Source: SetupPSRCloud_5.0.2.exe |
Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI |
Source: SetupPSRCloud_5.0.2.exe |
Static PE information: certificate valid |
Source: SetupPSRCloud_5.0.2.exe |
Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: SetupPSRCloud_5.0.2.exe |
Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI |
Source: classification engine |
Classification label: clean1.winEXE@3/1@0/0 |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
File created: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
File read: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Source: unknown |
Process created: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe "C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe" |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp "C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp" /SL5="$603B2,23154778,874496,C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe" |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Process created: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp "C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp" /SL5="$603B2,23154778,874496,C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe" |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Section loaded: version.dll |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Section loaded: netapi32.dll |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Section loaded: netutils.dll |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Section loaded: uxtheme.dll |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Section loaded: apphelp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: mpr.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: version.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: netapi32.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: winhttp.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: netutils.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: uxtheme.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: kernel.appcore.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: wtsapi32.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: winsta.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: textinputframework.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: coreuicomponents.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: coremessaging.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: ntmarta.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: wintypes.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: textshaping.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Section loaded: dwmapi.dll |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Window found: window name: TSelectLanguageForm |
Source: SetupPSRCloud_5.0.2.exe |
Static PE information: certificate valid |
Source: SetupPSRCloud_5.0.2.exe |
Static file information: File size 24045024 > 1048576 |
Source: SetupPSRCloud_5.0.2.exe |
Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: SetupPSRCloud_5.0.2.exe |
Static PE information: section name: .didata |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
File created: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Jump to dropped file |
Source: C:\Users\user\Desktop\SetupPSRCloud_5.0.2.exe |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |
Source: C:\Users\user\AppData\Local\Temp\is-SE40O.tmp\SetupPSRCloud_5.0.2.tmp |
Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX |