: bcp47langs.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: slc.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: sppc.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: onecorecommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Section loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: cryptbase.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: msi.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: cabinet.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: msxml3.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: windows.storage.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: wldp.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: profapi.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: textinputframework.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: coreuicomponents.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: coremessaging.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: ntmarta.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: wintypes.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: srclient.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: spp.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: powrprof.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: vssapi.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: vsstrace.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: umpdc.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: usoapi.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: sxproxy.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: cryptsp.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: rsaenh.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: feclient.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: srpapi.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: tsappcmp.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: netapi32.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: wkscli.dll
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Section loaded: netutils.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: spp.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srclient.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: srcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vssapi.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ktmw32.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vsstrace.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: wer.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: bcd.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: powrprof.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: umpdc.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: ntmarta.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: dsrole.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: msxml3.dll
Source: C:\Windows\System32\SrTasks.exe Section loaded: vss_ps.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: tsappcmp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: userenv.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: profapi.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: sspicli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netapi32.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wkscli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: netutils.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: wldp.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mscoree.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: version.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: vcruntime140_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ucrtbase_clr0400.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: rstrtmgr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ncrypt.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntasn1.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: windows.storage.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: pcacli.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\System32\msiexec.exe Section loaded: ntmarta.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: apphelp.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: aclayers.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: mpr.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: msi.dll
Source: C:\Windows\SysWOW64\msiexec.exe Section loaded: version.dll
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32
Source: C:\Windows\System32\msiexec.exe Registry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{114CA666-974E-4CC7-BE0E-45C1F713825B}
Source: TlsPatcher-1.1.1.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: TlsPatcher-1.1.1.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: TlsPatcher-1.1.1.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: TlsPatcher-1.1.1.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: TlsPatcher-1.1.1.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: TlsPatcher-1.1.1.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: TlsPatcher-1.1.1.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: TlsPatcher-1.1.1.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: TlsPatcher-1.1.1.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: TlsPatcher-1.1.1.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: TlsPatcher-1.1.1.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: TlsPatcher-1.1.1.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: TlsPatcher-1.1.1.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: TlsPatcher-1.1.1.exe Static PE information: section name: .wixburn
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe File created: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe File created: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.ba\wixstdba.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIC7C4.tmp Jump to dropped file
Source: C:\Windows\System32\msiexec.exe File created: C:\Windows\Installer\MSIC7C4.tmp Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File created: C:\Users\user\AppData\Local\Temp\TLS_Patcher_v1.1.1_20241030011659_000_LevelUp.Integrations.TlsPatcher.Installer_1.1.1_x64.msi.log
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe File created: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.ba\license.rtf
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Registry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SystemRestore
Source: C:\Windows\System32\SrTasks.exe Registry key value modified: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {fe0fc20b-fc4f-4233-98e4-e30940c5703c}
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {fe0fc20b-fc4f-4233-98e4-e30940c5703c}
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {fe0fc20b-fc4f-4233-98e4-e30940c5703c}
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Registry value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce {fe0fc20b-fc4f-4233-98e4-e30940c5703c}
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exe Process information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.ba\wixstdba.dll Jump to dropped file
Source: C:\Windows\System32\msiexec.exe Dropped PE file which has not been started: C:\Windows\Installer\MSIC7C4.tmp Jump to dropped file
Source: C:\Windows\System32\SrTasks.exe TID: 5080 Thread sleep time: -300000s >= -30000s
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File Volume queried: C:\Windows FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exe File Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\NULL
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\vcRuntimeAdditional_amd64
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\NULL
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe File opened: C:\ProgramData\Package Cache\{0025DD72-A959-45B5-A0A3-7EFEB15A8050}v14.36.32532\packages\NULL
Source: C:\Windows\System32\msiexec.exe Process information queried: ProcessInformation
Source: C:\Users\user\Desktop\TlsPatcher-1.1.1.exe Process created: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe "C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe" -burn.clean.room="C:\Users\user\Desktop\TlsPatcher-1.1.1.exe" -burn.filehandle.attached=524 -burn.filehandle.self=520
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Process created: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe "C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe" -q -burn.elevated BurnPipe.{567FAD9A-84D5-4F0A-B05E-A60CC1098593} {A2E813C1-ACFD-4546-839C-313841CBE496} 6316
Source: C:\Users\user\AppData\Local\Temp\{7237ACD7-6703-4D28-844D-D93F0C6C709E}\.cr\TlsPatcher-1.1.1.exe Queries volume information: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.ba\logo.png VolumeInformation
Source: C:\Windows\System32\msiexec.exe Queries volume information: C:\ VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\{65096706-3665-413A-A3D6-FEF50A7ACF69}\.be\LevelUp.Integrations.TlsPatcher.Bootstrapper.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
⊘No contacted IP infos