Click to jump to signature section
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static PE information: certificate valid |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://ccsca2021.crl.certum.pl/ccsca2021.crl0s |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://ccsca2021.ocsp-certum.com05 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://crl.certum.pl/ctnca.crl0k |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://crl.certum.pl/ctnca2.crl0l |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://crl.certum.pl/ctsca2021.crl0o |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://repository.certum.pl/ccsca2021.cer0 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://repository.certum.pl/ctnca.cer09 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://repository.certum.pl/ctnca2.cer09 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://repository.certum.pl/ctsca2021.cer0A |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://s.symcb.com/universal-root.crl0 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://s.symcd.com06 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://subca.ocsp-certum.com01 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://subca.ocsp-certum.com02 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://subca.ocsp-certum.com05 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://ts-aia.ws.symantec.com/sha256-tss-ca.cer0( |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://ts-crl.ws.symantec.com/sha256-tss-ca.crl0 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://ts-ocsp.ws.symantec.com0; |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: http://www.certum.pl/CPS0 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: https://d.symcb.com/cps0% |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: https://d.symcb.com/rpa0 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: https://d.symcb.com/rpa0. |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.00000000022C3000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1698856525.00000000025AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://tortoisegit.org |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1650871083.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1656036498.0000000003490000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://tortoisegit.org.https://tortoisegit.org.https://tortoisegit.org |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000003.1698856525.00000000025AA000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://tortoisegit.orgA |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.00000000022C3000.00000004.00001000.00020000.00000000.sdmp | String found in binary or memory: https://tortoisegit.orgQ6 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: https://www.certum.pl/CPS0 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000000.1654433570.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.dr | String found in binary or memory: https://www.innosetup.com/ |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002580000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FB40000.00000004.00001000.00020000.00000000.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp, 00000001.00000000.1654433570.0000000000401000.00000020.00000001.01000000.00000004.sdmp, TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.dr | String found in binary or memory: https://www.remobjects.com/ps |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.dr | Static PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000000.1650550452.00000000004C6000.00000002.00000001.01000000.00000003.sdmp | Binary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1700591721.0000000002288000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFilenamekernel32j% vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652813555.000000007FE35000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe, 00000000.00000003.1652184920.0000000002878000.00000004.00001000.00020000.00000000.sdmp | Binary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Binary or memory string: OriginalFileName vs TortoiseGit-2.15.0.1-Hotfix-64bit.exe |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI |
Source: classification engine | Classification label: clean3.winEXE@3/2@0/0 |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | File created: C:\Users\user\AppData\Local\Programs | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | File created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization | Jump to behavior |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | String found in binary or memory: /LOADINF="filename" |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | File read: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Jump to behavior |
Source: unknown | Process created: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe "C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe" | |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Process created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp" /SL5="$2043C,1792279,832512,C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe" | |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Process created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp" /SL5="$2043C,1792279,832512,C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe" | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Section loaded: apphelp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: mpr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: version.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: netapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: winhttp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: netutils.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: uxtheme.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: kernel.appcore.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: wtsapi32.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: winsta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: textinputframework.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: coreuicomponents.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: coremessaging.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: ntmarta.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: wintypes.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: windows.storage.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: wldp.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: profapi.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: shfolder.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: rstrtmgr.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: ncrypt.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: ntasn1.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Section loaded: textshaping.dll | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Key value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner | Jump to behavior |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static PE information: certificate valid |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static file information: File size 2642464 > 1048576 |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Static PE information: section name: .didata |
Source: TortoiseGit-2.15.0.1-Hotfix-64bit.tmp.0.dr | Static PE information: section name: .didata |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | File created: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Jump to dropped file |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | File created: C:\Users\user\AppData\Local\Temp\is-279VF.tmp\_isetup\_setup64.tmp | Jump to dropped file |
Source: C:\Users\user\Desktop\TortoiseGit-2.15.0.1-Hotfix-64bit.exe | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Process information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX | Jump to behavior |
Source: C:\Users\user\AppData\Local\Temp\is-C5IQ9.tmp\TortoiseGit-2.15.0.1-Hotfix-64bit.tmp | Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-279VF.tmp\_isetup\_setup64.tmp | Jump to dropped file |