Windows Analysis Report
cylanceprotectsetupwithoptics.exe

Overview

General Information

Sample name: cylanceprotectsetupwithoptics.exe
Analysis ID: 1426789
MD5: 796375900c5f33db332ff8143f243083
SHA1: 9baf9183df0a5ca02cd49dbe04d99578821b27f7
SHA256: bab72dfa7eed0ce4814580312ccba4fca4a136f4bb6f93a9f8f9648614d9ec68
Infos:

Detection

Score: 10
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Signatures

Allocates memory with a write watch (potentially for evading sandboxes)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality to read the PEB
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
Found evaded block containing many API calls
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses Microsoft's Enhanced Cryptographic Provider
Uses code obfuscation techniques (call, push, ret)
Uses the system / local time for branch decision (may execute only at specific dates)

Classification

Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B19EB7 DecryptFileW, 1_2_00B19EB7
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3F961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError, 1_2_00B3F961
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B19C99 DecryptFileW,DecryptFileW, 1_2_00B19C99
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_00899EB7 DecryptFileW, 2_2_00899EB7
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008BF961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError, 2_2_008BF961
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_00899C99 DecryptFileW,DecryptFileW, 2_2_00899C99
Source: cylanceprotectsetupwithoptics.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: cylanceprotectsetupwithoptics.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe.1.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb8 source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\mbahost.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.2.dr
Source: Binary string: e:\jenkins\sign2\workspace\UnifiedInstaller\REL\1070\exe\src\bundledinstaller\Cylance.Host.Installer.CustomBootstrapperWithOptics\obj\Release\Cylance.Host.Installer.CustomBootstrapperWithOptics.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3389746389.0000000006AE9000.00000002.00000001.01000000.0000000B.sdmp, Cylance.Host.Installer.CustomBootstrapperWithOptics.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\core\BootstrapperCore.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B44315 FindFirstFileW,FindClose, 1_2_00B44315
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B1993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 1_2_00B1993E
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B37A87 FindFirstFileExW, 1_2_00B37A87
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B03BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 1_2_00B03BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008C4315 FindFirstFileW,FindClose, 2_2_008C4315
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_0089993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 2_2_0089993E
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B7A87 FindFirstFileExW, 2_2_008B7A87
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_00883BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 2_2_00883BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E83BF6A FindFirstFileExA, 2_2_6E83BF6A
Source: cylanceprotectsetupwithoptics.exe String found in binary or memory: http://appsyndication.org/2006/appsyn
Source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe.1.dr String found in binary or memory: http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://defaultcontainer/Cylance.Host.Installer.CustomBootstrapperWithOptics;component/mainview.xamld
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://defaultcontainer/Cylance.Host.Installer.CustomBootstrapperWithOptics;component/resources/inst
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://foo/bar/mainview.baml
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://foo/bar/mainview.bamld
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://foo/mainview.xaml
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://foo/resources/installerBannerProtect.bmp
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3387948625.00000000044A4000.00000004.00000800.00020000.00000000.sdmp String found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
Source: cylanceprotectsetupwithoptics.exe String found in binary or memory: http://wixtoolset.org/
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr, Microsoft.Deployment.WindowsInstaller.dll.2.dr String found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
Source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr, Microsoft.Deployment.WindowsInstaller.dll.2.dr String found in binary or memory: http://wixtoolset.org/news/
Source: mbapreq.thm.2.dr String found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010
Source: cylanceprotectsetupwithoptics.exe String found in binary or memory: http://wixtoolset.org/telemetry/v
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2C0FA 1_2_00B2C0FA
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B06184 1_2_00B06184
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3022D 1_2_00B3022D
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3A3B0 1_2_00B3A3B0
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B30662 1_2_00B30662
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B0A7EF 1_2_00B0A7EF
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3A85E 1_2_00B3A85E
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B169CC 1_2_00B169CC
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2F919 1_2_00B2F919
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B30A97 1_2_00B30A97
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B32B21 1_2_00B32B21
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B32D50 1_2_00B32D50
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3ED4C 1_2_00B3ED4C
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2FE15 1_2_00B2FE15
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008AC0FA 2_2_008AC0FA
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_00886184 2_2_00886184
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B022D 2_2_008B022D
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008BA3B0 2_2_008BA3B0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B0662 2_2_008B0662
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_0088A7EF 2_2_0088A7EF
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008BA85E 2_2_008BA85E
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008969CC 2_2_008969CC
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008AF919 2_2_008AF919
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B0A97 2_2_008B0A97
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B2B21 2_2_008B2B21
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008BED4C 2_2_008BED4C
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B2D50 2_2_008B2D50
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008AFE15 2_2_008AFE15
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_066C9645 2_2_066C9645
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06ADE1CE 2_2_06ADE1CE
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E83DCFE 2_2_6E83DCFE
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E837025 2_2_6E837025
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E83D850 2_2_6E83D850
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E836DF6 2_2_6E836DF6
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E842978 2_2_6E842978
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: String function: 00B431C7 appears 83 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: String function: 00B01F20 appears 54 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: String function: 00B4061A appears 34 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: String function: 00B4012F appears 678 times
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: String function: 00B037D3 appears 496 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: String function: 008C31C7 appears 83 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: String function: 00881F20 appears 54 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: String function: 008837D3 appears 496 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: String function: 008C061A appears 34 times
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: String function: 008C012F appears 678 times
Source: cylanceprotectsetupwithoptics.exe Binary or memory string: OriginalFilename vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe Binary or memory string: OriginalFilename vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388997416.00000000066D4000.00000002.00000001.01000000.0000000A.sdmp Binary or memory string: OriginalFilenameBootstrapperCore.dll\ vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3389912943.0000000006AF0000.00000002.00000001.01000000.0000000B.sdmp Binary or memory string: OriginalFilenameCylance.Host.Installer.CustomBootstrapperWithOptics.dll vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameMicrosoft.Deployment.WindowsInstaller.dll\ vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3393334798.000000006E84E000.00000002.00000001.01000000.00000007.sdmp Binary or memory string: OriginalFilenamembahost.dll\ vs cylanceprotectsetupwithoptics.exe
Source: cylanceprotectsetupwithoptics.exe Static PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP
Source: classification engine Classification label: clean10.winEXE@3/35@0/0
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3FD20 FormatMessageW,GetLastError,LocalFree, 1_2_00B3FD20
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B044E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 1_2_00B044E9
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008844E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle, 2_2_008844E9
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B42F23 GetModuleHandleA,GetLastError,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CoCreateInstance,ExitProcess, 1_2_00B42F23
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B26945 ChangeServiceConfigW,GetLastError, 1_2_00B26945
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Mutant created: NULL
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\ Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: cabinet.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: msi.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: version.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: wininet.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: comres.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: clbcatq.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: msasn1.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: crypt32.dll 1_2_00B01070
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Command line argument: feclient.dll 1_2_00B01070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: cabinet.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: msi.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: version.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: wininet.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: comres.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: clbcatq.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: msasn1.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: crypt32.dll 2_2_00881070
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Command line argument: feclient.dll 2_2_00881070
Source: cylanceprotectsetupwithoptics.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: cylanceprotectsetupwithoptics.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: cylanceprotectsetupwithoptics.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: cylanceprotectsetupwithoptics.exe String found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe File read: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe "C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe"
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Process created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe "C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Process created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe "C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528 Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: msi.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: msi.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: version.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: mscoree.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: vcruntime140_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: ucrtbase_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: dwrite.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: msvcp140_clr0400.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: d3d9.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: d3d10warp.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: wtsapi32.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: winsta.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: powrprof.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: umpdc.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: resourcepolicyclient.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: dxcore.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: msctfui.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: uiautomationcore.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Section loaded: d3dcompiler_47.dll Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F6D90F11-9C73-11D3-B32E-00C04F990BB4}\InProcServer32 Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dll Jump to behavior
Source: cylanceprotectsetupwithoptics.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: cylanceprotectsetupwithoptics.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: cylanceprotectsetupwithoptics.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: cylanceprotectsetupwithoptics.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: cylanceprotectsetupwithoptics.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: cylanceprotectsetupwithoptics.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: cylanceprotectsetupwithoptics.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: cylanceprotectsetupwithoptics.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe.1.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb8 source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\mbahost.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000002.3393236997.000000006E844000.00000002.00000001.01000000.00000007.sdmp, mbahost.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixStdBA.pdb source: mbapreq.dll.2.dr
Source: Binary string: e:\jenkins\sign2\workspace\UnifiedInstaller\REL\1070\exe\src\bundledinstaller\Cylance.Host.Installer.CustomBootstrapperWithOptics\obj\Release\Cylance.Host.Installer.CustomBootstrapperWithOptics.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3389746389.0000000006AE9000.00000002.00000001.01000000.0000000B.sdmp, Cylance.Host.Installer.CustomBootstrapperWithOptics.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\core\BootstrapperCore.pdb source: cylanceprotectsetupwithoptics.exe, cylanceprotectsetupwithoptics.exe, 00000002.00000002.3388972113.00000000066C2000.00000002.00000001.01000000.0000000A.sdmp, BootstrapperCore.dll.2.dr
Source: Binary string: C:\agent\_work\8\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: cylanceprotectsetupwithoptics.exe, 00000002.00000003.2147458515.000000000112F000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.2.dr
Source: cylanceprotectsetupwithoptics.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: cylanceprotectsetupwithoptics.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: cylanceprotectsetupwithoptics.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: cylanceprotectsetupwithoptics.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: cylanceprotectsetupwithoptics.exe Static PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: cylanceprotectsetupwithoptics.exe Static PE information: section name: .wixburn
Source: cylanceprotectsetupwithoptics.exe.1.dr Static PE information: section name: .wixburn
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2E876 push ecx; ret 1_2_00B2E889
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008AE876 push ecx; ret 2_2_008AE889
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEADCD push ss; retf 2_2_06AEADCE
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1AF push es; ret 2_2_06AEB1B0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1BA push es; ret 2_2_06AEB1BC
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1B4 push es; ret 2_2_06AEB1B6
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1E9 push es; ret 2_2_06AEB1EC
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1E3 push es; ret 2_2_06AEB1E6
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1CC push es; ret 2_2_06AEB1DA
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1C7 push es; ret 2_2_06AEB1C8
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1C1 push es; ret 2_2_06AEB1C2
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB1DD push es; ret 2_2_06AEB1E0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_06AEB15A push es; ret 2_2_06AEB1AA
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E8344E6 push ecx; ret 2_2_6E8344F9
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E8420 push es; ret 2_2_043E8436
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E7522 push esp; retf 2_2_043E7531
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E87E0 push es; ret 2_2_043E87F0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E705A pushfd ; iretd 2_2_043E7089
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E704A pushad ; iretd 2_2_043E7059
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E3268 pushfd ; iretd 2_2_043E3341
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E3343 pushfd ; iretd 2_2_043E3341
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_043E7ECF push es; ret 2_2_043E7ED0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dll Jump to dropped file
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dll Jump to dropped file
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe File created: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Memory allocated: 3420000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Memory allocated: 4440000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Memory allocated: 6440000 memory reserve | memory write watch Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Dropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Dropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbapreq.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Dropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\mbahost.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Dropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dll Jump to dropped file
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Dropped PE file which has not been started: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Microsoft.Deployment.WindowsInstaller.dll Jump to dropped file
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Evaded block: after key decision
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Check user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe API coverage: 9.1 %
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 00B3FE5Dh 1_2_00B3FDC2
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B3FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 00B3FE56h 1_2_00B3FDC2
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008BFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 008BFE5Dh 2_2_008BFDC2
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008BFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 008BFE56h 2_2_008BFDC2
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B44315 FindFirstFileW,FindClose, 1_2_00B44315
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B1993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 1_2_00B1993E
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B37A87 FindFirstFileExW, 1_2_00B37A87
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B03BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 1_2_00B03BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008C4315 FindFirstFileW,FindClose, 2_2_008C4315
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_0089993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose, 2_2_0089993E
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B7A87 FindFirstFileExW, 2_2_008B7A87
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_00883BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose, 2_2_00883BC3
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E83BF6A FindFirstFileExA, 2_2_6E83BF6A
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B4962D VirtualQuery,GetSystemInfo, 1_2_00B4962D
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe API call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe API call chain: ExitProcess graph end node
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2E625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_00B2E625
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B34812 mov eax, dword ptr fs:[00000030h] 1_2_00B34812
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B4812 mov eax, dword ptr fs:[00000030h] 2_2_008B4812
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E838EB1 mov eax, dword ptr fs:[00000030h] 2_2_6E838EB1
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B038D4 GetProcessHeap,RtlAllocateHeap, 1_2_00B038D4
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2E188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 1_2_00B2E188
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2E625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_00B2E625
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2E773 SetUnhandledExceptionFilter, 1_2_00B2E773
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B33BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 1_2_00B33BB0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008AE188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_008AE188
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008AE625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_008AE625
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008AE773 SetUnhandledExceptionFilter, 2_2_008AE773
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_008B3BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_008B3BB0
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E837E39 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_6E837E39
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E834321 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter, 2_2_6E834321
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Code function: 2_2_6E8344FB SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess, 2_2_6E8344FB
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Process created: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe "C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe" -burn.clean.room="C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe" -burn.filehandle.attached=512 -burn.filehandle.self=528 Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B415CB InitializeSecurityDescriptor,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,SetEntriesInAclA,SetSecurityDescriptorOwner,GetLastError,SetSecurityDescriptorGroup,GetLastError,SetSecurityDescriptorDacl,GetLastError,CoInitializeSecurity,LocalFree, 1_2_00B415CB
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B4393B AllocateAndInitializeSid,CheckTokenMembership, 1_2_00B4393B
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B2E9A7 cpuid 1_2_00B2E9A7
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\BootstrapperCore.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Temp\{2386AC95-A39D-40D2-9EDA-FF9EA8E5DA36}\.ba\Cylance.Host.Installer.CustomBootstrapperWithOptics.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemXml\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemXml.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\PresentationFramework-SystemCore\v4.0_4.0.0.0__b77a5c561934e089\PresentationFramework-SystemCore.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationTypes\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationTypes.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\UIAutomationProvider\v4.0_4.0.0.0__31bf3856ad364e35\UIAutomationProvider.dll VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\segoeui.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Queries volume information: C:\Windows\Fonts\seguisb.ttf VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B14CE8 ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,GetLastError,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree, 1_2_00B14CE8
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B4858F GetSystemTime, 1_2_00B4858F
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B060BA GetUserNameW,GetLastError, 1_2_00B060BA
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B48733 GetTimeZoneInformation,SystemTimeToTzSpecificLocalTime, 1_2_00B48733
Source: C:\Users\user\Desktop\cylanceprotectsetupwithoptics.exe Code function: 1_2_00B0508D GetModuleHandleW,CoInitializeEx,GetVersionExW,GetLastError,CoUninitialize, 1_2_00B0508D
Source: C:\Windows\Temp\{D29CB8BE-513E-4B9E-B69F-E8CB205B8828}\.cr\cylanceprotectsetupwithoptics.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
No contacted IP infos