Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
TortoiseGit-2.15.0.1-Hotfix-64bit.exe

Overview

General Information

Sample name:TortoiseGit-2.15.0.1-Hotfix-64bit.exe
Analysis ID:1428708
MD5:225cc0331d839e8dbea3f6dc320c59b2
SHA1:cc0795986ae7bcc67e6733e6c83aae7e5a80a2b2
SHA256:cb7581b6f859154ac0ed03ef7414eb5ee82002ccf3cad3aa93647d0c7efe19b7
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

Drops PE files
Found dropped PE file which has not been started or loaded
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
  • System is w10x64
  • TortoiseGit-2.15.0.1-Hotfix-64bit.exe (PID: 6828 cmdline: "C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe" MD5: 225CC0331D839E8DBEA3F6DC320C59B2)
    • TortoiseGit-2.15.0.1-Hotfix-64bit.tmp (PID: 5676 cmdline: "C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp" /SL5="$2043C,1792279,832512,C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe" MD5: F7545D5A5837D3B545E0B0C77BA6D8C5)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic PE information: certificate valid
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://ccsca2021.crl.certum.pl/ccsca2021.crl0s
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://ccsca2021.ocsp-certum.com05
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://crl.certum.pl/ctnca.crl0k
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://crl.certum.pl/ctnca2.crl0l
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://crl.certum.pl/ctsca2021.crl0o
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://repository.certum.pl/ccsca2021.cer0
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://repository.certum.pl/ctnca.cer09
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://repository.certum.pl/ctnca2.cer09
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://repository.certum.pl/ctsca2021.cer0A
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://s.symcb.com/universal-root.crl0
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://s.symcd.com06
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://subca.ocsp-certum.com01
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://subca.ocsp-certum.com02
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://subca.ocsp-certum.com05
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0(
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://ts-ocsp.ws.symantec.com0;
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: http://www.certum.pl/CPS0
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: https://d.symcb.com/cps0%
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: https://d.symcb.com/rpa0
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: https://d.symcb.com/rpa0.
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.00000000022C3000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1698856525.00000000025AA000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://tortoisegit.org
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1650871083.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1656036498.0000000003490000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://tortoisegit.org.https://tortoisegit.org.https://tortoisegit.org
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1698856525.00000000025AA000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://tortoisegit.orgA
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.00000000022C3000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://tortoisegit.orgQ6
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: https://www.certum.pl/CPS0
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000000.1654433570.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.drString found in binary or memory: https://www.innosetup.com/
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000000.1654433570.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.drString found in binary or memory: https://www.remobjects.com/ps
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000000.1650550452.00000000004C6000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.0000000002288000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenamekernel32j% vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FE35000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002878000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeBinary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: classification engineClassification label: clean3.winEXE@3/2@0/0
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpFile created: C:\Users\user\AppData\Local\ProgramsJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeFile created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmpJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeString found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeFile read: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe "C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe"
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeProcess created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp" /SL5="$2043C,1792279,832512,C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe"
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeProcess created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp" /SL5="$2043C,1792279,832512,C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe" Jump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: mpr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: version.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: wtsapi32.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: winsta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: shfolder.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: rstrtmgr.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: ncrypt.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: ntasn1.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic PE information: certificate valid
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic file information: File size 2642464 > 1048576
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exeStatic PE information: section name: .didata
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.drStatic PE information: section name: .didata
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeFile created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpFile created: C:\Users\user\AppData\Local\Temp\is-279VF.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-279VF.tmp\_isetup\_setup64.tmpJump to dropped file
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
1
Process Injection
1
Masquerading
OS Credential Dumping2
System Owner/User Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Process Injection
LSASS Memory1
System Information Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)1
DLL Side-Loading
Security Account ManagerQuery RegistrySMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
TortoiseGit-2.15.0.1-Hotfix-64bit.exe0%ReversingLabs
TortoiseGit-2.15.0.1-Hotfix-64bit.exe1%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\is-279VF.tmp\_isetup\_setup64.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-279VF.tmp\_isetup\_setup64.tmp0%VirustotalBrowse
C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp0%ReversingLabs
C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp0%VirustotalBrowse
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://subca.ocsp-certum.com050%URL Reputationsafe
https://www.remobjects.com/ps0%URL Reputationsafe
http://subca.ocsp-certum.com020%URL Reputationsafe
http://subca.ocsp-certum.com010%URL Reputationsafe
http://ccsca2021.ocsp-certum.com050%URL Reputationsafe
http://ccsca2021.ocsp-certum.com050%URL Reputationsafe
https://www.innosetup.com/1%VirustotalBrowse
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupUTortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
    high
    http://repository.certum.pl/ctsca2021.cer0ATortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
      high
      https://tortoisegit.orgQ6TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.00000000022C3000.00000004.00001000.00020000.00000000.sdmpfalse
        unknown
        http://crl.certum.pl/ctsca2021.crl0oTortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
          high
          http://repository.certum.pl/ctnca.cer09TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
            high
            http://crl.certum.pl/ctnca.crl0kTortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
              high
              http://subca.ocsp-certum.com05TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
              • URL Reputation: safe
              unknown
              https://tortoisegit.org.https://tortoisegit.org.https://tortoisegit.orgTortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1650871083.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1656036498.0000000003490000.00000004.00001000.00020000.00000000.sdmpfalse
                unknown
                https://www.remobjects.com/psTortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000000.1654433570.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.drfalse
                • URL Reputation: safe
                unknown
                http://subca.ocsp-certum.com02TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                • URL Reputation: safe
                unknown
                http://subca.ocsp-certum.com01TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                • URL Reputation: safe
                unknown
                https://www.innosetup.com/TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000000.1654433570.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.drfalseunknown
                https://tortoisegit.orgTortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.00000000022C3000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1698856525.00000000025AA000.00000004.00001000.00020000.00000000.sdmpfalse
                  high
                  http://crl.certum.pl/ctnca2.crl0lTortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                    high
                    http://repository.certum.pl/ctnca2.cer09TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                      high
                      http://ccsca2021.crl.certum.pl/ccsca2021.crl0sTortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                        high
                        http://ccsca2021.ocsp-certum.com05TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                        • URL Reputation: safe
                        • URL Reputation: safe
                        unknown
                        https://www.certum.pl/CPS0TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                          high
                          https://tortoisegit.orgATortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1698856525.00000000025AA000.00000004.00001000.00020000.00000000.sdmpfalse
                            unknown
                            http://www.certum.pl/CPS0TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                              high
                              http://repository.certum.pl/ccsca2021.cer0TortoiseGit-2.15.0.1-Hotfix-64bit.exefalse
                                high
                                No contacted IP infos
                                Joe Sandbox version:40.0.0 Tourmaline
                                Analysis ID:1428708
                                Start date and time:2024-04-19 12:33:16 +02:00
                                Joe Sandbox product:CloudBasic
                                Overall analysis duration:0h 2m 48s
                                Hypervisor based Inspection enabled:false
                                Report type:full
                                Cookbook file name:default.jbs
                                Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                Number of analysed new started processes analysed:2
                                Number of new started drivers analysed:0
                                Number of existing processes analysed:0
                                Number of existing drivers analysed:0
                                Number of injected processes analysed:0
                                Technologies:
                                • HCA enabled
                                • EGA enabled
                                • AMSI enabled
                                Analysis Mode:default
                                Analysis stop reason:Timeout
                                Sample name:TortoiseGit-2.15.0.1-Hotfix-64bit.exe
                                Detection:CLEAN
                                Classification:clean3.winEXE@3/2@0/0
                                EGA Information:Failed
                                HCA Information:
                                • Successful, ratio: 100%
                                • Number of executed functions: 0
                                • Number of non-executed functions: 0
                                Cookbook Comments:
                                • Found application associated with file extension: .exe
                                • Stop behavior analysis, all processes terminated
                                No simulations
                                No context
                                No context
                                No context
                                No context
                                MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                C:\Users\user\AppData\Local\Temp\is-279VF.tmp\_isetup\_setup64.tmp$RWRW8GN.exeGet hashmaliciousUnknownBrowse
                                  SecuriteInfo.com.Program.Unwanted.5412.9308.3353.exeGet hashmaliciousPureLog StealerBrowse
                                    SecuriteInfo.com.Program.Unwanted.5412.9308.3353.exeGet hashmaliciousPureLog StealerBrowse
                                      ltVDtWrs13.exeGet hashmaliciousUnknownBrowse
                                        SecuriteInfo.com.FileRepMalware.18165.2747.exeGet hashmaliciousUnknownBrowse
                                          SecuriteInfo.com.FileRepMalware.18165.2747.exeGet hashmaliciousUnknownBrowse
                                            Emcon.Zvit.2.0.exeGet hashmaliciousUnknownBrowse
                                              SecuriteInfo.com.FileRepPup.2542.22578.exeGet hashmaliciousUnknownBrowse
                                                SecuriteInfo.com.FileRepPup.2542.22578.exeGet hashmaliciousUnknownBrowse
                                                  Emcon.Zvit.2.0.exeGet hashmaliciousUnknownBrowse
                                                    Process:C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp
                                                    File Type:PE32+ executable (console) x86-64, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):6144
                                                    Entropy (8bit):4.720366600008286
                                                    Encrypted:false
                                                    SSDEEP:96:sfkcXegaJ/ZAYNzcld1xaX12p+gt1sONA0:sfJEVYlvxaX12C6A0
                                                    MD5:E4211D6D009757C078A9FAC7FF4F03D4
                                                    SHA1:019CD56BA687D39D12D4B13991C9A42EA6BA03DA
                                                    SHA-256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
                                                    SHA-512:17257F15D843E88BB78ADCFB48184B8CE22109CC2C99E709432728A392AFAE7B808ED32289BA397207172DE990A354F15C2459B6797317DA8EA18B040C85787E
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                                    Joe Sandbox View:
                                                    • Filename: $RWRW8GN.exe, Detection: malicious, Browse
                                                    • Filename: SecuriteInfo.com.Program.Unwanted.5412.9308.3353.exe, Detection: malicious, Browse
                                                    • Filename: SecuriteInfo.com.Program.Unwanted.5412.9308.3353.exe, Detection: malicious, Browse
                                                    • Filename: ltVDtWrs13.exe, Detection: malicious, Browse
                                                    • Filename: SecuriteInfo.com.FileRepMalware.18165.2747.exe, Detection: malicious, Browse
                                                    • Filename: SecuriteInfo.com.FileRepMalware.18165.2747.exe, Detection: malicious, Browse
                                                    • Filename: Emcon.Zvit.2.0.exe, Detection: malicious, Browse
                                                    • Filename: SecuriteInfo.com.FileRepPup.2542.22578.exe, Detection: malicious, Browse
                                                    • Filename: SecuriteInfo.com.FileRepPup.2542.22578.exe, Detection: malicious, Browse
                                                    • Filename: Emcon.Zvit.2.0.exe, Detection: malicious, Browse
                                                    Reputation:high, very likely benign file
                                                    Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......^...............l...............=\......=\......=\......Rich............................PE..d.....R..........#............................@.............................`.......,......................................................<!.......P..H....@..0.................................................................... ...............................text............................... ..`.rdata..|.... ......................@..@.data...,....0......................@....pdata..0....@......................@..@.rsrc...H....P......................@..@................................................................................................................................................................................................................................................................................................................................
                                                    Process:C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe
                                                    File Type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                    Category:dropped
                                                    Size (bytes):3199488
                                                    Entropy (8bit):6.325055527156509
                                                    Encrypted:false
                                                    SSDEEP:49152:2WGtLBcXqFpBR6SVb8kq4pgquLMMji4NYxtJpkxhGjIHTbQ333TY:6tLutqgwh4NYxtJpkxhGj333T
                                                    MD5:F7545D5A5837D3B545E0B0C77BA6D8C5
                                                    SHA1:6F66EEA352C84D19243161B3A0F8C5B9DB041B01
                                                    SHA-256:75C5D113B9E9E678A89EBD19C6BA63F0869197673BCE53A9866C60E3A03A6C3B
                                                    SHA-512:4110986B6F295FA1F347909EAECDB169EC0CD2D6AB657515404221926B526A2A0BC0C63A2D7C99D4D22887B9C773FD5B3AF98ABEA4B687EA721C243CE030C4E7
                                                    Malicious:false
                                                    Antivirus:
                                                    • Antivirus: ReversingLabs, Detection: 0%
                                                    • Antivirus: Virustotal, Detection: 0%, Browse
                                                    Reputation:low
                                                    Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7........................................................................................................................................PE..L......c.................L,.........hf,......p,...@...........................1...........@......@....................-.......-..9...................................................................................-.......-......................text.... ,......",................. ..`.itext...(...@,..*...&,............. ..`.data...X....p,......P,.............@....bss.....y....-..........................idata...9....-..:....,.............@....didata.......-.......-.............@....edata........-......*-.............@..@.tls....L.....-..........................rdata..]............,-.............@..@.rsrc.................-.............@..@..............1.......0.............@..@........................................................
                                                    File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                    Entropy (8bit):7.708469519675203
                                                    TrID:
                                                    • Win32 Executable (generic) a (10002005/4) 98.04%
                                                    • Inno Setup installer (109748/4) 1.08%
                                                    • InstallShield setup (43055/19) 0.42%
                                                    • Win32 EXE PECompact compressed (generic) (41571/9) 0.41%
                                                    • Win16/32 Executable Delphi generic (2074/23) 0.02%
                                                    File name:TortoiseGit-2.15.0.1-Hotfix-64bit.exe
                                                    File size:2'642'464 bytes
                                                    MD5:225cc0331d839e8dbea3f6dc320c59b2
                                                    SHA1:cc0795986ae7bcc67e6733e6c83aae7e5a80a2b2
                                                    SHA256:cb7581b6f859154ac0ed03ef7414eb5ee82002ccf3cad3aa93647d0c7efe19b7
                                                    SHA512:4bce04ffc0385b3b7b4430fba7b6db6a1e3bd68b081f1ba419cef6137f377aa272ac4da785df1a6366613e73b6b5e7ee3d98718f82864eb1307e9da4f420f788
                                                    SSDEEP:49152:TBuZrEUCB2GubU1sySuiqY/iuiueR+lhlZ9j6pjIMGFT43G:VkLQ2GubnypY/viueR+lh79aEbJ43G
                                                    TLSH:ACC5E03BF268A53ED46A0A3246B383209977BA51B81A8C1F47FC344DCF765701E3B656
                                                    File Content Preview:MZP.....................@...............................................!..L.!..This program must be run under Win32..$7.......................................................................................................................................
                                                    Icon Hash:0c0c2d33ceec80aa
                                                    Entrypoint:0x4b5eec
                                                    Entrypoint Section:.itext
                                                    Digitally signed:true
                                                    Imagebase:0x400000
                                                    Subsystem:windows gui
                                                    Image File Characteristics:RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
                                                    DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                    Time Stamp:0x63ECF218 [Wed Feb 15 14:54:16 2023 UTC]
                                                    TLS Callbacks:
                                                    CLR (.Net) Version:
                                                    OS Version Major:6
                                                    OS Version Minor:1
                                                    File Version Major:6
                                                    File Version Minor:1
                                                    Subsystem Version Major:6
                                                    Subsystem Version Minor:1
                                                    Import Hash:e569e6f445d32ba23766ad67d1e3787f
                                                    Signature Valid:true
                                                    Signature Issuer:CN=Certum Code Signing 2021 CA, O=Asseco Data Systems S.A., C=PL
                                                    Signature Validation Error:The operation completed successfully
                                                    Error Number:0
                                                    Not Before, Not After
                                                    • 02/10/2023 12:50:02 01/10/2024 12:50:01
                                                    Subject Chain
                                                    • E=mail@cs-ware.de, CN="Open Source Developer, Sven Strickroth", O=Open Source Developer, S=Bavaria, C=DE
                                                    Version:3
                                                    Thumbprint MD5:3E8590545275CFAB975A7128D1093D26
                                                    Thumbprint SHA-1:1FD1CBDD7D6000FAA25BAD31D430DB14C7F6087F
                                                    Thumbprint SHA-256:B7A9127FB44D138812E316F6C355A6BE63F19419B79216B4E99ACEF605C329A1
                                                    Serial:1BA539E2B21FEF16BB48E41E1A3023B1
                                                    Instruction
                                                    push ebp
                                                    mov ebp, esp
                                                    add esp, FFFFFFA4h
                                                    push ebx
                                                    push esi
                                                    push edi
                                                    xor eax, eax
                                                    mov dword ptr [ebp-3Ch], eax
                                                    mov dword ptr [ebp-40h], eax
                                                    mov dword ptr [ebp-5Ch], eax
                                                    mov dword ptr [ebp-30h], eax
                                                    mov dword ptr [ebp-38h], eax
                                                    mov dword ptr [ebp-34h], eax
                                                    mov dword ptr [ebp-2Ch], eax
                                                    mov dword ptr [ebp-28h], eax
                                                    mov dword ptr [ebp-14h], eax
                                                    mov eax, 004B14B8h
                                                    call 00007F0454DA88A5h
                                                    xor eax, eax
                                                    push ebp
                                                    push 004B65E2h
                                                    push dword ptr fs:[eax]
                                                    mov dword ptr fs:[eax], esp
                                                    xor edx, edx
                                                    push ebp
                                                    push 004B659Eh
                                                    push dword ptr fs:[edx]
                                                    mov dword ptr fs:[edx], esp
                                                    mov eax, dword ptr [004BE634h]
                                                    call 00007F0454E4B397h
                                                    call 00007F0454E4AEEAh
                                                    lea edx, dword ptr [ebp-14h]
                                                    xor eax, eax
                                                    call 00007F0454DBE344h
                                                    mov edx, dword ptr [ebp-14h]
                                                    mov eax, 004C1D84h
                                                    call 00007F0454DA3497h
                                                    push 00000002h
                                                    push 00000000h
                                                    push 00000001h
                                                    mov ecx, dword ptr [004C1D84h]
                                                    mov dl, 01h
                                                    mov eax, dword ptr [004238ECh]
                                                    call 00007F0454DBF4C7h
                                                    mov dword ptr [004C1D88h], eax
                                                    xor edx, edx
                                                    push ebp
                                                    push 004B654Ah
                                                    push dword ptr fs:[edx]
                                                    mov dword ptr fs:[edx], esp
                                                    call 00007F0454E4B41Fh
                                                    mov dword ptr [004C1D90h], eax
                                                    mov eax, dword ptr [004C1D90h]
                                                    cmp dword ptr [eax+0Ch], 01h
                                                    jne 00007F0454E5163Ah
                                                    mov eax, dword ptr [004C1D90h]
                                                    mov edx, 00000028h
                                                    call 00007F0454DBFDBCh
                                                    mov edx, dword ptr [004C1D90h]
                                                    NameVirtual AddressVirtual Size Is in Section
                                                    IMAGE_DIRECTORY_ENTRY_EXPORT0xc40000x9a.edata
                                                    IMAGE_DIRECTORY_ENTRY_IMPORT0xc20000xfdc.idata
                                                    IMAGE_DIRECTORY_ENTRY_RESOURCE0xc70000x11000.rsrc
                                                    IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_SECURITY0x2809680x48b8
                                                    IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_TLS0xc60000x18.rdata
                                                    IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_IAT0xc22f40x254.idata
                                                    IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0xc30000x1a4.didata
                                                    IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                    IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                    NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                    .text0x10000xb39e40xb3a0043af0a9476ca224d8e8461f1e22c94daFalse0.34525867693110646data6.357635049994181IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                    .itext0xb50000x16880x1800185e04b9a1f554e31f7f848515dc890cFalse0.54443359375data5.971425428435973IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                    .data0xb70000x37a40x3800cab2107c933b696aa5cf0cc6c3fd3980False0.36097935267857145data5.048648594372454IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .bss0xbb0000x6de80x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .idata0xc20000xfdc0x1000e7d1635e2624b124cfdce6c360ac21cdFalse0.3798828125data5.029087481102678IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .didata0xc30000x1a40x2008ced971d8a7705c98b173e255d8c9aa7False0.345703125data2.7509822285969876IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .edata0xc40000x9a0x2008d4e1e508031afe235bf121c80fd7d5fFalse0.2578125data1.877162954504408IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                    .tls0xc50000x180x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                    .rdata0xc60000x5d0x2008f2f090acd9622c88a6a852e72f94e96False0.189453125data1.3838943752217987IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                    .rsrc0xc70000x110000x11000d414582535e7d25721aa3182da4fac7fFalse0.18645163143382354data3.697991290087331IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                    NameRVASizeTypeLanguageCountryZLIB Complexity
                                                    RT_ICON0xc76780xa68Device independent bitmap graphic, 64 x 128 x 4, image size 2048EnglishUnited States0.1174924924924925
                                                    RT_ICON0xc80e00x668Device independent bitmap graphic, 48 x 96 x 4, image size 1152EnglishUnited States0.15792682926829268
                                                    RT_ICON0xc87480x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishUnited States0.23387096774193547
                                                    RT_ICON0xc8a300x128Device independent bitmap graphic, 16 x 32 x 4, image size 128EnglishUnited States0.39864864864864863
                                                    RT_ICON0xc8b580x1628Device independent bitmap graphic, 64 x 128 x 8, image size 4096, 256 important colorsEnglishUnited States0.08339210155148095
                                                    RT_ICON0xca1800xea8Device independent bitmap graphic, 48 x 96 x 8, image size 2304, 256 important colorsEnglishUnited States0.1023454157782516
                                                    RT_ICON0xcb0280x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 1024, 256 important colorsEnglishUnited States0.10649819494584838
                                                    RT_ICON0xcb8d00x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsEnglishUnited States0.10838150289017341
                                                    RT_ICON0xcbe380x12e5PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.8712011577424024
                                                    RT_ICON0xcd1200x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16896EnglishUnited States0.05668398677373642
                                                    RT_ICON0xd13480x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.08475103734439834
                                                    RT_ICON0xd38f00x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.09920262664165103
                                                    RT_ICON0xd49980x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.2047872340425532
                                                    RT_STRING0xd4e000x360data0.34375
                                                    RT_STRING0xd51600x260data0.3256578947368421
                                                    RT_STRING0xd53c00x45cdata0.4068100358422939
                                                    RT_STRING0xd581c0x40cdata0.3754826254826255
                                                    RT_STRING0xd5c280x2d4data0.39226519337016574
                                                    RT_STRING0xd5efc0xb8data0.6467391304347826
                                                    RT_STRING0xd5fb40x9cdata0.6410256410256411
                                                    RT_STRING0xd60500x374data0.4230769230769231
                                                    RT_STRING0xd63c40x398data0.3358695652173913
                                                    RT_STRING0xd675c0x368data0.3795871559633027
                                                    RT_STRING0xd6ac40x2a4data0.4275147928994083
                                                    RT_RCDATA0xd6d680x10data1.5
                                                    RT_RCDATA0xd6d780x2c4data0.6384180790960452
                                                    RT_RCDATA0xd703c0x2cdata1.1818181818181819
                                                    RT_GROUP_ICON0xd70680xbcdataEnglishUnited States0.6170212765957447
                                                    RT_VERSION0xd71240x584dataEnglishUnited States0.28824362606232296
                                                    RT_MANIFEST0xd76a80x7a8XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.3377551020408163
                                                    DLLImport
                                                    kernel32.dllGetACP, GetExitCodeProcess, LocalFree, CloseHandle, SizeofResource, VirtualProtect, VirtualFree, GetFullPathNameW, ExitProcess, HeapAlloc, GetCPInfoExW, RtlUnwind, GetCPInfo, GetStdHandle, GetModuleHandleW, FreeLibrary, HeapDestroy, ReadFile, CreateProcessW, GetLastError, GetModuleFileNameW, SetLastError, FindResourceW, CreateThread, CompareStringW, LoadLibraryA, ResetEvent, GetVersion, RaiseException, FormatMessageW, SwitchToThread, GetExitCodeThread, GetCurrentThread, LoadLibraryExW, LockResource, GetCurrentThreadId, UnhandledExceptionFilter, VirtualQuery, VirtualQueryEx, Sleep, EnterCriticalSection, SetFilePointer, LoadResource, SuspendThread, GetTickCount, GetFileSize, GetStartupInfoW, GetFileAttributesW, InitializeCriticalSection, GetSystemWindowsDirectoryW, GetThreadPriority, SetThreadPriority, GetCurrentProcess, VirtualAlloc, GetSystemInfo, GetCommandLineW, LeaveCriticalSection, GetProcAddress, ResumeThread, GetVersionExW, VerifyVersionInfoW, HeapCreate, GetWindowsDirectoryW, VerSetConditionMask, GetDiskFreeSpaceW, FindFirstFileW, GetUserDefaultUILanguage, lstrlenW, QueryPerformanceCounter, SetEndOfFile, HeapFree, WideCharToMultiByte, FindClose, MultiByteToWideChar, LoadLibraryW, SetEvent, CreateFileW, GetLocaleInfoW, GetSystemDirectoryW, DeleteFileW, GetLocalTime, GetEnvironmentVariableW, WaitForSingleObject, WriteFile, ExitThread, DeleteCriticalSection, TlsGetValue, GetDateFormatW, SetErrorMode, IsValidLocale, TlsSetValue, CreateDirectoryW, GetSystemDefaultUILanguage, EnumCalendarInfoW, LocalAlloc, GetUserDefaultLangID, RemoveDirectoryW, CreateEventW, SetThreadLocale, GetThreadLocale
                                                    comctl32.dllInitCommonControls
                                                    version.dllGetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
                                                    user32.dllCreateWindowExW, TranslateMessage, CharLowerBuffW, CallWindowProcW, CharUpperW, PeekMessageW, GetSystemMetrics, SetWindowLongW, MessageBoxW, DestroyWindow, CharUpperBuffW, CharNextW, MsgWaitForMultipleObjects, LoadStringW, ExitWindowsEx, DispatchMessageW
                                                    oleaut32.dllSysAllocStringLen, SafeArrayPtrOfIndex, VariantCopy, SafeArrayGetLBound, SafeArrayGetUBound, VariantInit, VariantClear, SysFreeString, SysReAllocStringLen, VariantChangeType, SafeArrayCreate
                                                    netapi32.dllNetWkstaGetInfo, NetApiBufferFree
                                                    advapi32.dllConvertStringSecurityDescriptorToSecurityDescriptorW, RegQueryValueExW, AdjustTokenPrivileges, GetTokenInformation, ConvertSidToStringSidW, LookupPrivilegeValueW, RegCloseKey, OpenProcessToken, RegOpenKeyExW
                                                    NameOrdinalAddress
                                                    TMethodImplementationIntercept30x4541a8
                                                    __dbk_fcall_wrapper20x40d0a0
                                                    dbkFCallWrapperAddr10x4be63c
                                                    Language of compilation systemCountry where language is spokenMap
                                                    EnglishUnited States
                                                    No network behavior found

                                                    Click to jump to process

                                                    Click to jump to process

                                                    Click to dive into process behavior distribution

                                                    Click to jump to process

                                                    Target ID:0
                                                    Start time:12:34:05
                                                    Start date:19/04/2024
                                                    Path:C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe"
                                                    Imagebase:0x400000
                                                    File size:2'642'464 bytes
                                                    MD5 hash:225CC0331D839E8DBEA3F6DC320C59B2
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:Borland Delphi
                                                    Reputation:low
                                                    Has exited:true

                                                    Target ID:1
                                                    Start time:12:34:05
                                                    Start date:19/04/2024
                                                    Path:C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp
                                                    Wow64 process (32bit):true
                                                    Commandline:"C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp" /SL5="$2043C,1792279,832512,C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe"
                                                    Imagebase:0x400000
                                                    File size:3'199'488 bytes
                                                    MD5 hash:F7545D5A5837D3B545E0B0C77BA6D8C5
                                                    Has elevated privileges:true
                                                    Has administrator privileges:true
                                                    Programmed in:Borland Delphi
                                                    Antivirus matches:
                                                    • Detection: 0%, ReversingLabs
                                                    • Detection: 0%, Virustotal, Browse
                                                    Reputation:low
                                                    Has exited:true

                                                    No disassembly