Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
h32trial.exe

Overview

General Information

Sample name:h32trial.exe
Analysis ID:1416967
MD5:eb2bf9d3d51f4f4c866933a0a7938be4
SHA1:faf78b4e641a8d583d565556ac189cf7af2f796d
SHA256:5bf7ae786d283912cb409fc5c580e1db95ab067eb0ccfbc1aee4ae4cfe6ef866
Infos:

Detection

Score:52
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for dropped file
Sigma detected: Potential Persistence Via App Paths Default Property
Creates a process in suspended mode (likely to inject code)
Creates files inside the system directory
Deletes files inside the Windows folder
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
Queries the volume information (name, serial number etc) of a device
Registers a DLL
Sigma detected: Use Short Name Path in Command Line
Stores files to the Windows start menu directory
Stores large binary data to the registry
Tries to load missing DLLs
Uses 32bit PE files

Classification

  • System is w10x64_ra
  • h32trial.exe (PID: 1796 cmdline: "C:\Users\user\Desktop\h32trial.exe" MD5: EB2BF9D3D51F4F4C866933A0A7938BE4)
    • vsetupt.exe (PID: 6632 cmdline: "C:\Users\user\AppData\Local\Temp\vsetupt.exe" MD5: 34598094678D948F35B37A3C42D6D43C)
    • GLJ7B5F.tmp (PID: 6676 cmdline: "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\olepro32.dll MD5: 6F608D264503796BEBD7CD66B687BE92)
    • GLJ7B5F.tmp (PID: 6688 cmdline: "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\oleaut32.dll MD5: 6F608D264503796BEBD7CD66B687BE92)
    • GLJ7B5F.tmp (PID: 6700 cmdline: "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\VSPELL32.OCX MD5: 6F608D264503796BEBD7CD66B687BE92)
    • GLJ7B5F.tmp (PID: 6720 cmdline: "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\mfc42.dll MD5: 6F608D264503796BEBD7CD66B687BE92)
    • regsvr32.exe (PID: 6772 cmdline: "C:\Windows\System32\regsvr32.exe" /s vbscript.dll MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
    • regsvr32.exe (PID: 6796 cmdline: "C:\Windows\System32\regsvr32.exe" /s jscript.dll MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
    • regsvr32.exe (PID: 6824 cmdline: "C:\Windows\System32\regsvr32.exe" /s vspell32.ocx MD5: 878E47C8656E53AE8A8A21E927C6F7E0)
    • HAWIN32.EXE (PID: 6860 cmdline: "C:\PROGRA~2\HAWin32\HAWIN32.EXE" MD5: 67663D098D4D26AD3CEF9D61691C6920)
  • HAWIN32.EXE (PID: 1360 cmdline: "C:\Program Files (x86)\HAWin32\HAWIN32.EXE" MD5: 67663D098D4D26AD3CEF9D61691C6920)
  • cleanup
No yara matches

System Summary

barindex
Source: Registry Key setAuthor: Nasreddine Bencherchali (Nextron Systems): Data: Details: C:\Program Files (x86)\HAWin32\hadll32.dll, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\h32trial.exe, ProcessId: 1796, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\HAWin32.exe\HaIcons\(Default)
Source: Process startedAuthor: frack113, Nasreddine Bencherchali: Data: Command: "C:\PROGRA~2\HAWin32\HAWIN32.EXE" , CommandLine: "C:\PROGRA~2\HAWin32\HAWIN32.EXE" , CommandLine|base64offset|contains: , Image: C:\Program Files (x86)\HAWin32\HAWIN32.EXE, NewProcessName: C:\Program Files (x86)\HAWin32\HAWIN32.EXE, OriginalFileName: C:\Program Files (x86)\HAWin32\HAWIN32.EXE, ParentCommandLine: "C:\Users\user\Desktop\h32trial.exe", ParentImage: C:\Users\user\Desktop\h32trial.exe, ParentProcessId: 1796, ParentProcessName: h32trial.exe, ProcessCommandLine: "C:\PROGRA~2\HAWin32\HAWIN32.EXE" , ProcessId: 6860, ProcessName: HAWIN32.EXE
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXE (copy)Virustotal: Detection: 11%Perma Link
Source: C:\Program Files (x86)\HAWin32\~GLH001b.TMPVirustotal: Detection: 10%Perma Link
Source: h32trial.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\My Files\INSTALL.LOG
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\Temp\GLF873A.tmp
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\Temp\~GLH0000.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\GLBSINST.%$D
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\~GLH0011.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\~GLH0012.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\~GLH0013.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH005f.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0060.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0061.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0069.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006a.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006c.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006e.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0070.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0071.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0072.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0074.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0075.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0079.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007b.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007c.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007d.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007e.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007f.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0080.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\temp.000
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\PreviewSoft
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\PreviewSoft\HyperACCESS_8.4_6C2D.lic
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\PreviewSoft\HyperACCESS_8.4_6C2D.prf
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxb410.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxt410.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxp410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEFile created: C:\Windows\SysWOW64\ws811164.ocx
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEFile created: C:\Windows\HAWIN32.INI
Source: C:\Users\user\Desktop\h32trial.exeFile deleted: C:\Windows\Fonts\GLBSINST.%$D
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: apphelp.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: acgenral.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: uxtheme.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: winmm.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: samcli.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: msacm32.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: version.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: userenv.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: dwmapi.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: urlmon.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: mpr.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: sspicli.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: winmmbase.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: winmmbase.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: iertutil.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: srvcli.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: netutils.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: aclayers.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: sfc.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: sfc_os.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: kernel.appcore.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: textinputframework.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: coreuicomponents.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: coremessaging.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: ntmarta.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: wintypes.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: textshaping.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: riched32.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: riched20.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: usp10.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: msls31.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: windows.storage.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: wldp.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: propsys.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: profapi.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: edputil.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: windows.staterepositoryps.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: appresolver.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: bcp47langs.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: slc.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: sppc.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: onecorecommonproxystub.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: onecoreuapcommonproxystub.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: pcacli.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: cabinet.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: linkinfo.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: ntshrui.dll
Source: C:\Users\user\Desktop\h32trial.exeSection loaded: cscapi.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeSection loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: olepro32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: vspell32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: mfcans32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: oc30.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: msvcrt20.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: oc30loc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: oc30zzz.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: oc30zz.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: apphelp.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: acgenral.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: uxtheme.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmm.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: samcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: msacm32.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: version.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: userenv.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: dwmapi.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: urlmon.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: mpr.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sspicli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: winmmbase.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: iertutil.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: srvcli.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: netutils.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: aclayers.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: sfc_os.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: rtvideo.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: kernel.appcore.dll
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpSection loaded: mfc42.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: vbscript.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: jscript.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: iertutil.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: apphelp.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: aclayers.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mpr.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: sfc_os.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: kernel.appcore.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: uxtheme.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: vspell32.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mfcans32.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: oc30.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: msvcrt20.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: mfcans32.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: oc30loc.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: oc30zzz.dll
Source: C:\Windows\SysWOW64\regsvr32.exeSection loaded: oc30zz.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: apphelp.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: acgenral.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: uxtheme.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: winmm.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: samcli.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: msacm32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: version.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: userenv.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: dwmapi.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: urlmon.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: mpr.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: sspicli.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: winmmbase.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: winmmbase.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: iertutil.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: srvcli.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: netutils.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: aclayers.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: sfc.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: sfc_os.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: vboxp410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: vboxb410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: hadll32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: msvcp60.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: mfc42.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: msvcp60.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: mfc42.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: vboxt410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wsock32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: mmdevapi.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: devobj.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: ksuser.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: avrt.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: audioses.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: powrprof.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: umpdc.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: midimap.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: resourcepolicyclient.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: textinputframework.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: coremessaging.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: ntmarta.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: textshaping.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: vboxp410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: vboxb410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: hadll32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: msvcp60.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: mfc42.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: winmm.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: version.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: vboxt410.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wsock32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: winmmbase.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: mmdevapi.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: devobj.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: ksuser.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: kernel.appcore.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: avrt.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: audioses.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: powrprof.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: umpdc.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: msacm32.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: midimap.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: resourcepolicyclient.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: uxtheme.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: textinputframework.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: coreuicomponents.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: coremessaging.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: ntmarta.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: wintypes.dll
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXESection loaded: textshaping.dll
Source: h32trial.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP
Source: classification engineClassification label: mal52.winEXE@20/126@0/0
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\c:/windows/previewsoft/hyperaccess_8.4_6c2d.prf
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\c:/windows/previewsoft/hyperaccess_8.4_6c2d.lic
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: NULL
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\software/classes/.drv/{d9e97102-346b-f906-a026-d15fd6b0f870}
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\c:/windows/system32/ws811164.ocx
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\c:/os985612.bin
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\23fU4oq5ctI507Wg
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\clsid/{181c4948-d1f3-d43f-d06a-c59969205125}
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEMutant created: \Sessions\1\BaseNamedObjects\mHWDTtNqqVWdr-Dv
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Local\Temp\GLC7B3F.tmp
Source: h32trial.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\h32trial.exeFile read: C:\Users\user\Desktop\desktop.ini
Source: C:\Users\user\Desktop\h32trial.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\h32trial.exeFile read: C:\Users\user\Desktop\h32trial.exe
Source: unknownProcess created: C:\Users\user\Desktop\h32trial.exe "C:\Users\user\Desktop\h32trial.exe"
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\vsetupt.exe "C:\Users\user\AppData\Local\Temp\vsetupt.exe"
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\olepro32.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\oleaut32.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\VSPELL32.OCX
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\mfc42.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s jscript.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vspell32.ocx
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Program Files (x86)\HAWin32\HAWIN32.EXE "C:\PROGRA~2\HAWin32\HAWIN32.EXE"
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\vsetupt.exe "C:\Users\user\AppData\Local\Temp\vsetupt.exe"
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\olepro32.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\oleaut32.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\VSPELL32.OCX
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp "C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp" C:\Windows\System32\mfc42.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s jscript.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vspell32.ocx
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Program Files (x86)\HAWin32\HAWIN32.EXE "C:\PROGRA~2\HAWin32\HAWIN32.EXE"
Source: unknownProcess created: C:\Program Files (x86)\HAWin32\HAWIN32.EXE "C:\Program Files (x86)\HAWin32\HAWIN32.EXE"
Source: C:\Users\user\Desktop\h32trial.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEWindow found: window name: SysTabControl32
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Windows\SysWOW64\RICHED32.DLL
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: h32trial.exeStatic file information: File size 8039501 > 1048576
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0071.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0055.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH000e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0038.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0080.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0004.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007b.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Local\Temp\~GLH0005.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\My Files\~GLH0001.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0054.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH001d.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH003a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\~GLH0011.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH005f.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0061.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\~GLH0012.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0020.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\temp.000Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH002c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0046.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Local\Temp\GLM7D54.tmpJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0060.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0036.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0082.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH004a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0069.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0006.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007d.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH002e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0048.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0072.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0052.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0040.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0022.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH001b.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Local\Temp\GLC7B3F.tmpJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0042.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0050.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH004c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0008.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH003e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007f.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0034.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH000a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0024.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0075.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0074.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0007.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0028.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH004e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\My Files\~GLH0002.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH000b.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH003c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0032.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0030.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Local\Temp\~GLH0000.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH000c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0026.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH000d.TMPJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxb410.dllJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH002a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0009.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\~GLH0044.TMPJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxp410.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxt410.dllJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0071.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0060.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007f.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0080.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0069.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007b.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007d.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0072.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH006e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\~GLH0011.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0075.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH005f.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0061.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH0074.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\Fonts\~GLH0012.TMPJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxb410.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxp410.dllJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Windows\SysWOW64\~GLH007e.TMPJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeFile created: C:\Windows\SysWOW64\vboxt410.dllJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\temp.000Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Program Files (x86)\HAWin32\My Files\INSTALL.LOG
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS\Uninstall.lnk
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Folder.lnk
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS.lnk
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Host.lnk
Source: C:\Users\user\Desktop\h32trial.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HyperACCESS\HyperACCESS Graphics Viewer.lnk
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Hilgraeve\HAWin32\8.0 ConnectionKeys2
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\vsetupt.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: NOALIGNMENTFAULTEXCEPT | NOGPFAULTERRORBOX | NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\SysWOW64\regsvr32.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeProcess information set: FAILCRITICALERRORS | NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0071.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0055.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0038.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0080.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH006c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007b.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmpJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\My Files\~GLH0001.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0054.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH001d.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH003a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH006e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\Fonts\~GLH0011.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH005f.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0061.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\Fonts\~GLH0012.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0020.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0046.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH002c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\temp.000Jump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH006a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLM7D54.tmpJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0060.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0036.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0082.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH004a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0069.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0006.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007d.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0048.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH002e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0072.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0052.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0040.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0022.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH001b.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\GLC7B3F.tmpJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0042.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0050.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH004c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0008.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH007f.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH003e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0034.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0024.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0075.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Windows\SysWOW64\~GLH0074.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0007.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0028.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH004e.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\My Files\~GLH0002.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000b.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH003c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0032.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0030.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\~GLH0000.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0026.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000c.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH000d.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH002a.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0044.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeDropped PE file which has not been started: C:\Program Files (x86)\HAWin32\~GLH0009.TMPJump to dropped file
Source: C:\Users\user\Desktop\h32trial.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\Temp\GLF873A.tmp
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\Temp\~GLH0000.TMP
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\
Source: C:\Users\user\Desktop\h32trial.exeFile opened: C:\Users\user\AppData\Local\Temp\
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Users\user\AppData\Local\Temp\vsetupt.exe "C:\Users\user\AppData\Local\Temp\vsetupt.exe"
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vbscript.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s jscript.dll
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Windows\SysWOW64\regsvr32.exe "C:\Windows\System32\regsvr32.exe" /s vspell32.ocx
Source: C:\Users\user\Desktop\h32trial.exeProcess created: C:\Program Files (x86)\HAWin32\HAWIN32.EXE "C:\PROGRA~2\HAWin32\HAWIN32.EXE"
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Users\user\Desktop\h32trial.exeQueries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEQueries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEQueries volume information: C:\ VolumeInformation
Source: C:\Program Files (x86)\HAWin32\HAWIN32.EXEQueries volume information: C:\ VolumeInformation
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
DLL Side-Loading
11
Process Injection
1
Regsvr32
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
Registry Run Keys / Startup Folder
1
DLL Side-Loading
32
Masquerading
LSASS Memory2
File and Directory Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
Registry Run Keys / Startup Folder
1
Modify Registry
Security Account Manager12
System Information Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
Process Injection
NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
File Deletion
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
h32trial.exe2%ReversingLabs
h32trial.exe2%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\GLC7B3F.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\GLC7B3F.tmp0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\GLF873A.tmp (copy)0%ReversingLabs
C:\Users\user\AppData\Local\Temp\GLF873A.tmp (copy)1%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\GLJ7B5F.tmp0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\GLM7D54.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\GLM7D54.tmp1%VirustotalBrowse
C:\PROGRA~2\HAWin32\~GLH001c.TMP (copy)0%ReversingLabs
C:\PROGRA~2\HAWin32\~GLH001c.TMP (copy)3%VirustotalBrowse
C:\Program Files (x86)\HAWin32\HADLL32.DLL (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\HADLL32.DLL (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\HANCSOCK.DLL (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\HANCSOCK.DLL (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\HANXDRCT.DLL (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\HANXDRCT.DLL (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\HANXSOCK.DLL (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\HANXSOCK.DLL (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\HAWIN32.EXE (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\HAWIN32.EXE (copy)11%VirustotalBrowse
C:\Program Files (x86)\HAWin32\LFKODAK.DLL (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\LFKODAK.DLL (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\My Files\UNINSTAL.EXE (copy)5%ReversingLabs
C:\Program Files (x86)\HAWin32\My Files\UNINSTAL.EXE (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\My Files\UNWISE32.EXE (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\My Files\UNWISE32.EXE (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\RESETREG.EXE (copy)0%ReversingLabs
C:\Program Files (x86)\HAWin32\RESETREG.EXE (copy)4%VirustotalBrowse
C:\Program Files (x86)\HAWin32\register.exe (copy)4%ReversingLabs
C:\Program Files (x86)\HAWin32\register.exe (copy)0%VirustotalBrowse
C:\Program Files (x86)\HAWin32\~GLH001b.TMP0%ReversingLabs
C:\Program Files (x86)\HAWin32\~GLH001b.TMP10%VirustotalBrowse
C:\Program Files (x86)\HAWin32\~GLH001d.TMP0%ReversingLabs
C:\Program Files (x86)\HAWin32\~GLH001d.TMP1%VirustotalBrowse
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1416967
Start date and time:2024-03-28 11:17:24 +01:00
Joe Sandbox product:CloudBasic
Overall analysis duration:
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:defaultwindowsinteractivecookbook.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:25
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
Analysis Mode:stream
Analysis stop reason:Timeout
Sample name:h32trial.exe
Detection:MAL
Classification:mal52.winEXE@20/126@0/0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Exclude process from analysis (whitelisted): dllhost.exe
  • Excluded domains from analysis (whitelisted): fs.microsoft.com, slscr.update.microsoft.com, fe3cr.delivery.mp.microsoft.com
  • Not all processes where analyzed, report is missing behavior information
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 3%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:49BBAF1C63A0EB054AC7003FC7B50C7F
SHA1:2F70F87FAA17DE4742B5D39EC3702DD1A4687085
SHA-256:BC74DA8691FEF36D32756F91C02C54A69C3596FD4901DB585B78A1B674058CFB
SHA-512:8FEB114452C521C946F5728779D50B02A38AE8539AB6ABB30970DD332E71A2539F3EAE480F1FD508DB5CA5F6E51DBCD8BC1B23A1DDEE9297A4944C7C7EA5C7A1
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$........+...J.E.J.E.J.E.h.E.J.E.V.E.J.E.U.E.J.E.h.E.J.E0V.E.J.E.h.E.J.E.h.E.J.E.l.E.J.E[U.E.J.E[U.E.J.E.J.E.O.E.U.E.J.E.J.E.J.EtL.E.J.E.l.E.J.E.l.E.K.ELj.E.J.ERich.J.E........................PE..L..../.X...........!.........p......#........................................P......u...............................p!.........,....`...Y......................T2..............................................0....................................text............................... ..`.rdata..\...........................@..@.data...H...........................@....rsrc....Y...`...`...P..............@..@.reloc.............................@..BB..L....+.[J....n.[J....8.yM...."..N...../.V....5..W....+.$X....cW.X....-..L.......W.....P.W.....:U...../.V.......W ...........WINMM.dll.VERSION.dll.MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:AE2AAD74B42EABE69A096EFDA6C1AEE5
SHA1:56A7944BA1F78D9DAC790D295542DB6C2AC8F42B
SHA-256:795B8847C8F65DF5ACF8E8D8464EA47D61D2CBC33875927834AC1972A2E8ACC3
SHA-512:AAFBEEE2E0C83DF6682334C93DF11D3D84C46DEDD3EDC2E6F9E3B299E90FE83B01B857126662AD7059D1111A5170E9CA8453A43F27DC152422C664A6F495F95C
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........;d.Z...Z...Z..=E...Z...F...Z...x...Z...x...Z...x...Z...|...Z...Z..*Z...|...Z..F\...Z..~z...Z..Rich.Z..........PE..L..../.X...........!.....0...P......c........@.......................................[...............................R.......M.......p..........................h....................................................@...............................text.... .......0.................. ..`.rdata.......@... ...@..............@..@.data...4....`.......`..............@....rsrc........p.......p..............@..@.reloc..............................@..B./.X8...8.yMD..."..NN..../.VY...+.$Xf...c.[Jq...........HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.WSOCK32.dll............................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:033678DB8A7927E496098C5DEE71CF8C
SHA1:88AE01DD2EAB51F525ACE145FBEFB4939AD7F947
SHA-256:D1301D2FEC57A3C8B7D57DEBA0245C6C431B6056D239A042A31E62FFE81FDB02
SHA-512:FFBD40EEA9AB35504C01818E91D86744AB0337979CBAA38D51A1F2EC61611AF315D2634FB970F297D50244856926F7BBA926A06855D9CD787B94BBB0DC66B552
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............iv..iv..iv..uz..iv.Wve..iv..K}..iv.hux..iv..K|..iv..Kr..iv..Or..iv..iw..hv..O}..iv.,op..iv..O|..iv..Ir..iv.Rich.iv.................PE..L..../.X...........!................*........ .......................................z............................................................................................................................... ...............................text............................... ..`.rdata..m.... ....... ..............@..@.data............0..................@....rsrc................@..............@..@.reloc..&!.......0...P..............@..B./.XH...8.yMT..."..N^..../.Vi...5..Wv...+.$X.......W.....:U............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.ADVAPI32.dll.COMCTL32.dll............................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:2D2C9726B4868CDC157F01347C6B3B20
SHA1:3BDC9E6123BCE8728B41178BD31A6876CAA82C5E
SHA-256:2D3CAE13817A5E16F78203D7344AB4D136A854BDFAF590ED5DDF7D09E443EAC8
SHA-512:FCBD6B827289A8A2CD41C312BB00C8F3F56A9CE01338C84D25716C1088CDF142DED7A8B91DC6AED5BB772AB7F14466C2ABD74F9BEC34E1502D0C7228C241D0BC
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................}.....B....................................................>......Rich...........................PE..L..../.X...........!.....0...P......Y7.......@......................................qO...............................U.......O..x....p..X.......................................................................|....@...............................text....).......0.................. ..`.rdata.......@... ...@..............@..@.data........`.......`..............@....rsrc...X....p.......p..............@..@.reloc..x...........................@..B./.X8...8.yMD..."..NN..../.VY...5..Wf...+.$Xp...........HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll..............................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:03BC07B4FE4161219B3300AB9D468B93
SHA1:670F9C3D9BD2E58B7649DC5C55DC2E5CB28EEA1D
SHA-256:CDF90A9D56BAAFE6E7CEA84BBC89A8F06899593FF6FE1C476296DC99EE2897E2
SHA-512:F40DD3D79F123026F4F5E5CC3727ABAB000B3A30275313829D9194F8281A1A147D08D2171C22D5C71CD7B47EDE335024F088DF9CAEEB0948EA16766D6EAAA496
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........A...A...A.......I......C.......@.......D.......C...w...C.......@.......C...A...@...A...........@...w...J.......E...RichA...........................PE..L..../.X...........!.....0...`......f3.......@......................................WQ...............................^......pW..........X.......................p....................................................@...............................text....'.......0.................. ..`.rdata...%...@...0...@..............@..@.data........p.......p..............@....rsrc...X...........................@..@.reloc..(...........................@..B./.XH...n.[JT...8.yM`..."..Nj..../.Vu...+.$X....cW.X.......W............HADLL32.dll.MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.GDI32.dll.ADVAPI32.dll.............................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:D2164F35F81529FADFDA1ABAAB43424A
SHA1:EA9231E0815C878480BCB71A80F8EA862DB0742B
SHA-256:15BC75036BC322FE5CC6EA4E53AA8238D50FE5E35F672696F2A047C608205FCC
SHA-512:86439EFDEF414C7194156BF869ECEE043B9CB745C2A7109B4729EA0433A18F1960A406327608E7A95DC8020EDAC3284A62DEE549FE62F486AEA01A9A6FE8B860
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........5..tf..tf..tf..xf..tfE.gf..tfz.zf..tf...f..tf..~f..tf..pf..tf..pf..tf..tf..tf..ufN.tf>.rf..tf...f..tf..pf..tfRich..tf........PE..L..../.X...........!.....0..........&7.......@......................................................................@c.......]..........."...........................................................................@...............................text....+.......0.................. ..`.rdata..]+...@...0...@..............@..@.data...t....p.......p..............@....rsrc....".......0..................@..@.reloc..............................@..B./.X@...8.yML..."..NV..../.Va...+.$Xn......Wy...c.[J............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.ADVAPI32.dll.WSOCK32.dll.......................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:59C3D89D99C2B34C4F96C6AA5BB8C3DC
SHA1:E0434F53664EB55F65EAEBF94D7AE837C8548374
SHA-256:C489B615D86E7B451C94A72AA3994EE91A8B81B8E4A9E72DE10765E9E42484D5
SHA-512:C19DB6BD6D047B193078E5E12EFDB6E04C2CEE06069A4C374452B77F8A726660CDE3442BB548FDE9846DE3F6B0BD7905F189C4DFF9082C65793C11AD73F5C643
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........5..f..f..f...f...fM..f...f...f...fr..f..f...f...f...f..f..f..f..f...f..f0..f6..f...f..f...f..f...f...f...fRich..f........................PE..L..../.X...........!.....0..........:7.......@.......................................................................c.......^..........."...........................................................................@...............................text....,.......0.................. ..`.rdata...+...@...0...@..............@..@.data........p.......p..............@....rsrc....".......0..................@..@.reloc..............................@..B./.X@...8.yML..."..NV..../.Va...+.$Xn......Wy...c.[J............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.ADVAPI32.dll.WSOCK32.dll...............................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:5C2E0559DC4D059ED50C55096ED94F76
SHA1:34865CD2AB40B0592694E7E839927A41F2586B1B
SHA-256:7683AB7239CCAE3C20164D8979944EC65365B7BF8B6D8C3E747F1C02B343BA7B
SHA-512:71F9FDF51EB9665DC91C5302AD2B07C0970C85EAAD2085891F23A7B79D4F22C2DCF445E90C1AFB3D79171D574720D68D0DD01CF9E4261ABE1B14286CA91CD84D
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Mk..,..,..,..03..,...0..,......,......,......,.....,..,..,..,..q,..K*..,.....,..s...,..Rich.,..........PE..L..../.X...........!.....p...P.......p..................................................................................|...`........................................................................................................................text...*g.......p.................. ..`.rdata...=.......@..................@..@.data...............................@....rsrc...............................@..@.reloc........... ..................@..B./.X@...8.yML..."..NV..../.Va...+.$Xn...cW.Xy......W............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.GDI32.dll.ADVAPI32.dll.................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:67663D098D4D26AD3CEF9D61691C6920
SHA1:6F34E686F44F8EDF3909A5727E5DADF03AFF0B5C
SHA-256:A74C3E9D5059ABF97535DD436A09D934DA64D7C71F79347FA16646BC42347DBE
SHA-512:ECF32D007BB8CD2785EE0AF036763F080E7D45C58B05AAE32DF74E48453727E155E265EF51615AC2E59BBDADB38DBBAD70C6A16CCE96A9A9952ABF8A9BB2CBE8
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 11%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........d.d...7...7...7}..7...7.'.7...7B..7...7.'.7...7.'.7...7.$.7...7.$.7...7)..7...7)..7...7...7...7>%.7...7.'.7...7...7...7Rich...7................PE..L...qp4A................p`.. m....................@..........................@......!.......................................`........0..............................................................................................................PREVIEW.D........................... ...WeijunLip`......p`..................`....rsrc........0......................@...........................................................................................................................MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll....................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:D15F6405F5F774C4179C935F36DB533B
SHA1:0DD1B1233CFC327E16F5FA7DF10240989A4C34B9
SHA-256:EFA707570BAD130F607449EB799E469FCFACAF78937314851AF7BF24F46A4E32
SHA-512:F9606C033FD942BFEFD03FE2979607CAA5604397CDE3EA06F9392165D05D10A26E4352A33AE42682AC6BFD2C3A555E66C0E85B3BB00EEBBA8CFA6958179DE7CE
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A.G2...........!.........X...............0....................................................... ...............0..........(....................................................................................................................text............................... ..`.rdata.......0......................@..@.data....A...@...0...$..............@....idata...............T..............@....reloc...............Z..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:81CB567C03C3A600528259255B217430
SHA1:CAB178749B294DA06EF1C011B95B25545EFAB976
SHA-256:0216D60C16EE15EA3C1229D5091D29B36A09DCF382D4AA9E4D245DD4CBDEF8E7
SHA-512:EDDD34F7375A48071E99B2F0992CC3F87558957342C5BA018BB141F18D40C41F1530DB2548C4831584CB0A63C02BBDCDB041ACD39CDF6D3CF65CBEE953623691
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:EA66574F89A4AB807C4F5D92CC876A77
SHA1:A4B9A0C975BB087FAC3A10218F8974B58CCAE038
SHA-256:4D8EFA7636A007957913A6D643DA3B621C6D37B84126FCCBE7DA143E356B8BB3
SHA-512:6DE6BD94CED918AB7A6123F20774F8D7E1795DD6B8F7C6D6987A11B89CCC9A28F4A5CD531B8A1291D1EDE2C9C08E045160C871B57D6CAA8BF4B11995BC9EFA70
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:36 2024, mtime=Thu Mar 28 09:18:36 2024, atime=Fri Jan 20 08:38:58 2017, length=126976, window=hide
Category:dropped
Size (bytes):940
Entropy (8bit):4.68705348358136
Encrypted:false
SSDEEP:
MD5:A544F15795514A0216ECF891FBBF0FE6
SHA1:3740B447A58519122C9B263812FB3F4942263BBE
SHA-256:2C7CF7237B97F61E4D227A13137CE3E0F62FBDCF15F138630FE4E0474D168A88
SHA-512:06CEFC58EC4A3BC89037B67000F08CDF72A8E9A9EB2927BD4B31C2DC2FA7134111D47004F4D7CFCEDC5D67FC94AD8283D78FB2DC12DB57E99BADA39139374142
Malicious:false
Reputation:unknown
Preview:L..................F.... ...Y$gK......mK.....%...s...............................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....b.2.....4J.L .convert.exe.H......|XSR|XSR..............................c.o.n.v.e.r.t...e.x.e.......Y...............-.......X...........@.]......C:\Program Files (x86)\HAWin32\convert.exe........\.....\.c.o.n.v.e.r.t...e.x.e.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:35 2024, atime=Fri Jan 20 08:38:58 2017, length=57344, window=hide
Category:dropped
Size (bytes):923
Entropy (8bit):4.67220093162392
Encrypted:false
SSDEEP:
MD5:06F9FD60563DD4700D7946CF463B4DA4
SHA1:5B3DC025CA84DBC323F20BF0664D05D474AF6B84
SHA-256:477114E64200167A7AD7F73F98E030C5B123EC8A4B2288BFCB7CCCB76DF8AC87
SHA-512:D93AA86FF0A18A3C6730A1202AF007B877E8E7B4694B048AC5477B673349BAE21E47CAF5C917619837F4E7E89A070C6EB68F0CE6A5F9ACF2EDE7BF5A3AAAF1E9
Malicious:false
Reputation:unknown
Preview:L..................F.... ...$3.K....O..K.....%...s..........................w....P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....Z.2.....4J.L .hagv.exe..B......|XRR|XRR..............................h.a.g.v...e.x.e.......V...............-.......U...........@.]......C:\Program Files (x86)\HAWin32\hagv.exe........\.....\.h.a.g.v...e.x.e.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Has Relative path, Has command line arguments, ctime=Sun Dec 31 23:06:32 1600, mtime=Sun Dec 31 23:06:32 1600, atime=Sun Dec 31 23:06:32 1600, length=0, window=hide
Category:dropped
Size (bytes):354
Entropy (8bit):2.795948730886399
Encrypted:false
SSDEEP:
MD5:00B10BB0387D41E3E319172DB9EBC8F2
SHA1:C97544A3BC544D14B8AD53558489B492ECAA90B8
SHA-256:F8AE11EFD9230E07292DBEAD7EE55B56DB5C72ED17C1F339E253C188F01870B1
SHA-512:831B16B5A00C8E49547C866B0043716947E031590831CE4883D85F0451008CEC05EACA9CA4CF39A4BA0C57E647C58BFCEC3144DBA2516C27D0E690C641E943B1
Malicious:false
Reputation:unknown
Preview:L..................F........................................................d.b.2...........WINHELP.EXE.H............................................W.I.N.H.E.L.P...E.X.E.......*.....\.....\.....\.....\.U.s.e.r.s.\.c.a.l.i.\.D.e.s.k.t.o.p.\.W.I.N.H.E.L.P...E.X.E.*.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.h.a.w.i.n.3.2...H.L.P.....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:35 2024, atime=Sat Jul 31 06:35:00 2004, length=31396, window=hide
Category:dropped
Size (bytes):947
Entropy (8bit):4.700814020068451
Encrypted:false
SSDEEP:
MD5:6ABC0F7AE3F9D1E7054C3973B4C16F33
SHA1:0DF9E333A364171C06EA8AB1F05B1F9752D18F2C
SHA-256:416A377EE72270F64156C9D15F24D4E4BDA8C3F3CB32AD0BD94146F0E19CD53F
SHA-512:BCC07DE0144CF2C3FF5B05C00EC8C1DA2413C9A7BD3E14EDB54ACF1E6057641E673D8764F1C364B19DA9F043B1EDEC097F793FBC01944529CFAF852EC9CC333A
Malicious:false
Reputation:unknown
Preview:L..................F.... ......K.......K......d.-....z...........................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....f.2..z...1`< .hahost32.exe..J......|XRR|XRR....H.........................h.a.h.o.s.t.3.2...e.x.e.......Z...............-.......Y...........@.]......C:\Program Files (x86)\HAWin32\hahost32.exe........\.....\.h.a.h.o.s.t.3.2...e.x.e.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:34 2024, atime=Sat Jul 31 06:34:58 2004, length=36016, window=hide
Category:dropped
Size (bytes):940
Entropy (8bit):4.697158592271482
Encrypted:false
SSDEEP:
MD5:776E95214AE8BCB32E70D1E8E5D61D3B
SHA1:1933E91B3AA93D7C3A61631126676A7731E49C41
SHA-256:683DEFE34F1A39162C2CE9767DF4C726857834C0855A44BA615BDD3643DFB48C
SHA-512:0FF8DD8439580C5FCABE1A9F5F2A378DFDC7171311F5B0AFEB48AE77AEB0C6DB2240239B3F5BDB133A91027503035BFF5D5716971A7FAA41CAE5CF1504C75A88
Malicious:false
Reputation:unknown
Preview:L..................F.... ......J....W..J.....}3.-................................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....b.2......1]< .HAWIN32.EXE.H......|XRR|XRR....?\........................H.A.W.I.N.3.2...E.X.E.......Y...............-.......X...........@.]......C:\Program Files (x86)\HAWin32\HAWIN32.EXE........\.....\.H.A.W.I.N.3.2...E.X.E.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Thu Mar 28 09:18:36 2024, mtime=Thu Mar 28 09:18:36 2024, atime=Thu Mar 28 09:18:36 2024, length=0, window=hide
Category:dropped
Size (bytes):997
Entropy (8bit):4.6738667609456215
Encrypted:false
SSDEEP:
MD5:D8D876F2EA65D8F05EBCB27892DF6060
SHA1:017345C08C8B685ADD5FDDC008681DBE0285624C
SHA-256:23E208AD9E455B540807C7241D003B94066E979BC4B8CE1CC60458EC4A114AB1
SHA-512:566457F23395B5C8065AED23EFF31A07FF13B56861CBF490AD7994668C36938339CC419FA14C57189CD58C11947C2593FA55B18C73D23D2042ED6AEA1A79C4C9
Malicious:false
Reputation:unknown
Preview:L..................F.........3.K......K.......K.................................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....Z.1.....|XSR..MYFILE~1..B......|XRR|XSR.....Z....................6..M.y. .F.i.l.e.s.....P.1.....|XSR..Lists.<......|XSR|XSR..............................L.i.s.t.s.......\...............-.......[...........@.]......C:\Program Files (x86)\HAWin32\My Files\Lists........\.L.i.s.t.s.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Thu Mar 28 09:18:37 2024, length=4096, window=hide
Category:dropped
Size (bytes):899
Entropy (8bit):4.7135183472241176
Encrypted:false
SSDEEP:
MD5:0477CE383C71347A1CB0A73B9D99EE67
SHA1:520836030C768A5FD2E56E1827D7A96CFDA46FC5
SHA-256:AAA96CF4D4BC00D3318A76D3B3CDDE3FE638D9C2429910B58483E6CFFE00CF89
SHA-512:BB640396E78B5AA4C4953E61B72E72C3F4229655691D231979F544BC8D609354B2993BB55C71B8D82B748D56254E3B30C3C6AE2C2BBC3D3F2D46B88F71C3CBF7
Malicious:false
Reputation:unknown
Preview:L..................F..........J.......L.....u.L............................w....P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....Z.1.....|XSR..MYFILE~1..B......|XRR|XSR.....Z....................6..M.y. .F.i.l.e.s.......V...............-.......U...........@.]......C:\Program Files (x86)\HAWin32\My Files................*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Description string, Has Relative path, Has Working directory, Archive, ctime=Thu Mar 28 09:18:36 2024, mtime=Thu Mar 28 09:18:36 2024, atime=Tue Oct 13 11:54:06 2009, length=33500, window=hide
Category:dropped
Size (bytes):1035
Entropy (8bit):4.675575865997553
Encrypted:false
SSDEEP:
MD5:05B601F436AF35C916B4138010CF395F
SHA1:60A9139AD48C5C2669FB97FD944BFFEE58244970
SHA-256:35FE6C5774DADF819B05F4A29FBE9AE6C541D0B87954E8C2BB82879E79F66664
SHA-512:A5599E207EC0308C66A7EAE65D112D7D775255065F8037BF976437D8D37282231D7E07545CC617D312ECF10F26488F71BEBF27AB8B7C397B55E860D8BAFE4B70
Malicious:false
Reputation:unknown
Preview:L..................F.... ......K....m(.K.....+[?.L.........................}....P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....`.2....M;.f .readme.doc..F......|XSR|XSR..............................r.e.a.d.m.e...d.o.c.......X...............-.......W...........@.]......C:\Program Files (x86)\HAWin32\readme.doc....I.n.s.t.a.l.l.a.t.i.o.n. .N.o.t.e.s.......\.....\.r.e.a.d.m.e...d.o.c...C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:34 2024, atime=Tue Oct 27 08:50:06 2009, length=184048, window=hide
Category:dropped
Size (bytes):2038
Entropy (8bit):3.5023849881867153
Encrypted:false
SSDEEP:
MD5:0991A198B1D1D68FECF251F34ED16675
SHA1:875CDD086D3E3EE3EC2DAEEB8276E1EFBD8F05D4
SHA-256:9BBF062CD4CBED0B6CCE98C55A23458CBDA055FA1BE213F12C34FF5284495F0F
SHA-512:A4F52D46342DBCCA6A1997022FD4E5A612FFDCA49A1CB8C3E379D61419E890871CF7B000D03166987D2425E1E786846BE850416CBE46A520641A80330BCB8042
Malicious:false
Reputation:unknown
Preview:L..................F.@.. ......J.....:.J.....[...V...............................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....Z.1.....|XSR..MYFILE~1..B......|XRR|XSR.....Z....................6..M.y. .F.i.l.e.s.....f.2.....[;CN .UNINSTAL.EXE..J......|XRR|XRR.....\........................U.N.I.N.S.T.A.L...E.X.E.......c...............-.......b...........@.]......C:\Program Files (x86)\HAWin32\My Files\UNINSTAL.EXE........\.U.N.I.N.S.T.A.L...E.X.E.'.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.M.y. .F.i.l.e.s...I.n.s.t.a.l.l...l.o.g.4.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.M.y. .F.i.l.e.s.\.u.w.u.n.i.n.s.t...i.c.o.........%ProgramFiles%\HAWin32\My Files\uwuninst.ico....................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:modified
Size (bytes):17591
Entropy (8bit):5.49756055498605
Encrypted:false
SSDEEP:
MD5:CE2D4682C3E2D1BF5A796187F19CC118
SHA1:803C1F0D29FA05C15D18FBED99B3BA5E9A832058
SHA-256:0D2628D935CB269A5DE07A723990B39407C67A78EDA095353E3CFFC445B71C9C
SHA-512:A0C0DB851E76759D97579EC4FBF85EB9FA4267F0BEB3BA3692912EEB125B2855EAB38467F34260EC374679ECA50A5AC9491903B1CE38E4BD2DA0E5CEF5924701
Malicious:false
Reputation:unknown
Preview:*** Installation Started 03/28/2024 11:17 ***..Title: HyperACCESS Installation..Source: C:\Users\user\Desktop\h32trial.exe | 03-28-2024 | 11:17:56 | 8039501..File Copy: C:\Program Files (x86)\HAWin32\My Files\uwuninst.ico | 10-13-2009 | 13:54:34 | | 1078 | 66c15a96..File Copy: C:\Program Files (x86)\HAWin32\HAWIN32.EXE | 08-31-2004 | 08:34:58 | 8.42.0.0 | 36016 | 46e4300..File Copy: C:\Program Files (x86)\HAWin32\HADLL32.DLL | 01-20-2017 | 10:38:52 | 9.1.1.0 | 1785856 | 12482c71..File Copy: C:\Program Files (x86)\HAWin32\HANXSOCK.DLL | 01-20-2017 | 10:38:54 | 9.1.1.0 | 49152 | ff43d786..File Copy: C:\Program Files (x86)\HAWin32\HANCSOCK.DLL | 01-20-2017 | 10:38:52 | 9.1.1.0 | 36864 | 5b1622f6..File Copy: C:\Program Files (x86)\HAWin32\HANXDRCT.DLL | 01-20-2017 | 10:38:54 | 9.1.1.0 | 40960 | ce580cd..File Copy: C:\Program Files (x86)\HAWin32\HANC_STD.DLL | 01-20-2017 | 10:38:52 | 9.1.1.0 | 36864 | f7b4ad4b..File Copy: C:\Program Files (x86)\HAWin32\HANXTAPI.DLL | 01-20-2017 | 10:38:54
Process:C:\Users\user\Desktop\h32trial.exe
File Type:news or mail, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:8FDCCF3FE614EB87B9E07EDFF1B7AFD3
SHA1:8B95606DE48F2FFE24AABBFC4D4563B74B21BB4E
SHA-256:E179862219912B85E64796D304E3D41F1EC38E777901450CF1E333274CF36598
SHA-512:0D6D9F49369145115E90E1573E22BC361F86505CA58B24BFC2FBF3B5D89055199A5A51944A5C10BC3DB432E3857A2C90317C20EDE0DCE6616BC1BE651ECD9D99
Malicious:false
Reputation:unknown
Preview:From: celestin@celestin.com (Celestin Company, Inc.)....Providers of Commercial Internet Access..The TEXT version of the POCIA Directory..=======================================.... *** 1 JUNE 1996 VERSION ***......Copyright 1994-1996 by Celestin Company, Inc. All rights reserved worldwide...The information in this directory is provided as-is and without any expressed..or implied warranties, including, without limitation, the implied warranties..of merchantability and fitness for a particular purpose. You may use the..information in this directory for non-commercial purposes only. Contact us..if you wish to use the directory for a commercial purpose. For example, if you..would like to post this file on a public BBS, you may do so. However, if you..would like to reproduce this file (in whole or in part) in a newsletter, book,..article, or other commercial media, please contact me.....All of the information in this directory was supplied to Celestin Company..directly by the service provi
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:5B586A871923574908C850F8B7FD3D67
SHA1:03D6E13C5B264DFD9C04E2113096108A36EB4091
SHA-256:7D4581A69AADC5CDEBB2E60F2994B00DE9E2B4D139B9AC9F197A512BDB476800
SHA-512:E6D229BAA312A1653C908A01F5770B59649F63FF22D6B2FD4DFC43ACA714F62076A1B3492B0E8CABD08AFF1324BBDFED2F0AC3691072BA7A7D62F3DD89656593
Malicious:false
Reputation:unknown
Preview:.... "QUICK" GUIDE TO INTERNET BBS's (SBI QUICK LIST).. -------------------------------------------------.. Copyright by Richard S. Mark (cerebus@dkeep.com).. Stephen Grande, SBI List Verifier.. Featured in BBS Magazine, Boardwatch, NetGuide and.. the new book, "Internet BBSs: A Guided Tour".. (see README.DOC for more information about this list).. SBIQ0497.LST (rev date: 03/26/97)....=============================================================================..WHERE TO FIND THE SBI FILES:....WWW: http://dkeep.com/sbi.htm - Includes a Guided Tour of Internet.. BBS's from around the world.....FTP: ftp.dkeep.com (in /library/sbi) - login: anonymous.. gcomm.com (in /internet) - login: anonymous.. ftp.netropolis.be (Belgium) (in /pub/sbi) - login: anonymous....FINGER: sbi@dkeep.com (Information about the S
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:9151C5112315D07CDEA0E747364E6A39
SHA1:460F1906C107E97228B9754FE884BEC0810CD9D7
SHA-256:FB9481048601DFAAD3291444310DD172765EDE5E4E20FEA531EE5F2F903EDE45
SHA-512:175157C088FFD4A59E2FF2630CAFE44E3E91174810FA61DD82D5E35808A8E5CE7F58EF0CBF81164BA7A94BD3B9C1EBA3A5554927F5ED8A1554BBD7E4730130AD
Malicious:false
Reputation:unknown
Preview: ================================================================.... USBBS158.LST.. A List of PC Bulletin Boards for DOS Users.. July 1997.... Please replace your list if it is more than 1 month old..... Editor: Bob Breedlove (breedlov@netcom.com).. Founder: P.L. Olympia.... ================================================================.... Copyright (c) 1992 Darwin Systems, Inc... All Rights Reserved.... LICENSE: Free distribution of the USBBS list is permitted and.. encouraged. But, you are not authorized to accept any remuneration in.. exchange for the USBBS list, make any modifications to the list.. (including adding any materials, such as advertising, to the list or.. to the archive in which it is distributed). You may not bundle the.. list with any other product or service without prior written a
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:472BDB99844ADD3E459055014DF539D2
SHA1:B0375E6345CB754403BB92352FC2EFA2A4F02034
SHA-256:9BA52BEC446E9F94A967308459A62956D6D87A51C3D3E3ED1421A8A1CD5BA017
SHA-512:1D30E1691552D1DD9E3E0A332FEECDC2662FC67A404B32EFA0A48C8CDE2B55CFD0FB358B4BCCB3F97A0B4D7061B567C3458812E574F38184E531B8143FB4B298
Malicious:false
Reputation:unknown
Preview:This information is current as of 08/06/95....BBS Phone No. BBS Name Verified Location..-------------- ------------------------- -------- -------------------------..-540-7324 Death Row! 07/09/95 Oceanside, CA, USA..201-223-0485 Labor Board 06/22/95 Secaucus, NJ, USA..201-284-0239 The ChatterBox BBS 07/11/95 Nutley, NJ, USA..201-301-9679 Madison Connection BBS 05/11/95 Madison, NJ, USA..201-385-2874 MENTI'S BAY HST BBS 07/07/95 Dumont, NJ, USA..201-481-4108 KA2HHB HAM BBS! 06/26/95 Newark, NJ, USA..201-523-2058 The Last Word BBS 07/30/95 Paterson, NJ, USA..201-569-6685 The Plain Brown Wrapper B 07/21/95 Cresskill, NJ, USA..201-614-8732 Psi-Kick BBS 06/10/95 Passaic, NJ, USA..201-625-1519 MT HED BBS 07/21/95 Parsippany, NJ, USA..201-633-0368 First Class BBS - Node 2 06/25/95 Paterson, NJ, USA..201-633-9346 First Class BBS - Node 2 06/25/95 Paterson, NJ
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):142531
Entropy (8bit):4.967034509611529
Encrypted:false
SSDEEP:
MD5:472BDB99844ADD3E459055014DF539D2
SHA1:B0375E6345CB754403BB92352FC2EFA2A4F02034
SHA-256:9BA52BEC446E9F94A967308459A62956D6D87A51C3D3E3ED1421A8A1CD5BA017
SHA-512:1D30E1691552D1DD9E3E0A332FEECDC2662FC67A404B32EFA0A48C8CDE2B55CFD0FB358B4BCCB3F97A0B4D7061B567C3458812E574F38184E531B8143FB4B298
Malicious:false
Reputation:unknown
Preview:This information is current as of 08/06/95....BBS Phone No. BBS Name Verified Location..-------------- ------------------------- -------- -------------------------..-540-7324 Death Row! 07/09/95 Oceanside, CA, USA..201-223-0485 Labor Board 06/22/95 Secaucus, NJ, USA..201-284-0239 The ChatterBox BBS 07/11/95 Nutley, NJ, USA..201-301-9679 Madison Connection BBS 05/11/95 Madison, NJ, USA..201-385-2874 MENTI'S BAY HST BBS 07/07/95 Dumont, NJ, USA..201-481-4108 KA2HHB HAM BBS! 06/26/95 Newark, NJ, USA..201-523-2058 The Last Word BBS 07/30/95 Paterson, NJ, USA..201-569-6685 The Plain Brown Wrapper B 07/21/95 Cresskill, NJ, USA..201-614-8732 Psi-Kick BBS 06/10/95 Passaic, NJ, USA..201-625-1519 MT HED BBS 07/21/95 Parsippany, NJ, USA..201-633-0368 First Class BBS - Node 2 06/25/95 Paterson, NJ, USA..201-633-9346 First Class BBS - Node 2 06/25/95 Paterson, NJ
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ISO-8859 text, with CRLF line terminators
Category:dropped
Size (bytes):398517
Entropy (8bit):4.827649207355049
Encrypted:false
SSDEEP:
MD5:9151C5112315D07CDEA0E747364E6A39
SHA1:460F1906C107E97228B9754FE884BEC0810CD9D7
SHA-256:FB9481048601DFAAD3291444310DD172765EDE5E4E20FEA531EE5F2F903EDE45
SHA-512:175157C088FFD4A59E2FF2630CAFE44E3E91174810FA61DD82D5E35808A8E5CE7F58EF0CBF81164BA7A94BD3B9C1EBA3A5554927F5ED8A1554BBD7E4730130AD
Malicious:false
Reputation:unknown
Preview: ================================================================.... USBBS158.LST.. A List of PC Bulletin Boards for DOS Users.. July 1997.... Please replace your list if it is more than 1 month old..... Editor: Bob Breedlove (breedlov@netcom.com).. Founder: P.L. Olympia.... ================================================================.... Copyright (c) 1992 Darwin Systems, Inc... All Rights Reserved.... LICENSE: Free distribution of the USBBS list is permitted and.. encouraged. But, you are not authorized to accept any remuneration in.. exchange for the USBBS list, make any modifications to the list.. (including adding any materials, such as advertising, to the list or.. to the archive in which it is distributed). You may not bundle the.. list with any other product or service without prior written a
Process:C:\Users\user\Desktop\h32trial.exe
File Type:news or mail, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):146442
Entropy (8bit):4.316035577155706
Encrypted:false
SSDEEP:
MD5:8FDCCF3FE614EB87B9E07EDFF1B7AFD3
SHA1:8B95606DE48F2FFE24AABBFC4D4563B74B21BB4E
SHA-256:E179862219912B85E64796D304E3D41F1EC38E777901450CF1E333274CF36598
SHA-512:0D6D9F49369145115E90E1573E22BC361F86505CA58B24BFC2FBF3B5D89055199A5A51944A5C10BC3DB432E3857A2C90317C20EDE0DCE6616BC1BE651ECD9D99
Malicious:false
Reputation:unknown
Preview:From: celestin@celestin.com (Celestin Company, Inc.)....Providers of Commercial Internet Access..The TEXT version of the POCIA Directory..=======================================.... *** 1 JUNE 1996 VERSION ***......Copyright 1994-1996 by Celestin Company, Inc. All rights reserved worldwide...The information in this directory is provided as-is and without any expressed..or implied warranties, including, without limitation, the implied warranties..of merchantability and fitness for a particular purpose. You may use the..information in this directory for non-commercial purposes only. Contact us..if you wish to use the directory for a commercial purpose. For example, if you..would like to post this file on a public BBS, you may do so. However, if you..would like to reproduce this file (in whole or in part) in a newsletter, book,..article, or other commercial media, please contact me.....All of the information in this directory was supplied to Celestin Company..directly by the service provi
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):44921
Entropy (8bit):3.79784649413321
Encrypted:false
SSDEEP:
MD5:5B586A871923574908C850F8B7FD3D67
SHA1:03D6E13C5B264DFD9C04E2113096108A36EB4091
SHA-256:7D4581A69AADC5CDEBB2E60F2994B00DE9E2B4D139B9AC9F197A512BDB476800
SHA-512:E6D229BAA312A1653C908A01F5770B59649F63FF22D6B2FD4DFC43ACA714F62076A1B3492B0E8CABD08AFF1324BBDFED2F0AC3691072BA7A7D62F3DD89656593
Malicious:false
Reputation:unknown
Preview:.... "QUICK" GUIDE TO INTERNET BBS's (SBI QUICK LIST).. -------------------------------------------------.. Copyright by Richard S. Mark (cerebus@dkeep.com).. Stephen Grande, SBI List Verifier.. Featured in BBS Magazine, Boardwatch, NetGuide and.. the new book, "Internet BBSs: A Guided Tour".. (see README.DOC for more information about this list).. SBIQ0497.LST (rev date: 03/26/97)....=============================================================================..WHERE TO FIND THE SBI FILES:....WWW: http://dkeep.com/sbi.htm - Includes a Guided Tour of Internet.. BBS's from around the world.....FTP: ftp.dkeep.com (in /library/sbi) - login: anonymous.. gcomm.com (in /internet) - login: anonymous.. ftp.netropolis.be (Belgium) (in /pub/sbi) - login: anonymous....FINGER: sbi@dkeep.com (Information about the S
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:AF63DCC6E1062D63E49358C69010AF80
SHA1:56B7F48FBCCCFB63584CC6E266CD0E482B44A9C4
SHA-256:7A16B0D3270C836D7A120DB2DDC81E77F1A493BBCD3C81B60A3E7FC3D204F308
SHA-512:156DDA341ED6778DA2B8DE51790AB775F1AEEE06867F52B6DEDC627ED394419F7A8AE04AA7163A30FFF0DD20B9586C5CE03150349B7B92101B8306D4E09B4020
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:68B9819A7BBDD7A160AF54D29197B6D3
SHA1:99231BC05ECCBEA4A4B9A0C80DD39BE6385F9932
SHA-256:A64555CC48E229AB79C873010D952EFD151332EC3E099163D6E8667642E83619
SHA-512:FE6B8C44350A95DE8688A581E01AF8639DB6CF0ED1AC07F7D99C2CFEC739570B593A5724C68E523E694ABFAC7020483C2BEB6252AF741034899E5E0329261467
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:C3C6C00BF2EE059E4A73E361B6D47276
SHA1:406B3433B056F58644332CD17A485D0978EAC2D4
SHA-256:EE382EB392757487FE4F2870C28FCC25806F278841F9271C1563765102933BC0
SHA-512:98CA5EA915D115DA6796A602CF73780CE52695300D3FC0908FCE91C1E297ACE66B5D7C4A9FE7AD160EB2A1E17240AA8CCF05B43935E9D2483FF2FE1C92D9153B
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 5%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m.d.)...)...)...)...(...)...o...K... ...v...+.......(.......(...Rich)...........PE..L...?l.;................."...........!.......@....@..........................p.......................................G..i...(A..d....`..@............................................................................@..(............................text...&!.......".................. ..`.rdata..y....@.......&..............@..@.data...x....P......................@....rsrc...@....`.......2..............@..@................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:2B85FE26CA828485BFF6A454B881A295
SHA1:FD448D4A9165BC848A1E6C579010A3EC21B4137E
SHA-256:7128574752F0A7DA1284D589C195AAFE25C29F825D7028CEBDB21A7ECC44DC00
SHA-512:310AC39DD9F13D18D87320E1A10167BA206F01819C384DBDA341EE8C63D57C6C6CD366F74FA26DB94E90904FF5B98388E62905866EE761344F93D532E8F0B2DD
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......e.T.!w:O!w:O!w:OZk6O#w:O|U1O w:O.k4O.w:O|U0O.w:O!w:O w:OCh)O.w:O!w;O.w:O~U0O w:O.q<O w:O.W>O w:ORich!w:O........PE..L......;..................................... ....@..................................................................=.......+...........&........................................................................... ..x............................text............................... ..`.rdata....... ... ..................@..@.data...<@...@...6...&..............@....rsrc....&.......(...\..............@..@................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:072D1933E9934F5AD60E57B0507044B6
SHA1:EDFB0142EB66924C481CA59E0B88D75036A6504D
SHA-256:B17F0565ABD23A16D2A3BFC587EE3AEF8FEA9B7B82A8CBC95592F289EDCFA37B
SHA-512:C4F53B7BF570199AD5C8F74FAB16F52070DAFC91213B327A46A98B4F3EFA2905D507E17B56FCF0B6D79F8B5CCD4AE88BFFCD9F99EADA96769BD5772A01B7A744
Malicious:false
Reputation:unknown
Preview:RIFFr%..WAVEfmt .........+...+......dataN%............{{.....||}...........~z|....}xz.....~|~....................|{.....|{y{{{zwtw{...~||..................{yutwz}~.{z|...................}yvwz{{xwwz............z{....}z{.....}{{....{{~..........}||{zz{|zzxx{....zyz.............}}.....zx|...{vv{...}z|}....}~~~.....}}...{{|......~}.....{{{......}.....}z{...|uuvuy}~yxy}...........~~............{yz|yy..~wz.............~.....ywstt{}yppu|...................}.z|{zuuuuux{{w{...............|...}vrrrx}ytqw~..........................||~~}..~|......}xxy{|{ywwy...~~~.....}z..............~~....{zz{{..{xz|{|...~.......}~...............wtqplq|....}x{....~z......~|......uutuv}~.{.~..................}||.y|z{rv}....}~............zvxzvtuvnktvwuw{yw....................uswxtxwutv}...........}z.....xrz}.||yrntuz|....................~...|..}yzwtvy...|}x{~...xww......~......||.....~||..........}.}...z}{|y.....~{.....}.}......~|..........{|pjiww...~.{~.....vz{s........rxz|..srtcgquw.xu..x...........~......z{w|.~u
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:E23A2BC3055A6F8A56497843560F5F52
SHA1:29F3B91E70E16A9B56AFCA7C19350A0D5D59F6B1
SHA-256:B66678862535F091CC6E90CCF7BFD209322BEB312695239E64E24115250E9839
SHA-512:7481F191D91D06B75192C6C2F96DE692221F8FBA7009A7DC0EC50682B51095A93948B4E418437322D9FFE8E0560CA081DAA19EC479592C6830C6AD6B533333DE
Malicious:false
Reputation:unknown
Preview:RIFF&4..WAVEfmt .........+...+......data.4..~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~...........~~~~~~........~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~}}}}~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.......~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.~...~~~~~~~~~~~~~~~~~~~~~~~~~}}}}}~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.~.~~~~~~.....~~~~~~~~~~~~~~..~~~~~~.~~...~.~~~~~~~~~~~}~~~~~~~~~~~~~~~~~~~~~...........~.~~~~~~~~...~~~~~~~~~~~~~~}}}}}}}}}}}}}}}}}}}}}~~~~~~~~~~~~~~~~~..........~~~~~~~~~~~~~~.~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~..........~~~~~~~~~~~~~~~~~~.~~~~~~~~~~~~~~~~}~~~~~~~~~~~~~}}}}}}}}~~~~~~~~~~~~~~~~~.~......~~~~~~~~~~~~~~..~~~~~~}}}}}}}}}}}}}}}~~~~~~~~~~}}~~~~~~~~~~~~~~~~~.~.~........~~~~~~~~~~~~~~..~~~~~~~~~~~.~~~~~~~~~~~~~~~~.~~.~.~~~~~~}}}}}}}}~~~~~~~~.~.~~~~~~~~~~~~~~~~~~~~~~}}}}}}}}}}}}}}}}}}}}}}~~~~~~~~~~~~~~~~~~~~~~~...............~~~~~~~~~~~~~~}}~~~~~~....~.~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~}}~}~~~~~~~~~~~~~~~..................~~~~~~~~~~~~.....~~~~}~~~~~~~~~~~~~~
Process:C:\Users\user\Desktop\h32trial.exe
File Type:C source, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:A0DA8AD054256BD445B0CC2F463DF43B
SHA1:AA9AEAB5B090B690F3978852AFBD53289B863C21
SHA-256:B1462994CE9E3BF590DBB6790D529A969826D64DE80DF51A3CAAD92581DD52DF
SHA-512:40C863CFB1062A507F80A1DEB5E972F4B4F33E2B4543841D1928A46B2CEB843C855B0E26A71C1B71CF7C9E36BB48F3E7D7E2372EDABBA3E1CB00B282AA852490
Malicious:false
Reputation:unknown
Preview:/* File: ha_auto.h.. *.. * Copyright 1996 by Hilgraeve Inc. -- Monroe, MI.. * All rights reserved.. *.. * Description:.. * This file defines all of the named constants used.. * by the Hilgraeve API. It is intended to be included.. * by any external script that is written in C++... *.. * $Revision: 2 $.. * $Date: 4/07/99 10:25a $.. */..#ifndef HA_AUTO_H..#define HA_AUTO_H....../*.. * Possible API return codes.. */..#define HA_ERR_OK 0 // no error..#define HA_ERR_BAD_CMD -1 // unrecognized API (won't happen)..#define HA_ERR_BAD_PARAM -2 // parameter out of range or wrong type..#define HA_ERR_BAD_HANDLE -3 // script handle invalid..#define HA_ERR_NO_MEMORY -4 // internal memory allocation failed..#define HA_ERR_NO_SESSION -5 // session no longer attached..#define HA_ERR_TIMED_OUT -6 // waiting function expired..#define HA_ERR_BUSY -7 // can't have two guys accessing at same time..#define HA_E
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:E0C16EB410E16471D67BE17C8C00F809
SHA1:509F3DFB6A482BABA464D5589681836D208786D5
SHA-256:5E9CD4703F0675E496447AA85CE7C47E2125A7B61A2C9ED28090FD623EE4E28A
SHA-512:89BA19BBE142F28E52D4BED9DC5DF68BB43861F0CD815B040F2D345082F7826DA665B671BD392B41D0B4C9DC6DA03C39010A23F6271CC737FB56860230570E0C
Malicious:false
Reputation:unknown
Preview:RIFF.h..WAVEfmt .........+...+......data.g..................x.|}..u..wo...t..o{.~z..y...s...t..}~.{.|.y...y...u..~......z}~.z...z.}z}......|.xy..|...u.~.y.}.{.y~}.x...u.}.x.|.~.pz|.x...p.y.s.x.ikqa..W..t..p.X..\..V.}[.dz.E}.d..P..o.pt.^~.^..o.fr.j..f..i~p.{wx...y.m..|..m.{s..}.Uy.]..T.ix.bu.X..g..y.g..f..q.wy.h..m.yq.z.}k.tq.{..r..y.x..f..l.tn.`i.Z..c.|j.dy.h~.s....sz.u..zqvv|h.yx~t}.l.pv.xy.i..k..n.mp.V.._.f_.[j.\..T..i.jg.j..i..b..p.rk._t.f.zp.et.ur......{..t.|..t..a.o|.ow.^.of.}r.n..q..o.w..tx.|.pv.qo.l.t|.j..b.~}.{..q..f..~.f..H~.l.]t.^z.l.~D..s.p..V..{.kj..{t{.uXx..kx...zi.}`....[..`vuv.ls.t.n<..P....Mw.X.|o..h.u.yP..m.|..a_.z.dt..fh..lv....g...|e..N....bo.Tkug..V..{{P..a....k\.r}yt..^r|{iX....s..eqy..k..|}lv.~d.t..K..a.e..Yf.r.{d..b.t..e..vyd...y...^\p.}s|..mrv..d...._x.\t...ob.lf.S..[..}.Nu.lw.z..Z..y.d..ia...gs.ubl|..{i..wW.......]yp..vr.urfc.~@..z.ur.Ym.}..[..f.x..]..q.rQ..Xwv..Vy.s..{..g.......aY....d..Ziwi.iX..b._..b....ra.y_....U..V.ir.ua...ia..q....zt...w...fn..cylt}\z.r.t
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:8D6EDCFDDF3BE65B23837AFDD3958EE4
SHA1:7E61271F613025A561687A8BDABBD5996FBDECE5
SHA-256:1B24170EA57CA84D77009E703B9151E6EAA3743B74331A0ADBCBA41F275B8055
SHA-512:C60499CDDCEDDE5F75D0FFAA1A4A09D6BEADE80E151AA01E2D6EDE6260FE689A879F1D7FC4035AD7F13672B0DF739430325DF4FF5EBD474AEAE5909C9FE8ED0E
Malicious:false
Reputation:unknown
Preview:; *..; * $Revision: 1.3 $..; * $Date: 1997/01/31 17:31:25 $..; *......; Global variables defined...;..string sPcPlusDir, sProgress1, sExportName, sFullName, sTemp..integer itemp......;/*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-..; * FUNCTION:..; * .main..; *..; * DESCRIPTION:..; * .This routine calls a few functions to obtain file names, then..; * .writes out a simple ascii file that can be used with Hilgraeve's..; * .convert program. The convert program reads the ascii file produced..; * .by this script and create HA\Win session files...; *..; * ARGUMENTS:..; *..; * RETURNS:..; *..; */..proc main...integer index, nDataBits, nParity, nStopBits, nLocalEcho, nFileIndex...string.sName, sNumber, sEmulation, sPCEmu...long.lRate...string.LineOut.....SelectDirectoryFile().....if strcmp sPcPlusDir $NULLSTR....Exit...endif.....if not $DIALCOUNT > 0....errormsg "There are no entries in this dialing directory"....Exit...endif.....GetExportFileName().....; Open th
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:A9C566976B21C5411399B44389927745
SHA1:AC9BBC0CBF52A3503F6D70D95E60E060669FF726
SHA-256:8730A39AAF6BEEBDA26856ED20C6DAA763B68D0301E7681E2E3554F2125D1B08
SHA-512:BDE4BDC9891AA97AB31693FD75552BB1AF422D4024EF20D57190E29D152428F75ECD4C78746B8DED1B8355139D911FD711D3C3A9D1DA1FCC79DDDA8C8E032492
Malicious:false
Reputation:unknown
Preview:; *..; * $Revision: 1.3 $..; * $Date: 1997/01/31 17:31:25 $..; *......; Global variables defined...;..string sPcPlusDir, sProgress1, sExportName, sTemp, sNumber..integer iCount......;/*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-..; * FUNCTION:..; * .main..; *..; * DESCRIPTION:..; * .This routine calls a few functions to obtain file names, then..; * .writes out a simple ascii file that can be used with Hilgraeve's..; * .convert program. The convert program reads the ascii file produced..; * .by this script and create HA\Win session files...; *..; * ARGUMENTS:..; *..; * RETURNS:..; *..; */..proc main...integer index, nDataBits, nParity, nStopBits, nLocalEcho, nFileIndex, iLoop...string.sName, sEmulation, sPCEmu...long.lRate...string.LineOut.....SelectDirectoryFile().....if strcmp sPcPlusDir $NULLSTR....Exit...endif.....dialcount DATA iCount...if iCount == 0....errormsg "There are no entries in this dialing directory"....Exit...endif.....GetExportFileName()
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:CE3DBC8A647E2D7586C94EE16529A8A1
SHA1:7668AAB9003C0BD4F4B22B97ADA340BB45FCFF97
SHA-256:C17138DCA991A4B26E11D02A81FB2100C5DCC506F25EF4C5E30A78BA1632570B
SHA-512:8FFE282519031E86CBA8BF430E60E622415C9510A53D31E6BECB8E52101F35B176AE2AB359358A0DE24605C095909C855BFCE6D034F02473BA5F8EF68D9FF088
Malicious:false
Reputation:unknown
Preview:; Export DATA and TELNET entries for HyperACCESS...; *..; * Copyright 1996 by Hilgraeve Inc. -- Monroe, MI..; * All rights reserved...; *..; * $Revision: 1.3 $..; * $Date: 1997/01/31 17:31:24 $..; *......; Global variables defined...;..string strProgress1..string strPcPlusDir, strExportName, strFullName, strTemp......;/*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-..; * FUNCTION:..; * .main..; *..; * DESCRIPTION:..; * .This routine calls a few functions to obtain file names, then..; * .writes out a simple ascii file that can be used with Hilgraeve's..; * .convert program. The convert program reads the ascii file produced..; * .by this script and create HAWin32 session files...; *..; */..proc main...integer nModemEntries, nTcpIpEntries, nEntries, nProgress...integer nFileId...integer index...string strEntryName, strCountryCode, strAreaCode, strPhoneNumber...long.lBaudRate.. .integer nDataBits, nParity, nStopBits, nLocalEcho...string.strTerminal...integer
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:388EB2CDFDD20A3B6B08FBA11685B3CE
SHA1:E0BAF5726E48C988CCB7591AF7FCB2AD46C53B30
SHA-256:91275361C505775725906519754B46EEB4F9F446611849E4EB2F53157E98A560
SHA-512:BCF2C690C0F6985D6609E7586974186DDC6F4552C28A5044B8F9122D1A975E184F9611E5C68A69F54E70A9F5D9A1350BE25C151B00B3ECA4119F7A80186F5814
Malicious:false
Reputation:unknown
Preview:...... ..........&...........(.......(... ...@......................................................................................................................................DDD...........DD...I.........DLL..........DLD............D.L.........I.............L............D@.............@.... ...............p..........wy.............ww............q.wy......................................;..........................<............<.............<..............:........................p...:............z..........................................................|.....................................................@.?...................................................................................................?............(....... ..........................................................................................................DD.....D...................@.....I...p...........?L......................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators, with escape sequences
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:BCEC6FCD2A2AB0A8820B790BE69F470F
SHA1:A537344CCE254C37A995332EF7A0767DEA8D611B
SHA-256:16B043ACAED1BC4BBAED0089BFAE8341600CC6DE3B31049E423E864A63CB4AD8
SHA-512:A8E3C18B80D89EF1876941729DC96FD9065DAB0919520AE4D6CC5AB16C27A7DEDB58CD3D9E0C4D2BD658DBB77F30DC44127D4C01894E2376C707DACADC7074B1
Malicious:false
Reputation:unknown
Preview:.....[0m.[2J.[1;37m...[1;34m********************************************.[0m ...[1;34m* *.[0m ...[1;34m* .[1;33mHyperACCESS Host.[1;35m for Windows 95 and NT.[1;34m *.[0m ...[1;34m* *.[0m ...[1;34m* .[1;34mby Hilgraeve.[1;34m *.[0m ...[1;34m* *.[0m ...[1;34m* .[1;31mCopyright .[1;32m1985 - 1996.[1;34m *.[0m ...[1;34m* *.[0m ...[1;34m********************************************.[0m ....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:4376F8D21BA411968BDAA11BCE594A3B
SHA1:8A03E7F64B2CEA09DD2D7CA72174A2855F96EF7F
SHA-256:2E31F7B23E28052C5B20A6B0FBD933BD4CF82ABA0A527927B6503E4B7E28BA76
SHA-512:789AF1C01174F299A45F168265795C643804A54761266546752E29886EF1DD756DDB5B2D5B483C63A10D1BAC344CDBE7467E12E4E61E0687AB40DF294E26560C
Malicious:false
Reputation:unknown
Preview:********************************************..* * ..* HyperACCESS Host *..* *..* by Hilgraeve *..* Copyright 1985 - 1999 *..* *..********************************************....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 22050 Hz
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:888E74E41B3A511F94A2896B480311D7
SHA1:C6422A432A1B47C060D99A8F71672BC599F34BA3
SHA-256:AA418FDBA869F5BCED85608F2B01863C699E2B34DFAF14EB557A98B40DB70143
SHA-512:962E4F68862010D1B0B9D24D1B3585EFAE9C86ADED5081110A77323D2A79B7643AC58048D6EA64239419DDC1A24877713FDB0B2B7B421D941D1C6A55710A0097
Malicious:false
Reputation:unknown
Preview:RIFF.V..WAVEfmt ........"V.."V......data.V..~....................~~~~~~~~~~~~~...~~~~~~..~~~~~~~~~}}}}}}|||||||||||||||||||||||||}}}}}}~............................jO/.................0U............pD3<Qepm]G5.9_............V/%4J\d]J3#!6k..............O/0CWa`R;'#:s..............s?-7JX]WG8:V...............E#%7JRM>*...1\............L$!4K\`R9 ..)Z............c7*4HY`V@&.."P.............N(%8N\^R;%..=p............g,..9P^]K1..$L.............S'.+BT[R<$. 9_..............E!.-BPVN9"...7k...........s5..7O^`O1...?s............w>#(=R]]L4$".Gk............O(.(:INF4!.."Fy.............[8,3DRUJ6!..8a.............c9&,?PVO>*..&Hw............a:)0APTL<(..-S............}L*%4JXXM<,(7W..............h9 #3EMJ<*..4Y.............N'.*>LOD1..)Fk.............zE$ /BNNB...'Ju............i:$(:KRM?*..,Ow............d7%,?PUN>(..2^.............Q.)6HUVJ6#.$>c.............U,$2ERTI4....U............._3&1DSWL6....Z.............^2'4GTWL5...'N.............g9)4GVZR>%..+\.............a5
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11000 Hz
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:1D630ED5E3C4D6681D5267E0EDED5ED4
SHA1:28ECC35BBB85614E7A357A9719BAB770FF7789AD
SHA-256:FC69197B7BF1D117FFDCA457AFF8D825B10945922E8097A6811331D0696002DF
SHA-512:0AD4ADCBA07E92BD0287C86FCCC2845C056A67D19D72054E4F6FA7026B82270F32ED8327E5BB2D5B3106C020917CEBFBD9B379CFCF5835F48BBADE4BDF0B19E6
Malicious:false
Reputation:unknown
Preview:RIFF`)..WAVEfmt .........*...*......data<).....zy{......~vpnqx.....ysqtz.......yvw|.....{smlpw.....~xuw|......~vrsw~....{smlqy......}yx{......{toosy.....xsqt{......~wuw|.....ypkkpx.....~wtv}......}upqv~....{snnr{......|ww|......yqmmrz.....xsrv}......}wuw}.....xqlkpy.....~xuw~......{rorw.....zrmns}......{ww|......wnkms{....~wsrv.......zutw~.....umjms|.....|wux.......wpnqx.....xqmnu.......yuw}.....~tmjmu~....|urrx.......xssw.....|rljnv......{vuy......~tmlqy....~unlox......~wuw~.....{qjinw.....|uqt{......}upqx.....zpjiox......zuv{......{rmms{....}tnmqz......{utx......xojjpy.....zsqu}......zsorz.....xojjq|......wsv}......wnknt}....{rmnt~......xsty......tkhks}.....wrrw.......vpos{.....tmilt......}vtx......~sljnw.....xqmow.......vrtz.....{pihmu.....~vrsz......~tnnt|....}slkow......{tsw~.....|rkhjov}....}uqu......vjhq.....~ywxyyz|.....ymgjx.....|olr~....xqnoqsvy......}ts{.....rc^dp.....{z{~.........tign}....ylfkx.....xuvxz{~......|pjo|....ud]ao..................se^bq.....tknz......xvwxyyz....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):164864
Entropy (8bit):5.17459659411454
Encrypted:false
SSDEEP:
MD5:2B85FE26CA828485BFF6A454B881A295
SHA1:FD448D4A9165BC848A1E6C579010A3EC21B4137E
SHA-256:7128574752F0A7DA1284D589C195AAFE25C29F825D7028CEBDB21A7ECC44DC00
SHA-512:310AC39DD9F13D18D87320E1A10167BA206F01819C384DBDA341EE8C63D57C6C6CD366F74FA26DB94E90904FF5B98388E62905866EE761344F93D532E8F0B2DD
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......e.T.!w:O!w:O!w:OZk6O#w:O|U1O w:O.k4O.w:O|U0O.w:O!w:O w:OCh)O.w:O!w;O.w:O~U0O w:O.q<O w:O.W>O w:ORich!w:O........PE..L......;..................................... ....@..................................................................=.......+...........&........................................................................... ..x............................text............................... ..`.rdata....... ... ..................@..@.data...<@...@...6...&..............@....rsrc....&.......(...\..............@..@................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):184048
Entropy (8bit):7.944896782485959
Encrypted:false
SSDEEP:
MD5:C3C6C00BF2EE059E4A73E361B6D47276
SHA1:406B3433B056F58644332CD17A485D0978EAC2D4
SHA-256:EE382EB392757487FE4F2870C28FCC25806F278841F9271C1563765102933BC0
SHA-512:98CA5EA915D115DA6796A602CF73780CE52695300D3FC0908FCE91C1E297ACE66B5D7C4A9FE7AD160EB2A1E17240AA8CCF05B43935E9D2483FF2FE1C92D9153B
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m.d.)...)...)...)...(...)...o...K... ...v...+.......(.......(...Rich)...........PE..L...?l.;................."...........!.......@....@..........................p.......................................G..i...(A..d....`..@............................................................................@..(............................text...&!.......".................. ..`.rdata..y....@.......&..............@..@.data...x....P......................@....rsrc...@....`.......2..............@..@................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows icon resource - 2 icons, 32x32, 16 colors, 16x16, 16 colors
Category:dropped
Size (bytes):1078
Entropy (8bit):4.03849608375113
Encrypted:false
SSDEEP:
MD5:388EB2CDFDD20A3B6B08FBA11685B3CE
SHA1:E0BAF5726E48C988CCB7591AF7FCB2AD46C53B30
SHA-256:91275361C505775725906519754B46EEB4F9F446611849E4EB2F53157E98A560
SHA-512:BCF2C690C0F6985D6609E7586974186DDC6F4552C28A5044B8F9122D1A975E184F9611E5C68A69F54E70A9F5D9A1350BE25C151B00B3ECA4119F7A80186F5814
Malicious:false
Reputation:unknown
Preview:...... ..........&...........(.......(... ...@......................................................................................................................................DDD...........DD...I.........DLL..........DLD............D.L.........I.............L............D@.............@.... ...............p..........wy.............ww............q.wy......................................;..........................<............<.............<..............:........................p...:............z..........................................................|.....................................................@.?...................................................................................................?............(....... ..........................................................................................................DD.....D...................@.....I...p...........?L......................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11000 Hz
Category:dropped
Size (bytes):10600
Entropy (8bit):5.068626138106944
Encrypted:false
SSDEEP:
MD5:1D630ED5E3C4D6681D5267E0EDED5ED4
SHA1:28ECC35BBB85614E7A357A9719BAB770FF7789AD
SHA-256:FC69197B7BF1D117FFDCA457AFF8D825B10945922E8097A6811331D0696002DF
SHA-512:0AD4ADCBA07E92BD0287C86FCCC2845C056A67D19D72054E4F6FA7026B82270F32ED8327E5BB2D5B3106C020917CEBFBD9B379CFCF5835F48BBADE4BDF0B19E6
Malicious:false
Reputation:unknown
Preview:RIFF`)..WAVEfmt .........*...*......data<).....zy{......~vpnqx.....ysqtz.......yvw|.....{smlpw.....~xuw|......~vrsw~....{smlqy......}yx{......{toosy.....xsqt{......~wuw|.....ypkkpx.....~wtv}......}upqv~....{snnr{......|ww|......yqmmrz.....xsrv}......}wuw}.....xqlkpy.....~xuw~......{rorw.....zrmns}......{ww|......wnkms{....~wsrv.......zutw~.....umjms|.....|wux.......wpnqx.....xqmnu.......yuw}.....~tmjmu~....|urrx.......xssw.....|rljnv......{vuy......~tmlqy....~unlox......~wuw~.....{qjinw.....|uqt{......}upqx.....zpjiox......zuv{......{rmms{....}tnmqz......{utx......xojjpy.....zsqu}......zsorz.....xojjq|......wsv}......wnknt}....{rmnt~......xsty......tkhks}.....wrrw.......vpos{.....tmilt......}vtx......~sljnw.....xqmow.......vrtz.....{pihmu.....~vrsz......~tnnt|....}slkow......{tsw~.....|rkhjov}....}uqu......vjhq.....~ywxyyz|.....ymgjx.....|olr~....xqnoqsvy......}ts{.....rc^dp.....{z{~.........tign}....ylfkx.....xuvxz{~......|pjo|....ud]ao..................se^bq.....tknz......xvwxyyz....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
Category:dropped
Size (bytes):13358
Entropy (8bit):3.312152064192855
Encrypted:false
SSDEEP:
MD5:E23A2BC3055A6F8A56497843560F5F52
SHA1:29F3B91E70E16A9B56AFCA7C19350A0D5D59F6B1
SHA-256:B66678862535F091CC6E90CCF7BFD209322BEB312695239E64E24115250E9839
SHA-512:7481F191D91D06B75192C6C2F96DE692221F8FBA7009A7DC0EC50682B51095A93948B4E418437322D9FFE8E0560CA081DAA19EC479592C6830C6AD6B533333DE
Malicious:false
Reputation:unknown
Preview:RIFF&4..WAVEfmt .........+...+......data.4..~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~...........~~~~~~........~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~}}}}~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.......~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.~...~~~~~~~~~~~~~~~~~~~~~~~~~}}}}}~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~.~.~~~~~~.....~~~~~~~~~~~~~~..~~~~~~.~~...~.~~~~~~~~~~~}~~~~~~~~~~~~~~~~~~~~~...........~.~~~~~~~~...~~~~~~~~~~~~~~}}}}}}}}}}}}}}}}}}}}}~~~~~~~~~~~~~~~~~..........~~~~~~~~~~~~~~.~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~..........~~~~~~~~~~~~~~~~~~.~~~~~~~~~~~~~~~~}~~~~~~~~~~~~~}}}}}}}}~~~~~~~~~~~~~~~~~.~......~~~~~~~~~~~~~~..~~~~~~}}}}}}}}}}}}}}}~~~~~~~~~~}}~~~~~~~~~~~~~~~~~.~.~........~~~~~~~~~~~~~~..~~~~~~~~~~~.~~~~~~~~~~~~~~~~.~~.~.~~~~~~}}}}}}}}~~~~~~~~.~.~~~~~~~~~~~~~~~~~~~~~~}}}}}}}}}}}}}}}}}}}}}}~~~~~~~~~~~~~~~~~~~~~~~...............~~~~~~~~~~~~~~}}~~~~~~....~.~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~}}~}~~~~~~~~~~~~~~~..................~~~~~~~~~~~~.....~~~~}~~~~~~~~~~~~~~
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
Category:dropped
Size (bytes):26660
Entropy (8bit):6.4328869057838896
Encrypted:false
SSDEEP:
MD5:E0C16EB410E16471D67BE17C8C00F809
SHA1:509F3DFB6A482BABA464D5589681836D208786D5
SHA-256:5E9CD4703F0675E496447AA85CE7C47E2125A7B61A2C9ED28090FD623EE4E28A
SHA-512:89BA19BBE142F28E52D4BED9DC5DF68BB43861F0CD815B040F2D345082F7826DA665B671BD392B41D0B4C9DC6DA03C39010A23F6271CC737FB56860230570E0C
Malicious:false
Reputation:unknown
Preview:RIFF.h..WAVEfmt .........+...+......data.g..................x.|}..u..wo...t..o{.~z..y...s...t..}~.{.|.y...y...u..~......z}~.z...z.}z}......|.xy..|...u.~.y.}.{.y~}.x...u.}.x.|.~.pz|.x...p.y.s.x.ikqa..W..t..p.X..\..V.}[.dz.E}.d..P..o.pt.^~.^..o.fr.j..f..i~p.{wx...y.m..|..m.{s..}.Uy.]..T.ix.bu.X..g..y.g..f..q.wy.h..m.yq.z.}k.tq.{..r..y.x..f..l.tn.`i.Z..c.|j.dy.h~.s....sz.u..zqvv|h.yx~t}.l.pv.xy.i..k..n.mp.V.._.f_.[j.\..T..i.jg.j..i..b..p.rk._t.f.zp.et.ur......{..t.|..t..a.o|.ow.^.of.}r.n..q..o.w..tx.|.pv.qo.l.t|.j..b.~}.{..q..f..~.f..H~.l.]t.^z.l.~D..s.p..V..{.kj..{t{.uXx..kx...zi.}`....[..`vuv.ls.t.n<..P....Mw.X.|o..h.u.yP..m.|..a_.z.dt..fh..lv....g...|e..N....bo.Tkug..V..{{P..a....k\.r}yt..^r|{iX....s..eqy..k..|}lv.~d.t..K..a.e..Yf.r.{d..b.t..e..vyd...y...^\p.}s|..mrv..d...._x.\t...ob.lf.S..[..}.Nu.lw.z..Z..y.d..ia...gs.ubl|..{i..wW.......]yp..vr.urfc.~@..z.ur.Ym.}..[..f.x..]..q.rQ..Xwv..Vy.s..{..g.......aY....d..Ziwi.iX..b._..b....ra.y_....U..V.ir.ua...ia..q....zt...w...fn..cylt}\z.r.t
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 22050 Hz
Category:dropped
Size (bytes):22252
Entropy (8bit):6.273557258675314
Encrypted:false
SSDEEP:
MD5:888E74E41B3A511F94A2896B480311D7
SHA1:C6422A432A1B47C060D99A8F71672BC599F34BA3
SHA-256:AA418FDBA869F5BCED85608F2B01863C699E2B34DFAF14EB557A98B40DB70143
SHA-512:962E4F68862010D1B0B9D24D1B3585EFAE9C86ADED5081110A77323D2A79B7643AC58048D6EA64239419DDC1A24877713FDB0B2B7B421D941D1C6A55710A0097
Malicious:false
Reputation:unknown
Preview:RIFF.V..WAVEfmt ........"V.."V......data.V..~....................~~~~~~~~~~~~~...~~~~~~..~~~~~~~~~}}}}}}|||||||||||||||||||||||||}}}}}}~............................jO/.................0U............pD3<Qepm]G5.9_............V/%4J\d]J3#!6k..............O/0CWa`R;'#:s..............s?-7JX]WG8:V...............E#%7JRM>*...1\............L$!4K\`R9 ..)Z............c7*4HY`V@&.."P.............N(%8N\^R;%..=p............g,..9P^]K1..$L.............S'.+BT[R<$. 9_..............E!.-BPVN9"...7k...........s5..7O^`O1...?s............w>#(=R]]L4$".Gk............O(.(:INF4!.."Fy.............[8,3DRUJ6!..8a.............c9&,?PVO>*..&Hw............a:)0APTL<(..-S............}L*%4JXXM<,(7W..............h9 #3EMJ<*..4Y.............N'.*>LOD1..)Fk.............zE$ /BNNB...'Ju............i:$(:KRM?*..,Ow............d7%,?PUN>(..2^.............Q.)6HUVJ6#.$>c.............U,$2ERTI4....U............._3&1DSWL6....Z.............^2'4GTWL5...'N.............g9)4GVZR>%..+\.............a5
Process:C:\Users\user\Desktop\h32trial.exe
File Type:RIFF (little-endian) data, WAVE audio, Microsoft PCM, 8 bit, mono 11025 Hz
Category:dropped
Size (bytes):9594
Entropy (8bit):7.162725634723695
Encrypted:false
SSDEEP:
MD5:072D1933E9934F5AD60E57B0507044B6
SHA1:EDFB0142EB66924C481CA59E0B88D75036A6504D
SHA-256:B17F0565ABD23A16D2A3BFC587EE3AEF8FEA9B7B82A8CBC95592F289EDCFA37B
SHA-512:C4F53B7BF570199AD5C8F74FAB16F52070DAFC91213B327A46A98B4F3EFA2905D507E17B56FCF0B6D79F8B5CCD4AE88BFFCD9F99EADA96769BD5772A01B7A744
Malicious:false
Reputation:unknown
Preview:RIFFr%..WAVEfmt .........+...+......dataN%............{{.....||}...........~z|....}xz.....~|~....................|{.....|{y{{{zwtw{...~||..................{yutwz}~.{z|...................}yvwz{{xwwz............z{....}z{.....}{{....{{~..........}||{zz{|zzxx{....zyz.............}}.....zx|...{vv{...}z|}....}~~~.....}}...{{|......~}.....{{{......}.....}z{...|uuvuy}~yxy}...........~~............{yz|yy..~wz.............~.....ywstt{}yppu|...................}.z|{zuuuuux{{w{...............|...}vrrrx}ytqw~..........................||~~}..~|......}xxy{|{ywwy...~~~.....}z..............~~....{zz{{..{xz|{|...~.......}~...............wtqplq|....}x{....~z......~|......uutuv}~.{.~..................}||.y|z{rv}....}~............zvxzvtuvnktvwuw{yw....................uswxtxwutv}...........}z.....xrz}.||yrntuz|....................~...|..}yzwtvy...|}x{~...xww......~......||.....~||..........}.}...z}{|y.....~{.....}.}......~|..........{|pjiww...~.{~.....vz{s........rxz|..srtcgquw.xu..x...........~......z{w|.~u
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):375
Entropy (8bit):2.1115151703902977
Encrypted:false
SSDEEP:
MD5:4376F8D21BA411968BDAA11BCE594A3B
SHA1:8A03E7F64B2CEA09DD2D7CA72174A2855F96EF7F
SHA-256:2E31F7B23E28052C5B20A6B0FBD933BD4CF82ABA0A527927B6503E4B7E28BA76
SHA-512:789AF1C01174F299A45F168265795C643804A54761266546752E29886EF1DD756DDB5B2D5B483C63A10D1BAC344CDBE7467E12E4E61E0687AB40DF294E26560C
Malicious:false
Reputation:unknown
Preview:********************************************..* * ..* HyperACCESS Host *..* *..* by Hilgraeve *..* Copyright 1985 - 1999 *..* *..********************************************....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators, with escape sequences
Category:dropped
Size (bytes):629
Entropy (8bit):3.297281667532821
Encrypted:false
SSDEEP:
MD5:BCEC6FCD2A2AB0A8820B790BE69F470F
SHA1:A537344CCE254C37A995332EF7A0767DEA8D611B
SHA-256:16B043ACAED1BC4BBAED0089BFAE8341600CC6DE3B31049E423E864A63CB4AD8
SHA-512:A8E3C18B80D89EF1876941729DC96FD9065DAB0919520AE4D6CC5AB16C27A7DEDB58CD3D9E0C4D2BD658DBB77F30DC44127D4C01894E2376C707DACADC7074B1
Malicious:false
Reputation:unknown
Preview:.....[0m.[2J.[1;37m...[1;34m********************************************.[0m ...[1;34m* *.[0m ...[1;34m* .[1;33mHyperACCESS Host.[1;35m for Windows 95 and NT.[1;34m *.[0m ...[1;34m* *.[0m ...[1;34m* .[1;34mby Hilgraeve.[1;34m *.[0m ...[1;34m* *.[0m ...[1;34m* .[1;31mCopyright .[1;32m1985 - 1996.[1;34m *.[0m ...[1;34m* *.[0m ...[1;34m********************************************.[0m ....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):9911
Entropy (8bit):5.095210596084981
Encrypted:false
SSDEEP:
MD5:CE3DBC8A647E2D7586C94EE16529A8A1
SHA1:7668AAB9003C0BD4F4B22B97ADA340BB45FCFF97
SHA-256:C17138DCA991A4B26E11D02A81FB2100C5DCC506F25EF4C5E30A78BA1632570B
SHA-512:8FFE282519031E86CBA8BF430E60E622415C9510A53D31E6BECB8E52101F35B176AE2AB359358A0DE24605C095909C855BFCE6D034F02473BA5F8EF68D9FF088
Malicious:false
Reputation:unknown
Preview:; Export DATA and TELNET entries for HyperACCESS...; *..; * Copyright 1996 by Hilgraeve Inc. -- Monroe, MI..; * All rights reserved...; *..; * $Revision: 1.3 $..; * $Date: 1997/01/31 17:31:24 $..; *......; Global variables defined...;..string strProgress1..string strPcPlusDir, strExportName, strFullName, strTemp......;/*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-..; * FUNCTION:..; * .main..; *..; * DESCRIPTION:..; * .This routine calls a few functions to obtain file names, then..; * .writes out a simple ascii file that can be used with Hilgraeve's..; * .convert program. The convert program reads the ascii file produced..; * .by this script and create HAWin32 session files...; *..; */..proc main...integer nModemEntries, nTcpIpEntries, nEntries, nProgress...integer nFileId...integer index...string strEntryName, strCountryCode, strAreaCode, strPhoneNumber...long.lBaudRate.. .integer nDataBits, nParity, nStopBits, nLocalEcho...string.strTerminal...integer
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):8529
Entropy (8bit):5.160632509737625
Encrypted:false
SSDEEP:
MD5:A9C566976B21C5411399B44389927745
SHA1:AC9BBC0CBF52A3503F6D70D95E60E060669FF726
SHA-256:8730A39AAF6BEEBDA26856ED20C6DAA763B68D0301E7681E2E3554F2125D1B08
SHA-512:BDE4BDC9891AA97AB31693FD75552BB1AF422D4024EF20D57190E29D152428F75ECD4C78746B8DED1B8355139D911FD711D3C3A9D1DA1FCC79DDDA8C8E032492
Malicious:false
Reputation:unknown
Preview:; *..; * $Revision: 1.3 $..; * $Date: 1997/01/31 17:31:25 $..; *......; Global variables defined...;..string sPcPlusDir, sProgress1, sExportName, sTemp, sNumber..integer iCount......;/*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-..; * FUNCTION:..; * .main..; *..; * DESCRIPTION:..; * .This routine calls a few functions to obtain file names, then..; * .writes out a simple ascii file that can be used with Hilgraeve's..; * .convert program. The convert program reads the ascii file produced..; * .by this script and create HA\Win session files...; *..; * ARGUMENTS:..; *..; * RETURNS:..; *..; */..proc main...integer index, nDataBits, nParity, nStopBits, nLocalEcho, nFileIndex, iLoop...string.sName, sEmulation, sPCEmu...long.lRate...string.LineOut.....SelectDirectoryFile().....if strcmp sPcPlusDir $NULLSTR....Exit...endif.....dialcount DATA iCount...if iCount == 0....errormsg "There are no entries in this dialing directory"....Exit...endif.....GetExportFileName()
Process:C:\Users\user\Desktop\h32trial.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):6992
Entropy (8bit):5.208006754598188
Encrypted:false
SSDEEP:
MD5:8D6EDCFDDF3BE65B23837AFDD3958EE4
SHA1:7E61271F613025A561687A8BDABBD5996FBDECE5
SHA-256:1B24170EA57CA84D77009E703B9151E6EAA3743B74331A0ADBCBA41F275B8055
SHA-512:C60499CDDCEDDE5F75D0FFAA1A4A09D6BEADE80E151AA01E2D6EDE6260FE689A879F1D7FC4035AD7F13672B0DF739430325DF4FF5EBD474AEAE5909C9FE8ED0E
Malicious:false
Reputation:unknown
Preview:; *..; * $Revision: 1.3 $..; * $Date: 1997/01/31 17:31:25 $..; *......; Global variables defined...;..string sPcPlusDir, sProgress1, sExportName, sFullName, sTemp..integer itemp......;/*=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-..; * FUNCTION:..; * .main..; *..; * DESCRIPTION:..; * .This routine calls a few functions to obtain file names, then..; * .writes out a simple ascii file that can be used with Hilgraeve's..; * .convert program. The convert program reads the ascii file produced..; * .by this script and create HA\Win session files...; *..; * ARGUMENTS:..; *..; * RETURNS:..; *..; */..proc main...integer index, nDataBits, nParity, nStopBits, nLocalEcho, nFileIndex...string.sName, sNumber, sEmulation, sPCEmu...long.lRate...string.LineOut.....SelectDirectoryFile().....if strcmp sPcPlusDir $NULLSTR....Exit...endif.....if not $DIALCOUNT > 0....errormsg "There are no entries in this dialing directory"....Exit...endif.....GetExportFileName().....; Open th
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):3072
Entropy (8bit):3.2916700603834257
Encrypted:false
SSDEEP:
MD5:81CB567C03C3A600528259255B217430
SHA1:CAB178749B294DA06EF1C011B95B25545EFAB976
SHA-256:0216D60C16EE15EA3C1229D5091D29B36A09DCF382D4AA9E4D245DD4CBDEF8E7
SHA-512:EDDD34F7375A48071E99B2F0992CC3F87558957342C5BA018BB141F18D40C41F1530DB2548C4831584CB0A63C02BBDCDB041ACD39CDF6D3CF65CBEE953623691
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):3072
Entropy (8bit):2.8343020131575245
Encrypted:false
SSDEEP:
MD5:AF63DCC6E1062D63E49358C69010AF80
SHA1:56B7F48FBCCCFB63584CC6E266CD0E482B44A9C4
SHA-256:7A16B0D3270C836D7A120DB2DDC81E77F1A493BBCD3C81B60A3E7FC3D204F308
SHA-512:156DDA341ED6778DA2B8DE51790AB775F1AEEE06867F52B6DEDC627ED394419F7A8AE04AA7163A30FFF0DD20B9586C5CE03150349B7B92101B8306D4E09B4020
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):3072
Entropy (8bit):2.886919730194774
Encrypted:false
SSDEEP:
MD5:68B9819A7BBDD7A160AF54D29197B6D3
SHA1:99231BC05ECCBEA4A4B9A0C80DD39BE6385F9932
SHA-256:A64555CC48E229AB79C873010D952EFD151332EC3E099163D6E8667642E83619
SHA-512:FE6B8C44350A95DE8688A581E01AF8639DB6CF0ED1AC07F7D99C2CFEC739570B593A5724C68E523E694ABFAC7020483C2BEB6252AF741034899E5E0329261467
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):3072
Entropy (8bit):2.8888881926780465
Encrypted:false
SSDEEP:
MD5:EA66574F89A4AB807C4F5D92CC876A77
SHA1:A4B9A0C975BB087FAC3A10218F8974B58CCAE038
SHA-256:4D8EFA7636A007957913A6D643DA3B621C6D37B84126FCCBE7DA143E356B8BB3
SHA-512:6DE6BD94CED918AB7A6123F20774F8D7E1795DD6B8F7C6D6987A11B89CCC9A28F4A5CD531B8A1291D1EDE2C9C08E045160C871B57D6CAA8BF4B11995BC9EFA70
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:C source, ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):8896
Entropy (8bit):5.0104791253793
Encrypted:false
SSDEEP:
MD5:A0DA8AD054256BD445B0CC2F463DF43B
SHA1:AA9AEAB5B090B690F3978852AFBD53289B863C21
SHA-256:B1462994CE9E3BF590DBB6790D529A969826D64DE80DF51A3CAAD92581DD52DF
SHA-512:40C863CFB1062A507F80A1DEB5E972F4B4F33E2B4543841D1928A46B2CEB843C855B0E26A71C1B71CF7C9E36BB48F3E7D7E2372EDABBA3E1CB00B282AA852490
Malicious:false
Reputation:unknown
Preview:/* File: ha_auto.h.. *.. * Copyright 1996 by Hilgraeve Inc. -- Monroe, MI.. * All rights reserved.. *.. * Description:.. * This file defines all of the named constants used.. * by the Hilgraeve API. It is intended to be included.. * by any external script that is written in C++... *.. * $Revision: 2 $.. * $Date: 4/07/99 10:25a $.. */..#ifndef HA_AUTO_H..#define HA_AUTO_H....../*.. * Possible API return codes.. */..#define HA_ERR_OK 0 // no error..#define HA_ERR_BAD_CMD -1 // unrecognized API (won't happen)..#define HA_ERR_BAD_PARAM -2 // parameter out of range or wrong type..#define HA_ERR_BAD_HANDLE -3 // script handle invalid..#define HA_ERR_NO_MEMORY -4 // internal memory allocation failed..#define HA_ERR_NO_SESSION -5 // session no longer attached..#define HA_ERR_TIMED_OUT -6 // waiting function expired..#define HA_ERR_BUSY -7 // can't have two guys accessing at same time..#define HA_E
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:40842D9CDF9F9FE134134317AFF13612
SHA1:296A7C89FDC41DF8B516878AE764B819998A0752
SHA-256:A4EEF119E7DD33C084F3F8D8A2CF4DF17CC6C1A6B682B29726434B00DE40601A
SHA-512:45B40761FD5F64F82C708D8CFBEF94FF0AA302906B4B3F74FF902B8DF789F162F3C141DAC5B042DACFC35A2D9C24DD96A1166D73D9442745CA98D2850246F863
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 4%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............V...V...V..V...V].V...V..V...V...V...Vb.V...V..V...VRich...V........PE..L......X.................`...`...............p....@..........................................................................u..<....................................................................................p...............................text....Q.......`.................. ..`.rdata..r....p.......p..............@..@.data...hK.......@..................@...........................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows HtmlHelp Data
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:DCE7CE2B5E7CE0EA366E12091531FB2A
SHA1:51CFA23236DB6A048D8506B964986FD402534DBF
SHA-256:3F24AD77835EB70B93DB6A77D248AB25C6DF3B10C98BF63F6157DA848DD3668B
SHA-512:8DB5329E15E975EB36A6F9EA2F529A8921E3321A7717C9EE1091360CBF8026C6D8BFD17B14C7FBC08074D76F24B70CFBAA4FE58C5C119990010F08193D06E8A4
Malicious:false
Reputation:unknown
Preview:ITSF....`.......i..........|.{.......".....|.{......."..`...............x.......T........................F..............ITSP....T...........................................j..].!......."..T...............PMGL................./..../#IDXHDR......./#ITBITS..../#STRINGS...P.../#SYSTEM....../#TOPICS.....@./#URLSTR...W.y./#URLTBL...G.../$FIftiMain..../$OBJINST...H.?./$WWAssociativeLinks/..../$WWAssociativeLinks/Property...D../$WWKeywordLinks/..../$WWKeywordLinks/BTree...L.L./$WWKeywordLinks/Data......./$WWKeywordLinks/Map....../$WWKeywordLinks/Property...$ ./hagv.hhc...X./HAGV.hhk..X.../html/..../html/hagv0085.htm...U.^./html/hagv0434.htm......./html/hagv0853.htm..`.../html/hagv0c4l.htm..B.C./html/hagv0vjk.htm...'.?./html/hagv0wc8.htm....<./html/hagv181c.htm..f.../html/hagv1g4z.htm...n.../html/hagv1sj8.htm.....i./html/hagv1tk7.htm...Q.{./html/hagv1vqd.htm...h.!./html/hagv225w.htm...k.u./html/hagv31ym.htm..=.;./html/hagv33uf.htm...M.;./html/hagv3i9e.htm.....~./html/hagv42b4.htm...f.../html/ha
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows help file Content, based "HAGV.HLP", ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:680D81A8D528AD05914CD192D49B5FB2
SHA1:A4D8F089A355F5BEF63CE5A5D00F30B1F7273554
SHA-256:58C0D4534F56CDCD02267F81A39B2D4BD57CD05372EDF7FD0406B848FC090DFB
SHA-512:3DDB5A14B46773972647FCEFB97CFED070233BF99D05FFD80AF16BBF89EDC353EC3DD23CE333E0925B6DBC2BCB2BF053ABE9A42F5205238F1E40FE5A90E54D58
Malicious:false
Reputation:unknown
Preview::Base HAGV.HLP..1 HyperACCESS Graphics Viewer Overview..2 Overview=main_index..1 File menu options..2 Open=AFX_HIDD_FILEOPEN..2 Print Setup=HID_FILE_PRINT_SETUP..2 Print Preview=HID_FILE_PRINT_PREVIEW..2 Print=HID_FILE_PRINT..2 Recently used files=HID_FILE_MRU_FILE1..1 Edit menu options..2 Copy=HID_EDIT_COPY..2 Zoom In=Edit_Zoom_In..2 Zoom Out=Edit_Zoom_Out..2 Fit image to Window=Edit_Fit_Image_to_Window..1 View menu options..2 Toolbar=AFX_HIDW_TOOLBAR..2 Status Bar=AFX_HIDW_STATUS_BAR..
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Windows Registry text (Win95 or above)
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:16A9E1E278C951186CE5D7B22A9DC533
SHA1:4E7FE7D74770A34280F4B9B07BFD7143EEDB76A0
SHA-256:56C3471FEA7910CB4BE69A9DD23164EEF2F9B150752F0A49AB27C3A3AF5D3479
SHA-512:A5A67B842FE192171D0A1ACB9BA23206CE5135AF81F7CA585B6507F4E8A8569FE9A1D6BA529C3E55F7C03A156AAD570ED0158B10DAE290FC6ADB74846AD4A1C9
Malicious:false
Reputation:unknown
Preview:REGEDIT4....; File: D:\uw\hagv\hagv.reg (Created: 11/6/96)..;..; Copyright 1996 by Hilgraeve Inc. -- Monroe, MI..; All rights reserved..;..; Description:..; Run "Regedit hagv.reg" to make HAGV the default graphics viewer - mrw..;..; $Revision: 1.2 $..; $Date: 1997/01/16 12:22:16 $..;....[HKEY_CLASSES_ROOT\.bmp] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.cmp] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.dcx] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.dib] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.eps] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.fpx] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.gif] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.ica] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.img] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jfif] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jpe] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jpeg] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jpg] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.mac] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.mpt] .. @="HAGVImage"..[HKEY_CLASSE
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows HtmlHelp Data
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:9AD660FDE96EEF9C1E87948070AFA11D
SHA1:238A240B653F7F6F42D3F610BEFD721532A2E3FB
SHA-256:DB5C7B3CF47647819EA5D3A2AAA3BEB3BCD908B866AB4937203F5C6CE5B5D763
SHA-512:3CCCE08F304FB25776DD537BD4BA6C531BF099A34A1F0AE64CB7366430F74D8B61C986E07B9F0667F94568E6FA86E0D6EB6CABBD01B058B9E919F4A179403BE0
Malicious:false
Reputation:unknown
Preview:ITSF....`.........@.......|.{.......".....|.{......."..`...............x.......T......................................ITSP....T...........................................j..].!......."..T...............PMGLH................/..../#IDXHDR......./#ITBITS..../#STRINGS.....u./#SYSTEM..F.../#TOPICS......P./#URLSTR..5..V./#URLTBL..m.H./$FIftiMain..../$OBJINST...^.?./$WWAssociativeLinks/..../$WWAssociativeLinks/Property...Z../$WWKeywordLinks/..../$WWKeywordLinks/BTree...I..L./$WWKeywordLinks/Data......./$WWKeywordLinks/Map....."./$WWKeywordLinks/Property...: ./HACTXT.txt......E./hawin32.hhc....../HAWIN32.hhk......../html/..../html/hact0241.htm...Y.@./html/hact0242.htm...n.N./html/hact02az.htm...8.P./html/hact02qt.htm...S.B./html/hact02zs.htm...p.y./html/hact03e9.htm...K.U./html/hact03hf.htm...S.w./html/hact0411.htm.....T./html/hact044v.htm...P.../html/hact04tw.htm...h.Y./html/hact04vg.htm...~.J./html/hact052r.htm...#.p./html/hact06gk.htm...y.Q./html/hact07s4.htm..._.(./html/hact08c3.htm...
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows help file Content, based "hawin32.HLP", ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:C463B704F4BB8F67212C3AD484A09421
SHA1:4EF1735A426766E112B4A9EC24F970ED17EEBF18
SHA-256:9A74D0FBE67867801ECDE9AAC90D8CBCD3DC7084A28A9D7A1A3CFEDDB05E07BF
SHA-512:AD502CA3FEAB8164EFBA97F99811E6E951EFEE6CBD58254B0346F164CC3AD8B90A255C78BA189848995266DA7FD3ACDA108EFB6C2E94AF0D8C2042618A6B69E0
Malicious:false
Reputation:unknown
Preview::Base hawin32.HLP>main..:Title HyperACCESS Help..1 Getting Started..2 HyperACCESS Overview=HyperACCESS_for_Windows_95_and_NT_Overview>main..2 Microsoft Office 97 Compatible=Microsoft_Office_97_Compatible>main..2 Modem Basics=Modem_Basics>main..2 Using drag and drop=Using_drag_and_drop>main..2 Using pop-up menus=Using_pop_up_menus>main..1 Selecting Settings..2 To select a terminal emulator=To_select_a_terminal_emulator>main..2 To select ASCII settings=To_select_ASCII_settings>(w95sec)..2 To specify how keys are to be used=To_specify_how_keys_are_to_be_used>(w95sec)..2 To select communications settings=To_select_communications_settings>(w95sec)..2 To select fonts=To_select_fonts>(w95sec)..2 To specify modem commands=To_specify_modem_commands>(w95sec)..1 Working with Notebooks..2 To add a notebook entry=To_add_a_notebook_entry>(w95sec)..2 To change the appearance of a notebook=To_change_the_appearance_of_a_notebook>(w95sec)..2 To change notebook entry defaults=To_change_notebook_entry_de
Process:C:\Users\user\Desktop\h32trial.exe
File Type:data
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:B221BB3FB2852F6DEF5B336D4AC079C2
SHA1:B224381061A0DF40D21ED931C79DA776242577BE
SHA-256:234677273D3B29017933F8030D99D80D44BEF9EC555F80436A5F18E2AB19BD89
SHA-512:B915738FBAF0F7933D2FB387730DEE7DDA84A0C7EA15A345800A793973ABB4ADA4A39C76B51E6482ACE726C388D54E76CAFDA69623903825DC9BBC61BF108548
Malicious:false
Reputation:unknown
Preview:MSFT................A............................................... ...................d.......,...........X.......d... ...........4...............@...................@...........................................\...............\...|0...........8...............................................8..p........................................................... !..T9..............................................................................................$!...N..............................................,...............................................%!...O......................................0.......D...............................................$!...O......................................H.......\...............................................$!..hr......................................`.......t...............................................%!..Ds......................................x.......................................................$!..Ds......................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:data
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:CEF07AB0923D8F2B180DCA7AC32F381E
SHA1:9832EBF2D91DD27DF06620016D3BFC92279C9D5A
SHA-256:966757B29CC5F532B7790889F41E07946A6951550F8DF8040A7461359A9A321B
SHA-512:A055D4CA96C17937E732FE668745487D6B28A6D8272427A25D57DCDA48FC365E9EF9183DEFF63379B1094A7CF7901B8F88097D52D8571684A5F19FB9E1AC7E18
Malicious:false
Reputation:unknown
Preview:......A........?..#6I.&...o.A#..2a.(x0..e.p.RT .A$a..3..A.&Q...%A.2i.,y2...>...2.gQ\...T...M.&....e.K.b..5.O.S.V..u.Q...Z%Z6*.jk^5./eW....%.w..y..)...`..:N.............x7+..X.L.c=K6-T.AV.v..5+..S.:..1.D."P.......9o.X.....9e.............~.......`"I..N......I.2...3|...h.8.."o...q.Y.B...D.-.......s.......i.1F.2.C..0p.....?...@.WE4E.r.a..A@ "A$....5".`W.!..-.P..3..B.C.I..5().B....9.0..7..D.'.P.-..b.3...:.......d.E..$.M..d. L..Xj..AAl.3k...=.b....F..e.aG..1..s...Ed ...0"......A..r....&D.n.A..C`pj.Q..*...j..c.z..:....4k....%.`.(./d.v..n.h.v.^.......u".$.zB)..x...]...?r(..?.8....t)..n.!.qE.@....x....s.".83...t .AG.A...U...90.p.....<...U..4...DLQ..3.q2.O.c......?2dS....DDHa.Q.. ....4......$...twE?O..X.n....4.s.rDC..s.`.....OT41..L.q).6. .A..r.$.p.I$.0sL2.....V....B.Q..t..B...3.&.\.x4...O._...M.P..hX.y...R..6t.{4..KG...y.L..4.C.]..*.C..F....D...r.a|.u.P.....)......2.+......3a..u....J....04P....R.<...~X.%K.P..@0...MFpG?.G.)t..w!.....<....$Gwv../."...G.\.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:C58810399B9D62F874F125B47B54BDED
SHA1:10AE3378B4946DAC8F8FDD37EBE01C0D37B42A57
SHA-256:6A1A07A38DAD76818F976315B50D2C1EC93D8BB6FDD1B2425A4161ACCE97174E
SHA-512:EA9E0A3D17087D03F9FE5D15BF6C086764FCC8F84C277D3131D65D49C4C1724F55BE9E2D3B1051804721D1E5C38351B13A181CA5D16A652F5779A4E627E1B7CA
Malicious:false
Reputation:unknown
Preview:{\rtf1\ansi\ansicpg1252\uc1 \deff0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f3\froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f32\froman\fcharset238\fprq2 Times New Roman CE;}{\f33\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f35\froman\fcharset161\fprq2 Times New Roman Greek;}..{\f36\froman\fcharset162\fprq2 Times New Roman Tur;}{\f37\froman\fcharset177\fprq2 Times New Roman (Hebrew);}{\f38\froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f39\froman\fcharset186\fprq2 Times New Roman Baltic;}..{\f40\fswiss\fcharset238\fprq2 Arial CE;}{\f41\fswiss\fcharset204\fprq2 Arial Cyr;}{\f43\fswiss\fcharset161\fprq2 Arial Greek;}{\f44\fswiss\fcharset162\fprq2 Arial Tur;}{\f45\fswiss\fcharset177\fprq2 Arial (Hebrew);}..{\f46\fswiss\fcharset178\fprq2 Arial (Arabic);}{\f47\fswiss\fcharset186\fprq2 Arial Baltic;}}{\colortbl;\red0\green0\blu
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:91BE38010FE0D92B06DE3E54816FD4EF
SHA1:85F357FD6D151A221B7DB93B0CBABFA082074D78
SHA-256:D8A923781623FC81CBA94D555D47370BAEA492F3237CC1537EFEC52F64E6BD38
SHA-512:84DE6E17D644B287C32AEFEE854AA2D6E590C4E3C391D37A91AEE6DB79F73C208923475DA7A16FFE61544E3E8662DD422BE1AADB37910C13926E8682ADF35A93
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 4%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................................V....n....V....Rich...........PE..L....~.7................."...........!.......@....@..........................p.......................................G..i...$A..d....`..@............................................................................@..$............................text.... .......".................. ..`.rdata..i....@.......&..............@..@.data........P......................@....rsrc...@....`.......2..............@..@................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):126976
Entropy (8bit):5.728660202665843
Encrypted:false
SSDEEP:
MD5:7C91C0B44F9ED4FAB795DF6DEFC09BE3
SHA1:F2817852C7BF8923C9DEB33D81C87DD9974696A2
SHA-256:9C399A84AA22B6B01046D374E19C77FF91ECE8ACD292E84FB415E1B9BFDD056D
SHA-512:096CFF42B037F5931769BFE58E6AA64308217E65E1BC12C3F3A67074C14236FC1E0E5E5CDA8579C8879DD8DDA5F09428787EAD4C929D17D2FADB62EEC32D2C30
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........S.O.=.O.=.O.=.4.1.L.=....A.=...6.L.=..3.J.=...7.C.=...9.M.=.y.9.M.=...6.N.=.O.<.p.=...9.L.=.O.=.N.=.y.7.J.=...;.N.=.y.6...=.RichO.=.................PE..L..../.X................. ..........X........0....@.........................................................................h...........X............................................................................0...............................text............ .................. ..`.rdata...}...0.......0..............@..@.data...............................@....rsrc...X........0..................@..@n.[JX...8.yMd..."..Nn..../.Vy...5..W....+.$X....cW.X....-..L.......W...../.V............MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.ADVAPI32.dll.ole32.dll................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):36016
Entropy (8bit):6.647007482669888
Encrypted:false
SSDEEP:
MD5:67663D098D4D26AD3CEF9D61691C6920
SHA1:6F34E686F44F8EDF3909A5727E5DADF03AFF0B5C
SHA-256:A74C3E9D5059ABF97535DD436A09D934DA64D7C71F79347FA16646BC42347DBE
SHA-512:ECF32D007BB8CD2785EE0AF036763F080E7D45C58B05AAE32DF74E48453727E155E265EF51615AC2E59BBDADB38DBBAD70C6A16CCE96A9A9952ABF8A9BB2CBE8
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........d.d...7...7...7}..7...7.'.7...7B..7...7.'.7...7.'.7...7.$.7...7.$.7...7)..7...7)..7...7...7...7>%.7...7.'.7...7...7...7Rich...7................PE..L...qp4A................p`.. m....................@..........................@......!.......................................`........0..............................................................................................................PREVIEW.D........................... ...WeijunLip`......p`..................`....rsrc........0......................@...........................................................................................................................MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll....................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):1785856
Entropy (8bit):5.933454245448798
Encrypted:false
SSDEEP:
MD5:49BBAF1C63A0EB054AC7003FC7B50C7F
SHA1:2F70F87FAA17DE4742B5D39EC3702DD1A4687085
SHA-256:BC74DA8691FEF36D32756F91C02C54A69C3596FD4901DB585B78A1B674058CFB
SHA-512:8FEB114452C521C946F5728779D50B02A38AE8539AB6ABB30970DD332E71A2539F3EAE480F1FD508DB5CA5F6E51DBCD8BC1B23A1DDEE9297A4944C7C7EA5C7A1
Malicious:true
Reputation:unknown
Preview:MZ......................@...................................8...........!..L.!This program cannot be run in DOS mode....$........+...J.E.J.E.J.E.h.E.J.E.V.E.J.E.U.E.J.E.h.E.J.E0V.E.J.E.h.E.J.E.h.E.J.E.l.E.J.E[U.E.J.E[U.E.J.E.J.E.O.E.U.E.J.E.J.E.J.EtL.E.J.E.l.E.J.E.l.E.K.ELj.E.J.ERich.J.E........................PE..L..../.X...........!.........p......#........................................P......u...............................p!.........,....`...Y......................T2..............................................0....................................text............................... ..`.rdata..\...........................@..@.data...H...........................@....rsrc....Y...`...`...P..............@..@.reloc.............................@..BB..L....+.[J....n.[J....8.yM...."..N...../.V....5..W....+.$X....cW.X....-..L.......W.....P.W.....:U...../.V.......W ...........WINMM.dll.VERSION.dll.MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.comdlg32.dll.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):49152
Entropy (8bit):4.388122183411988
Encrypted:false
SSDEEP:
MD5:D2164F35F81529FADFDA1ABAAB43424A
SHA1:EA9231E0815C878480BCB71A80F8EA862DB0742B
SHA-256:15BC75036BC322FE5CC6EA4E53AA8238D50FE5E35F672696F2A047C608205FCC
SHA-512:86439EFDEF414C7194156BF869ECEE043B9CB745C2A7109B4729EA0433A18F1960A406327608E7A95DC8020EDAC3284A62DEE549FE62F486AEA01A9A6FE8B860
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........5..tf..tf..tf..xf..tfE.gf..tfz.zf..tf...f..tf..~f..tf..pf..tf..pf..tf..tf..tf..ufN.tf>.rf..tf...f..tf..pf..tfRich..tf........PE..L..../.X...........!.....0..........&7.......@......................................................................@c.......]..........."...........................................................................@...............................text....+.......0.................. ..`.rdata..]+...@...0...@..............@..@.data...t....p.......p..............@....rsrc....".......0..................@..@.reloc..............................@..B./.X@...8.yML..."..NV..../.Va...+.$Xn......Wy...c.[J............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.ADVAPI32.dll.WSOCK32.dll.......................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):36864
Entropy (8bit):3.614516506092719
Encrypted:false
SSDEEP:
MD5:AE2AAD74B42EABE69A096EFDA6C1AEE5
SHA1:56A7944BA1F78D9DAC790D295542DB6C2AC8F42B
SHA-256:795B8847C8F65DF5ACF8E8D8464EA47D61D2CBC33875927834AC1972A2E8ACC3
SHA-512:AAFBEEE2E0C83DF6682334C93DF11D3D84C46DEDD3EDC2E6F9E3B299E90FE83B01B857126662AD7059D1111A5170E9CA8453A43F27DC152422C664A6F495F95C
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........;d.Z...Z...Z..=E...Z...F...Z...x...Z...x...Z...x...Z...|...Z...Z..*Z...|...Z..F\...Z..~z...Z..Rich.Z..........PE..L..../.X...........!.....0...P......c........@.......................................[...............................R.......M.......p..........................h....................................................@...............................text.... .......0.................. ..`.rdata.......@... ...@..............@..@.data...4....`.......`..............@....rsrc........p.......p..............@..@.reloc..............................@..B./.X8...8.yMD..."..NN..../.VY...+.$Xf...c.[Jq...........HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.WSOCK32.dll............................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):40960
Entropy (8bit):4.309483461771475
Encrypted:false
SSDEEP:
MD5:03BC07B4FE4161219B3300AB9D468B93
SHA1:670F9C3D9BD2E58B7649DC5C55DC2E5CB28EEA1D
SHA-256:CDF90A9D56BAAFE6E7CEA84BBC89A8F06899593FF6FE1C476296DC99EE2897E2
SHA-512:F40DD3D79F123026F4F5E5CC3727ABAB000B3A30275313829D9194F8281A1A147D08D2171C22D5C71CD7B47EDE335024F088DF9CAEEB0948EA16766D6EAAA496
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........A...A...A.......I......C.......@.......D.......C...w...C.......@.......C...A...@...A...........@...w...J.......E...RichA...........................PE..L..../.X...........!.....0...`......f3.......@......................................WQ...............................^......pW..........X.......................p....................................................@...............................text....'.......0.................. ..`.rdata...%...@...0...@..............@..@.data........p.......p..............@....rsrc...X...........................@..@.reloc..(...........................@..B./.XH...n.[JT...8.yM`..."..Nj..../.Vu...+.$X....cW.X.......W............HADLL32.dll.MSVCP60.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.GDI32.dll.ADVAPI32.dll.............................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):36864
Entropy (8bit):4.1816188209135525
Encrypted:false
SSDEEP:
MD5:2D2C9726B4868CDC157F01347C6B3B20
SHA1:3BDC9E6123BCE8728B41178BD31A6876CAA82C5E
SHA-256:2D3CAE13817A5E16F78203D7344AB4D136A854BDFAF590ED5DDF7D09E443EAC8
SHA-512:FCBD6B827289A8A2CD41C312BB00C8F3F56A9CE01338C84D25716C1088CDF142DED7A8B91DC6AED5BB772AB7F14466C2ABD74F9BEC34E1502D0C7228C241D0BC
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$....................}.....B....................................................>......Rich...........................PE..L..../.X...........!.....0...P......Y7.......@......................................qO...............................U.......O..x....p..X.......................................................................|....@...............................text....).......0.................. ..`.rdata.......@... ...@..............@..@.data........`.......`..............@....rsrc...X....p.......p..............@..@.reloc..x...........................@..B./.X8...8.yMD..."..NN..../.VY...5..Wf...+.$Xp...........HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll..............................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):118784
Entropy (8bit):4.534068978250936
Encrypted:false
SSDEEP:
MD5:5C2E0559DC4D059ED50C55096ED94F76
SHA1:34865CD2AB40B0592694E7E839927A41F2586B1B
SHA-256:7683AB7239CCAE3C20164D8979944EC65365B7BF8B6D8C3E747F1C02B343BA7B
SHA-512:71F9FDF51EB9665DC91C5302AD2B07C0970C85EAAD2085891F23A7B79D4F22C2DCF445E90C1AFB3D79171D574720D68D0DD01CF9E4261ABE1B14286CA91CD84D
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........Mk..,..,..,..03..,...0..,......,......,......,.....,..,..,..,..q,..K*..,.....,..s...,..Rich.,..........PE..L..../.X...........!.....p...P.......p..................................................................................|...`........................................................................................................................text...*g.......p.................. ..`.rdata...=.......@..................@..@.data...............................@....rsrc...............................@..@.reloc........... ..................@..B./.X@...8.yML..."..NV..../.Va...+.$Xn...cW.Xy......W............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.GDI32.dll.ADVAPI32.dll.................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):229376
Entropy (8bit):6.549940747613996
Encrypted:false
SSDEEP:
MD5:033678DB8A7927E496098C5DEE71CF8C
SHA1:88AE01DD2EAB51F525ACE145FBEFB4939AD7F947
SHA-256:D1301D2FEC57A3C8B7D57DEBA0245C6C431B6056D239A042A31E62FFE81FDB02
SHA-512:FFBD40EEA9AB35504C01818E91D86744AB0337979CBAA38D51A1F2EC61611AF315D2634FB970F297D50244856926F7BBA926A06855D9CD787B94BBB0DC66B552
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............iv..iv..iv..uz..iv.Wve..iv..K}..iv.hux..iv..K|..iv..Kr..iv..Or..iv..iw..hv..O}..iv.,op..iv..O|..iv..Ir..iv.Rich.iv.................PE..L..../.X...........!................*........ .......................................z............................................................................................................................... ...............................text............................... ..`.rdata..m.... ....... ..............@..@.data............0..................@....rsrc................@..............@..@.reloc..&!.......0...P..............@..B./.XH...8.yMT..."..N^..../.Vi...5..Wv...+.$X.......W.....:U............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.USER32.dll.ADVAPI32.dll.COMCTL32.dll............................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):49152
Entropy (8bit):4.402424358144974
Encrypted:false
SSDEEP:
MD5:59C3D89D99C2B34C4F96C6AA5BB8C3DC
SHA1:E0434F53664EB55F65EAEBF94D7AE837C8548374
SHA-256:C489B615D86E7B451C94A72AA3994EE91A8B81B8E4A9E72DE10765E9E42484D5
SHA-512:C19DB6BD6D047B193078E5E12EFDB6E04C2CEE06069A4C374452B77F8A726660CDE3442BB548FDE9846DE3F6B0BD7905F189C4DFF9082C65793C11AD73F5C643
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........5..f..f..f...f...fM..f...f...f...fr..f..f...f...f...f..f..f..f..f...f..f0..f6..f...f..f...f..f...f...f...fRich..f........................PE..L..../.X...........!.....0..........:7.......@.......................................................................c.......^..........."...........................................................................@...............................text....,.......0.................. ..`.rdata...+...@...0...@..............@..@.data........p.......p..............@....rsrc....".......0..................@..@.reloc..............................@..B./.X@...8.yML..."..NV..../.Va...+.$Xn......Wy...c.[J............HADLL32.dll.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.ADVAPI32.dll.WSOCK32.dll...............................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (console) Intel 80386, for MS Windows
Category:dropped
Size (bytes):49152
Entropy (8bit):4.47967589343775
Encrypted:false
SSDEEP:
MD5:40842D9CDF9F9FE134134317AFF13612
SHA1:296A7C89FDC41DF8B516878AE764B819998A0752
SHA-256:A4EEF119E7DD33C084F3F8D8A2CF4DF17CC6C1A6B682B29726434B00DE40601A
SHA-512:45B40761FD5F64F82C708D8CFBEF94FF0AA302906B4B3F74FF902B8DF789F162F3C141DAC5B042DACFC35A2D9C24DD96A1166D73D9442745CA98D2850246F863
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..............V...V...V..V...V].V...V..V...V...V...Vb.V...V..V...VRich...V........PE..L......X.................`...`...............p....@..........................................................................u..<....................................................................................p...............................text....Q.......`.................. ..`.rdata..r....p.......p..............@..@.data...hK.......@..................@...........................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:data
Category:dropped
Size (bytes):29508
Entropy (8bit):4.980695889759043
Encrypted:false
SSDEEP:
MD5:B221BB3FB2852F6DEF5B336D4AC079C2
SHA1:B224381061A0DF40D21ED931C79DA776242577BE
SHA-256:234677273D3B29017933F8030D99D80D44BEF9EC555F80436A5F18E2AB19BD89
SHA-512:B915738FBAF0F7933D2FB387730DEE7DDA84A0C7EA15A345800A793973ABB4ADA4A39C76B51E6482ACE726C388D54E76CAFDA69623903825DC9BBC61BF108548
Malicious:false
Reputation:unknown
Preview:MSFT................A............................................... ...................d.......,...........X.......d... ...........4...............@...................@...........................................\...............\...|0...........8...............................................8..p........................................................... !..T9..............................................................................................$!...N..............................................,...............................................%!...O......................................0.......D...............................................$!...O......................................H.......\...............................................$!..hr......................................`.......t...............................................%!..Ds......................................x.......................................................$!..Ds......................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:data
Category:dropped
Size (bytes):1739203
Entropy (8bit):7.757747388153473
Encrypted:false
SSDEEP:
MD5:CEF07AB0923D8F2B180DCA7AC32F381E
SHA1:9832EBF2D91DD27DF06620016D3BFC92279C9D5A
SHA-256:966757B29CC5F532B7790889F41E07946A6951550F8DF8040A7461359A9A321B
SHA-512:A055D4CA96C17937E732FE668745487D6B28A6D8272427A25D57DCDA48FC365E9EF9183DEFF63379B1094A7CF7901B8F88097D52D8571684A5F19FB9E1AC7E18
Malicious:false
Reputation:unknown
Preview:......A........?..#6I.&...o.A#..2a.(x0..e.p.RT .A$a..3..A.&Q...%A.2i.,y2...>...2.gQ\...T...M.&....e.K.b..5.O.S.V..u.Q...Z%Z6*.jk^5./eW....%.w..y..)...`..:N.............x7+..X.L.c=K6-T.AV.v..5+..S.:..1.D."P.......9o.X.....9e.............~.......`"I..N......I.2...3|...h.8.."o...q.Y.B...D.-.......s.......i.1F.2.C..0p.....?...@.WE4E.r.a..A@ "A$....5".`W.!..-.P..3..B.C.I..5().B....9.0..7..D.'.P.-..b.3...:.......d.E..$.M..d. L..Xj..AAl.3k...=.b....F..e.aG..1..s...Ed ...0"......A..r....&D.n.A..C`pj.Q..*...j..c.z..:....4k....%.`.(./d.v..n.h.v.^.......u".$.zB)..x...]...?r(..?.8....t)..n.!.qE.@....x....s.".83...t .AG.A...U...90.p.....<...U..4...DLQ..3.q2.O.c......?2dS....DDHa.Q.. ....4......$...twE?O..X.n....4.s.rDC..s.`.....OT41..L.q).6. .A..r.$.p.I$.0sL2.....V....B.Q..t..B...3.&.\.x4...O._...M.P..hX.y...R..6t.{4..KG...y.L..4.C.]..*.C..F....D...r.a|.u.P.....)......2.+......3a..u....J....04P....R.<...~X.%K.P..@0...MFpG?.G.)t..w!.....<....$Gwv../."...G.\.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):31396
Entropy (8bit):7.180794310963059
Encrypted:false
SSDEEP:
MD5:85DABF911B4BE0DE58517A9E9175CFDF
SHA1:3D454860FDB347E6D6E3710A0A2B77804DCE1832
SHA-256:96AA81C8ED9735CEEC9007B3F1D7B06FDA39ACAB95747879DF1CABD5FD5E6EDE
SHA-512:4A92413425DE07B8D5A4E3685918929E31F8F12A903D50E749017263B153DF754DBA2F2BC9656FB2CCE2E8B0F74AB5A75EEE33BCDDB006D1F71D750CCB6B42DB
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 10%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........d.d...7...7...7}..7...7.'.7...7B..7...7.'.7...7.'.7...7.$.7...7.$.7...7)..7...7)..7...7...7...7>%.7...7.'.7...7...7...7Rich...7................PE..L...qp4A................._..tj....................@..........................0......d.......................................`........ ..............................................................................................................PREVIEW.D........................... ...WeijunLi._......._..................`....rsrc........ .......p..E~1\MTHOMP~1@...........................................................................................................................MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll....................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):57344
Entropy (8bit):4.661735817597003
Encrypted:false
SSDEEP:
MD5:A1A7677D90909B2D6BA228AA8F79B097
SHA1:8FD7A82BF150CA556B00C81982849BD451D9ADD2
SHA-256:41D5E914504A19DD5D4DDFD0D5C3BE45519CB1D85A881297CCFA054098A4F028
SHA-512:5FD81FB71DF9EF6385C794CD08E98EC1F5AE3CA95764CE54371CE7D9040D208A671107013335C59A7C57D4D9E5C28E7BD9D910E3266D94BAB4416F6694974534
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 1%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........................#............................................................X.......Rich............................PE..L..../.X.................@...........G.......P....@................................."........................................q..........PH...........................................................................P..h............................text....<.......@.................. ..`.rdata..t....P...0...P..............@..@.data...............................@....rsrc...PH.......P..................@..@....H.......U...8.yMb..."..Nl..../.Vw...+.$X....cW.X.......W............LTKRN70N.dll.LTFIL70N.DLL.MFC42.DLL.MSVCRT.dll.KERNEL32.dll.USER32.dll.GDI32.dll.ADVAPI32.dll...................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Windows Registry text (Win95 or above)
Category:dropped
Size (bytes):1541
Entropy (8bit):5.258328110585826
Encrypted:false
SSDEEP:
MD5:16A9E1E278C951186CE5D7B22A9DC533
SHA1:4E7FE7D74770A34280F4B9B07BFD7143EEDB76A0
SHA-256:56C3471FEA7910CB4BE69A9DD23164EEF2F9B150752F0A49AB27C3A3AF5D3479
SHA-512:A5A67B842FE192171D0A1ACB9BA23206CE5135AF81F7CA585B6507F4E8A8569FE9A1D6BA529C3E55F7C03A156AAD570ED0158B10DAE290FC6ADB74846AD4A1C9
Malicious:false
Reputation:unknown
Preview:REGEDIT4....; File: D:\uw\hagv\hagv.reg (Created: 11/6/96)..;..; Copyright 1996 by Hilgraeve Inc. -- Monroe, MI..; All rights reserved..;..; Description:..; Run "Regedit hagv.reg" to make HAGV the default graphics viewer - mrw..;..; $Revision: 1.2 $..; $Date: 1997/01/16 12:22:16 $..;....[HKEY_CLASSES_ROOT\.bmp] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.cmp] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.dcx] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.dib] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.eps] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.fpx] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.gif] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.ica] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.img] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jfif] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jpe] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jpeg] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.jpg] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.mac] .. @="HAGVImage"..[HKEY_CLASSES_ROOT\.mpt] .. @="HAGVImage"..[HKEY_CLASSE
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24064
Entropy (8bit):5.264048170151945
Encrypted:false
SSDEEP:
MD5:63D13718F1A4A6C46C2A888B69BFB5D6
SHA1:5A04D39CC31E743248EA95C7F1E7B7204C32B1CF
SHA-256:8B4ADACB2386978EC2A94BC442D0205E14D1AFB9DC52FED11DE3CE4C58D71CF8
SHA-512:E7271F39804CE90FBF4A9AA733FC5610E0018F5FB4D44EE5ABA50746E4C307CC0D51FC9A63779D7ED3D2F0EBEB37B39A8ECC9441F456FDA37E8BD945FBCB56E6
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...|o.2...........!...7.0...*......G+.......@.......................................................'..................................4....................... ....................................................................................text..../.......0.................. ..`.bss.........@...........................rdata..G....P.......4..............@..@.data........`.......6..............@....idata...............J..............@....edata...............P..............@..@.rsrc...4............T..............@..@.reloc...............Z..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):186880
Entropy (8bit):6.180754098459938
Encrypted:false
SSDEEP:
MD5:24321428B4D1F4EA0208FA2C038A50D9
SHA1:C0E33015BF3A3710A660C32ACD31376B2F0720C2
SHA-256:E1A7541ACBF99352D7D8A2047333F7EA8A573D3A07DD45C2E4AD622956B17303
SHA-512:2BDEBA8FA053C6FE3FEF70F3E43558A65F87C0AB6B2BF923D043AEBDB115D4819067A54BA931830EE2AE700653DABEAD0A79356D7071A14F78424E96C39F9F14
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Ro.2...........!...7.....................@...............................0.......................'..................................4.................... .......................................................................................text...Z-.......................... ..`.bss....p....@...........................rdata..g....P.......2..............@..@.data...p....`.......4..............@....idata..............................@....edata..............................@..@.rsrc...4...........................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):23040
Entropy (8bit):5.208256979378633
Encrypted:false
SSDEEP:
MD5:7A6ABCEEE9F1317D789FB66F85BFC77C
SHA1:95662BE366CCB432F3DEA5736B2ADA4165B74D50
SHA-256:56B653A0BEF1184E2AF7B3E5B27987DEEC59DD8C1BA6E15F7DEA4BFBD8535DB3
SHA-512:01090BBA03B9F35D86608AFAA49B9D853942825A004D3F481F10D0C59D6CE20267578E7C4C9B6CA7021A9744A6056C1F505A6CB2D7A0A75AFEEE30C223EB50BF
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...sn.2...........!...7.0...&......Z+.......@.......................................................'..........................4.......4.......................|....................................................................................text..../.......0.................. ..`.bss....t....@...........................rdata..G....P.......4..............@..@.data........`.......6..............@....idata..4............H..............@....edata...............L..............@..@.rsrc...4............P..............@..@.reloc...............V..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):173568
Entropy (8bit):5.979905615542371
Encrypted:false
SSDEEP:
MD5:56DD9D305E6EE38821463B29EF5A9360
SHA1:525CDFC8CC36D7CEAF720D2A448AF26AB18D4026
SHA-256:DDB10FD752742B93F931DFA220155D58E6FBB52D4997F3C0AC9A2001BC99AFDC
SHA-512:7DDBE677732C1C79BD863FC744A9B41C68C8C97687C1ECB26B850284C5F6A81599748D65B41CEC1873545A1D60E3A232782D9F6BAF4B330333EF30F62FAA783E
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....o.2...........!...7.V...L......6P.......p.......................................................'..................................d!...........................................................................................................text....T.......V.................. ..`.bss.........p...........................rdata...............Z..............@..@.data................`..............@....idata...............v..............@....edata...............z..............@..@.rsrc...d!......."...~..............@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):32768
Entropy (8bit):5.650130014268679
Encrypted:false
SSDEEP:
MD5:93D7490AF17514E89AF47D562729C591
SHA1:3BC942252DBA16A9B32F252C04E3D22AE70A478B
SHA-256:6DCD6B3269DCC070E5BF41A34DEAB7E46F576AF942A2366A482D21B1C62466CD
SHA-512:C751F0112455E368837C9C74A6E3DD491598921FE47D1F0EC7911CFDEFED79BABE8268D46C660E91E822A08C1CCEDBF07E690ABDEBBE131FAAB5CB3D105E30E2
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....o.2...........!...7.T...(.......M.......p.......................................................'..................................4............................................................................................................text...6R.......T.................. ..`.bss....t....p...........................rdata...............X..............@..@.data................Z..............@....idata...............l..............@....edata...............r..............@..@.rsrc...4............v..............@..@.reloc..l............|..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):20480
Entropy (8bit):4.886080308849216
Encrypted:false
SSDEEP:
MD5:A324A48F1AA95C87AC9D8675CA1D8AD1
SHA1:F1B98F4D5ED1FF2CFC239907310EDC368FE19DB4
SHA-256:D5F9A096D89DCFF1DDAABE66B0ED2BD052E218B0F42E54AEEEA8287BA4CBB045
SHA-512:97AC38766F577A4AED71A64BC901131A5C4A73EFC42AF81BEBD3B94EBD7B969959B75BFF419BEBC2D602CBDAB9D63710B93B1116963F5D12011EB5B9137CFD5F
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...>p.2...........!...7.&...&......v .......@.......................................................'..........................,.......4............................................................................................................text....$.......&.................. ..`.bss....t....@...........................rdata..G....P.......*..............@..@.data........`.......,..............@....idata..,............>..............@....edata...............B..............@..@.rsrc...4............F..............@..@.reloc...............L..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):18944
Entropy (8bit):4.8188110916850135
Encrypted:false
SSDEEP:
MD5:193B25CC278B097F58B9653E3DC58859
SHA1:B37CED6FC61A8D212AED5679A6EAAAA5DEE1990C
SHA-256:7246F76CE4F3CD700254C187B5C8CAD01A4D6091163994F8DB343D7812C96DC8
SHA-512:E8B671792D113A0E01DD63D14A12F9032B3F38AC59E45918A8519352CC0A03E38F866AB4C4129EAD40C05D14727647D6FACE8E88C9993FE61A5BED2BCCDCB8B0
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p.2...........!...7. ...&......@........0.......................................................'.......................p..p.......4............................................................................................................text............ .................. ..`.bss....t....0...........................rdata..G....@.......$..............@..@.data........P.......&..............@....idata..p....p.......8..............@....edata...............<..............@..@.rsrc...4............@..............@..@.reloc...............F..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):19456
Entropy (8bit):4.810079029217241
Encrypted:false
SSDEEP:
MD5:592D195C1AF08E879DF29F2BF1450FE5
SHA1:07FABBDE07FB71994DFE33AA5CE7F420AB75A17E
SHA-256:95BAEF4937ECDA178535AA05C9B0736CEAC9A67199152E664345DEB9F044AE6B
SHA-512:C852FA0D69E99D9B148CE6B385F5D9B9C81C97ADC4F41BAB208E097C7AF5E67087DD2F7E1EDBFF624DE3F959020F94C1C37DCD45DC37A9DC1221C5E1A80BB284
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p.2...........!...7."...&...............@.......................................................'..........................,.......4............................................................................................................text...T!.......".................. ..`.bss....t....@...........................rdata..G....P.......&..............@..@.data........`.......(..............@....idata..,............:..............@....edata...............>..............@..@.rsrc...4............B..............@..@.reloc...............H..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):19456
Entropy (8bit):4.8758944941781355
Encrypted:false
SSDEEP:
MD5:196E99CD54C64836F072F9B399DAAAB0
SHA1:F095C8E83E7FAF4E0408455419EA4A2C67722D04
SHA-256:F0A6181BCECF46C668B93BACB48FA9972AF925C450A66BDA51A900258868FDA5
SHA-512:26977088F30B70E45076E7C8903920DC7276C41DA757B5FFE00C79EACFAAC786069BBEA4A5B06B27224ECCC3006DE7C66D56E829DA16E9C723711409B9476D34
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Dr.2...........!...7."...&......(........@.......................................................'..................}...............4.......................L....................................................................................text...v!.......".................. ..`.bss....t....@...........................rdata..G....P.......&..............@..@.data........`.......(..............@....idata...............:..............@....edata..}............>..............@..@.rsrc...4............B..............@..@.reloc...............H..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24064
Entropy (8bit):5.28201590412618
Encrypted:false
SSDEEP:
MD5:8700CAB20F2CCA4AE56D466B30624992
SHA1:CFEF501165DD9ECC287A4ACD5900B39D3C32556F
SHA-256:B09A8800E560D37AA3EAEA924098D73A07B25205D4C640E4C7A805972B3405EB
SHA-512:3A333CDDD2CB173CB2CDAE9401D4DAB9695261DFAB18E004DE21D31322638E279FF3B35F9FF7373036D30D380DFE26D0EF511D40963B5DFED70AC63A4990F2E0
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p.2...........!...7.4...&......./.......P.......................................................'..........................,.......4.......................d....................................................................................text....3.......4.................. ..`.bss....t....P...........................rdata..G....`.......8..............@..@.data........p.......:..............@....idata..,............L..............@....edata...............P..............@..@.rsrc...4............T..............@..@.reloc...............Z..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24064
Entropy (8bit):5.233228747310242
Encrypted:false
SSDEEP:
MD5:64018FB2B5152F4F32CC8FFEA1A79744
SHA1:86143A9DCA3F5D1997EAAE5F7755D6D5090DC075
SHA-256:930A9CF80567119C1BDEF3BEA292AA9537E0A5DAFB8954E7815DC2B1AA9AD536
SHA-512:FB5EB5552D6A33C9DF4798EE8FB46330A69DA3FD0E37A6F5C4C609A10665DD19F90F09411B000B24013654F7804BA9B37D3B2AC5D084F83A72B4BB4E5F18AF27
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....p.2...........!...7.4...&......B/.......P.......................................................'..........................4.......4.......................4....................................................................................text....3.......4.................. ..`.bss....t....P...........................rdata..G....`.......8..............@..@.data........p.......:..............@....idata..4............L..............@....edata...............P..............@..@.rsrc...4............T..............@..@.reloc...............Z..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):111616
Entropy (8bit):6.462425723495829
Encrypted:false
SSDEEP:
MD5:7BE132446715A4B9B44DEF2AAE9CF375
SHA1:63A1055D15CEEF74B9C1FCA6FADF673FFAF1F8E9
SHA-256:7EB12E63251756AEB6B2EFEDC00F7A153286D332B4D3DC81DCC6F5D24635F882
SHA-512:A3D5B0EB75E40478E57420F2C86369373AAE261E290EA68D26B4B562571AFE0CACE400247C7D4527668BA12B8614FC216012BB10C82A4C121899CF3D1C2B5D54
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.2...........!...7.b...N..."...........................................0.......................'..................................4.................... ..p....................................................................................text....`.......b.................. ..`.bss.....!...............................rdata..'............f..............@..@.data....-...........h..............@....idata..............................@....edata..............................@..@.rsrc...4...........................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):22016
Entropy (8bit):5.136918922111934
Encrypted:false
SSDEEP:
MD5:AE951EBB5C7CED8972ED9815A2D4664E
SHA1:59238CD377B736BDD0FE1ADB78197DCDDBE25832
SHA-256:8F471C3FDF24AFCA6F5F14F5CCE7D9BCFC94799F669EAB6A5287D1B2495899F7
SHA-512:E26ADD723EE43AD6AC158DCB96DE0C756E00B35A67EA7757A2443A0792D06B14D8B903BEFBC3648B37C110D1870CD561DF8AA3A79621ADC04C3358BB6EB2A08C
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...ar.2...........!...7.,...&.......'.......@.......................................................'..........................<.......4............................................................................................................text....,.......,.................. ..`.bss....t....@...........................rdata..G....P.......0..............@..@.data........`.......2..............@....idata..<............D..............@....edata...............H..............@..@.rsrc...4............L..............@..@.reloc...............R..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):19456
Entropy (8bit):4.902482426939933
Encrypted:false
SSDEEP:
MD5:5207B570D8F6EF377BCCB9D4DE7970F3
SHA1:1D6A441437530BAFB456E3FB1F45849EF40B2949
SHA-256:B4E99C246104F574ACA7C9F0B2300EA94B3B5E445C8B24EDF273E53719AF3B9F
SHA-512:334E6DF3E6D077D81181A015561DA0BCCB67A0C13C786000DE6AFE8EE0D635C519BC9338095D204838D5ABF01DBE5CD0668F7DEC31B26F6CDC5549907C9BA8A2
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...}r.2...........!...7."...&......X........@.......................................................'..........................,.......4............................................................................................................text....!.......".................. ..`.bss....t....@...........................rdata..G....P.......&..............@..@.data........`.......(..............@....idata..,............:..............@....edata...............>..............@..@.rsrc...4............B..............@..@.reloc...............H..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):20992
Entropy (8bit):5.056945634866892
Encrypted:false
SSDEEP:
MD5:0E038E698328C4B5B129918860E77147
SHA1:9A0886FA1156D75ADDFCA295029F83D2DBD15D33
SHA-256:10FCC03AF80ABC026A8EBD62E56603B5BBDDD2542837EC331B8D019845D54762
SHA-512:84C285A4B9E773FCC9BD4F9DD3262E4DA5797B45DF409CF3008D8C4151E9E320837EFC1955B2424A10330AF795C06D5896491A50FBEED5375D6FCE2826D112AC
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.2...........!...7.(...&......*#.......@.......................................................'..........................4.......4.......................\....................................................................................text...x'.......(.................. ..`.bss....t....@...........................rdata..G....P.......,..............@..@.data........`......................@....idata..4............@..............@....edata...............D..............@..@.rsrc...4............H..............@..@.reloc...............N..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):64512
Entropy (8bit):6.116767925524969
Encrypted:false
SSDEEP:
MD5:AB41F2C63C7725291B8F0332F1BB0C0B
SHA1:C8B32C288DD62FCCC83A7A14D5F510C94B4D6A7A
SHA-256:213F84B52269728DA4C75754743353AC59F3E83B0A01FA6CBFCC303C394F2712
SHA-512:FA0F92D9BA482E11CE973FE9B2E31B540CDB824325162914EEDF525965C9A0EBC169D871D641A329F647751A66B8BBF094B9FF13E2A014D27CA11C97264D0AA6
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r.2...........!...7.....<..............................................`.......................'...............0....... ..H....@..4....................P..p....................................................................................text............................... ..`.bss....p................................rdata..............................@..@.data.... ......."..................@....idata..H.... ......................@....edata.......0......................@..@.rsrc...4....@......................@..@.reloc.......P......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):20480
Entropy (8bit):4.964086095338811
Encrypted:false
SSDEEP:
MD5:3D7E1AFE79D238A41DA4BF5247257841
SHA1:E9F4CAF53E232461BB260DC6C54BE4E42921D22C
SHA-256:D3E442CBE2627EBEEC760CA02EA4D229CF2BFE9E27540225CE17C683729D9AEB
SHA-512:3A0D55C70515AD2A7D9EA2C98BD60049A26B0B6855018D4F005CD28ECB1ED41EA20D454785D28B33BCECEDE26AE45B6E859C314B052496C97E3050710C1531A0
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...as.2...........!...7.&...&......~!.......@.......................................................'..........................,.......4............................................................................................................text....%.......&.................. ..`.bss....t....@...........................rdata..G....P.......*..............@..@.data........`.......,..............@....idata..,............>..............@....edata...............B..............@..@.rsrc...4............F..............@..@.reloc...............L..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):21504
Entropy (8bit):5.010973293770967
Encrypted:false
SSDEEP:
MD5:CC5ADF1CE7F2FA0F9F66DF9771B37996
SHA1:62944A7416F5D77843779BE770AE459538777CA6
SHA-256:963EEDE41CBEB998318E4875AF6741E063961CACA419067A504D8D12D1961F63
SHA-512:A3E5D152B92EAC13AF62098E7D307DD01D3AF7C56E45D88917E59726B881141ECF6D056DC521BF07798B2E7DD4A8FC6D90EA88961551D9828CA1448331C42848
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Ds.2...........!...7.(...(.......".......@.......................................................'..................-...............4.......................T....................................................................................text....&.......(.................. ..`.bss....t....@...........................rdata..G....P.......,..............@..@.data........`......................@....idata...............@..............@....edata..-............F..............@..@.rsrc...4............J..............@..@.reloc...............P..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):26112
Entropy (8bit):5.366002096431201
Encrypted:false
SSDEEP:
MD5:0EAD07DDFD393530F0C8C56668B888AD
SHA1:05CE38168C3D5504AC9AC2B2523636814BC37993
SHA-256:922E8A884E8B482F6FC2DE5B0EA334C2A04A749A81C77204E0591EC1175A931F
SHA-512:6075B1DCC78CD4D0FA9EF07F62A04A7713DD3661368F4737346132D554F3F133AE7FE2571DBC37BFA1C6FBB4A3B2F45A29F18905C866377526D8CAF0B47A77A3
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L..."p.2...........!...7.8...*.......*.......P.......................................................'..................................4.......................x....................................................................................text....6.......8.................. ..`.bss....t....P...........................rdata..G....`.......<..............@..@.data........p.......>..............@....idata...............R..............@....edata...............V..............@..@.rsrc...4............Z..............@..@.reloc..r............`..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):18944
Entropy (8bit):4.750582192236029
Encrypted:false
SSDEEP:
MD5:9E646618E993B7B370D631329FF5788A
SHA1:C0AB8FA8DA388612D5D97A4DBEEACAF7CA6D43FE
SHA-256:FF85467EDD7A225AD6BE2A1A39A5F47D88A70CC2F29D4DEEB8EB7FA656685A4B
SHA-512:28AA235CF7A15ABB5A46E0FFD792A559311C9D4854C62F1E251EB549FB246BAD4AD9FC1C47389833D7CDC31A7243B1E27EB2B08474963A64349E7AE5BCCAA16D
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....s.2...........!...7. ...&...............0.......................................................'.......................p..^.......4............................................................................................................text............ .................. ..`.bss....t....0...........................rdata..G....@.......$..............@..@.data........P.......&..............@....idata..^....p.......8..............@....edata...............<..............@..@.rsrc...4............@..............@..@.reloc...............F..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):19968
Entropy (8bit):4.930894930897832
Encrypted:false
SSDEEP:
MD5:CBF675D16DA0E9246EC825B247F314DC
SHA1:789CC314FE332C8AFE68A8DBF6750A805179285C
SHA-256:466328AC5D9BC9B7F71BA0030E612955ECAEC61A832A5B37D8B25B5625E995B7
SHA-512:30FBF508ABC91BA9F6DE00183D8429AE4DE1A24CA7B265DA5A933F58C719BCDBD769905AEB01BF0BC55C47B8D2C346F8BABF1343C990452F0CB5DA3107BCE003
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......2...........!...7.$...&......Z........@.......................................................'..........................Z.......4.......................h....................................................................................text....".......$.................. ..`.bss....t....@...........................rdata..G....P.......(..............@..@.data........`.......*..............@....idata..Z............<..............@....edata...............@..............@..@.rsrc...4............D..............@..@.reloc...............J..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):17920
Entropy (8bit):4.541494880945343
Encrypted:false
SSDEEP:
MD5:9BAB5B647D8DCE9156CD788366F9FB3E
SHA1:69958E4006821B15FC174E94AA4199E79EC98DDD
SHA-256:2497F2E40AF14D51905CF5414EC6BBADABD33CB95771B2AC03DBB12C71035DF0
SHA-512:1875DEE3525F2295CE6C732EDC6E9407342377AF2872AF9E62887B9E978638065C10DF06B16B6B7FA9477129CDBEC8652480D07661CBC26C1816E7F8FD3F969D
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...Sn.2...........!...7.....(...............0.......................................................'.......................p..n.......4............................................................................................................text............................... ..`.bss....t....0...........................rdata..G....@......................@..@.data........P....... ..............@....idata..n....p.......2..............@....edata...............8..............@..@.rsrc...4............<..............@..@.reloc...............B..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):29184
Entropy (8bit):5.4444066531985476
Encrypted:false
SSDEEP:
MD5:D53F14137F49B14608333B3300898DB7
SHA1:C4B2D5686F1AB12E6897D184D45EB5540B7AD0BF
SHA-256:54EE23B030B683210EABCBD35733430EBAE3AAA804A4E8161E2F978822A22031
SHA-512:B45C54F4F05FCF0540B69D733BB1C829B3DE2A98DDEDB9A2F61345C66D11BE723B4DA219BDAFB724C64AD60DFAD45336B3603EB7813E2D51182828E470F68313
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...`p.2...........!...7.H...&.......A.......`.......................................................'..................................4............................................................................................................text...(F.......H.................. ..`.bss....t....`...........................rdata..W....p.......L..............@..@.data................N..............@....idata...............b..............@....edata...............f..............@..@.rsrc...4............h..............@..@.reloc..4............n..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25088
Entropy (8bit):5.174559625094688
Encrypted:false
SSDEEP:
MD5:83647028FA8469173E5634F1FCE1DB56
SHA1:B87140C168DEFE7A07B4F0AE9374FE700589A8DE
SHA-256:40C496A5821EB61D4576113CF1798666596163ABC40DD31FAAA3FC8068FF8C64
SHA-512:DC955F72C18E3CD6469ECC01EBFEC7ACBBFD7680B216C1529702DF6C3DBADB0F1545B87DBBD0F95E162F5C2AAF79882B23601A911E54DE628E5E55F9771367F9
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...~p.2...........!...7.6...(......./.......P.......................................................'..........................$.......4.......................(....................................................................................text....4.......6.................. ..`.bss....t....P...........................rdata..W....`.......:..............@..@.data........p.......>..............@....idata..$............P..............@....edata...............T..............@..@.rsrc...4............X..............@..@.reloc...............^..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):53760
Entropy (8bit):5.965820957508259
Encrypted:false
SSDEEP:
MD5:8FAB2A6815A08F86A5B2EDBB5521DACD
SHA1:D007E5C101E637281806801B409A1B9D2CCC74BB
SHA-256:85BAB04440CD3BEBEC742DED2F22098250552A5BAEF51FC09346CFFD03A09C57
SHA-512:8300164D2B51B9BA68B4E2F0C230727F1CEC6F2035D487F688C529BDA72B38BA46797ED2CCBBEB2D617303AFBF87B47BAD2FE7DB1DB23F5429309BD4D324FCDA
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....k.2...........!...7.....8......z........................................0.......................'..........................H.......4.................... ..d....................................................................................text...4........................... ..`.bss.....................................rdata..e...........................@..@.data...............................@....idata..H...........................@....edata..............................@..@.rsrc...4...........................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):347136
Entropy (8bit):6.3517998873634465
Encrypted:false
SSDEEP:
MD5:CDAD34A6683587CF821B10B35C40CE23
SHA1:61C210E4328D3F6B97498C22C55F48A2528E2572
SHA-256:82599B09AEA03F021AECC565DDAB0D45DF4ED643664E7D018ED35C554AD7B9F9
SHA-512:27E54E2396DA2E8CC56DFC48B1ED4701DB18982D093B00BA16662DE3C7937DDEB2AA15A2A50F9F1F174247FFD739DEA6D4776061E9206813228DD35A803E4248
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....W.2...........!...7.2..........R(.......P.......................................................'...............`..^....P..........4............................................................................................................text....0.......2.................. ..`.bss.........P...........................rdata..G....`.......6..............@..@.data...T....p.......8..............@....idata.......P......................@....edata..^....`......................@..@.rsrc...4............,..............@..@.reloc...............2..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):91136
Entropy (8bit):6.197298290353305
Encrypted:false
SSDEEP:
MD5:D15F6405F5F774C4179C935F36DB533B
SHA1:0DD1B1233CFC327E16F5FA7DF10240989A4C34B9
SHA-256:EFA707570BAD130F607449EB799E469FCFACAF78937314851AF7BF24F46A4E32
SHA-512:F9606C033FD942BFEFD03FE2979607CAA5604397CDE3EA06F9392165D05D10A26E4352A33AE42682AC6BFD2C3A555E66C0E85B3BB00EEBBA8CFA6958179DE7CE
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A.G2...........!.........X...............0....................................................... ...............0..........(....................................................................................................................text............................... ..`.rdata.......0......................@..@.data....A...@...0...$..............@....idata...............T..............@....reloc...............Z..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):35328
Entropy (8bit):5.743694510287527
Encrypted:false
SSDEEP:
MD5:7FA8C765DB5F79C148F300978C03822D
SHA1:9DFE140F91FEBB4F34D7FBFC0F0A65E4D52DB1DD
SHA-256:B177D0EE4E8E1FC2651136DEC049494035132C411DBCBDCBDBAF235766B03314
SHA-512:3C444A76F3A50804AA2E181E03703C7C4466E86E84DADA7390E1B86741A7C1544A786A2BC157D40E18BE9F24D8DD38A11E8CD4B685635D111033CF2FB80E778A
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....o.2...........!...7.R...4.......*.......p.......................................................'..................U...............4.......................<....................................................................................text....Q.......R.................. ..`.bss....p....p...........................rdata..w............V..............@..@.data...`............X..............@....idata...............t..............@....edata..U............z..............@..@.rsrc...4............~..............@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows HtmlHelp Data
Category:dropped
Size (bytes):18167
Entropy (8bit):5.949915746466114
Encrypted:false
SSDEEP:
MD5:DCE7CE2B5E7CE0EA366E12091531FB2A
SHA1:51CFA23236DB6A048D8506B964986FD402534DBF
SHA-256:3F24AD77835EB70B93DB6A77D248AB25C6DF3B10C98BF63F6157DA848DD3668B
SHA-512:8DB5329E15E975EB36A6F9EA2F529A8921E3321A7717C9EE1091360CBF8026C6D8BFD17B14C7FBC08074D76F24B70CFBAA4FE58C5C119990010F08193D06E8A4
Malicious:false
Reputation:unknown
Preview:ITSF....`.......i..........|.{.......".....|.{......."..`...............x.......T........................F..............ITSP....T...........................................j..].!......."..T...............PMGL................./..../#IDXHDR......./#ITBITS..../#STRINGS...P.../#SYSTEM....../#TOPICS.....@./#URLSTR...W.y./#URLTBL...G.../$FIftiMain..../$OBJINST...H.?./$WWAssociativeLinks/..../$WWAssociativeLinks/Property...D../$WWKeywordLinks/..../$WWKeywordLinks/BTree...L.L./$WWKeywordLinks/Data......./$WWKeywordLinks/Map....../$WWKeywordLinks/Property...$ ./hagv.hhc...X./HAGV.hhk..X.../html/..../html/hagv0085.htm...U.^./html/hagv0434.htm......./html/hagv0853.htm..`.../html/hagv0c4l.htm..B.C./html/hagv0vjk.htm...'.?./html/hagv0wc8.htm....<./html/hagv181c.htm..f.../html/hagv1g4z.htm...n.../html/hagv1sj8.htm.....i./html/hagv1tk7.htm...Q.{./html/hagv1vqd.htm...h.!./html/hagv225w.htm...k.u./html/hagv31ym.htm..=.;./html/hagv33uf.htm...M.;./html/hagv3i9e.htm.....~./html/hagv42b4.htm...f.../html/ha
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows help file Content, based "HAGV.HLP", ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):492
Entropy (8bit):5.266784744426353
Encrypted:false
SSDEEP:
MD5:680D81A8D528AD05914CD192D49B5FB2
SHA1:A4D8F089A355F5BEF63CE5A5D00F30B1F7273554
SHA-256:58C0D4534F56CDCD02267F81A39B2D4BD57CD05372EDF7FD0406B848FC090DFB
SHA-512:3DDB5A14B46773972647FCEFB97CFED070233BF99D05FFD80AF16BBF89EDC353EC3DD23CE333E0925B6DBC2BCB2BF053ABE9A42F5205238F1E40FE5A90E54D58
Malicious:false
Reputation:unknown
Preview::Base HAGV.HLP..1 HyperACCESS Graphics Viewer Overview..2 Overview=main_index..1 File menu options..2 Open=AFX_HIDD_FILEOPEN..2 Print Setup=HID_FILE_PRINT_SETUP..2 Print Preview=HID_FILE_PRINT_PREVIEW..2 Print=HID_FILE_PRINT..2 Recently used files=HID_FILE_MRU_FILE1..1 Edit menu options..2 Copy=HID_EDIT_COPY..2 Zoom In=Edit_Zoom_In..2 Zoom Out=Edit_Zoom_Out..2 Fit image to Window=Edit_Fit_Image_to_Window..1 View menu options..2 Toolbar=AFX_HIDW_TOOLBAR..2 Status Bar=AFX_HIDW_STATUS_BAR..
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows HtmlHelp Data
Category:dropped
Size (bytes):246036
Entropy (8bit):7.846213487265666
Encrypted:false
SSDEEP:
MD5:9AD660FDE96EEF9C1E87948070AFA11D
SHA1:238A240B653F7F6F42D3F610BEFD721532A2E3FB
SHA-256:DB5C7B3CF47647819EA5D3A2AAA3BEB3BCD908B866AB4937203F5C6CE5B5D763
SHA-512:3CCCE08F304FB25776DD537BD4BA6C531BF099A34A1F0AE64CB7366430F74D8B61C986E07B9F0667F94568E6FA86E0D6EB6CABBD01B058B9E919F4A179403BE0
Malicious:false
Reputation:unknown
Preview:ITSF....`.........@.......|.{.......".....|.{......."..`...............x.......T......................................ITSP....T...........................................j..].!......."..T...............PMGLH................/..../#IDXHDR......./#ITBITS..../#STRINGS.....u./#SYSTEM..F.../#TOPICS......P./#URLSTR..5..V./#URLTBL..m.H./$FIftiMain..../$OBJINST...^.?./$WWAssociativeLinks/..../$WWAssociativeLinks/Property...Z../$WWKeywordLinks/..../$WWKeywordLinks/BTree...I..L./$WWKeywordLinks/Data......./$WWKeywordLinks/Map....."./$WWKeywordLinks/Property...: ./HACTXT.txt......E./hawin32.hhc....../HAWIN32.hhk......../html/..../html/hact0241.htm...Y.@./html/hact0242.htm...n.N./html/hact02az.htm...8.P./html/hact02qt.htm...S.B./html/hact02zs.htm...p.y./html/hact03e9.htm...K.U./html/hact03hf.htm...S.w./html/hact0411.htm.....T./html/hact044v.htm...P.../html/hact04tw.htm...h.Y./html/hact04vg.htm...~.J./html/hact052r.htm...#.p./html/hact06gk.htm...y.Q./html/hact07s4.htm..._.(./html/hact08c3.htm...
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows help file Content, based "hawin32.HLP", ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):7028
Entropy (8bit):4.854119447116968
Encrypted:false
SSDEEP:
MD5:C463B704F4BB8F67212C3AD484A09421
SHA1:4EF1735A426766E112B4A9EC24F970ED17EEBF18
SHA-256:9A74D0FBE67867801ECDE9AAC90D8CBCD3DC7084A28A9D7A1A3CFEDDB05E07BF
SHA-512:AD502CA3FEAB8164EFBA97F99811E6E951EFEE6CBD58254B0346F164CC3AD8B90A255C78BA189848995266DA7FD3ACDA108EFB6C2E94AF0D8C2042618A6B69E0
Malicious:false
Reputation:unknown
Preview::Base hawin32.HLP>main..:Title HyperACCESS Help..1 Getting Started..2 HyperACCESS Overview=HyperACCESS_for_Windows_95_and_NT_Overview>main..2 Microsoft Office 97 Compatible=Microsoft_Office_97_Compatible>main..2 Modem Basics=Modem_Basics>main..2 Using drag and drop=Using_drag_and_drop>main..2 Using pop-up menus=Using_pop_up_menus>main..1 Selecting Settings..2 To select a terminal emulator=To_select_a_terminal_emulator>main..2 To select ASCII settings=To_select_ASCII_settings>(w95sec)..2 To specify how keys are to be used=To_specify_how_keys_are_to_be_used>(w95sec)..2 To select communications settings=To_select_communications_settings>(w95sec)..2 To select fonts=To_select_fonts>(w95sec)..2 To specify modem commands=To_specify_modem_commands>(w95sec)..1 Working with Notebooks..2 To add a notebook entry=To_add_a_notebook_entry>(w95sec)..2 To change the appearance of a notebook=To_change_the_appearance_of_a_notebook>(w95sec)..2 To change notebook entry defaults=To_change_notebook_entry_de
Process:C:\Users\user\Desktop\h32trial.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):33500
Entropy (8bit):5.083762597634261
Encrypted:false
SSDEEP:
MD5:C58810399B9D62F874F125B47B54BDED
SHA1:10AE3378B4946DAC8F8FDD37EBE01C0D37B42A57
SHA-256:6A1A07A38DAD76818F976315B50D2C1EC93D8BB6FDD1B2425A4161ACCE97174E
SHA-512:EA9E0A3D17087D03F9FE5D15BF6C086764FCC8F84C277D3131D65D49C4C1724F55BE9E2D3B1051804721D1E5C38351B13A181CA5D16A652F5779A4E627E1B7CA
Malicious:false
Reputation:unknown
Preview:{\rtf1\ansi\ansicpg1252\uc1 \deff0\deflang1033\deflangfe1033{\fonttbl{\f0\froman\fcharset0\fprq2{\*\panose 02020603050405020304}Times New Roman;}{\f1\fswiss\fcharset0\fprq2{\*\panose 020b0604020202020204}Arial;}..{\f3\froman\fcharset2\fprq2{\*\panose 05050102010706020507}Symbol;}{\f32\froman\fcharset238\fprq2 Times New Roman CE;}{\f33\froman\fcharset204\fprq2 Times New Roman Cyr;}{\f35\froman\fcharset161\fprq2 Times New Roman Greek;}..{\f36\froman\fcharset162\fprq2 Times New Roman Tur;}{\f37\froman\fcharset177\fprq2 Times New Roman (Hebrew);}{\f38\froman\fcharset178\fprq2 Times New Roman (Arabic);}{\f39\froman\fcharset186\fprq2 Times New Roman Baltic;}..{\f40\fswiss\fcharset238\fprq2 Arial CE;}{\f41\fswiss\fcharset204\fprq2 Arial Cyr;}{\f43\fswiss\fcharset161\fprq2 Arial Greek;}{\f44\fswiss\fcharset162\fprq2 Arial Tur;}{\f45\fswiss\fcharset177\fprq2 Arial (Hebrew);}..{\f46\fswiss\fcharset178\fprq2 Arial (Arabic);}{\f47\fswiss\fcharset186\fprq2 Arial Baltic;}}{\colortbl;\red0\green0\blu
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):117390
Entropy (8bit):7.8829302186730486
Encrypted:false
SSDEEP:
MD5:91BE38010FE0D92B06DE3E54816FD4EF
SHA1:85F357FD6D151A221B7DB93B0CBABFA082074D78
SHA-256:D8A923781623FC81CBA94D555D47370BAEA492F3237CC1537EFEC52F64E6BD38
SHA-512:84DE6E17D644B287C32AEFEE854AA2D6E590C4E3C391D37A91AEE6DB79F73C208923475DA7A16FFE61544E3E8662DD422BE1AADB37910C13926E8682ADF35A93
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................................V....n....V....Rich...........PE..L....~.7................."...........!.......@....@..........................p.......................................G..i...$A..d....`..@............................................................................@..$............................text.... .......".................. ..`.rdata..i....@.......&..............@..@.data........P......................@....rsrc...@....`.......2..............@..@................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Fri Jan 20 08:38:58 2017, length=57344, window=hide
Category:dropped
Size (bytes):1003
Entropy (8bit):4.612070560163086
Encrypted:false
SSDEEP:
MD5:8ABAD0E2DA567CDCDE86C978EFCE6DC8
SHA1:6A635CE9FA0E6DEBDF5891052624D00BD3B67A71
SHA-256:731E6F730DC2261587F236342C1044AD92306069DE2D07C4B89AB07A5ECB2C73
SHA-512:29B23D66BE0C53D0EDBC25CA6A08C0E861B7696F73BBEAE969CD8A23AB461BFB491442D93AD329FF7B0F9154DAD0C093C2192B30688E02C64A1983A62E31389E
Malicious:false
Reputation:unknown
Preview:L..................F.... ...$3.K....Tr.L.....%...s..........................w....P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....Z.2.....4J.L .hagv.exe..B......|XRR|XRR..............................h.a.g.v...e.x.e.......V...............-.......U...........@.]......C:\Program Files (x86)\HAWin32\hagv.exe..6.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.h.a.g.v...e.x.e.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM...?.............
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:35 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Sat Jul 31 06:35:00 2004, length=31396, window=hide
Category:dropped
Size (bytes):1027
Entropy (8bit):4.649347422334324
Encrypted:false
SSDEEP:
MD5:35BD63CBD78627874C7D974AA3BBCE55
SHA1:E8ED9A64FC9DCF97231E2138F2226B16DFD319A7
SHA-256:24CFCF4AE50ECEF5FCFC067115EFA4283B6B2095E956951409AEED122D040A39
SHA-512:8593FDF9404791BA051F990D29C2B3A591FF9C50FEA40C94A2619AE6D39A72DD49B5C938DBE7CB83FE2D0676B0768A7AF0F1C2170C0794F9DDB471341306CAD3
Malicious:false
Reputation:unknown
Preview:L..................F.... ......K.....v.L......d.-....z...........................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....f.2..z...1`< .hahost32.exe..J......|XRR|XRR....H.........................h.a.h.o.s.t.3.2...e.x.e.......Z...............-.......Y...........@.]......C:\Program Files (x86)\HAWin32\hahost32.exe..:.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.h.a.h.o.s.t.3.2...e.x.e.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H....
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Sat Jul 31 06:34:58 2004, length=36016, window=hide
Category:dropped
Size (bytes):1020
Entropy (8bit):4.646579603462603
Encrypted:false
SSDEEP:
MD5:E5E7A835FA0BCF61C51E2D0A1C511799
SHA1:D28B76C1054323FAA324B70D856467C0E2AB407F
SHA-256:DABCCB6DCC2BE6B927C3B4776484201FD01DA796FE047003009D3688AE080DE9
SHA-512:383EEF865AA2A7DAF5350A7B6E9BDBC32505DCD53FF441D1A329DCBB0C551340B098DC55D5AAEEE11D2DAA13D3B17E7ABC0DD3E3C738DA1E629E14B95749A7BD
Malicious:false
Reputation:unknown
Preview:L..................F.... ......J.....,.L.....}3.-................................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....b.2......1]< .HAWIN32.EXE.H......|XRR|XRR....?\........................H.A.W.I.N.3.2...E.X.E.......Y...............-.......X...........@.]......C:\Program Files (x86)\HAWin32\HAWIN32.EXE..9.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.H.A.W.I.N.3.2...E.X.E.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.2.1.-.2.2.4.6.1.2.2.6.5.8.-.3.6.9.3.4.0.5.1.1.7.-.2.4.7.6.7.5.6.6.3.4.-.1.0.0.3.........9...1SPS..mD..pH.H@..=x.....h....H.....K...YM
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):165376
Entropy (8bit):6.414796139900392
Encrypted:false
SSDEEP:
MD5:8C97D8BB1470C6498E47B12C5A03CE39
SHA1:15D233B22F1C3D756DCA29BCC0021E6FB0B8CDF7
SHA-256:A87F19F9FEE475D2B2E82ACFB4589BE6D816B613064CD06826E1D4C147BEB50A
SHA-512:7AD0B2B0319DA52152C2595EE45045D0C06B157CDAAA56AD57DDE9736BE3E45FD7357949126F80D3E72B21510F9BF69D010D51B3967A7644662808BEED067C3F
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............i...i...i...u...i...K...i..ru...i...K...i...i..h...v..i...K...i..6o...i...I..i..Rich.i..........PE..L...M.)=...........!................i...................................................................................5............p.. ........................(...................................................................................text............................... ..`.rdata...&.......(..................@..@.data....M... ...>..................@....rsrc... ....p.......D..............@..@.reloc.../.......0...V..............@..B................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:3B2E23D259394C701050486E642D14FA
SHA1:4E9661C4BA84400146B80B905F46A0F7EF4D62EB
SHA-256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
SHA-512:2B792296DFFA4E43BC85295DC7691BD29762CE5D9D5EAFAA74E199E6A8E5B24AA85D0A1B27776D4719A49B0D29ABCF6F240746A209528E608B596B560E5A3B88
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 1%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........9...W...W...W...W...W...V...W..D...W..]...W...S...W.Rich..W.................PE..L......;...........!.........................0...............................`......................................P:..z...`5...............................P.......................................................0...............................text............................... ..`.rdata.......0......................@..@.data........@.......$..............@....reloc.......P.......(..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):2560
Entropy (8bit):2.496115780383093
Encrypted:false
SSDEEP:
MD5:6F608D264503796BEBD7CD66B687BE92
SHA1:BB82145E86516859DAE6D4B3BFFB08C727B13C65
SHA-256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D
SHA-512:C14B7EC747357C232F9D958B44760E3A018DF628291E87DE52B8174CCC4ADA546EBA90A0E70172D1DB54FECA01B40CD3AEAA61B8A2B6F22D414BAAD1F62E8E54
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........XjS.9...9...9...9...9...%...9..Rich.9..........PE..L......4..................................... ....@..........................@....................................... ..5... ..(.................................................................................... .. ............................text...#........................... ..`.rdata..%.... ......................@..@.data...>....0......................@...........................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):12800
Entropy (8bit):5.560863816211663
Encrypted:false
SSDEEP:
MD5:484CB68472473A1A84FF07996BB8C1F6
SHA1:BCE9D810F2558E73854E7C8E05F122B002558E9A
SHA-256:15BB390AF019D92E1D02771B02335FA360DB1BB34BCF4F0C72705027428F4FF1
SHA-512:5F756D11290E0240FABEAB6CB638F7E42024B95B5A44EEA6B44DBA610919A9D9D5654A87AF29EF249FB22BFB9EAE7DADD3ABB42FAA594A465EFA1FF358A2FD47
Malicious:true
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 1%, Browse
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............o...o...o...o...o...o...o...p..o...M..o.."O...o..Rich.o..........PE..L.....*=...........!.........................0...............................`......................................`3..O....0..d............................P..`....................................................0...............................text............................... ..`.rdata.......0......................@..@.data...P....@......."..............@....reloc..n....P.......,..............@..B........................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:34598094678D948F35B37A3C42D6D43C
SHA1:054B9E438AE8FFD71FE5A87F1C152AC4457A9EF6
SHA-256:67AE6DC51BA66C50443E3B288B5EC88649CC0C50DDF79B2062E6957B57BB8BE1
SHA-512:F03DE6E0813EFD1BD9BCDC0B755A8348A0A1FB16A9D166C94022E73F4D8807ED70261890E284A7E433108D2BE8CD89428C35372CC5D3CF46345F898E7309E165
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......5.............................n....... ....@.................................................................................................................................................................H................................text............................... ..`.rdata..`$... ...&..................@..@.data....a...P...F...8..............@....idata...............~..............@....rsrc...............................@..@........................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\HAWin32\HAWIN32.EXE
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):1536
Entropy (8bit):1.1464700112623651
Encrypted:false
SSDEEP:
MD5:72F5C05B7EA8DD6059BF59F50B22DF33
SHA1:D5AF52E129E15E3A34772806F6C5FBF132E7408E
SHA-256:1DC0C8D7304C177AD0E74D3D2F1002EB773F4B180685A7DF6BBE75CCC24B0164
SHA-512:6FF1E2E6B99BD0A4ED7CA8A9E943551BCD73A0BEFCACE6F1B1106E88595C0846C9BB76CA99A33266FFEC2440CF6A440090F803ABBF28B208A6C7BC6310BEB39E
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\HAWin32\HAWIN32.EXE
File Type:data
Category:dropped
Size (bytes):512
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
Malicious:false
Reputation:unknown
Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\HAWin32\HAWIN32.EXE
File Type:Composite Document File V2 Document, Cannot read section info
Category:dropped
Size (bytes):16384
Entropy (8bit):0.3613836054883338
Encrypted:false
SSDEEP:
MD5:679672A5004E0AF50529F33DB5469699
SHA1:427A4EC3281C9C4FAEB47A22FFBE7CA3E928AFB0
SHA-256:205D000AA762F3A96AC3AD4B25D791B5F7FC8EFB9056B78F299F671A02B9FD21
SHA-512:F8615C5E5CF768A94E06961C7C8BEF99BEB43E004A882A4E384F5DD56E047CA59B963A59971F78DCF4C35D1BB92D3A9BC7055BFA3A0D597635DE1A9CE06A3476
Malicious:false
Reputation:unknown
Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):10752
Entropy (8bit):5.670351023521305
Encrypted:false
SSDEEP:
MD5:3B2E23D259394C701050486E642D14FA
SHA1:4E9661C4BA84400146B80B905F46A0F7EF4D62EB
SHA-256:166D7156142F3EE09FA69EB617DD22E4FD248AA80A1AC08767DB6AD99A2705C1
SHA-512:2B792296DFFA4E43BC85295DC7691BD29762CE5D9D5EAFAA74E199E6A8E5B24AA85D0A1B27776D4719A49B0D29ABCF6F240746A209528E608B596B560E5A3B88
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........9...W...W...W...W...W...V...W..D...W..]...W...S...W.Rich..W.................PE..L......;...........!.........................0...............................`......................................P:..z...`5...............................P.......................................................0...............................text............................... ..`.rdata.......0......................@..@.data........@.......$..............@....reloc.......P.......(..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):874180
Entropy (8bit):7.565562663542464
Encrypted:false
SSDEEP:
MD5:34598094678D948F35B37A3C42D6D43C
SHA1:054B9E438AE8FFD71FE5A87F1C152AC4457A9EF6
SHA-256:67AE6DC51BA66C50443E3B288B5EC88649CC0C50DDF79B2062E6957B57BB8BE1
SHA-512:F03DE6E0813EFD1BD9BCDC0B755A8348A0A1FB16A9D166C94022E73F4D8807ED70261890E284A7E433108D2BE8CD89428C35372CC5D3CF46345F898E7309E165
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......5.............................n....... ....@.................................................................................................................................................................H................................text............................... ..`.rdata..`$... ...&..................@..@.data....a...P...F...8..............@....idata...............~..............@....rsrc...............................@..@........................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\HAWin32\HAWIN32.EXE
File Type:ASCII text, with CRLF line terminators
Category:modified
Size (bytes):44064
Entropy (8bit):6.059737817453338
Encrypted:false
SSDEEP:
MD5:E6B84FA6EA0D1D91A317F8D7FBF3CF7C
SHA1:6D29F2A7AB32574B2C0596B1473652347350E90F
SHA-256:9B17DF6662E6FDB5AB2DDE36840F46EB937DE42E021250BAE1642EC3DC1FE079
SHA-512:E67857505B84AD845B7EE6D72DBC6BF200E0DA97E4D380090F9FDDFF9641B732D5B79350AFA66EA226CB23103781AD6629EC0474B863C3A7B74BA3E8851A3BBF
Malicious:false
Reputation:unknown
Preview:------------------------------------------------------------------------..BEGIN_LICENCE_TEXT....[Trial Parameters]..type=DAYS..start=1711621118..enddate=0..totaldays=15..totalhours=0..totalexec=0..hours=0..exec=1....[Root Directory]..path=C:\PROGRA~2\HAWin32........END_LICENCE_TEXT..------------------------------------------------------------------------..3/pSmsbRaNIgIYiJk+2zmnigqDXOic3XJ8qXruW2xBTGz2TmZkUnOozojsoYmWWZZzLoz1jz..ukHPaHahVUFBAAD9BOKW+XNXEm2Uw3YHSz8FFFoEkTTVS4cD1OW8awj1wGMPvxPH/2pTsg3k..iZu6LS2mBPwmgQqVlgO5RnWdqEIBytjtHuW3dA6YbabYsP/456PYD/rZ0x8az89HQkvimRTI..+DFF+mgh674B0dEWVWb7aScc+Nu/sLyXiak5WVp+RzrNJT9vo1hpP/w2YOPlt1SZwWlNgLum..8xY3xi/8mbbGluzyCYbZR/+Z2tUf/dvoibNp4mmjZo+Td0Ne84N4ZFiuiPnc3B1KyfLtdRZF..QiG7xnxKwt+SlDz0Ox/BxnCUBtVBDrJTSM/ck/oY274+C6lgl2N/GDOSdCWj2j5pGAqzl3XG..udktFjF2XIKoX2m5RUVPcOnOLUF4TWVjxQwKCvlKz0LkNt7sK/sc4TABwu/+JdgWv0WnDlW5..Pnt/v6kWSRt+azq2J2nlTZ3Xs0nrYYUG4HHCznwF+FjNeR/8P4x9DkuYfLF/JPKe+djNlMLP..9aZLslXSaso4mSgTugrbXtWQe5T712ps4YNYgSgTwy6wahXZ2h
Process:C:\Program Files (x86)\HAWin32\HAWIN32.EXE
File Type:data
Category:dropped
Size (bytes):457
Entropy (8bit):7.479943321398481
Encrypted:false
SSDEEP:
MD5:6B8AD357C770D0520DD6D85C5C4365AE
SHA1:AAB1CE1F7060D21D92DFE0D56C259DA50D169B6C
SHA-256:DB03B40B7E299C92440CC6ED0090F10629DB4F8C9C2359EF36C230658789EFA4
SHA-512:B79661B3D65F88A17A9BD381B8DF2AF028F8CDF004A6ECEEDBEB951B39358B1FD52770C261825DF7B196F89E2FD7BEFAFF5DFE131E34DDE8D32B33FF06DCC888
Malicious:false
Reputation:unknown
Preview:f...:..)....j..'....d..v....z.8.L.';.8b....T>.Fe.r.dX1../b.......l..n.CY4F..W..O=.Hc....=.L..F...j..n..W...d.....q.iOX~.....^.3.Q.7_..>....".@..._ NP.....K.W+.W/^Y.@..d.....L8.i...L.I.....Q...k....[3.g....z.......R...Z..'..k......;XM....R_;G.3..^...\...=.;. {.M.W{..og...C\.:J@k....[.R%....:....2...s.,.a.@......R........f...-|.T....pV.F....:;....E......d...$afZ2.Y..Y.%9>....".P.L.Ca.x.n.c3...,.z/...q@.....E..b...@C...e.......D.e....m.F
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Thu Mar 28 09:18:37 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Thu Mar 28 09:18:37 2024, length=0, window=hide
Category:dropped
Size (bytes):1153
Entropy (8bit):4.6113921498270996
Encrypted:false
SSDEEP:
MD5:AC455704C6858D2FAC167B538043CFC5
SHA1:4DC19DDAE14AA3CE8F0B438099E28317BD4F300E
SHA-256:0E8A2E8E7A898F1168BC83DCD6EF19865FA8266CEB993B148DBEA28E3C6E5246
SHA-512:8210CADBBBCFA9C99384E8D76DD1A10C39E40534289AFB192F67179C9400BF280B5166B89D5105D6696837D63AECA4D4084514379795EBC09C4667F5621AE513
Malicious:false
Reputation:unknown
Preview:L..................F.........u.L....>..L....>..L.................................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....Z.1.....|XSR..MYFILE~1..B......|XRR|XSR.....Z....................6..M.y. .F.i.l.e.s.....`.1.....|XSR..HYPERA~1..H......|XSR|XSR....kY....................6..H.y.p.e.r.A.C.C.E.S.S.......b...............-.......a...........@.]......C:\Program Files (x86)\HAWin32\My Files\HyperACCESS..K.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.M.y. .F.i.l.e.s.\.H.y.p.e.r.A.C.C.E.S.S.........*................@Z|...K.J.........`.......X.......849224...........hT..CrF.f4... ...............%..hT..CrF.f4... ...............%.............1SPS.XF.L8C....&.m.q............/...S.-.1.-.5.-.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Has command line arguments, Icon number=0, Archive, ctime=Thu Mar 28 09:18:34 2024, mtime=Thu Mar 28 09:18:37 2024, atime=Tue Oct 27 08:50:06 2009, length=184048, window=hide
Category:dropped
Size (bytes):2160
Entropy (8bit):3.5176520980356645
Encrypted:false
SSDEEP:
MD5:9C4D99E701702F588959A71AEFAEF9E4
SHA1:22BEC063A57240752F5DBB7704674CDD10C8C7AC
SHA-256:45F073F2221264463786606BDE30A53B9F8F4E8C1B596DA7A66D3A6E570AE140
SHA-512:E030DCCFCD023B7A3141FC6C832CCFDE6FF846486AF656D5E88DCE9BCF16795A9E38A54385C798F265F54AC33F3DC502DEE837573CF77F7B74A2539777086EE9
Malicious:false
Reputation:unknown
Preview:L..................F.@.. ......J....>..L.....[...V...............................P.O. .:i.....+00.../C:\.....................1.....|XRR..PROGRA~2.........O.I|XRR....................V......W..P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.)...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.7.....V.1.....|XSR..HAWin32.@......|XRR|XSR.....Z.....................x..H.A.W.i.n.3.2.....Z.1.....|XSR..MYFILE~1..B......|XRR|XSR.....Z....................6..M.y. .F.i.l.e.s.....f.2.....[;CN .UNINSTAL.EXE..J......|XRR|XRR.....\........................U.N.I.N.S.T.A.L...E.X.E.......c...............-.......b...........@.]......C:\Program Files (x86)\HAWin32\My Files\UNINSTAL.EXE..L.....\.....\.....\.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.M.y. .F.i.l.e.s.\.U.N.I.N.S.T.A.L...E.X.E.'.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.M.y. .F.i.l.e.s...I.n.s.t.a.l.l...l.o.g.4.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s. .(.x.8.6.).\.H.A.W.i.n.3.2.\.M.y. .F.i.l.e.s.\.u.w.u.
Process:C:\Users\user\Desktop\h32trial.exe
File Type:TrueType Font data, 15 tables, 1st "OS/2", 14 names, Macintosh, Key CapsRegular14352839Key Caps NormalConverter: Windows Type 1 Installer V1.0d.
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:08F172BF26062E768DC8F31483BE76E9
SHA1:1EB29B23487B6AC205C00E6EEC52130F989798F2
SHA-256:8EFF1BBAB9365F8F99CC11DE2777689DBF3D087351D7DE5A4E9C42CCC3604167
SHA-512:332BD8CDDAFD9C6D9BFD5A062138D745D2C9A6F97A7CE532743D4999622AF159DF91EA9DD321AD1ED14BBDB70C8C1D452D23037CED66C12782E75FAEB194A795
Malicious:false
Reputation:unknown
Preview:...........pOS/2...........Ncmap..........cvt .G.O...|....fpgm.(.C...L...0gasp............glyf.a..........headl.K....H...6hhea..1........$hmtxL# k.......\kern............loca.C.3........maxp.......P... namee.....p....post.n....\....prepa.?:.......Z.........@........""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS-DOS executable, NE for MS Windows 3.x (DLL or font)
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:FBBC6B6B50E599E8B8F3E94283FAF893
SHA1:3A11720D18C78B83C312878DAF542BBFAE5C45DE
SHA-256:F11E60D1987419265F8B2729672A12A9229C0F8889F0256CAAE2308D1F089937
SHA-512:8F70B7A593C7D521709942A04DBFAE2E9E22D65F9C7689AF1AD25CDF57868786F3AE23181DECB7A4C2E218DF1E03DF43C337E249F784B7ECDCCD71DFE0C015BB
Malicious:true
Reputation:unknown
Preview:MZN.....................@...............................................!..L.!This program cannot be run in DOS mode...$........NE.........,....................'.@.@.......S...............................9.P...............Q...0...........0...........0...........0...........0.......{...0.......|.V.0...................0..........FONTS.....!FONTRES 100,96,96 : HyperFont Dk......................Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Dk..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Dk..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Dk......u...Generated by Fontographer 3.5...................................`.`................. .... .A.......g........HyperFont Dk......H...Generated by Fontographer 3.5...................................`.`................. .
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS-DOS executable, NE for MS Windows 3.x (DLL or font)
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:F3D8BF637E6BA999C44F2E8A13A2BDD9
SHA1:35F597A3F548D6CE9C95CC8FAD23CA74A3A56D9F
SHA-256:85773621A3446336482049C3DC8AA312028A184B6EB4F8867DACAF5B21848701
SHA-512:2BF0F47C1F11E2A7CA64A811A285E5CF5CE3C1A21E46F5F092B09AE5D52606CBBA1AF73105EBF54981C23ABAD47E9DEDD3602408BCB01650350371404D011A27
Malicious:true
Reputation:unknown
Preview:MZN.....................@...............................................!..L.!This program cannot be run in DOS mode...$........NE.........,....................'.@.@.......S...............................9.P...............Q...0...........0...........0...........0...........0.......{...0.......|.V.0...................0..........FONTS.....!FONTRES 100,96,96 : HyperFont Lt......................Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Lt..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Lt..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Lt......u...Generated by Fontographer 3.5...................................`.`................. .... .A.......g........HyperFont Lt......H...Generated by Fontographer 3.5...................................`.`................. .
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS-DOS executable, NE for MS Windows 3.x (DLL or font)
Category:dropped
Size (bytes):40256
Entropy (8bit):3.9502052128558947
Encrypted:false
SSDEEP:
MD5:F3D8BF637E6BA999C44F2E8A13A2BDD9
SHA1:35F597A3F548D6CE9C95CC8FAD23CA74A3A56D9F
SHA-256:85773621A3446336482049C3DC8AA312028A184B6EB4F8867DACAF5B21848701
SHA-512:2BF0F47C1F11E2A7CA64A811A285E5CF5CE3C1A21E46F5F092B09AE5D52606CBBA1AF73105EBF54981C23ABAD47E9DEDD3602408BCB01650350371404D011A27
Malicious:true
Reputation:unknown
Preview:MZN.....................@...............................................!..L.!This program cannot be run in DOS mode...$........NE.........,....................'.@.@.......S...............................9.P...............Q...0...........0...........0...........0...........0.......{...0.......|.V.0...................0..........FONTS.....!FONTRES 100,96,96 : HyperFont Lt......................Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Lt..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Lt..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Lt......u...Generated by Fontographer 3.5...................................`.`................. .... .A.......g........HyperFont Lt......H...Generated by Fontographer 3.5...................................`.`................. .
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS-DOS executable, NE for MS Windows 3.x (DLL or font)
Category:dropped
Size (bytes):40256
Entropy (8bit):4.156863620517611
Encrypted:false
SSDEEP:
MD5:FBBC6B6B50E599E8B8F3E94283FAF893
SHA1:3A11720D18C78B83C312878DAF542BBFAE5C45DE
SHA-256:F11E60D1987419265F8B2729672A12A9229C0F8889F0256CAAE2308D1F089937
SHA-512:8F70B7A593C7D521709942A04DBFAE2E9E22D65F9C7689AF1AD25CDF57868786F3AE23181DECB7A4C2E218DF1E03DF43C337E249F784B7ECDCCD71DFE0C015BB
Malicious:true
Reputation:unknown
Preview:MZN.....................@...............................................!..L.!This program cannot be run in DOS mode...$........NE.........,....................'.@.@.......S...............................9.P...............Q...0...........0...........0...........0...........0.......{...0.......|.V.0...................0..........FONTS.....!FONTRES 100,96,96 : HyperFont Dk......................Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Dk..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Dk..........Generated by Fontographer 3.5...................................`.`................. .... .A................HyperFont Dk......u...Generated by Fontographer 3.5...................................`.`................. .... .A.......g........HyperFont Dk......H...Generated by Fontographer 3.5...................................`.`................. .
Process:C:\Users\user\Desktop\h32trial.exe
File Type:TrueType Font data, 15 tables, 1st "OS/2", 14 names, Macintosh, Key CapsRegular14352839Key Caps NormalConverter: Windows Type 1 Installer V1.0d.
Category:dropped
Size (bytes):74104
Entropy (8bit):6.728181776699146
Encrypted:false
SSDEEP:
MD5:08F172BF26062E768DC8F31483BE76E9
SHA1:1EB29B23487B6AC205C00E6EEC52130F989798F2
SHA-256:8EFF1BBAB9365F8F99CC11DE2777689DBF3D087351D7DE5A4E9C42CCC3604167
SHA-512:332BD8CDDAFD9C6D9BFD5A062138D745D2C9A6F97A7CE532743D4999622AF159DF91EA9DD321AD1ED14BBDB70C8C1D452D23037CED66C12782E75FAEB194A795
Malicious:false
Reputation:unknown
Preview:...........pOS/2...........Ncmap..........cvt .G.O...|....fpgm.(.C...L...0gasp............glyf.a..........headl.K....H...6hhea..1........$hmtxL# k.......\kern............loca.C.3........maxp.......P... namee.....p....post.n....\....prepa.?:.......Z.........@........""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""""
Process:C:\Users\user\AppData\Local\Temp\vsetupt.exe
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):43241
Entropy (8bit):6.058323133241636
Encrypted:false
SSDEEP:
MD5:BFDF42FE283994B22A72824576255A95
SHA1:EB8C37023ADA10E9E3BAAEFF7D1842CED5718EC9
SHA-256:700D293E3D76A0A139341A4839C3599BB1F7C917648CD33D7732380532D4A75A
SHA-512:1CE1C929CC44CB60F439381508A0A9AD39FF2C5B50F69DD2F98B3C727482519D857938F6BDF1691C43B7CC9575EB0EE2335B338E36BC4C27846C0EB2F2F43DA1
Malicious:false
Reputation:unknown
Preview:------------------------------------------------------------------------..BEGIN_LICENCE_TEXT....[Trial Parameters]..type=DAYS..start=0..enddate=0..totaldays=15..totalhours=0..totalexec=0..hours=0..exec=0........END_LICENCE_TEXT..------------------------------------------------------------------------..pRDMQY8ECBtqa7a3IrZve3XoMw5JDsnx3Dnb3Tyc820RiAM5+KvkvI7vxQnPz7cQhf7kPTb6..X4C6b172Z+4yCv8QS1JxrtFUa/LtNv/VMwA7oE6FKnoqi2bb90BnK2V9I0DE0GqMALO6jYct..uKY6OgAAM5VYia0wgWRu3K/fHzaND0AnXUICX+WKX3Q7w9CBPh/YZrE5jdZtZDAXQclWeIGm..lBGsWOAzGsI3/a6Cez8tKezaOXTPSW/Ib5PHvaV5XHQjsnctYjctbEQc2jtVHXK8QQ++SgYC..sdEGHKsivx4ma+1L9Gimgtd2ggTDaeQs5eMJ5hDLFqdkz6ftZdn7XKgia9Zq0z1SrKC58Jqi..PwPPckLSbGxCunRvke+jT9hVYP0odrA0IYyWSJPEzvzaaqDKdEzStlxxZKRqCSm96uevDgxn..Vv1Oycx73ynV3pewKojY0ifhurJdUSG4O0zxtw+tCFARjbZf+cAutvayaAOChTd2DVyT9yoX../uU3oR+8L/XiN3V83ur/KRPNtG9V4fjjI/qgLJU4yyOmPfbG4T9eOHOYW+ncn/CwY82wGORq..HZ1eB6DTniSzGrf54563WrW98ucaTnvabs47V/uoCbkvu8goWt3qeAvHgK17wOM6UFUuPFV/..I9y0eGMgXerFRzBZJ7ulR9C21RiPudm
Process:C:\Users\user\AppData\Local\Temp\vsetupt.exe
File Type:data
Category:dropped
Size (bytes):155057
Entropy (8bit):7.998926482153051
Encrypted:true
SSDEEP:
MD5:3437E7105DA6CBCFE33ED06C8911F48D
SHA1:25CADFCF602605B3C65773AD3A504FDDA6A13F31
SHA-256:07C7EACFA5879C7F371BEB0685999705F9929B8EAF1369E424C14134AE861358
SHA-512:E1682862D279487ADDDBB4C6436550BC5A6B7AE99AEE0E66D2CA92436E809F16D3D44556111115541ED09B218FCB67F1995CDD330C8B667C85D184CB348EE248
Malicious:false
Reputation:unknown
Preview:............B..Ys.z._...C........nk.\O..Q..8].K@..3}......-.c0..F...........X..*Bq...w......G..T......4Y7...k....O.4.C.$.i.p..6...a.?.P.`..^f.;.h`..C......s...3....;Dl.$...m2..W.7K.+E.1..H..4mg..T......(..u.N.|.4....z.>7...xA.*...p...b...........Ou.8...]...i..`..</f..qG..vHp...<;.3...i.jS......*.M.\..#..M..9..n.#..>....>G.N.1z.5.;?.7..G.<.#....F.9}..."..n..On.q...{.M*c..G..x.7...Sc*X....<6.0..n.sH]......1....."...u.....mQ...q.....r.O....1.O*..#U.i.e%.y....K.....*.{........d.@!.Q*W.BK]<...q$H....aJ,..Mq.e.._..E..ci3.PD..5.Z".C...9.*4P.4.l.a#.P...j?S.>|L..t.9..f....N.w0b.../..H......T/d.,..)..4...m#."|..........".Ut..X+<.F..*......0..l........B........ t[.#w+.@._gi..O.I..;........+.p....k.t].mL."..hVxKt....{7...s..R.5....V....2R....}.......bnH4'......)|k!<'.#H.`u.....(.......i1.G..J..H2..&.[.'..W...........;C ]2;F.M..L.i{....n.b.~..J.nITD..xd... ..._.g............'..].mw.,r.._.}..rpA...d...s.S...g.i......8....1}......+..*.....b...u?.l..h
Process:C:\Users\user\Desktop\h32trial.exe
File Type:data
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:19018A3FC0A354361D00ED59E1FBAD6B
SHA1:8865CA917CE445E10C4C59F1A0D393DB5159D343
SHA-256:68E008CF02C45A853FBADD959068600DD4D8EAE4B33AE0F7C21B77F7AA7A92C4
SHA-512:C1E2B98E5C610531966399CEA49AA9FE45A62D3B815155D979BA4B10C2662989435DD739EDA5DA676589848E97F1F5C2934AD89B820B52FB57187C6E8F6B5B3B
Malicious:false
Reputation:unknown
Preview:........C.......WN.....9.................................}..rd.Copyright (c) 1995 by Visual Components, Inc. All Rights Reserved...............................................................................................................................e......."e.*j.-..1.?6.?:.?A.:..,.-k./.?4n.)l.)q.)s.;.;.1v.0.1z.)}.7.?>.4.?6..8~.-.6../.?:.0.).6.1.;.<..1.?7B.+.?3.)...D.6..;...D.1..;..).).?6..6..,|.:.-.,..;..).?*.?-.?.../.?0.?1..4.?8D.<..*.?,.?5..6.@;..)..5..,..3..).?-.?=..6..1x.A..:..<..9..=..-..:..@..)..6..,..-..:..1..)i.-..1..7..6..3.?9..1..)y.6B.=..)..5..*..)A.-.?0.?1D./.?6..0..-..<..)..4..4..7..?D.7..7..)z?-s?1..5e?7D.;b.:x?Bu.1w.4v.4..7t.6..:q?;..1p.+n?6f.)m..D.6j.;...D.).@1..;..,..7d.6c.1..<a.-`.:..)Y?,V?/O?3..62?<..0X.-W.1u.-..:S?A..-.@7Q.5P.-..-K?4G?7..=D.4J.-D.7.@=..1E?7B.+D.)..1...D.8??;..0>.1<?7..4;..D.-B@17?;..)5.+...D.+.@;..)/.-.@1p.8.))?0#?1"?7.??..-..:'.+&.<%.1$.+..7.+.?/.?4{.0.=..6.-..:.)..0.?7..8.?:.:..7..,.).?4..4..).?7..+.7.-.=..)..:..
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows 3.0 help, Mon Jun 26 07:46:43 1995, 15819 bytes
Category:dropped
Size (bytes):0
Entropy (8bit):0.0
Encrypted:false
SSDEEP:
MD5:1784DAFFC1A6443BE7A6AD11ED0F7C72
SHA1:F6CD5A668145384952EAC87989B9526EE3FFDA1F
SHA-256:D86D6BB75F04C18314E047D1A99D16AB0C712F35ADD8EE8DA0C4E6CA60D1B069
SHA-512:E520CF934E63F9AAD3356CB7E4CCF9F672F949FDF61CC2E1F46694B2ACB1ADD517B94AE861A85F8B8F53DB5F967587C0FB0DFBB1BBA54C471F19D28D950180E5
Malicious:false
Reputation:unknown
Preview:?_..S........=..C...:........H...................(.-.6.<.E.J.U.].h.n...........................:.A.O.a.i.w.........................4.?.B.R.V.............'.-.2.5.9.<.C.F.L.W.Z.c.p.y.~...................................................$.+.4.:.A.J.P.W.].c.o.y.........................................................#.-.1.5.8.>.H.L.R.Y._.g.m.x.|...........................................(./.8.@.J.S.].h.l.p.s.w.|............................(such) a.re consi.dered sp.ell..corr.ectly wi.thout se.arching .the dict.ionaries..Add to .Custom b.utton an.d list b.oxAllCan.ce.@"@Chan.gesCheck.%...loseCu-z.nz.O0DiPFo.undHelpa@.However,.If cB.ed,@Ignore.0 .t..@.@.0Limi.tL..of su.g....sMov.P.sl......Not... } .` S8p.@..pwordNum@bersOK.AO4pe. /. *Qch oices..St.7.ar...P. .@[A.PerformQ.A.@Press..P.rompt Re.place...A.@..P%q&PW......*.. edi.!f.S."6SN.. .@.PSu`bsequ..Jq .40 .!a.The.. saurumQTh@isTo cM!ad c3R oh..ry0, pi]...y .f&.."."so ...is."visib.l-.,."pa.."."k{.i a..d....lPWhen=.W.. Q+rin .by9.a.log..aB#.?
Process:C:\Users\user\AppData\Local\Temp\vsetupt.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):98371
Entropy (8bit):7.961314597437931
Encrypted:false
SSDEEP:
MD5:1039A4C9819BA571B4A14DA4099B009E
SHA1:DAC67CB41A3B5F57919F4F50E2ED9D5407880CFA
SHA-256:2BF5AA891A82916251C8AA70F3EDF7F2F28624491DEDCBDC8FF0B5F65259EC17
SHA-512:E9B657A8819E5EBBD2D776A10BC791604DAD24163F05726652B74E49F860798134B0392BB6D5A3A3A850BCC77A185F2531E98857E6BB0EE6D14A95B13B863A1E
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......5...........!....8w...z.......@.......@.......................................C..............................hA..9...`@..........x...........................................................................................................PREVIEW.N .......................... ...WeijunLi8w...@..8w..................`....rsrc.32p.......p....|...GetWindowsD@....reloc.e................CreateFileMa@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\vsetupt.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):172592
Entropy (8bit):6.270592417228582
Encrypted:false
SSDEEP:
MD5:0AE5DE9875B37057A0EECB66E00E81E7
SHA1:C9A2FAF1FC6020A927DB586EFBDBC2D41EE1FC23
SHA-256:B2BD46C4431D33A11B1F1AED3AE1BED1E7BAE4A145927BB03A9A2BD2781A4E7A
SHA-512:2A55C7F7F8B1BA756C5D69EB5B2643A7A8BA37E3E4D4B729413D96B42D9AAB900895BA1BA7B07067362DC67F9576269E7AB458D938B798F18D8A18FB5D228AA9
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...S..5...........!................Pm.............................................................................../..[.......x...................................................................................p................................text............................... ..`.rdata..; ......."..................@..@.data...Lb...@...F... ..............@....idata..r............f..............@....rsrc................t..............@..@.reloc..&(.......*...x..............@..B................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\AppData\Local\Temp\vsetupt.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):236099
Entropy (8bit):7.960959296663238
Encrypted:false
SSDEEP:
MD5:A4EB1789476EA18AEDB1C8D0B954CB9C
SHA1:B8687321F2B4FEB724103576F1DE3856F03CE1E1
SHA-256:DF79373E9058847CF58691561D95C1A310949DB6D34A7B3520FF36717FC0A331
SHA-512:B0EC82A6357B7FFCBC64A8D5C7F731A95EC185330B65053B4604674BAD9C86CD9961464BDBA42A34F0A8735F90A3A91FB77E41B73E1DA23101D2E7E3296C1BFF
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......5...........!....D....................................................0..........................................n...`...........|j................... ......................................................................................PREVIEW.4i.......................... ...WeijunLiD.......D...................`....rsrc.2.d.......d........dll.c.VKERN@....reloc.l..... ..........DevCapsA.cto@..B................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\HAWin32\HAWIN32.EXE
File Type:data
Category:dropped
Size (bytes):451
Entropy (8bit):7.522043179863921
Encrypted:false
SSDEEP:
MD5:70F0B0A38C1725212ECA0D7FC3667B95
SHA1:2F778781EACEDB4DCA6F6D0B343467DD159BF2A0
SHA-256:A14C7B3868F3D32A7C92F640D5CE2060D504E717E7F78E345BB4B1AB37CE8106
SHA-512:58C61670379B06B4AEAD298FA062324CF4A02241411D1C81E50AD43DF8FB05F0623A796DC821398755B56D8FE49C17D68694C3EE1EB3E4633C6E61622A8D6468
Malicious:false
Reputation:unknown
Preview:.+..t...ED..ZT.%..m.s.......Yn.e.YF.>....Z..E.|....i...K...ww....N.......'.?./...@...&.........I`....;........./jd..9..B..%\............-...+...e.c...a3....&..ps.7$%]..3,.Tr....C..._.......}g.....>t).9...a?._..V...[.;$...3.......[o.;...D... 6.R...r.a&..n....4(m.q.,...F.% ..1..`.....6tgU....,..~.n..;!...........b.H_=........*..A............Q.e...LIV..gQ....T&s%Yh=.._...s*.M..............[a......|.%.2.UA}b..-D"...V~U.-.t.;.CiD.$Q..
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):164112
Entropy (8bit):5.883996446621416
Encrypted:false
SSDEEP:
MD5:A19E02FA0A7769D6CC0148AA44F1E189
SHA1:CF44E886038237EA21D2939B7BA014517484AB48
SHA-256:692BCF87C28D2EB84FA7DC88A2171F10971E8BBCDD59523520DF612F80897217
SHA-512:7DC9215C41F14ECE9AADACC59DC551C2C70622790B0CE5B9ACC1041D7ED6A59A55FE940764C2A253ECF25C6A8ADF8E3BC4525C231F0D41F483D485D2B75D27D4
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......e.'r!.I!!.I!!.I!w.Z!*.I!!.I!..I!Rich!.I!........PE..L.....C8...........#.................*... ........^i............................. ..v...............................p................0...3...................p...... #......................................H........ ...............................text....... ....... .............. ..`.data...TX.......P..................@....rsrc....3...0...@... ..............@..@.reloc..:....p... ...`..............@..B4.D8@...0[.8M...4.D8W.....+8b...5.D8l...4.D8v...6.D8............KERNEL32.dll.NTDLL.DLL.USER32.dll.GDI32.dll.ole32.dll.ADVAPI32.dll.OLEAUT32.dll.................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):614672
Entropy (8bit):6.643773070354558
Encrypted:false
SSDEEP:
MD5:CD21F4F87BFB2A1C31814DEE90D852CC
SHA1:6134230DB389A05B13515EFBC2910FF521CA2557
SHA-256:EBAF9D77E46D6ED4D5E76762F744DEB71F3DCA0D02B53927EB3CFABCB8691890
SHA-512:18D663FD9BDD8232A814096CA078FD741598BF224EB449B597755AD118D7BD53D36F7094C8F7A17CF2C65336A1FA8262E79F4CF3DC2DC12C1E4675A8D7F4C074
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......ibW.-.9.-.9.-.9...7.(.9.{.*.,.9.-.9.o.9.Rich-.9.................PE..L...6.D8...........#.....P..........#..............w.........................P......V3..............................pO..%$...?...................................i...>......................................X...|....................................text....E.......P... .............. ..`.data....c...`...p...p..............@....rsrc...............................@..@.reloc...i.......p..................@..B5.D88...4.D8B.....+8M...4.D8W...0[.8d...4.D8n...........ole32.dll.USER32.dll.GDI32.dll.KERNEL32.dll.NTDLL.DLL.ADVAPI32.dll......................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):16896
Entropy (8bit):4.0921638899064625
Encrypted:false
SSDEEP:
MD5:4D00D927A8E0441446652EE28296AB88
SHA1:E9DD1CB4197278A57C727D4BF7D0EB2379F860AF
SHA-256:DF68A9D5455818EC17855B3A9BE290260D57C29118BB8F3D7F57B1A406A18429
SHA-512:3F0E8D7F6445D5EADBC77EB294C7529AABDD841A18D822470E64C6F63AE9DB32187BF925891043C5D88DDCC7894316EFA85956D84BDC400FDF74D7F1E572E6E9
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......eU!.!4O.!4O.!4O.!4O. 4O.Rich!4O.................PE..L...H..8...........!.........@...............................................`..........................................................0=...................P.......................................................................................rsrc...0=.......>..................@..@.reloc.......P.......@..............@..B............H..8............ .......8.......H..8............P.......H..8............h.......H..8....................H..8....................@:...........J..@.............T.Y.P.E.L.I.B.MSFT................A...........*................................... ...................d.......,...........X....... ...........L...........x.......@...........l.......4...........`.......(...........T...................H...........t.......<...............h...........................................L...P.......
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):426256
Entropy (8bit):6.410577932259873
Encrypted:false
SSDEEP:
MD5:999B16D5C4CB530C56FB16ED295AD031
SHA1:466F60B0CF931D166A48215A9DDEC26E419D4F6A
SHA-256:7C4860FED81EC95E16B6F99A2F9439BABB14BFECEFFB77B7983ACC4F4556A8A7
SHA-512:F3BDE72C4AEFEEF84449E916F9044A08BF980A14089C36EE2633DC07226BBCA77BF96ED30A5B166BA4F962CF42F9DCF2D0B8D4CEFD632B7CD562431B48891F40
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$................................E......Rich...........PE..L....F.6....8......#.............................`k................................"................................K......@M...........m...................@...;..@L.................................................. ............................text................ .............. ..`.rdata..^Z.......`..................@..@.data....`...`...`...p..............@....rsrc...@n.......p..................@..@.reloc...;...@...@...@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):487696
Entropy (8bit):6.525342386566272
Encrypted:false
SSDEEP:
MD5:12E8934872C3A128BB07C9774FF11045
SHA1:E86439E8A9EF344AAFDC1B7DC93B9F5579A6AB63
SHA-256:80E6859E25235ECE216947753547FA9D39CEE84434859A85024E4A55EDF62B50
SHA-512:7C3909EC257265C792D98C931C0943B0BAC236407353337B4B9F8C2421F4BD3032340FAD148E6B00A77270A5E76BF88CD883B18268E10E2691E02BCDDC1F7A8A
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............................../...E......Rich...........PE..L....F.6...........#.........`...................pk.........................`......................................@k.......m..........8>......................LJ...l..................................................0............................text................ .............. ..`.rdata.."v..........................@..@.data....A.......P..................@....rsrc...h>.......@..................@..@.reloc..LJ.......P... ..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):83968
Entropy (8bit):5.816421335970949
Encrypted:false
SSDEEP:
MD5:893E8BD85B8EFEE1B13706536B67D2E0
SHA1:A1E1F2C70DA3B13CF119E4533B37E5D723F740F4
SHA-256:6E47336FFA991F4CE75557CC0716AB8DA54959672A327D8EC4C87044EF804661
SHA-512:A60B14F8854F26DD642CE8FA15466273CC0C8545014F2A2CDA9CDE0C4A7FAA00D9FEE9808F4610C8A2E91A1F68634F9B4A35D90A046BEFF820F7D66E44710230
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....${0...........!...7.P...........^.......`...............................................................................................................p..t....................................................................................text....O.......P.................. ..`.bss....(....`...........................rdata..."...p...$...T..............@..@.data...p............x..............@....idata..............................@....edata..............................@..@.rsrc...............................@..@.reloc..l....p.......6..............@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):67584
Entropy (8bit):6.078655911062136
Encrypted:false
SSDEEP:
MD5:4E3DE749F4C6E1BF975234499DC577B9
SHA1:0ED4DDC5CE33727790F974505160B37B47AF2688
SHA-256:F49E41073D0F693E8B874E6D143D05638C4F56FE245C09FF1A06683C0DDA0207
SHA-512:CA8692675516C3A8DE43F2944B0803C2FCA705ECFCF64DED7B8BFBAD086A9DBE472D4E450E06199E44D206C58F8AED9C7ADD08320E7D759F94ECA2AE4A65DC1C
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...[.n0...........!...7.....Z......0........................................`.......................................................0..|....................P.......................................................................................text.............................. ..`.bss.....................................rdata..*...........................@..@.data...X...........................@....idata..............................@....edata..............................@..@.rsrc...|....0......................@..@.reloc..Z....P......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:data
Category:dropped
Size (bytes):264288
Entropy (8bit):6.6692259983102735
Encrypted:false
SSDEEP:
MD5:19018A3FC0A354361D00ED59E1FBAD6B
SHA1:8865CA917CE445E10C4C59F1A0D393DB5159D343
SHA-256:68E008CF02C45A853FBADD959068600DD4D8EAE4B33AE0F7C21B77F7AA7A92C4
SHA-512:C1E2B98E5C610531966399CEA49AA9FE45A62D3B815155D979BA4B10C2662989435DD739EDA5DA676589848E97F1F5C2934AD89B820B52FB57187C6E8F6B5B3B
Malicious:false
Reputation:unknown
Preview:........C.......WN.....9.................................}..rd.Copyright (c) 1995 by Visual Components, Inc. All Rights Reserved...............................................................................................................................e......."e.*j.-..1.?6.?:.?A.:..,.-k./.?4n.)l.)q.)s.;.;.1v.0.1z.)}.7.?>.4.?6..8~.-.6../.?:.0.).6.1.;.<..1.?7B.+.?3.)...D.6..;...D.1..;..).).?6..6..,|.:.-.,..;..).?*.?-.?.../.?0.?1..4.?8D.<..*.?,.?5..6.@;..)..5..,..3..).?-.?=..6..1x.A..:..<..9..=..-..:..@..)..6..,..-..:..1..)i.-..1..7..6..3.?9..1..)y.6B.=..)..5..*..)A.-.?0.?1D./.?6..0..-..<..)..4..4..7..?D.7..7..)z?-s?1..5e?7D.;b.:x?Bu.1w.4v.4..7t.6..:q?;..1p.+n?6f.)m..D.6j.;...D.).@1..;..,..7d.6c.1..<a.-`.:..)Y?,V?/O?3..62?<..0X.-W.1u.-..:S?A..-.@7Q.5P.-..-K?4G?7..=D.4J.-D.7.@=..1E?7B.+D.)..1...D.8??;..0>.1<?7..4;..D.-B@17?;..)5.+...D.+.@;..)/.-.@1p.8.))?0#?1"?7.??..-..:'.+&.<%.1$.+..7.+.?/.?4{.0.=..6.-..:.)..0.?7..8.?:.:..7..,.).?4..4..).?7..+.7.-.=..)..:..
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):37136
Entropy (8bit):4.434609734680732
Encrypted:false
SSDEEP:
MD5:7B194F51F6B52233C33A7D0D88A91581
SHA1:459DC713FD52197D025FB7B4B4833ED5DCA73A87
SHA-256:7C05339DA12624396D9911263DC7C993FC2E757E130009465A511045BF06D344
SHA-512:DD835FA6D8F57159FF045BC3C89D1EEA965411A34F1A8D0232ED58A1FDE885CB3E489FDD01D2BF31AEC606130A6B6DC6E3E7602ECB852326DC293604793504CC
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...qk.4.................J...J...............`.......................................8......................................\T..P...............................................................................T....................................text....I.......J.................. ..`.data....<...`...*...Z..............@....rsrc...............................@..@%.!4(...$.!45...%.!4?...(.!4J...........KERNEL32.dll.NTDLL.DLL.USER32.dll.ole32.dll.....................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386 (stripped to external PDB), for MS Windows
Category:dropped
Size (bytes):133904
Entropy (8bit):6.410570565128733
Encrypted:false
SSDEEP:
MD5:887582BAD242AEF74512020722823105
SHA1:79FE1D851B8CEDEEF909753FD4D19D76B65245C7
SHA-256:CEFCC02BC9980BB2CFFB34E8CDF057772553186F2CB510C2C7225729CEFFCD27
SHA-512:CD37BD1396C4FEF9B07E750AFDC550918361BE09B396349D93F9ED92A409C9EC2095136A3673B153579D453C8A9834708185E1B3DA746965DF86AB94A9DCDC15
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...../...........#...7.....p........... ..........................................................................0..........x....P.......................`..t...`................................................................................text............................... ..`.orpc...E.... ...................... ..`.olebrk............................. ..`.bss.....................................rdata...!......."..................@..@.data...b...........................@....idata..R...........................@..@.edata.......0......................@..@.rsrc........P......................@..@.reloc..t....`......................@..B................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):253952
Entropy (8bit):6.5137954580748785
Encrypted:false
SSDEEP:
MD5:B2DC6C360040526B4F1DF7A6E292BDCE
SHA1:D030775A35E88488FEC326CD4B4F61ADFB3B73D9
SHA-256:A7D47ED69FC91D0A891EABFA39BEC191DDF91A27E49404E10B044876A55DE9C5
SHA-512:3E56E5BF80A8BC3AAAFFE71B430841F0809999D411A4403AE731CF1A2DE6E22162BF852A6A16B8B13C450DD094D67431C96A2A534E699F02BDA24650262B6595
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....L/...........!...2.....................................................P...........................................q......<.... .......................0..$....................................................................................text............................... ..`.bss.....................................rdata..`...........................@..@.data... s.......t..................@....idata...............@..............@....edata...q.......r...L..............@..@.rsrc........ ......................@..@.reloc..$....0......................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):640512
Entropy (8bit):6.1079406666212215
Encrypted:false
SSDEEP:
MD5:9A810980D0A632FB161B9F39938E4F86
SHA1:30329AD6A6C8E3974B496F8218FA2ED821CEDF0C
SHA-256:9FBE8F35FC0B150A57E2660A368A5FB0A2051561476E5C02F5FB51F733A18256
SHA-512:FAC107495544AA3485172BF4F3456749C7593824C41F35A3FFEDB8F50BDCD7F62B16639554A5296E52250264C4DB070676AD0BDBC13E620C19CEC72E11A32CC4
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....../...........!...7.D.......6..:........`....._.....................................................................,.......2...@..4........................|......T............................................................................text....C.......D.................. ..`.bss.....5...`...........................rdata..J............H..............@..@.data...|............V..............@....idata...2.......4...t..............@....edata...,..........................@..@.rsrc...4....@......................@..@.reloc..d...........................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:MS Windows 3.0 help, Mon Jun 26 07:46:43 1995, 15819 bytes
Category:dropped
Size (bytes):15819
Entropy (8bit):5.621230348072978
Encrypted:false
SSDEEP:
MD5:1784DAFFC1A6443BE7A6AD11ED0F7C72
SHA1:F6CD5A668145384952EAC87989B9526EE3FFDA1F
SHA-256:D86D6BB75F04C18314E047D1A99D16AB0C712F35ADD8EE8DA0C4E6CA60D1B069
SHA-512:E520CF934E63F9AAD3356CB7E4CCF9F672F949FDF61CC2E1F46694B2ACB1ADD517B94AE861A85F8B8F53DB5F967587C0FB0DFBB1BBA54C471F19D28D950180E5
Malicious:false
Reputation:unknown
Preview:?_..S........=..C...:........H...................(.-.6.<.E.J.U.].h.n...........................:.A.O.a.i.w.........................4.?.B.R.V.............'.-.2.5.9.<.C.F.L.W.Z.c.p.y.~...................................................$.+.4.:.A.J.P.W.].c.o.y.........................................................#.-.1.5.8.>.H.L.R.Y._.g.m.x.|...........................................(./.8.@.J.S.].h.l.p.s.w.|............................(such) a.re consi.dered sp.ell..corr.ectly wi.thout se.arching .the dict.ionaries..Add to .Custom b.utton an.d list b.oxAllCan.ce.@"@Chan.gesCheck.%...loseCu-z.nz.O0DiPFo.undHelpa@.However,.If cB.ed,@Ignore.0 .t..@.@.0Limi.tL..of su.g....sMov.P.sl......Not... } .` S8p.@..pwordNum@bersOK.AO4pe. /. *Qch oices..St.7.ar...P. .@[A.PerformQ.A.@Press..P.rompt Re.place...A.@..P%q&PW......*.. edi.!f.S."6SN.. .@.PSu`bsequ..Jq .40 .!a.The.. saurumQTh@isTo cM!ad c3R oh..ry0, pi]...y .f&.."."so ...is."visib.l-.,."pa.."."k{.i a..d....lPWhen=.W.. Q+rin .by9.a.log..aB#.?
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):995383
Entropy (8bit):6.360989821832431
Encrypted:false
SSDEEP:
MD5:A430FAAE0A4DB973500B6C882F8848E5
SHA1:072BE63A429756DA60F4B4D0D4B59288B295C380
SHA-256:52E1EB5EB51F0B08FE08A6AB97F522247161A816A8296B7BBA87D2865F3985FD
SHA-512:608F8FBBC52C1C50EBE0E3BC772D2869FC985892DA18AD2A406C283E716DC4FD73BB07A229D7D64D5FCCF4E39CBDCACCA7D9FB27F1CCDBE02AB5AC97E828A0AE
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........eY.I.7.I.7.I.7.I.7...7.+.$.O.7...9.L.7.0%=.O.7.I.6...7.0%<...7...1.H.7.0%3.M.7.RichI.7.........................PE..L....C8...........!.........p......#]............7l......................... .......................................`..vm...................................0..l...@...T.......................................h....................................text................ .............. ..`.rdata...G.......P..................@..@.data...Tt..........................@....rsrc...............................@..@.reloc..l....0.......@..............@..B'..70...4.D8;...0[.8H.....+8R...4.D8\...........MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.GDI32.dll.USER32.dll..................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):295000
Entropy (8bit):6.323302897526103
Encrypted:false
SSDEEP:
MD5:055B02D711CDEDB8C5997274C4E99CB8
SHA1:5C816EEB6E4D5F1C11E9F56C992EE7D452E7C0F9
SHA-256:D7CEA69A98579D928E534070F5293E80ED7DF38BAF611B20717EF55AA1344A18
SHA-512:4774431FE768E424F46C833236A41D68F05D98ED14353B04428A5D190DBE213BB56087A5E5CCA5CD98598F2C1611FDDFED3A7A79BBD362BC02E586CC367907C0
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......`...$b..$b..$b..F}..'b..$b...b...}..7b...d..%b...~..gb...}...c...}..%b..Rich$b..........PE..L...'..7...........!..... ...0......H........ .....x.........................`......E................................Z...=.. ...6.... ..............8p.. ....0...&......T............................................0..4............................text...M........ ... .............. ..`.rdata...u...0.......@..............@..@.data....m.......p..................@....rsrc........ .......0..............@..@.reloc...&...0...0...@..............@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):401462
Entropy (8bit):6.398634590192804
Encrypted:false
SSDEEP:
MD5:6050BCC1B23F3DF7A1876CBDCBAC8232
SHA1:8770EC0910B7CC9A0461A40DFB495EE7F5B4267B
SHA-256:2B6B93C2D66969EB00258E2B5AD6172DECEBADA096E3B1B077A3380C80E4A072
SHA-512:84BD1695304C3098BB82BDF06CC5A756F3E7C4E6C7A22E9DD266D49619A34BA7BAA833B167D49954D3AAA1860ADAC195D9B19F1252F09CC9657ECCBECC5934F9
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........)ZK.G.K.G.K.G.).T.I.G...I.J.G.K.F...G...L.Y.G...M.o.G...A.J.G...C.O.G.RichK.G.........PE..L...Z..5...........!.........`.....................x................................i................................8..D`......V................................,..@...T...............................................h............................text................ .............. ..`.rdata..............................@..@.data............ ..................@....rsrc...............................@..@.reloc...,.......0..................@..B................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):77878
Entropy (8bit):5.182274197429194
Encrypted:false
SSDEEP:
MD5:C520E54CB1DFA71EDB3C52EA2C28F1AC
SHA1:CB6E932269387971DA456852EF3E9370F8E3F57C
SHA-256:62FD0613602FE8F4E15801497C64AF587F8C5F9E6330529BB960D962179520E1
SHA-512:C65D2DF8EF350D780011F7B138F6444E30C909132FCCAE77E903B39126F5B369131FEF368286120DEECB6C0BA354F856A43A98F500C5A525F1378CA778966F3C
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........H...)...)...)...6...)..75...)...)...)..\6...)..\6...).../...)..\6...)..Rich.)..................PE..L...f..7...........!...............................x......................... ...................................... ....?......V...............................\.......T.......................................D....................................text... r........... .............. ..`.rdata..bX.......`..................@..@.data...<...........................@....rsrc...............................@..@.reloc..\............ ..............@..B'..7 ...4.D8+...0[.88...........MSVCRT.dll.KERNEL32.dll.NTDLL.DLL.......................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):326656
Entropy (8bit):6.586268084685628
Encrypted:false
SSDEEP:
MD5:146263312871D16BA8E06B3CF68B88DF
SHA1:D572150593FB6544CCB1FEDA3FC0D3800E34B64B
SHA-256:1DED954D583F8BC620073F750A14987D370581763F742E564C8371C59651FABD
SHA-512:780646D94791C54C8521EAAE020DE214669E571E4C76C071A0693714000B0F9AB5704F967CF6FBD919A664A8CE041D4F115D8EB5C5E2755F206B56BB2A0F34D5
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....)1...........!.........F.......7............ ..........................P...........................................x......(...............................l-..................................................T...,............................text.../........................... ..`.rdata..............................@..@.data....L.......2..................@....idata..N...........................@....rsrc...............................@..@.reloc...1.......2..................@..B................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\h32trial.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24576
Entropy (8bit):1.8637167302968631
Encrypted:false
SSDEEP:
MD5:398E10C9DFEC73049FEB6600EEA58C88
SHA1:D9A20F517887731B01BC02CAD7632EF79D47CF35
SHA-256:46787FF221751C07836497F596D1171C1B634D61E153EC1535BEEA4874E7B56D
SHA-512:A7C448623750D49D955B0707F5BACE61E747C5508555BEAFFDDEE4E0250F1AA1D289F83142ED787F5E8D16D64D12AC1B80E933FB26ECE937C149878EE70FA62B
Malicious:true
Reputation:unknown
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........O..`!..`!..`!..B*..`!..|/..`!..B+..`!..B%..`!..` ..`!.-.2..`!..`!..`!..F*..`!.Vf'..`!.n@%..`!.Rich.`!.................PE..L..../.X...........!.........@............... ...............................`.......q..............................@(..k...p&..d....@..h....................P..`...............................................X.... ..L............................text............................... ..`.rdata....... ....... ..............@..@.data........0.......0..............@....rsrc...h....@.......@..............@..@.reloc.......P.......P..............@..B./.V(......W2..."..N?..../.VJ...........ole32.dll.ADVAPI32.dll.MSVCRT.dll.KERNEL32.dll..........................................................................................................................................................................................................................
Process:C:\Program Files (x86)\HAWin32\HAWIN32.EXE
File Type:data
Category:dropped
Size (bytes):473
Entropy (8bit):7.554605221101577
Encrypted:false
SSDEEP:
MD5:EC6F0A3E43FFD69CE4AE5DF29EB748C3
SHA1:722D57A6B21C4D15E7EC5DC147CA81216A274194
SHA-256:F240A9DA0143C7ED3460E18A09A0A366FB73F96CD6CAFBB980448B0B0B81D408
SHA-512:FD95230D32187CC1FE568DE4EA6B82ECE99A8D6194905CD9D348370D2CB5B9A7D08916559FFF787CA673950F267CB39F94F4D110B5E630947ECFF5F9F8A190F2
Malicious:false
Reputation:unknown
Preview:ho..-.s...23..j..........w$.....kf.../.....5..".IY....{....+..>.2P....w.P.......%..m.*..e........8.....l.x<.b.}c...u..}..u.'...k..Y}..,.......$.[r.p...Gp.Z...2.....cRM_...._."85..of..K.7L.N..n...;.(..m....?s!....[k....M.F&...~U.U..B.n.....s.....vw._n......x.a.C\...Z#....4....D....N.p.#E.DoN.Q.......x. ..S.....,.)Q..{sn.........5U......E9.~..+.\.e.<..4...h$.I?........D..W... LRe.I.H4.+G*..5..z.z.q..N.y.......m...GN.>]S.j.0.]A.s..Kb..U.D...l..].....Y..
File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.998924029767712
TrID:
  • Win32 Executable (generic) a (10002005/4) 92.68%
  • Wise Installer executable (786502/1) 7.29%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:h32trial.exe
File size:8'039'501 bytes
MD5:eb2bf9d3d51f4f4c866933a0a7938be4
SHA1:faf78b4e641a8d583d565556ac189cf7af2f796d
SHA256:5bf7ae786d283912cb409fc5c580e1db95ab067eb0ccfbc1aee4ae4cfe6ef866
SHA512:92d138d8fbb42f2fc025bb6a67d24abd19abf32830a29b29bb708fbb3b1e9016a1a56dfa2fb70cb383ea533aa472e361dec481b8c3e725358b9c325508b75342
SSDEEP:196608:MWY9IKJfTV3n2pHZ4I+mzqZsCYvAEger+/AICTw:MWw5TRoHZ5Y3YvrgJAICTw
TLSH:1A86338919F42511E6075AF366A12342CFDB8BFB8B8C5F03E0A51FF7412BD4D52528BA
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......m.d.)...)...)...)...(...)...o...K... ...v...+.......(.......(...Rich)...........PE..L...?l.;................."...........!.....
Icon Hash:6f566745a7297639
Entrypoint:0x4021af
Entrypoint Section:.text
Digitally signed:false
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP
DLL Characteristics:
Time Stamp:0x3BD86C3F [Thu Oct 25 19:47:11 2001 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:4
OS Version Minor:0
File Version Major:4
File Version Minor:0
Subsystem Version Major:4
Subsystem Version Minor:0
Import Hash:e41c25ab7824b3df73334188c40518ae
Instruction
push ebp
mov ebp, esp
sub esp, 0000052Ch
push ebx
push esi
push edi
push 00000001h
pop esi
push 00000004h
mov dword ptr [ebp-18h], esi
call dword ptr [00404054h]
call dword ptr [00404050h]
mov edi, eax
mov dword ptr [ebp-0Ch], edi
mov al, byte ptr [edi]
cmp al, 22h
jne 00007FD77CD06BD2h
mov al, byte ptr [edi+01h]
inc edi
mov dword ptr [ebp-0Ch], edi
xor ebx, ebx
cmp al, bl
je 00007FD77CD06B0Fh
cmp al, 22h
je 00007FD77CD06B0Bh
mov al, byte ptr [edi+01h]
inc edi
mov dword ptr [ebp-0Ch], edi
jmp 00007FD77CD06AF1h
cmp byte ptr [edi], 00000022h
jne 00007FD77CD06B06h
inc edi
mov dword ptr [ebp-0Ch], edi
cmp byte ptr [edi], 00000020h
jne 00007FD77CD06B0Bh
inc edi
cmp byte ptr [edi], 00000020h
je 00007FD77CD06AFCh
mov dword ptr [ebp-0Ch], edi
push ebx
call dword ptr [0040406Ch]
cmp byte ptr [edi], 0000002Fh
mov dword ptr [ebp-08h], eax
jne 00007FD77CD06B66h
mov al, byte ptr [edi+01h]
cmp al, 53h
je 00007FD77CD06B06h
cmp al, 73h
jne 00007FD77CD06B08h
mov dword ptr [00405358h], esi
mov al, byte ptr [edi+01h]
cmp al, 4Dh
je 00007FD77CD06B06h
cmp al, 6Dh
jne 00007FD77CD06B0Eh
cmp byte ptr [edi+02h], 00000034h
jne 00007FD77CD06B08h
mov dword ptr [004053ECh], esi
mov al, byte ptr [edi+01h]
cmp al, 58h
je 00007FD77CD06B06h
cmp al, 78h
jne 00007FD77CD06B14h
cmp byte ptr [edi+02h], 0000003Dh
jne 00007FD77CD06B0Eh
mov dword ptr [0040541Ch], esi
mov dword ptr [004053ECh], esi
mov al, byte ptr [edi+01h]
cmp al, 4Dh
je 00007FD77CD06B06h
cmp al, 6Dh
jne 00007FD77CD06B16h
cmp byte ptr [edi+02h], 00000035h
jne 00007FD77CD06B10h
cmp byte ptr [edi+03h], 00000000h
Programming Language:
  • [EXP] VC++ 6.0 SP5 build 8804
  • [LNK] VC++ 6.0 SP5 build 8804
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x47100x69.rdata
IMAGE_DIRECTORY_ENTRY_IMPORT0x41280x64.rdata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x60000x640.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x40000x128.rdata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x21260x2200c71643c087e2557d0b1d36c694eccccfFalse0.6276424632352942data6.194416114222621IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.rdata0x40000x7790x800d026ce795e3c5fa0e2c0bce1de427a45False0.4853515625data4.781205748145283IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.data0x50000x4780x400c7c41671d08e5cd17ae9b12731e3de24False0.501953125DOS executable (block device driver)3.9576586521600507IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.rsrc0x60000x6400x800809bcee20a015b7e963549ffa3580539False0.31591796875data2.886996501295001IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_ICON0x60f00x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 0EnglishUnited States0.42473118279569894
RT_GROUP_ICON0x63d80x14dataEnglishUnited States1.2
RT_VERSION0x63f00x24cdataEnglishUnited States0.4336734693877551
DLLImport
KERNEL32.dlllstrcpyA, GetCommandLineA, SetErrorMode, lstrlenA, MulDiv, GetTempFileNameA, GetWindowsDirectoryA, GetModuleFileNameA, GetModuleHandleA, FormatMessageA, lstrcatA, GetLastError, _lwrite, _llseek, GlobalUnlock, _lopen, GlobalAlloc, GlobalFree, _lclose, _lcreat, LoadLibraryA, GetProcAddress, FreeLibrary, OpenFile, GetVersionExA, GetCurrentProcess, WinExec, ExitProcess, _lread, LocalFree, GetTempPathA, GlobalLock
USER32.dllGetDC, BeginPaint, EndPaint, InvalidateRect, PostQuitMessage, SendMessageA, DefWindowProcA, GetClientRect, CreateWindowExA, DrawTextA, ReleaseDC, ShowWindow, SetWindowPos, UpdateWindow, SetTimer, LoadIconA, wsprintfA, MessageBoxA, ExitWindowsEx, RegisterClassA, LoadCursorA
GDI32.dllDeleteObject, GetStockObject, GetDeviceCaps, PatBlt, CreateSolidBrush, TextOutA, SetTextColor, SetBkMode, SelectObject, StretchDIBits, CreateFontA, RealizePalette, SelectPalette, CreatePalette
ADVAPI32.dllOpenProcessToken, AdjustTokenPrivileges, LookupPrivilegeValueA
NameOrdinalAddress
_MainWndProc@1610x402a80
_StubFileWrite@1220x403082
Language of compilation systemCountry where language is spokenMap
EnglishUnited States