Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
filmora-idco_setup_full1901.exe

Overview

General Information

Sample name:filmora-idco_setup_full1901.exe
Analysis ID:1428767
MD5:aeb7797267cb552cf82e0348c985543e
SHA1:a080667a17d09a4e6b333c6a99a528c75e9da468
SHA256:b26919b9167cc1ac3c06ff8b2506ff50b23ffa346b9203cafce3972f702fe31e
Infos:

Detection

Score:14
Range:0 - 100
Whitelisted:false
Confidence:40%

Compliance

Score:48
Range:0 - 100

Signatures

Sigma detected: Execution from Suspicious Folder
Abnormal high CPU Usage
Allocates memory with a write watch (potentially for evading sandboxes)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Dropped file seen in connection with other malware
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

Analysis Advice

Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
Sample monitors window changes (e.g. starting applications), analyze the sample with the 'Simulates keyboard and window changes' cookbook
  • System is w10x64_ra
  • filmora-idco_setup_full1901.exe (PID: 7016 cmdline: "C:\Users\user\Desktop\filmora-idco_setup_full1901.exe" MD5: AEB7797267CB552CF82E0348C985543E)
    • NFWCHK.exe (PID: 6168 cmdline: C:\Users\Public\Documents\Wondershare\NFWCHK.exe MD5: 27CFB3990872CAA5930FA69D57AEFE7B)
      • conhost.exe (PID: 6160 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
No yara matches

System Summary

barindex
Source: Process startedAuthor: Florian Roth (Nextron Systems), Tim Shelton: Data: Command: C:\Users\Public\Documents\Wondershare\NFWCHK.exe, CommandLine: C:\Users\Public\Documents\Wondershare\NFWCHK.exe, CommandLine|base64offset|contains: , Image: C:\Users\Public\Documents\Wondershare\NFWCHK.exe, NewProcessName: C:\Users\Public\Documents\Wondershare\NFWCHK.exe, OriginalFileName: C:\Users\Public\Documents\Wondershare\NFWCHK.exe, ParentCommandLine: "C:\Users\user\Desktop\filmora-idco_setup_full1901.exe", ParentImage: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe, ParentProcessId: 7016, ParentProcessName: filmora-idco_setup_full1901.exe, ProcessCommandLine: C:\Users\Public\Documents\Wondershare\NFWCHK.exe, ProcessId: 6168, ProcessName: NFWCHK.exe
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: filmora-idco_setup_full1901.exe, 00000000.00000000.1119233376.00000000003CA000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: -----BEGIN PUBLIC KEY-----memstr_db5fc684-b

Compliance

barindex
Source: filmora-idco_setup_full1901.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: filmora-idco_setup_full1901.exeStatic PE information: certificate valid
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeFile opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dllJump to behavior
Source: filmora-idco_setup_full1901.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: G:\devops_yanfa\workspace\p-4663c901377d457795e7a5c44ce670aa\src\bin\WAE_ENG.pdb source: filmora-idco_setup_full1901.exe
Source: Binary string: G:\devops_yanfa\workspace\p-4663c901377d457795e7a5c44ce670aa\src\bin\WAE_ENG.pdbn" source: filmora-idco_setup_full1901.exe
Source: Binary string: E:\MobileGo\Trunk\PC\Setup\Framework_Lite\DotNetChecker\obj\x86\Release\NFWCHK.pdb source: filmora-idco_setup_full1901.exe, NFWCHK.exe.0.dr
Source: Joe Sandbox ViewIP Address: 23.34.82.12 23.34.82.12
Source: Joe Sandbox ViewIP Address: 47.254.80.199 47.254.80.199
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://23.34.82.12/cbs_down/filmora-idco_64bit_full1901.exe
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://23.34.82.12/cbs_down/filmora-idco_64bit_full1901.exey
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://23.34.82.26/cbs_down/filmora-idco_64bit_full1901.exe
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0=
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.com/in
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://download.wondershare.com/inst/NetFxLite.exe
Source: filmora-idco_setup_full1901.exe, 00000000.00000003.1980986954.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A48000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A8C000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A41000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down
Source: filmora-idco_setup_full1901.exe, 00000000.00000003.1900772172.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2386212187.000000000BE90000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1913987875.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1918842662.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1971922486.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1976584877.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1883788985.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1927103496.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1909528066.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1922570929.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1931777431.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1905075119.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1980986954.000000000BE93000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down.exe
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bi
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_
Source: filmora-idco_setup_full1901.exe, wsWAE.log.0.drString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exe
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeS
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeSY
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeSl
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeSr:
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.execom
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exewin_x64
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down1
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_down3
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_downP
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2386212187.000000000BE90000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1971922486.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1976584877.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1980986954.000000000BE93000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_downexe
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_downm
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_downo;
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_downp
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://download.wondershare.net/cbs_downq
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://ocsp.digicert.com0
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://ocsp.digicert.com0A
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://ocsp.digicert.com0C
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://ocsp.digicert.com0X
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://platform.wondershare.cc
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://platform.wondershare.cc/
Source: filmora-idco_setup_full1901.exe, 00000000.00000003.1151227324.0000000000D30000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://platform.wondershare.cc/rest/v2/downloader/runtime/?client_sign=
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://pop.wondersha
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://pop.wondershare.com/filmora-license.html
Source: filmora-idco_setup_full1901.exeString found in binary or memory: http://www.digicert.com/CPS0
Source: filmora-idco_setup_full1901.exe, 00000000.00000003.2068524982.000000000BFD6000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.2032533661.000000000F0F4000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.2045645040.000000000BF73000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://223.5.5.5
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://223.5.5.5Mzc4Miop0xjZfMjQzNzgwOTYzOTcyMTg4MTY=&uid=/resolve?type=1&short=1&name=&ak=&key=&ts
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://223.6.6.6
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://analytics.300624.com:8106/sa?project=
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.300624.com:8106/sa?project=UA_Wae_Web
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://analytics.wondershare.cc:8106/sa?project=
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.wondershare.cc:8106/sa?project=UA_Wae_Web
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://analytics.wondershare.cc:8106/sa?project=UA_Wae_Web:
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://analytics.wondershare.cc:8106/sa?project=https://analytics.300624.com:8106/sa?project=downlo
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://curl.se/docs/alt-svc.html
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://curl.se/docs/http-cookies.html
Source: filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download.wond
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://download.wondershare.net/cbs_down/filmora-idco_full1901.exe
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://download.wondershare.net/cbs_down/filmora-idco_full1901.exey
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://filmora.wondershare.net/install/filmora-win-idco.html?act=install
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A10000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://filmora.wondershare.net/install/filmora-win-idco.html?act=installap
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://pc-api.300624.com
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://pc-api.wondershare.cc
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://prod-web.wondershare.cc/api/v1/prodweb/trk&os=Windows
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://wae.tmp
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://www.wondershare.com/company/end-user-license-agreement.html
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://www.wondershare.com/privacy.html
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C70000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.wondershare.com/privacy.htmle.html
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess Stats: CPU usage > 24%
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeCode function: 2_2_00007FFEC92C6DF42_2_00007FFEC92C6DF4
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeCode function: 2_2_00007FFEC92C90B02_2_00007FFEC92C90B0
Source: Joe Sandbox ViewDropped File: C:\Users\Public\Documents\Wondershare\NFWCHK.exe 43881549228975C7506B050BCE4D9B671412D3CDC08C7516C9DBBB7F50C25146
Source: filmora-idco_setup_full1901.exeStatic PE information: Resource name: EXE type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
Source: filmora-idco_setup_full1901.exeStatic PE information: Resource name: ZIPRES type: Zip archive data, at least v2.0 to extract, compression method=deflate
Source: filmora-idco_setup_full1901.exe, 00000000.00000000.1119294056.0000000000429000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameNFWCHK.exe0 vs filmora-idco_setup_full1901.exe
Source: filmora-idco_setup_full1901.exeBinary or memory string: OriginalFilenameNFWCHK.exe0 vs filmora-idco_setup_full1901.exe
Source: filmora-idco_setup_full1901.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
Source: classification engineClassification label: clean14.winEXE@4/76@0/6
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeFile created: C:\Users\Public\Documents\Wondershare\Jump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeMutant created: NULL
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6160:120:WilError_03
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeFile created: C:\Users\user\AppData\Local\Temp\WondershareJump to behavior
Source: filmora-idco_setup_full1901.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: filmora-idco_setup_full1901.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.72%
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: filmora-idco_setup_full1901.exeString found in binary or memory: <?xml version="1.0" encoding="UTF-8"?> <config> <Status>1</Status> <JoinExp>1</JoinExp> <SelectLang>English</SelectLang> <InstallPath>C:\Users\user\AppData\Local\</InstallPath> <AgreeExtInstall>1</AgreeExtInstall> </config>
Source: filmora-idco_setup_full1901.exeString found in binary or memory: https://filmora.wondershare.net/install/filmora-win-idco.html?act=install
Source: filmora-idco_setup_full1901.exeString found in binary or memory: C:\Users\user\AppData\Local\</InstallPath>
Source: filmora-idco_setup_full1901.exeString found in binary or memory: dir=[%s]prodstarttimeprodstartcode&product_version=&installtime=&m_nProductID=client_sign=;[WARN] %d - jump url=[%s] is invalid.&?[WARN] %d - thanks url=[%s] is invalid.&?thank_you_pagepagedownloader_web1browserdownpackage_pagepagedownloader_webretrycbs_down[INFO] %d - set select lang=[%s].\\\\[INFO] %d - BuildInstallPara, common./VERYSILENT /NOPAGE [INFO] %d - BuildInstallPara, product startup=[%d]..logWAE-" /LOG="/VERYSILENT /NOPAGE /LANG=" /WAEWIN= /DIR="" /installpath: " /PID=[INFO] %d - BuildInstallPara product arg.token /TOKEN_PRODUCTINSTALL_ARG= /NOTRUN[INFO] %d - BuildInstallPara dependent startup=[%d]..log" /WAEWIN=WAE- /LOG="/VERYSILENT /NOPAGE /LANG= /PID=" /DIR="" /installpath: "[INFO] %d - BuildInstallPara dependent arg.token /TOKEN_PRODUCTINSTALL_ARG= /NOTRUN" /HOSTINFOPATH="3264[INFO] %d - BuildProductAndDepentTask, bit=[%s] package.64downpackagebits32downpackagebitsstartupproduct1[INFO] %d - BuildProductAndDepentTask, use local x86 down url.1[INFO] %d - BuildProductAndDepentTask, use local x64 down url.[INFO] %d - query package size=[%I64u] by domain_url.[WARN] %d - dir=[%s], disk_free_size=[%lld],,true[INFO] %d - already install wcc.1.NET Frameworkdotnetver[INFO] %d - PrepareDown0[INFO] %d - set host hwnd=[%x].-startmodel:floatmode[INFO] %d - startup wcc ret=[%d]:
Source: filmora-idco_setup_full1901.exeString found in binary or memory: dir=[%s]prodstarttimeprodstartcode&product_version=&installtime=&m_nProductID=client_sign=;[WARN] %d - jump url=[%s] is invalid.&?[WARN] %d - thanks url=[%s] is invalid.&?thank_you_pagepagedownloader_web1browserdownpackage_pagepagedownloader_webretrycbs_down[INFO] %d - set select lang=[%s].\\\\[INFO] %d - BuildInstallPara, common./VERYSILENT /NOPAGE [INFO] %d - BuildInstallPara, product startup=[%d]..logWAE-" /LOG="/VERYSILENT /NOPAGE /LANG=" /WAEWIN= /DIR="" /installpath: " /PID=[INFO] %d - BuildInstallPara product arg.token /TOKEN_PRODUCTINSTALL_ARG= /NOTRUN[INFO] %d - BuildInstallPara dependent startup=[%d]..log" /WAEWIN=WAE- /LOG="/VERYSILENT /NOPAGE /LANG= /PID=" /DIR="" /installpath: "[INFO] %d - BuildInstallPara dependent arg.token /TOKEN_PRODUCTINSTALL_ARG= /NOTRUN" /HOSTINFOPATH="3264[INFO] %d - BuildProductAndDepentTask, bit=[%s] package.64downpackagebits32downpackagebitsstartupproduct1[INFO] %d - BuildProductAndDepentTask, use local x86 down url.1[INFO] %d - BuildProductAndDepentTask, use local x64 down url.[INFO] %d - query package size=[%I64u] by domain_url.[WARN] %d - dir=[%s], disk_free_size=[%lld],,true[INFO] %d - already install wcc.1.NET Frameworkdotnetver[INFO] %d - PrepareDown0[INFO] %d - set host hwnd=[%x].-startmodel:floatmode[INFO] %d - startup wcc ret=[%d]:
Source: filmora-idco_setup_full1901.exeString found in binary or memory: <Url_Install><![CDATA[https://filmora.wondershare.net/install/filmora-win-idco.html?act=install]]></Url_Install>
Source: filmora-idco_setup_full1901.exeString found in binary or memory: </Installurl>
Source: filmora-idco_setup_full1901.exeString found in binary or memory: <InstallTime>240</InstallTime>
Source: unknownProcess created: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe "C:\Users\user\Desktop\filmora-idco_setup_full1901.exe"
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess created: C:\Users\Public\Documents\Wondershare\NFWCHK.exe C:\Users\Public\Documents\Wondershare\NFWCHK.exe
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess created: C:\Users\Public\Documents\Wondershare\NFWCHK.exe C:\Users\Public\Documents\Wondershare\NFWCHK.exeJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: dbghelp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: winhttp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: dbgcore.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: sspicli.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: secur32.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: schannel.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: windowscodecs.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: msimg32.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: ieframe.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: wkscli.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: urlmon.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: srvcli.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: msftedit.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: windows.globalization.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: bcp47mrm.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: globinputhost.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: msiso.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: mshtml.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: powrprof.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: umpdc.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: srpapi.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: msimtf.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: dxgi.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: mlang.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: resourcepolicyclient.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: wininet.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: d2d1.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: dwrite.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: d3d11.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: d3d10warp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: dxcore.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: uiautomationcore.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: msls31.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: napinsp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: pnrpnsp.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: wshbth.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: nlaapi.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: winrnr.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeSection loaded: explorerframe.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: mscoree.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: apphelp.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: version.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: wldp.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{4657278A-411B-11d2-839A-00C04FD918D0}\InProcServer32Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeFile opened: C:\Windows\SysWOW64\Msftedit.dllJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: filmora-idco_setup_full1901.exeStatic PE information: certificate valid
Source: filmora-idco_setup_full1901.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
Source: filmora-idco_setup_full1901.exeStatic file information: File size 1995256 > 1048576
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeFile opened: C:\Windows\WinSxS\amd64_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.9672_none_88e266cb2fac7c0d\MSVCR80.dllJump to behavior
Source: filmora-idco_setup_full1901.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x138400
Source: filmora-idco_setup_full1901.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: filmora-idco_setup_full1901.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: filmora-idco_setup_full1901.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: filmora-idco_setup_full1901.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: filmora-idco_setup_full1901.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: filmora-idco_setup_full1901.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: filmora-idco_setup_full1901.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: filmora-idco_setup_full1901.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: G:\devops_yanfa\workspace\p-4663c901377d457795e7a5c44ce670aa\src\bin\WAE_ENG.pdb source: filmora-idco_setup_full1901.exe
Source: Binary string: G:\devops_yanfa\workspace\p-4663c901377d457795e7a5c44ce670aa\src\bin\WAE_ENG.pdbn" source: filmora-idco_setup_full1901.exe
Source: Binary string: E:\MobileGo\Trunk\PC\Setup\Framework_Lite\DotNetChecker\obj\x86\Release\NFWCHK.pdb source: filmora-idco_setup_full1901.exe, NFWCHK.exe.0.dr
Source: filmora-idco_setup_full1901.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: filmora-idco_setup_full1901.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: filmora-idco_setup_full1901.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: filmora-idco_setup_full1901.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: filmora-idco_setup_full1901.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00D6126A push esi; retf 0_2_00D61279
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA3ECD push eax; retf 0_2_00CA3ECE
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA0AD1 push eax; retf 0_2_00CA0AD2
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA0CD5 push esi; retf 0_2_00CA0CD6
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA54E9 push ebp; retf 0000h0_2_00CA553E
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA1E89 push ds; retf 0000h0_2_00CA1E8A
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA5489 push esp; retf 0000h0_2_00CA5496
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA0AA9 push cs; retf 0000h0_2_00CA0AAA
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA10B0 push ecx; retf 0_2_00CA10B2
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA0CB1 push esp; retf 0_2_00CA0CB2
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00C934B4 push edx; retf 0_2_00C934CA
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA106F push ebx; retf 0_2_00CA1072
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA0E63 push cs; retf 0000h0_2_00CA0E66
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA1660 push ss; retf 0000h0_2_00CA1662
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA1005 push cs; retf 0000h0_2_00CA1026
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA1031 push ecx; retf 0_2_00CA1032
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA09CD push ebp; retf 0_2_00CA09D6
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA0FE4 push ebx; retf 0_2_00CA0FF2
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00C9A797 push C700001Bh; ret 0_2_00C9A7C1
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA09A4 push ebp; retf 0_2_00CA09B6
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA53BD push ebx; retf 0000h0_2_00CA53BE
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA3F5D push ebx; retf 0_2_00CA3F5E
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00C97D67 push ss; retf 0_2_00C97D6A
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00CA0D31 push esp; retf 0_2_00CA0D32
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00C748F8 pushfd ; iretd 0_2_00C748F9
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_00C7265D push esi; retf 0_2_00C7265E
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_05A832A1 push eax; iretd 0_2_05A832A2
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_05A83275 push eax; iretd 0_2_05A83276
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_05A6A305 push ecx; iretd 0_2_05A6A317
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_05A6A48E push edi; iretd 0_2_05A6A4B4
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeCode function: 0_2_05A6A311 push ecx; iretd 0_2_05A6A317
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeFile created: C:\Users\Public\Documents\Wondershare\NFWCHK.exeJump to dropped file
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeMemory allocated: 54C0000 memory reserve | memory write watchJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeMemory allocated: 1560000 memory reserve | memory write watchJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeMemory allocated: 3330000 memory reserve | memory write watchJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeMemory allocated: 1B330000 memory commit | memory reserve | memory write watchJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 300000Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 300000Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 7200000Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 7200000Jump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeWindow / User API: threadDelayed 8030Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe TID: 7036Thread sleep time: -94500s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe TID: 7040Thread sleep time: -77100000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe TID: 7108Thread sleep time: -71400000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe TID: 7040Thread sleep time: -14400000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe TID: 7108Thread sleep time: -14400000s >= -30000sJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exe TID: 7036Thread sleep time: -2409000s >= -30000sJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exe TID: 6276Thread sleep time: -1844674407370954s >= -30000sJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exe TID: 6332Thread sleep time: -922337203685477s >= -30000sJump to behavior
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 300000Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 300000Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 7200000Jump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeThread delayed: delay time: 7200000Jump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeThread delayed: delay time: 922337203685477Jump to behavior
Source: filmora-idco_setup_full1901.exeBinary or memory string: Hyper-V RAW
Source: filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeProcess created: C:\Users\Public\Documents\Wondershare\NFWCHK.exe C:\Users\Public\Documents\Wondershare\NFWCHK.exeJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeQueries volume information: C:\Windows\Fonts\timesi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeQueries volume information: C:\Windows\Fonts\timesbd.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeQueries volume information: C:\Windows\Fonts\timesbi.ttf VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeQueries volume information: C:\Windows\Fonts\times.ttf VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration.Install\2.0.0.0__b03f5f7f11d50a3a\System.Configuration.Install.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_64\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll VolumeInformationJump to behavior
Source: C:\Users\Public\Documents\Wondershare\NFWCHK.exeQueries volume information: C:\Windows\assembly\GAC_64\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\filmora-idco_setup_full1901.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts2
Command and Scripting Interpreter
1
DLL Side-Loading
11
Process Injection
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote Services11
Archive Collected Data
1
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/JobBoot or Logon Initialization Scripts1
DLL Side-Loading
1
Disable or Modify Tools
LSASS Memory31
Virtualization/Sandbox Evasion
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)31
Virtualization/Sandbox Evasion
Security Account Manager1
Application Window Discovery
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook11
Process Injection
NTDS12
System Information Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Obfuscated Files or Information
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
filmora-idco_setup_full1901.exe0%ReversingLabs
SourceDetectionScannerLabelLink
C:\Users\Public\Documents\Wondershare\NFWCHK.exe0%ReversingLabs
No Antivirus matches
No Antivirus matches
No Antivirus matches
No contacted domains info
NameSourceMaliciousAntivirus DetectionReputation
http://23.34.82.26/cbs_down/filmora-idco_64bit_full1901.exefilmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpfalse
    unknown
    https://223.5.5.5filmora-idco_setup_full1901.exefalse
      unknown
      http://download.wondershare.net/cbs_downo;filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpfalse
        high
        http://platform.wondershare.cc/filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpfalse
          high
          http://www.jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupUfilmora-idco_setup_full1901.exe, 00000000.00000003.2068524982.000000000BFD6000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.2032533661.000000000F0F4000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.2045645040.000000000BF73000.00000004.00000020.00020000.00000000.sdmpfalse
            high
            https://download.wondershare.net/cbs_down/filmora-idco_full1901.exefilmora-idco_setup_full1901.exefalse
              high
              http://download.wondershare.com/infilmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpfalse
                high
                http://23.34.82.12/cbs_down/filmora-idco_64bit_full1901.exefilmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  https://filmora.wondershare.net/install/filmora-win-idco.html?act=installfilmora-idco_setup_full1901.exefalse
                    high
                    http://download.wondershare.net/cbs_downfilmora-idco_setup_full1901.exe, 00000000.00000003.1980986954.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A48000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A8C000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A41000.00000004.00000020.00020000.00000000.sdmpfalse
                      high
                      http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exewin_x64filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A10000.00000004.00000020.00020000.00000000.sdmpfalse
                        high
                        https://prod-web.wondershare.cc/api/v1/prodweb/trk&os=Windowsfilmora-idco_setup_full1901.exefalse
                          high
                          http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeSYfilmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpfalse
                            high
                            http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exefilmora-idco_setup_full1901.exe, wsWAE.log.0.drfalse
                              high
                              https://pc-api.wondershare.ccfilmora-idco_setup_full1901.exefalse
                                high
                                http://download.wondershare.net/cbs_downqfilmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpfalse
                                  high
                                  https://analytics.300624.com:8106/sa?project=UA_Wae_Webfilmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpfalse
                                    unknown
                                    https://analytics.wondershare.cc:8106/sa?project=filmora-idco_setup_full1901.exefalse
                                      high
                                      http://pop.wondershafilmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpfalse
                                        unknown
                                        http://download.wondershare.net/cbs_downmfilmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpfalse
                                          high
                                          http://download.wondershare.net/cbs_downpfilmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpfalse
                                            high
                                            https://www.wondershare.com/privacy.htmlfilmora-idco_setup_full1901.exefalse
                                              high
                                              https://223.5.5.5Mzc4Miop0xjZfMjQzNzgwOTYzOTcyMTg4MTY=&uid=/resolve?type=1&short=1&name=&ak=&key=&tsfilmora-idco_setup_full1901.exefalse
                                                low
                                                http://download.wondershare.net/cbs_down/filmora-idco_64bit_filmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  high
                                                  http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeSlfilmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpfalse
                                                    high
                                                    https://www.wondershare.com/company/end-user-license-agreement.htmlfilmora-idco_setup_full1901.exefalse
                                                      high
                                                      http://platform.wondershare.ccfilmora-idco_setup_full1901.exefalse
                                                        high
                                                        https://curl.se/docs/http-cookies.htmlfilmora-idco_setup_full1901.exefalse
                                                          unknown
                                                          http://download.wondershare.net/cbs_downPfilmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                            high
                                                            http://platform.wondershare.cc/rest/v2/downloader/runtime/?client_sign=filmora-idco_setup_full1901.exe, 00000000.00000003.1151227324.0000000000D30000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              high
                                                              https://download.wondfilmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C93000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                unknown
                                                                https://curl.se/docs/alt-svc.htmlfilmora-idco_setup_full1901.exefalse
                                                                  unknown
                                                                  https://filmora.wondershare.net/install/filmora-win-idco.html?act=installapfilmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A10000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                    high
                                                                    https://pc-api.300624.comfilmora-idco_setup_full1901.exefalse
                                                                      unknown
                                                                      https://analytics.wondershare.cc:8106/sa?project=UA_Wae_Webfilmora-idco_setup_full1901.exe, filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                        high
                                                                        https://analytics.wondershare.cc:8106/sa?project=https://analytics.300624.com:8106/sa?project=downlofilmora-idco_setup_full1901.exefalse
                                                                          high
                                                                          https://analytics.300624.com:8106/sa?project=filmora-idco_setup_full1901.exefalse
                                                                            unknown
                                                                            https://download.wondershare.net/cbs_down/filmora-idco_full1901.exeyfilmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                              high
                                                                              http://download.wondershare.net/cbs_down.exefilmora-idco_setup_full1901.exe, 00000000.00000003.1900772172.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000002.2386212187.000000000BE90000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1913987875.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1918842662.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1971922486.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1976584877.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1883788985.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1927103496.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1909528066.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1922570929.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1931777431.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1905075119.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1980986954.000000000BE93000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                high
                                                                                http://download.wondershare.com/inst/NetFxLite.exefilmora-idco_setup_full1901.exefalse
                                                                                  high
                                                                                  https://wae.tmpfilmora-idco_setup_full1901.exefalse
                                                                                    unknown
                                                                                    http://download.wondershare.net/cbs_down1filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                      high
                                                                                      http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.execomfilmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A10000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                        high
                                                                                        http://pop.wondershare.com/filmora-license.htmlfilmora-idco_setup_full1901.exefalse
                                                                                          high
                                                                                          http://download.wondershare.net/cbs_down3filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005ACB000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            high
                                                                                            http://download.wondershare.net/cbs_downexefilmora-idco_setup_full1901.exe, 00000000.00000002.2386212187.000000000BE90000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1971922486.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1976584877.000000000BE93000.00000004.00000020.00020000.00000000.sdmp, filmora-idco_setup_full1901.exe, 00000000.00000003.1980986954.000000000BE93000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                              high
                                                                                              https://analytics.wondershare.cc:8106/sa?project=UA_Wae_Web:filmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                high
                                                                                                https://www.wondershare.com/privacy.htmle.htmlfilmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C70000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                  high
                                                                                                  http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeSr:filmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                    high
                                                                                                    http://download.wondershare.net/cbs_down/filmora-idco_64bit_full1901.exeSfilmora-idco_setup_full1901.exe, 00000000.00000002.2380025162.0000000000C78000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                      high
                                                                                                      https://223.6.6.6filmora-idco_setup_full1901.exefalse
                                                                                                        unknown
                                                                                                        http://23.34.82.12/cbs_down/filmora-idco_64bit_full1901.exeyfilmora-idco_setup_full1901.exe, 00000000.00000002.2384496374.0000000005A66000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                          unknown
                                                                                                          http://download.wondershare.net/cbs_down/filmora-idco_64bifilmora-idco_setup_full1901.exefalse
                                                                                                            high
                                                                                                            • No. of IPs < 25%
                                                                                                            • 25% < No. of IPs < 50%
                                                                                                            • 50% < No. of IPs < 75%
                                                                                                            • 75% < No. of IPs
                                                                                                            IPDomainCountryFlagASNASN NameMalicious
                                                                                                            47.251.49.246
                                                                                                            unknownUnited States
                                                                                                            45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
                                                                                                            23.34.82.12
                                                                                                            unknownUnited States
                                                                                                            25019SAUDINETSTC-ASSAfalse
                                                                                                            47.254.80.199
                                                                                                            unknownUnited States
                                                                                                            45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
                                                                                                            23.34.82.26
                                                                                                            unknownUnited States
                                                                                                            25019SAUDINETSTC-ASSAfalse
                                                                                                            47.88.57.97
                                                                                                            unknownUnited States
                                                                                                            45102CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdCfalse
                                                                                                            IP
                                                                                                            127.0.0.1
                                                                                                            Joe Sandbox version:40.0.0 Tourmaline
                                                                                                            Analysis ID:1428767
                                                                                                            Start date and time:2024-04-19 15:38:25 +02:00
                                                                                                            Joe Sandbox product:CloudBasic
                                                                                                            Overall analysis duration:0h 6m 27s
                                                                                                            Hypervisor based Inspection enabled:false
                                                                                                            Report type:full
                                                                                                            Cookbook file name:defaultwindowsinteractivecookbook.jbs
                                                                                                            Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                            Number of analysed new started processes analysed:15
                                                                                                            Number of new started drivers analysed:0
                                                                                                            Number of existing processes analysed:0
                                                                                                            Number of existing drivers analysed:0
                                                                                                            Number of injected processes analysed:0
                                                                                                            Technologies:
                                                                                                            • HCA enabled
                                                                                                            • EGA enabled
                                                                                                            • AMSI enabled
                                                                                                            Analysis Mode:default
                                                                                                            Analysis stop reason:Timeout
                                                                                                            Sample name:filmora-idco_setup_full1901.exe
                                                                                                            Detection:CLEAN
                                                                                                            Classification:clean14.winEXE@4/76@0/6
                                                                                                            EGA Information:Failed
                                                                                                            HCA Information:
                                                                                                            • Successful, ratio: 57%
                                                                                                            • Number of executed functions: 53
                                                                                                            • Number of non-executed functions: 0
                                                                                                            Cookbook Comments:
                                                                                                            • Found application associated with file extension: .exe
                                                                                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, SIHClient.exe, SgrmBroker.exe, MoUsoCoreWorker.exe, conhost.exe, svchost.exe
                                                                                                            • Execution Graph export aborted for target NFWCHK.exe, PID 6168 because it is empty
                                                                                                            • Execution Graph export aborted for target filmora-idco_setup_full1901.exe, PID 7016 because there are no executed function
                                                                                                            • Not all processes where analyzed, report is missing behavior information
                                                                                                            • Report size getting too big, too many NtCreateFile calls found.
                                                                                                            • Report size getting too big, too many NtDeviceIoControlFile calls found.
                                                                                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                                                                                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                            • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                                                            • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                            • Report size getting too big, too many NtWriteFile calls found.
                                                                                                            • Skipping network analysis since amount of network traffic is too extensive
                                                                                                            • VT rate limit hit for: filmora-idco_setup_full1901.exe
                                                                                                            TimeTypeDescription
                                                                                                            15:38:53API Interceptor4760125x Sleep call for process: filmora-idco_setup_full1901.exe modified
                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                            47.251.49.246recoverit_setup_full4134.exeGet hashmaliciousUnknownBrowse
                                                                                                              https://drfoneair.wondershare.com/Get hashmaliciousUnknownBrowse
                                                                                                                23.34.82.12file.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                  osvpYbj9SC.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                    file.exeGet hashmaliciousRisePro StealerBrowse
                                                                                                                      e0Ae1lY8DL.exeGet hashmaliciousUnknownBrowse
                                                                                                                        BtO55PhUbM.exeGet hashmaliciousUnknownBrowse
                                                                                                                          file.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                            Payment Advice Batch#876756.jpeg .SVGGet hashmaliciousAgentTesla, HTMLPhisherBrowse
                                                                                                                              ODDBALL0.exeGet hashmaliciousAmadey, RisePro StealerBrowse
                                                                                                                                47.254.80.199recoverit_setup_full4134.exeGet hashmaliciousUnknownBrowse
                                                                                                                                  https://www.edrawmax.com/online/share.html?code=235a0cc4c01511eeb72a0a951ba8b83dGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                                                                                                                    https://www.edrawmax.com/online/share.html?code=235a0cc4c01511eeb72a0a951ba8b83dGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                                                                                                                      https://www.edrawmax.com/online/share.html?code=235a0cc4c01511eeb72a0a951ba8b83dGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                                                                                                                        https://www.edrawmax.com/online/share.html?code=235a0cc4c01511eeb72a0a951ba8b83dGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                                                                                                                          https://www.edrawmax.com/online/share.html?code=235a0cc4c01511eeb72a0a951ba8b83dGet hashmaliciousHtmlDropper, HTMLPhisherBrowse
                                                                                                                                            https://www.edrawmax.com/online/share.html?code=6ff2799ebde611ee80880a54be41f961Get hashmaliciousUnknownBrowse
                                                                                                                                              https://tracedm-ap-southeast-1.aliyun.com/trace/v1/report?bid=20221123&env=17870283361186532041&mac=73310&mf=pdfcloud%40mail-service.wondershare.com&msgid=ee12d1b7-58c3-4a31-b3d2-3d27cc17b3b2%40alibaba.com&sac=0&tag=API&tid=task20221123&to=john%40jrgrif.com.au&tpl=&ts=1669185545&type=0&url=https%3A%2F%2Fdocumentcloud.wondershare.com%2Fshare%2Freview%2F4TOdulHoE4tDDJkYojwSieEYmk6u5ppAEg8icFW9-omyLzIMpcz1BrmzGLoJZVTVdt_NTVnv_nNTApsf2vDh6A%3Flang%3Den-us&v=1.0&sign=3d00d92ef44c0af98c6f2c3fd80b2aa4Get hashmaliciousUnknownBrowse
                                                                                                                                                https://www.hipdf.com/download-file?share_id=TJFSlUuhm3TrYHMFvuLGhAGet hashmaliciousUnknownBrowse
                                                                                                                                                  https://www.hipdf.com/download-file?share_id=TJFSlUuhm3TrYHMFvuLGhAGet hashmaliciousUnknownBrowse
                                                                                                                                                    23.34.82.26BtO55PhUbM.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                      47.88.57.97recoverit_setup_full4134.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                        No context
                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                        CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC2.jpg.exeGet hashmaliciousCobaltStrike, Metasploit, ReflectiveLoaderBrowse
                                                                                                                                                        • 8.218.236.5
                                                                                                                                                        http://www.sushi-idea.comGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.246.136.185
                                                                                                                                                        SecuriteInfo.com.Trojan.KillProc2.23108.29569.31585.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.243.79.202
                                                                                                                                                        PO_La-Tanerie04180240124.vbsGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                                        • 47.91.88.207
                                                                                                                                                        PO_La-Tanerie04180240124.batGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                                        • 47.91.88.207
                                                                                                                                                        4XAsw9FSr5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.241.21.33
                                                                                                                                                        rc21AW1MZD.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.220.102.72
                                                                                                                                                        hYN45tzxwl.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.218.15.223
                                                                                                                                                        aga94GHd1L.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 47.252.147.82
                                                                                                                                                        16rBksY5gH.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.222.72.244
                                                                                                                                                        CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC2.jpg.exeGet hashmaliciousCobaltStrike, Metasploit, ReflectiveLoaderBrowse
                                                                                                                                                        • 8.218.236.5
                                                                                                                                                        http://www.sushi-idea.comGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.246.136.185
                                                                                                                                                        SecuriteInfo.com.Trojan.KillProc2.23108.29569.31585.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.243.79.202
                                                                                                                                                        PO_La-Tanerie04180240124.vbsGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                                        • 47.91.88.207
                                                                                                                                                        PO_La-Tanerie04180240124.batGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                                        • 47.91.88.207
                                                                                                                                                        4XAsw9FSr5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.241.21.33
                                                                                                                                                        rc21AW1MZD.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.220.102.72
                                                                                                                                                        hYN45tzxwl.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.218.15.223
                                                                                                                                                        aga94GHd1L.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 47.252.147.82
                                                                                                                                                        16rBksY5gH.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.222.72.244
                                                                                                                                                        SAUDINETSTC-ASSAczEunnbk7b.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 159.47.222.152
                                                                                                                                                        Gq7FlDf6cE.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 178.86.249.202
                                                                                                                                                        E3kpuuuOfy.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 142.247.166.28
                                                                                                                                                        Vedtb2CYvY.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 212.118.147.131
                                                                                                                                                        vEnh6fr6F0.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 159.42.98.189
                                                                                                                                                        szBCKC8yTb.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 37.105.134.66
                                                                                                                                                        https://ecouterrepondeurvocal.pro/35-hnJZibGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 23.34.82.23
                                                                                                                                                        d94i39z585.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 170.101.238.219
                                                                                                                                                        x86.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 178.86.249.223
                                                                                                                                                        2EFEN3j6ml.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 95.184.102.145
                                                                                                                                                        SAUDINETSTC-ASSAczEunnbk7b.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 159.47.222.152
                                                                                                                                                        Gq7FlDf6cE.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 178.86.249.202
                                                                                                                                                        E3kpuuuOfy.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 142.247.166.28
                                                                                                                                                        Vedtb2CYvY.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 212.118.147.131
                                                                                                                                                        vEnh6fr6F0.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 159.42.98.189
                                                                                                                                                        szBCKC8yTb.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 37.105.134.66
                                                                                                                                                        https://ecouterrepondeurvocal.pro/35-hnJZibGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 23.34.82.23
                                                                                                                                                        d94i39z585.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 170.101.238.219
                                                                                                                                                        x86.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 178.86.249.223
                                                                                                                                                        2EFEN3j6ml.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 95.184.102.145
                                                                                                                                                        CNNIC-ALIBABA-US-NET-APAlibabaUSTechnologyCoLtdC2.jpg.exeGet hashmaliciousCobaltStrike, Metasploit, ReflectiveLoaderBrowse
                                                                                                                                                        • 8.218.236.5
                                                                                                                                                        http://www.sushi-idea.comGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.246.136.185
                                                                                                                                                        SecuriteInfo.com.Trojan.KillProc2.23108.29569.31585.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.243.79.202
                                                                                                                                                        PO_La-Tanerie04180240124.vbsGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                                        • 47.91.88.207
                                                                                                                                                        PO_La-Tanerie04180240124.batGet hashmaliciousFormBook, GuLoaderBrowse
                                                                                                                                                        • 47.91.88.207
                                                                                                                                                        4XAsw9FSr5.elfGet hashmaliciousUnknownBrowse
                                                                                                                                                        • 47.241.21.33
                                                                                                                                                        rc21AW1MZD.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.220.102.72
                                                                                                                                                        hYN45tzxwl.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.218.15.223
                                                                                                                                                        aga94GHd1L.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 47.252.147.82
                                                                                                                                                        16rBksY5gH.elfGet hashmaliciousMiraiBrowse
                                                                                                                                                        • 8.222.72.244
                                                                                                                                                        No context
                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                        C:\Users\Public\Documents\Wondershare\NFWCHK.exerecoverit_setup_full4134.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                          Filmora-Wondershare-Installer.exeGet hashmaliciousSERVHELPERBrowse
                                                                                                                                                            ViJoy.exeGet hashmaliciousSERVHELPERBrowse
                                                                                                                                                              filmora_64bit_setup_full1083.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                drfone_backup_setup_full3369.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                  recoverit_setup_full4153.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                    win-drfone_setup_full3360.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):7168
                                                                                                                                                                      Entropy (8bit):4.201546276827661
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:6xtpP1w73SSxzvevFTFaWuJkJS6WiSf8wp5THVe6VoVDV+VgIV2VrV6VZVClVRw+:s1G3Nz2tH1WT/+TuzyRv2/oqeD+zNt
                                                                                                                                                                      MD5:27CFB3990872CAA5930FA69D57AEFE7B
                                                                                                                                                                      SHA1:5E1C80D61E8DB0CDC0C9B9FA3B2E36D156D45F8F
                                                                                                                                                                      SHA-256:43881549228975C7506B050BCE4D9B671412D3CDC08C7516C9DBBB7F50C25146
                                                                                                                                                                      SHA-512:A1509024872C99C1CF63F42D9F3C5F063AFDE4E9490C21611551DDD2322D136CE9240256113C525305346CF7B66CCCA84C3DF67637C8FECBFEEBF14FFA373A2A
                                                                                                                                                                      Malicious:true
                                                                                                                                                                      Antivirus:
                                                                                                                                                                      • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                      Joe Sandbox View:
                                                                                                                                                                      • Filename: recoverit_setup_full4134.exe, Detection: malicious, Browse
                                                                                                                                                                      • Filename: Filmora-Wondershare-Installer.exe, Detection: malicious, Browse
                                                                                                                                                                      • Filename: ViJoy.exe, Detection: malicious, Browse
                                                                                                                                                                      • Filename: filmora_64bit_setup_full1083.exe, Detection: malicious, Browse
                                                                                                                                                                      • Filename: drfone_backup_setup_full3369.exe, Detection: malicious, Browse
                                                                                                                                                                      • Filename: recoverit_setup_full4153.exe, Detection: malicious, Browse
                                                                                                                                                                      • Filename: win-drfone_setup_full3360.exe, Detection: malicious, Browse
                                                                                                                                                                      Reputation:moderate, very likely benign file
                                                                                                                                                                      Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......U............................>0... ...@....@.. ....................................@................................../..K....@.......................`......h/............................................... ............... ..H............text...D.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................ 0......H........!...............................................................0..W.......(....(....(....(....(....(....(....(....(....(....(.........r...p.o....(....(.........*.........;;......V....s....&rA..p(....*Fs....&r...p(....*Fs....&r...p(....*Fs....&rG..p(....*Fs....&r...p(....*Fs....&r...p(....*Fs....&re..p(....*.r...p(....*Fs....&r...p(....*Fs....&rm..p(....*Fs....&rm..p(....*..(....*BSJB............v2.0.50727......l.......#~..4.......#Strings............#US.........#GUI
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:XML 1.0 document, ASCII text
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):223
                                                                                                                                                                      Entropy (8bit):4.885882229328509
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:6:TMVBdTtdcIjkfVymRMT4/0xvFM7VNQAlk7V2b5DuACQIT:TMHdRd9ofVymhsvFKzlJ5D9CxT
                                                                                                                                                                      MD5:5BABF2A106C883A8E216F768DB99AD51
                                                                                                                                                                      SHA1:F39E84A226DBF563BA983C6F352E68D561523C8E
                                                                                                                                                                      SHA-256:9E676A617EB0D0535AC05A67C0AE0C0E12D4E998AB55AC786A031BFC25E28300
                                                                                                                                                                      SHA-512:D4596B0AAFE03673083EEF12F01413B139940269255D10256CF535853225348752499325A5DEF803FA1189E639F4A2966A0FBB18E32FE8D27E11C81C9E19A0BB
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:<?xml version="1.0" encoding="utf-8" ?>.<configuration>. <startup useLegacyV2RuntimeActivationPolicy="true">. <supportedRuntime version="v2.0.50727"/>. <supportedRuntime version="v4.0"/>. </startup>.</configuration>
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:XML 1.0 document, ASCII text, with CRLF, LF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):231
                                                                                                                                                                      Entropy (8bit):5.057140645816762
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:6:TMVBd//l4McSaXfvO6uRN23hZ384Lkb4Xu:TMHdHl4zvvL338pbWu
                                                                                                                                                                      MD5:5A524D7178A0AD7E93057AE4F6E4DEE1
                                                                                                                                                                      SHA1:A17B5AC52A0744754F4AD07508CF2ECD5D783F4C
                                                                                                                                                                      SHA-256:D66C1CB6C4136C49EABDA7414FE0D5F156ADBA0771C0C415375C4598C812D969
                                                                                                                                                                      SHA-512:2F841EE0D933CF83E6A4ECD384F39465AC3CED78023F7882F217B3569C7605E4CE127CC60F2420BC27CF4CE2C5FAEDB6DFC0EABAE4A02E3D01E9AC5911A06538
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:<?xml version="1.0" encoding="UTF-8"?>.<config>..<Status>1</Status>..<JoinExp>1</JoinExp>..<SelectLang>English</SelectLang>..<InstallPath>C:\Users\user\AppData\Local\</InstallPath>..<AgreeExtInstall>1</AgreeExtInstall>..</config>..
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:data
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):541451636
                                                                                                                                                                      Entropy (8bit):0.0
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:
                                                                                                                                                                      MD5:D8CB2A263850170444C84A6040C49FD1
                                                                                                                                                                      SHA1:0FBE43E80C638AB0F8D80DB5CB0CB40FC5401FED
                                                                                                                                                                      SHA-256:D81923C8A9067E8633F59D0043913FB857720B9DF0FF75863BD6D38EC2D51200
                                                                                                                                                                      SHA-512:271124B961079258A7A141DFF6D8D4780696F18831713D40B09357E152058B48EE34F0AFD3539F55C399F235B689227DCA5293486297DB3E4446ACD1D8DBB43F
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):3126
                                                                                                                                                                      Entropy (8bit):5.268366129060765
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:96:oLHQMqGpQbRSW71G5KjLOmVeQIGUlwLmrCrSGOD:QtqGpQFn71YKjPJIzlwLmeO/D
                                                                                                                                                                      MD5:16A55B1E259AB28A918D25A3A047B44C
                                                                                                                                                                      SHA1:CEF2457E47C8362C452BB9D585CBEC4C6E067F6A
                                                                                                                                                                      SHA-256:D0F4313058DAAD9B910E10033769216E464D28D276DEF180A9DC9637F306F739
                                                                                                                                                                      SHA-512:07F32B36F62D9DFEE53A8A538217B5D3C5202BC15C89121DD9F5334B1D0F774E37B16F56EEE18C048D54AD53FD11ED48394FC4BA76126970EEED8D47C701A62C
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-24 7:29:42] [INFO] 7020 - OnClick install...[2024-04-24 7:29:42] [INFO] 7156 - sensors, event=[downloader_click]...[2024-04-24 7:29:42] [INFO] 7020 - server_ver=[], installed_ver=[], cmp=[0]..[2024-04-24 7:29:42] [INFO] 7020 - check install path, begin...[2024-04-24 7:29:42] [INFO] 7020 - check install path, end ret=[1]...[2024-04-24 7:29:42] [INFO] 7020 - install path=[C:\Users\user\AppData\Local]...[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, call wae mgr...[2024-04-24 7:39:43] [INFO] 3880 - lang_name=[English], lang_code=[ENG]..[2024-04-24 7:39:43] [INFO] 3880 - BuildInstallPara, product startup=[1]...[2024-04-24 7:39:43] [INFO] 3880 - WaeMgr StartDownTask: 1901, C:\Users\Public\Documents\Wondershare\, , ,..[2024-04-24 7:39:43] [INFO] 3880 - WriteRunConfig..[2024-04-24 7:39:43] [INFO] 7036 - handle type=[0], pid=[1901], taskid=[0]..[2024-04-24 7:39:43] [INFO] 3880 - WaeWnd Download, create install thread...[2024-04-
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      File Type:ISO-8859 text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):34776
                                                                                                                                                                      Entropy (8bit):4.863728047712355
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:48:ojctjX/N+S7Mk88mYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYXbbbq+Zut:oA7Mkdut
                                                                                                                                                                      MD5:C92E8F0A7ABE56FA9B3C79CB1C7F3CB2
                                                                                                                                                                      SHA1:74924219AB9668B8A79CA1898405A619D42A61DE
                                                                                                                                                                      SHA-256:CF6A166CB25AB3823AA379F28AAE976C7239266070F70842476FFA2C50CF5C9D
                                                                                                                                                                      SHA-512:EC87F57EA578B183B5B77334C9DC48ADAEC22D8D19F3CD3AE28287D776233A5EFF3B2E907D745D62935F138CC4351D373ADFD6F49CEC90B3F4412526826347DA
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 1..[2024-04-19 16:13:53] [INFO] 7020 - OnCreate 3..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 1..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:skin.xml, (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 2..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create:(null), (null)..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 4..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 6..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 7..[2024-04-19 16:13:53] [INFO] 7020 - CDialogBuilder::Create 9..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 0..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStdStringPtrMap::Find_: 83, 1..[2024-04-19 16:13:53] [INFO] 7020 - CStd
                                                                                                                                                                      Process:C:\Users\Public\Documents\Wondershare\NFWCHK.exe
                                                                                                                                                                      File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                      Category:dropped
                                                                                                                                                                      Size (bytes):531
                                                                                                                                                                      Entropy (8bit):4.535782341778288
                                                                                                                                                                      Encrypted:false
                                                                                                                                                                      SSDEEP:12:E29002CF2ukjF26K9P2yr2UO02im/e4/2q8326K9w26K97:f90PVvM6KYyiUGi5q8G6KR6Kl
                                                                                                                                                                      MD5:253AA8FA326429A98BF3147D3AF60BBD
                                                                                                                                                                      SHA1:483404DCC5C7BFCB7D78C4131042FA6961E9A6D8
                                                                                                                                                                      SHA-256:7B3077115D1C499F3D4CC121237500803CD0CC49C460595EE7CC5EBD9BAB7E1B
                                                                                                                                                                      SHA-512:06AC0B813F854DF3EDA775ABEB71D02251334BC7CA62A6A6E1C60B9B304BF64E307179F556956C0D08B36CB4C678A42EDC6DCC69F77007D5D034D938C948B97D
                                                                                                                                                                      Malicious:false
                                                                                                                                                                      Preview:.Net Framework 2.0 System.Drawing is well....Net Framework 2.0 System.Xml is well....Net Framework 2.0 System.Windows.Forms is well....Net Framework 2.0 System.Configuration is well....Net Framework 2.0 System.Management is well....Net Framework 2.0 System.Transactions is well....Net Framework 2.0 System.Data is well....Net Framework 2.0 Accessibility is well....Net Framework 2.0 System.ServiceProcess is well....Net Framework 2.0 System.Configuration.Install is well....Net Framework 2.0 System.Configuration.Install is well...
                                                                                                                                                                      File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                                                                                                                                      Entropy (8bit):6.856534738347142
                                                                                                                                                                      TrID:
                                                                                                                                                                      • Win32 Executable (generic) Net Framework (10011505/4) 49.72%
                                                                                                                                                                      • Win32 Executable (generic) a (10002005/4) 49.68%
                                                                                                                                                                      • Windows ActiveX control (116523/4) 0.58%
                                                                                                                                                                      • Generic Win/DOS Executable (2004/3) 0.01%
                                                                                                                                                                      • DOS Executable Generic (2002/1) 0.01%
                                                                                                                                                                      File name:filmora-idco_setup_full1901.exe
                                                                                                                                                                      File size:1'995'256 bytes
                                                                                                                                                                      MD5:aeb7797267cb552cf82e0348c985543e
                                                                                                                                                                      SHA1:a080667a17d09a4e6b333c6a99a528c75e9da468
                                                                                                                                                                      SHA256:b26919b9167cc1ac3c06ff8b2506ff50b23ffa346b9203cafce3972f702fe31e
                                                                                                                                                                      SHA512:7545e8cabe300d2f2588861de74addd68b046de1e033a9f91696d68674ea682f629341ad627fc60b95c462b29232fec34e567fa340887e9e93a631c1127c3891
                                                                                                                                                                      SSDEEP:49152:BFwWwzOx2YlkXEYTy0iTvTEaMKCTZQCoNTZYgi6T:DPwzOPD0cEaqoNt
                                                                                                                                                                      TLSH:6795BF12BBC2C0B3E6B20271487667295EB9BE70573085CBA3D45E1D1E31AD2BD39367
                                                                                                                                                                      File Content Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......................9y..............z&........,.......-.....z&......z&...............Dg.....z&................,......G(............
                                                                                                                                                                      Icon Hash:1f1b33134d312b0e
                                                                                                                                                                      Entrypoint:0x5069f0
                                                                                                                                                                      Entrypoint Section:.text
                                                                                                                                                                      Digitally signed:true
                                                                                                                                                                      Imagebase:0x400000
                                                                                                                                                                      Subsystem:windows gui
                                                                                                                                                                      Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                                                                                                                                      DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                                                                                                                                                                      Time Stamp:0x65A247A2 [Sat Jan 13 08:19:46 2024 UTC]
                                                                                                                                                                      TLS Callbacks:
                                                                                                                                                                      CLR (.Net) Version:
                                                                                                                                                                      OS Version Major:6
                                                                                                                                                                      OS Version Minor:0
                                                                                                                                                                      File Version Major:6
                                                                                                                                                                      File Version Minor:0
                                                                                                                                                                      Subsystem Version Major:6
                                                                                                                                                                      Subsystem Version Minor:0
                                                                                                                                                                      Import Hash:f82f221937e6ca9e120ffb597da1ae7d
                                                                                                                                                                      Signature Valid:true
                                                                                                                                                                      Signature Issuer:CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US
                                                                                                                                                                      Signature Validation Error:The operation completed successfully
                                                                                                                                                                      Error Number:0
                                                                                                                                                                      Not Before, Not After
                                                                                                                                                                      • 20/04/2022 02:00:00 06/04/2025 01:59:59
                                                                                                                                                                      Subject Chain
                                                                                                                                                                      • CN="Wondershare Technology Group Co.,Ltd", O="Wondershare Technology Group Co.,Ltd", L=\u62c9\u8428\u5e02, S=\u897f\u85cf\u81ea\u6cbb\u533a, C=CN, SERIALNUMBER=91540195754285145H, OID.2.5.4.15=Private Organization, OID.1.3.6.1.4.1.311.60.2.1.2=\u897f\u85cf\u81ea\u6cbb\u533a, OID.1.3.6.1.4.1.311.60.2.1.3=CN
                                                                                                                                                                      Version:3
                                                                                                                                                                      Thumbprint MD5:547A43E2E4A99883FE2E25952664247A
                                                                                                                                                                      Thumbprint SHA-1:F61CA74F7B4B27007B4AE9825131DD6FB675B1D0
                                                                                                                                                                      Thumbprint SHA-256:9FD4A0B764D38473638CB73E7826E3887CBDCBE0ED5B7E21E1ED2441E1199F3C
                                                                                                                                                                      Serial:03E3821761E35A96B454DE9E4D5A5012
                                                                                                                                                                      Instruction
                                                                                                                                                                      call 00007FAD5D3BEFAEh
                                                                                                                                                                      jmp 00007FAD5D3A7FC5h
                                                                                                                                                                      push 00000014h
                                                                                                                                                                      push 0058A448h
                                                                                                                                                                      call 00007FAD5D3B876Fh
                                                                                                                                                                      call 00007FAD5D3B34F9h
                                                                                                                                                                      movzx esi, ax
                                                                                                                                                                      push 00000002h
                                                                                                                                                                      call 00007FAD5D3BEF41h
                                                                                                                                                                      pop ecx
                                                                                                                                                                      mov eax, 00005A4Dh
                                                                                                                                                                      cmp word ptr [00400000h], ax
                                                                                                                                                                      je 00007FAD5D3A7FC6h
                                                                                                                                                                      xor ebx, ebx
                                                                                                                                                                      jmp 00007FAD5D3A7FF5h
                                                                                                                                                                      mov eax, dword ptr [0040003Ch]
                                                                                                                                                                      cmp dword ptr [eax+00400000h], 00004550h
                                                                                                                                                                      jne 00007FAD5D3A7FADh
                                                                                                                                                                      mov ecx, 0000010Bh
                                                                                                                                                                      cmp word ptr [eax+00400018h], cx
                                                                                                                                                                      jne 00007FAD5D3A7F9Fh
                                                                                                                                                                      xor ebx, ebx
                                                                                                                                                                      cmp dword ptr [eax+00400074h], 0Eh
                                                                                                                                                                      jbe 00007FAD5D3A7FCBh
                                                                                                                                                                      cmp dword ptr [eax+004000E8h], ebx
                                                                                                                                                                      setne bl
                                                                                                                                                                      mov dword ptr [ebp-1Ch], ebx
                                                                                                                                                                      call 00007FAD5D3B6480h
                                                                                                                                                                      test eax, eax
                                                                                                                                                                      jne 00007FAD5D3A7FCAh
                                                                                                                                                                      push 0000001Ch
                                                                                                                                                                      call 00007FAD5D3A80A1h
                                                                                                                                                                      pop ecx
                                                                                                                                                                      call 00007FAD5D3B4F0Dh
                                                                                                                                                                      test eax, eax
                                                                                                                                                                      jne 00007FAD5D3A7FCAh
                                                                                                                                                                      push 00000010h
                                                                                                                                                                      call 00007FAD5D3A8090h
                                                                                                                                                                      pop ecx
                                                                                                                                                                      call 00007FAD5D3BEFBAh
                                                                                                                                                                      and dword ptr [ebp-04h], 00000000h
                                                                                                                                                                      call 00007FAD5D3B8AF1h
                                                                                                                                                                      test eax, eax
                                                                                                                                                                      jns 00007FAD5D3A7FCAh
                                                                                                                                                                      push 0000001Bh
                                                                                                                                                                      call 00007FAD5D3A8076h
                                                                                                                                                                      pop ecx
                                                                                                                                                                      call dword ptr [0053A300h]
                                                                                                                                                                      mov dword ptr [005968C4h], eax
                                                                                                                                                                      call 00007FAD5D3BEFD5h
                                                                                                                                                                      mov dword ptr [00594550h], eax
                                                                                                                                                                      call 00007FAD5D3BEB92h
                                                                                                                                                                      test eax, eax
                                                                                                                                                                      jns 00007FAD5D3A7FCAh
                                                                                                                                                                      Programming Language:
                                                                                                                                                                      • [ASM] VS2013 build 21005
                                                                                                                                                                      • [ C ] VS2013 build 21005
                                                                                                                                                                      • [ C ] VS2010 SP1 build 40219
                                                                                                                                                                      • [C++] VS2013 build 21005
                                                                                                                                                                      • [RES] VS2013 build 21005
                                                                                                                                                                      • [LNK] VS2013 UPD5 build 40629
                                                                                                                                                                      NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_IMPORT0x18aee40x17c.rdata
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_RESOURCE0x1990000x3e778.rsrc
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_SECURITY0x1e1e000x53f8.reloc
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_BASERELOC0x1d80000x119f4.reloc
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_DEBUG0x13a9600x38.rdata
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_TLS0x1772480x18.rdata
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x1772000x40.rdata
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_IAT0x13a0000x848.rdata
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                      IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                      NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                      .text0x10000x13832d0x138400143f1b9b34f6caae72118e0748e28ffaFalse0.5342078350180144data6.64488854015202IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                      .rdata0x13a0000x53ab00x53c004a551f04364b8bbed6467d7ef02b18c6False0.359404151119403data5.396343868291315IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                      .data0x18e0000x98e80x5600589e498b6179834b38991067d58da005False0.2195221656976744Matlab v4 mat-file (little endian) \315\314\014@, text, rows 1, columns 180, imaginary4.183639853872594IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                      .tls0x1980000x110x200bf619eac0cdf3f68d496ea9344137e8bFalse0.02734375data0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                      .rsrc0x1990000x3e7780x3e8005de8416726c5df42dbec67c957e845f5False0.83195703125data7.664206010264442IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                      .reloc0x1d80000x119f40x11a009098db0702c112fbb8946ecda5edd65bFalse0.5646470523049646data6.615266166313139IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                      NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                      EXE0x1994100x1c00PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS WindowsEnglishUnited States0.3685825892857143
                                                                                                                                                                      PNG0x19b0100x812PNG image data, 111 x 10, 8-bit/color RGBA, non-interlacedEnglishUnited States0.861568247821878
                                                                                                                                                                      PNG0x19b8240x12678PNG image data, 600 x 400, 8-bit/color RGBA, non-interlacedEnglishUnited States1.0004112278467578
                                                                                                                                                                      XML0x1ade9c0x81dXML 1.0 document, Unicode text, UTF-8 textEnglishUnited States0.44294655753490614
                                                                                                                                                                      XML0x1ae6bc0xdfXML 1.0 document, ASCII textEnglishUnited States0.6771300448430493
                                                                                                                                                                      XML0x1ae79c0x1706XML 1.0 document, ASCII textEnglishUnited States0.32694265354597896
                                                                                                                                                                      ZIPRES0x1afea40xc951Zip archive data, at least v2.0 to extract, compression method=deflateEnglishUnited States0.8493703552787318
                                                                                                                                                                      RT_ICON0x1bc7f80x8004PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9953924081533015
                                                                                                                                                                      RT_ICON0x1c47fc0xa5dfPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9977627581659327
                                                                                                                                                                      RT_ICON0x1ceddc0x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 96000.2782157676348548
                                                                                                                                                                      RT_ICON0x1d13840x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9600EnglishUnited States0.3712655601659751
                                                                                                                                                                      RT_ICON0x1d392c0x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 42240.3602251407129456
                                                                                                                                                                      RT_ICON0x1d49d40x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4224EnglishUnited States0.4523921200750469
                                                                                                                                                                      RT_ICON0x1d5a7c0x468Device independent bitmap graphic, 16 x 32 x 32, image size 10880.5514184397163121
                                                                                                                                                                      RT_ICON0x1d5ee40x468Device independent bitmap graphic, 16 x 32 x 32, image size 1088EnglishUnited States0.601063829787234
                                                                                                                                                                      RT_GROUP_ICON0x1d634c0x3edata0.8064516129032258
                                                                                                                                                                      RT_GROUP_ICON0x1d638c0x3edataEnglishUnited States0.8064516129032258
                                                                                                                                                                      RT_VERSION0x1d63cc0xa3cdataEnglishUnited States0.34083969465648856
                                                                                                                                                                      RT_MANIFEST0x1d6e080x970XML 1.0 document, Unicode text, UTF-8 (with BOM) text, with very long lines (2356), with CRLF line terminatorsEnglishUnited States0.3220198675496689
                                                                                                                                                                      DLLImport
                                                                                                                                                                      COMCTL32.dllInitCommonControlsEx, _TrackMouseEvent
                                                                                                                                                                      WLDAP32.dll
                                                                                                                                                                      CRYPT32.dllCertAddCertificateContextToStore, CryptQueryObject, CryptDecodeObjectEx, CertFindExtension, CertFreeCertificateChain, CertFreeCertificateChainEngine, CertGetCertificateChain, CertCreateCertificateChainEngine, CertEnumCertificatesInStore, CertOpenStore, CryptStringToBinaryA, CertFindCertificateInStore, PFXImportCertStore, CertCloseStore, CertFreeCertificateContext
                                                                                                                                                                      KERNEL32.dllReleaseMutex, CreateMutexW, CreateDirectoryW, GetFileAttributesW, LocalFileTimeToFileTime, SetFilePointer, SetFileTime, SystemTimeToFileTime, LocalFree, FormatMessageW, VerSetConditionMask, GetLocalTime, lstrcmpiW, lstrcpynW, lstrcpyW, SetLastError, FreeLibrary, GetSystemDirectoryA, LoadLibraryA, GetModuleHandleA, QueryPerformanceFrequency, SleepEx, QueryPerformanceCounter, VerifyVersionInfoA, GetEnvironmentVariableA, PeekNamedPipe, WaitForMultipleObjects, GetFileType, GetStdHandle, MoveFileExA, GetFileSizeEx, CreateFileA, GetDriveTypeW, GetCurrentProcess, GetLogicalDriveStringsW, GetDiskFreeSpaceExW, GetEnvironmentVariableW, SetErrorMode, CreateProcessW, LoadLibraryExW, GetExitCodeProcess, TerminateProcess, lstrcmpW, SetEndOfFile, TerminateThread, GetFileAttributesExW, CreateThread, SetFilePointerEx, SetFileAttributesW, EnterCriticalSection, SetEnvironmentVariableA, WriteConsoleW, InitializeSListHead, MulDiv, GetThreadTimes, GetFullPathNameW, SetStdHandle, ReadConsoleW, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetModuleFileNameA, FlushFileBuffers, GetConsoleMode, GetConsoleCP, GetModuleHandleExW, GetCurrentThread, GetOEMCP, IsValidCodePage, EnumSystemLocalesW, IsValidLocale, GetLocaleInfoW, LCMapStringW, CompareStringW, GetTimeFormatW, GetDateFormatW, GetStartupInfoW, UnhandledExceptionFilter, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, MoveFileExW, SystemTimeToTzSpecificLocalTime, FindClose, FindNextFileW, FindFirstFileExW, FileTimeToSystemTime, GetFileInformationByHandle, FileTimeToLocalFileTime, AreFileApisANSI, RtlUnwind, GetCommandLineA, GetCPInfo, ExitThread, IsProcessorFeaturePresent, IsDebuggerPresent, GetStringTypeW, EncodePointer, WideCharToMultiByte, GlobalAlloc, lstrlenW, GlobalUnlock, GlobalLock, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, GetSystemTimeAsFileTime, CloseHandle, SetEvent, WaitForSingleObject, GetTimeZoneInformation, GetProcAddress, GetCurrentThreadId, FindResourceW, LoadResource, SizeofResource, LockResource, FindResourceExW, HeapDestroy, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, GetProcessHeap, GetSystemDefaultLCID, GetModuleHandleW, GetTickCount, ReadFile, GetFileSize, GetCurrentDirectoryW, ExitProcess, GetACP, OutputDebugStringW, MultiByteToWideChar, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, DeleteFileW, CreateSemaphoreW, SetUnhandledExceptionFilter, FreeResource, OpenProcess, GetCurrentProcessId, GetModuleFileNameW, VirtualQuery, WriteFile, CreateFileW, lstrcatW, GetTempPathW, DecodePointer, GetLastError, RaiseException, InitializeCriticalSectionAndSpinCount, Sleep, CreateEventW, GetNativeSystemInfo, GetVersionExW, LoadLibraryW, GetUserDefaultLCID
                                                                                                                                                                      USER32.dllDrawTextW, CharPrevW, AdjustWindowRectEx, GetPropW, SetPropW, GetMenu, EnableWindow, GetWindowRgn, GetClassInfoExW, RegisterClassExW, FillRect, SetRect, EqualRect, SetWindowTextW, GetWindowTextW, GetWindowTextLengthW, DestroyMenu, IsWindowEnabled, UpdateWindow, wsprintfA, DrawTextA, GetKeyboardLayout, GetKeyNameTextW, MapVirtualKeyExW, GetShellWindow, SendMessageW, ScreenToClient, GetWindowRect, SetWindowPos, GetDC, ReleaseDC, GetSystemMetrics, wsprintfW, MessageBoxW, CreatePopupMenu, AppendMenuW, TrackPopupMenu, UpdateLayeredWindow, GetGUIThreadInfo, InvalidateRgn, CreateAcceleratorTableW, MoveWindow, ClientToScreen, GetCaretPos, SetCaretPos, GetWindowThreadProcessId, FindWindowW, GetLastActivePopup, PtInRect, LoadIconW, IsWindow, GetClassNameW, PostQuitMessage, GetCursorPos, IsIconic, ShowWindow, BringWindowToTop, SetForegroundWindow, SetActiveWindow, SetCursor, InflateRect, UnionRect, OffsetRect, LoadCursorW, IsZoomed, SetWindowRgn, GetClientRect, GetWindowLongW, SetWindowLongW, MonitorFromWindow, GetMonitorInfoW, GetMessageW, TranslateMessage, DispatchMessageW, PostMessageW, CreateWindowExW, DestroyWindow, IsWindowVisible, CharNextW, SetFocus, GetActiveWindow, GetFocus, GetKeyState, SetCapture, ReleaseCapture, SetTimer, KillTimer, BeginPaint, EndPaint, GetUpdateRect, InvalidateRect, MapWindowPoints, GetSysColor, IntersectRect, IsRectEmpty, GetParent, GetWindow, LoadImageW, DefWindowProcW, ShowCaret, HideCaret, GetCaretBlinkTime, CreateCaret, CallWindowProcW, RegisterClassW, EnableMenuItem
                                                                                                                                                                      GDI32.dllSetBitmapBits, GetBitmapBits, GetTextExtentPointA, PtInRegion, CreateRectRgn, CreatePatternBrush, GdiFlush, TextOutW, MoveToEx, GetObjectA, CreateDIBSection, SetTextColor, SetStretchBltMode, StretchBlt, SetBkMode, SetBkColor, ExtSelectClipRgn, SelectClipRgn, LineTo, GetClipBox, GetCharABCWidthsW, CreateSolidBrush, CreateRectRgnIndirect, CreatePenIndirect, CombineRgn, SetWindowOrgEx, GetObjectW, GetTextMetricsW, PlayEnhMetaFile, GetEnhMetaFileHeader, CreateEnhMetaFileW, CloseEnhMetaFile, SelectObject, SaveDC, RestoreDC, Rectangle, RemoveFontMemResourceEx, AddFontMemResourceEx, GetStockObject, GetDeviceCaps, DeleteDC, CreatePen, CreateFontIndirectW, CreateDIBitmap, CreateCompatibleDC, CreateCompatibleBitmap, BitBlt, DeleteObject, CreateRoundRectRgn, GetTextExtentPoint32W
                                                                                                                                                                      ADVAPI32.dllRegCreateKeyExW, CryptAcquireContextA, CryptGenRandom, CryptReleaseContext, CryptAcquireContextW, RegEnumKeyExW, CheckTokenMembership, FreeSid, RevertToSelf, AllocateAndInitializeSid, RegDeleteValueW, ImpersonateLoggedOnUser, RegQueryInfoKeyW, OpenProcessToken, RegSetValueExW, RegOpenKeyExW, CryptImportKey, CryptEncrypt, CryptDestroyKey, CryptCreateHash, CryptHashData, CryptGetHashParam, RegCloseKey, RegQueryValueExW, CryptDestroyHash
                                                                                                                                                                      SHELL32.dllShellExecuteW, Shell_NotifyIconW, SHGetFolderLocation, ShellExecuteExW, SHBrowseForFolderW, SHGetPathFromIDListW, SHGetMalloc, SHGetSpecialFolderLocation, SHFileOperationW, CommandLineToArgvW, DragQueryFileW, SHGetFolderPathW
                                                                                                                                                                      ole32.dllReleaseStgMedium, OleLockRunning, CLSIDFromProgID, CLSIDFromString, CreateStreamOnHGlobal, OleDuplicateData, DoDragDrop, CoCreateInstance, CoUninitialize, CoInitialize
                                                                                                                                                                      OLEAUT32.dllSysAllocString, VariantClear, GetErrorInfo, SysFreeString, VariantChangeType, VariantInit, VariantCopy
                                                                                                                                                                      SHLWAPI.dllwnsprintfW, PathFileExistsW
                                                                                                                                                                      gdiplus.dllGdipRotateWorldTransform, GdipTranslateWorldTransform, GdipDrawImageRectI, GdipGetPropertyItem, GdipGetPropertyItemSize, GdipImageGetFrameCount, GdipImageGetFrameDimensionsList, GdipImageGetFrameDimensionsCount, GdipGetImageHeight, GdipGetImageWidth, GdipSetStringFormatTrimming, GdipImageSelectActiveFrame, GdipSetStringFormatAlign, GdipSetStringFormatFlags, GdipCloneStringFormat, GdipDeleteStringFormat, GdipStringFormatGetGenericTypographic, GdipMeasureString, GdipDrawString, GdipDeleteFont, GdipCreateFontFromLogfontA, GdipCreateFontFromDC, GdipFillPath, GdipFillRectangleI, GdipDrawPath, GdipDrawRectangleI, GdipSetInterpolationMode, GdipSetTextRenderingHint, GdipSetSmoothingMode, GdipDeleteGraphics, GdipCreateFromHDC, GdipDisposeImage, GdipCloneImage, GdipLoadImageFromStreamICM, GdipLoadImageFromStream, GdipSetPenMode, GdipDeletePen, GdipCreatePen1, GdipCreateSolidFill, GdipDeleteBrush, GdipCloneBrush, GdipAddPathArc, GdipAddPathLine, GdipDeletePath, GdipCreatePath, GdipFree, GdipAlloc, GdiplusShutdown, GdiplusStartup, GdipSetStringFormatLineAlign
                                                                                                                                                                      IMM32.dllImmGetContext, ImmSetCompositionWindow, ImmReleaseContext
                                                                                                                                                                      dbghelp.dllMiniDumpWriteDump
                                                                                                                                                                      PSAPI.DLLGetModuleFileNameExW
                                                                                                                                                                      WS2_32.dllntohl, inet_ntoa, inet_addr, ioctlsocket, __WSAFDIsSet, select, WSACreateEvent, WSAEventSelect, WSACloseEvent, WSAEnumNetworkEvents, recvfrom, sendto, htonl, listen, accept, getaddrinfo, freeaddrinfo, WSASetLastError, connect, socket, getpeername, getsockopt, htons, bind, ntohs, getsockname, setsockopt, WSAIoctl, recv, WSACleanup, WSAGetLastError, send, WSAStartup, gethostname, gethostbyname, closesocket
                                                                                                                                                                      WINHTTP.dllWinHttpQueryHeaders, WinHttpOpen, WinHttpCloseHandle, WinHttpCrackUrl, WinHttpAddRequestHeaders, WinHttpConnect, WinHttpSendRequest, WinHttpSetTimeouts, WinHttpOpenRequest, WinHttpReceiveResponse
                                                                                                                                                                      VERSION.dllGetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
                                                                                                                                                                      Language of compilation systemCountry where language is spokenMap
                                                                                                                                                                      EnglishUnited States
                                                                                                                                                                      Skipped network analysis since the amount of network traffic is too extensive. Please download the PCAP and check manually.

                                                                                                                                                                      Click to jump to process

                                                                                                                                                                      Click to jump to process

                                                                                                                                                                      Click to dive into process behavior distribution

                                                                                                                                                                      Click to jump to process

                                                                                                                                                                      Target ID:0
                                                                                                                                                                      Start time:15:38:53
                                                                                                                                                                      Start date:19/04/2024
                                                                                                                                                                      Path:C:\Users\user\Desktop\filmora-idco_setup_full1901.exe
                                                                                                                                                                      Wow64 process (32bit):true
                                                                                                                                                                      Commandline:"C:\Users\user\Desktop\filmora-idco_setup_full1901.exe"
                                                                                                                                                                      Imagebase:0x290000
                                                                                                                                                                      File size:1'995'256 bytes
                                                                                                                                                                      MD5 hash:AEB7797267CB552CF82E0348C985543E
                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                      Reputation:low
                                                                                                                                                                      Has exited:false

                                                                                                                                                                      Target ID:2
                                                                                                                                                                      Start time:15:38:57
                                                                                                                                                                      Start date:19/04/2024
                                                                                                                                                                      Path:C:\Users\Public\Documents\Wondershare\NFWCHK.exe
                                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                                      Commandline:C:\Users\Public\Documents\Wondershare\NFWCHK.exe
                                                                                                                                                                      Imagebase:0xc10000
                                                                                                                                                                      File size:7'168 bytes
                                                                                                                                                                      MD5 hash:27CFB3990872CAA5930FA69D57AEFE7B
                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                      Antivirus matches:
                                                                                                                                                                      • Detection: 0%, ReversingLabs
                                                                                                                                                                      Reputation:moderate
                                                                                                                                                                      Has exited:true

                                                                                                                                                                      Target ID:3
                                                                                                                                                                      Start time:15:38:57
                                                                                                                                                                      Start date:19/04/2024
                                                                                                                                                                      Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                      Wow64 process (32bit):false
                                                                                                                                                                      Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                      Imagebase:0x7ff6684c0000
                                                                                                                                                                      File size:862'208 bytes
                                                                                                                                                                      MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                      Has elevated privileges:true
                                                                                                                                                                      Has administrator privileges:true
                                                                                                                                                                      Programmed in:C, C++ or other language
                                                                                                                                                                      Reputation:high
                                                                                                                                                                      Has exited:true

                                                                                                                                                                      Reset < >
                                                                                                                                                                        Strings
                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID: z#S'$z#S'
                                                                                                                                                                        • API String ID: 0-3267196045
                                                                                                                                                                        • Opcode ID: 00c12d911bd3a363dc5066dea4dc5176f0a580be4203f14895bac49bcdfa624a
                                                                                                                                                                        • Instruction ID: e6a69bb4a8aba1fe44393ca2cac6e240cbe344606e3a7e3b0c947f458ce23faa
                                                                                                                                                                        • Opcode Fuzzy Hash: 00c12d911bd3a363dc5066dea4dc5176f0a580be4203f14895bac49bcdfa624a
                                                                                                                                                                        • Instruction Fuzzy Hash: 49626030A1C6894FFBA99F2894557AD7BE0EF59300F5440ADF88ECB2A3DE34A945C741
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 78625b6fb62668aecd669d621a0655923dacda88851ff03591468ae242590916
                                                                                                                                                                        • Instruction ID: 0975abd2af93233f27ff191ad3ef596228d2bb126570e08cb04d2474b8b60416
                                                                                                                                                                        • Opcode Fuzzy Hash: 78625b6fb62668aecd669d621a0655923dacda88851ff03591468ae242590916
                                                                                                                                                                        • Instruction Fuzzy Hash: 62F16D30A0CA494FEB99AF2894557B97BD1EF96301F5540AEF4CEC72A3CF289845C781
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Strings
                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID: z#S'
                                                                                                                                                                        • API String ID: 0-726785185
                                                                                                                                                                        • Opcode ID: 45700cd09e17ebe62242afd9b8296d4968c3a08dcf715222856706446b61168d
                                                                                                                                                                        • Instruction ID: 0440ac19d3503e5c7ef4d92afa508a3c0c4ef3620d8ea166a149d0b6addb4e1c
                                                                                                                                                                        • Opcode Fuzzy Hash: 45700cd09e17ebe62242afd9b8296d4968c3a08dcf715222856706446b61168d
                                                                                                                                                                        • Instruction Fuzzy Hash: 20415530A0D54A4FFB89AF289465B793BE1EF56301F5540BAF48ECB1A3CE29A805C751
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Strings
                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID: 75'
                                                                                                                                                                        • API String ID: 0-222332350
                                                                                                                                                                        • Opcode ID: a89d4e6fc4dad90fd596bb6c699186ce00f23ca56a02028f131b3f4b244f4aa2
                                                                                                                                                                        • Instruction ID: da2ec625049999dcf5a181a4c8f96a34159c9f2f98f3ecd08927bcdb098c582b
                                                                                                                                                                        • Opcode Fuzzy Hash: a89d4e6fc4dad90fd596bb6c699186ce00f23ca56a02028f131b3f4b244f4aa2
                                                                                                                                                                        • Instruction Fuzzy Hash: F4D0A95510A39A0FC34BDB3884E04903F609F8B18038100EAC08ACF2A3DA160C0AC325
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 2238f974f8106bc396a459a81416a8b579624ea8d64e6c2aeee9be0dfb098f89
                                                                                                                                                                        • Instruction ID: a55bc52490cf199b9ade4a569e9bb007aa6c7ab8406567c87b4d2348eb25e6c4
                                                                                                                                                                        • Opcode Fuzzy Hash: 2238f974f8106bc396a459a81416a8b579624ea8d64e6c2aeee9be0dfb098f89
                                                                                                                                                                        • Instruction Fuzzy Hash: 1322732061CA994EFBA9DF1894517BD3BD1EF99300F54017AF8CEC7292DE28E941C792
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 613b42a7fb74b575d9c6e11aedd898786ae859854071c915a54db1649c47b2dc
                                                                                                                                                                        • Instruction ID: e9031dde180a97b0b8c6d5fb5b145fa64dafb3365d4516886552e0076c5865d2
                                                                                                                                                                        • Opcode Fuzzy Hash: 613b42a7fb74b575d9c6e11aedd898786ae859854071c915a54db1649c47b2dc
                                                                                                                                                                        • Instruction Fuzzy Hash: 7EA13E3170C6458FE789EF289495A797BE1EF9A305F5504BDF88AC72A3CE28A805C741
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 452d764811ed8dba6e3fe8a57206d1b50055ad8503720807579d7e45f6997efa
                                                                                                                                                                        • Instruction ID: b04ca211af50436e6c87f144e22dd72889a0498951a9f7c15e3ddf3c77e67ef7
                                                                                                                                                                        • Opcode Fuzzy Hash: 452d764811ed8dba6e3fe8a57206d1b50055ad8503720807579d7e45f6997efa
                                                                                                                                                                        • Instruction Fuzzy Hash: B081B030518A894FEB59DF28D8857A97FE1FF5A300F5441EAF889CB192DB38E845C781
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: d94db97646cccf2e65d3f70efe66f4df17728db9e91b92fdaf87723df4bf731b
                                                                                                                                                                        • Instruction ID: 50142beedc0b083e4a40c898a2674b7d1989a3b916aa1547483a2a2fd6141189
                                                                                                                                                                        • Opcode Fuzzy Hash: d94db97646cccf2e65d3f70efe66f4df17728db9e91b92fdaf87723df4bf731b
                                                                                                                                                                        • Instruction Fuzzy Hash: D1913E3061CA894FEB599F289451BB97BE1EF56300F5500AEF8CAC72A3DF24A945C742
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 7bdbd47761edc11efcb76f19b87efb52208d48e273b1bc5ef5f712e106591266
                                                                                                                                                                        • Instruction ID: 87464a0d0f510f40d5a50325b3e4f05dd2c71664474a335beaa7686fe5077f39
                                                                                                                                                                        • Opcode Fuzzy Hash: 7bdbd47761edc11efcb76f19b87efb52208d48e273b1bc5ef5f712e106591266
                                                                                                                                                                        • Instruction Fuzzy Hash: 81716920A1894A9FFB58EF189851ABC7BD1FF98341F50447AF84EC7592DF38A851C781
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 143ebb912b3e48fa5e343698cca336179b095c68d3954c7e77a451a72ca2878f
                                                                                                                                                                        • Instruction ID: 82b02f772c2346aab5b723f501174773c4934c1b5a7574cc086be55badef7c5f
                                                                                                                                                                        • Opcode Fuzzy Hash: 143ebb912b3e48fa5e343698cca336179b095c68d3954c7e77a451a72ca2878f
                                                                                                                                                                        • Instruction Fuzzy Hash: 85613D30A1C94A4EFB99AF2894557BD7AD1FF89301F9500BAF44EC72A2DF28E841D741
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 4a6e847eb6a740fab20ce24300b3bf357c756455d63080ca69c01b6092408e8e
                                                                                                                                                                        • Instruction ID: 4a3a19a7e42a912736533df23b720584352688e3dfc275fa62510f3c5436ed60
                                                                                                                                                                        • Opcode Fuzzy Hash: 4a6e847eb6a740fab20ce24300b3bf357c756455d63080ca69c01b6092408e8e
                                                                                                                                                                        • Instruction Fuzzy Hash: 7851733061CA9A4EFFB99F2898117FD3BD1EF59700F144169E88ECB292DE34A941D781
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 99e9cfe634308fbd7458248eabb9ec41fe192be4add86a7d524e5bfa8c99ead0
                                                                                                                                                                        • Instruction ID: 285619dea8e03bee7ba9b72b61c96953f712e1d3030c241d47e2db7b57d83633
                                                                                                                                                                        • Opcode Fuzzy Hash: 99e9cfe634308fbd7458248eabb9ec41fe192be4add86a7d524e5bfa8c99ead0
                                                                                                                                                                        • Instruction Fuzzy Hash: 57412450B18A461EFB9AAF2854567BC69C2AF8D301F9541BAF44ECB2E3DF286C41C341
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 9514ab24955e2345ed1dc6140a74316e49d9939151dd4fdf884d7aef0507bc5e
                                                                                                                                                                        • Instruction ID: 0f83599879aa093ee8238ea7b10cfca56a9ecbadb54eedb714c43ca3717ed632
                                                                                                                                                                        • Opcode Fuzzy Hash: 9514ab24955e2345ed1dc6140a74316e49d9939151dd4fdf884d7aef0507bc5e
                                                                                                                                                                        • Instruction Fuzzy Hash: A431B22061CA894FFF959F2898913B93FE0FF5A315F4411BAF88DC7192DA28D848C791
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 4a09c8a3cad5776cd1d94fda911acbf6f3a21120d517ae74409543ecced253b7
                                                                                                                                                                        • Instruction ID: 47e10028eb46ec4a2b1ac87bf5784a0aec5ed978ed7a728d932726b6d3188e24
                                                                                                                                                                        • Opcode Fuzzy Hash: 4a09c8a3cad5776cd1d94fda911acbf6f3a21120d517ae74409543ecced253b7
                                                                                                                                                                        • Instruction Fuzzy Hash: 16214A20709A484FEB98DF3C9499B793BE1EF9A311F5500F9F449CB2A7CA249C45C741
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 20e3b3722c9b2d82f3f192359f90aea62ba8d6f4351c90f8677595645a76b945
                                                                                                                                                                        • Instruction ID: f1abec60a08a673a5a25af893d9ad169618d8aee266b9c4fbc9196235d03131d
                                                                                                                                                                        • Opcode Fuzzy Hash: 20e3b3722c9b2d82f3f192359f90aea62ba8d6f4351c90f8677595645a76b945
                                                                                                                                                                        • Instruction Fuzzy Hash: C721F175A1CB484FE784EF38D49866ABBE1EBD9341F45447EF889C7265DA34D8808701
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: dc946fb67cf303ef3627ef3ca36afac7eacf7c6d75ae30fc75ef3f5de2e6ecca
                                                                                                                                                                        • Instruction ID: 45f233bdbf2b44c5b3cd3bff21b6c3c827092bc0183bb4e3b3f73e3fb5178284
                                                                                                                                                                        • Opcode Fuzzy Hash: dc946fb67cf303ef3627ef3ca36afac7eacf7c6d75ae30fc75ef3f5de2e6ecca
                                                                                                                                                                        • Instruction Fuzzy Hash: 9921603061890B8EF7A8EF249894BBA77D1FF95305F50057EE08BC69A2DE29F845C740
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 98c79acfe2d017d39644fca7d861ea6f33de6c6a680ed4a5ceb24c6f5bfca434
                                                                                                                                                                        • Instruction ID: 70b28c14a19d9c563cff473150ef7e96024d61d54164bb61546086560b0e734b
                                                                                                                                                                        • Opcode Fuzzy Hash: 98c79acfe2d017d39644fca7d861ea6f33de6c6a680ed4a5ceb24c6f5bfca434
                                                                                                                                                                        • Instruction Fuzzy Hash: B6212F20B1CD4A4FFBA8AF2860557BD6AD1EF99305F954479F44EC72E2CE28A940C381
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 9da2e5be2dad108b4f7c763aee3f4d68c83009f58f3ac00fe4b489aa3ab8875a
                                                                                                                                                                        • Instruction ID: 0f742d3fc15fc232f43dbf17c50cd83a6e04604834acbaee1d65aea3fd1632fb
                                                                                                                                                                        • Opcode Fuzzy Hash: 9da2e5be2dad108b4f7c763aee3f4d68c83009f58f3ac00fe4b489aa3ab8875a
                                                                                                                                                                        • Instruction Fuzzy Hash: 99216B50A186461EFB96AF3854553BC6AC1AF8D301F9540BAF44DCB2E3CF6C6C41C341
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: f8d6ec1e23870ff955ffe96a0983eda984bd95b95a287b0ec5a96e4f4893ccd1
                                                                                                                                                                        • Instruction ID: fae7b7036b10ea435e3df03be1b73566345b51662d4965af53f5dc42fb028e98
                                                                                                                                                                        • Opcode Fuzzy Hash: f8d6ec1e23870ff955ffe96a0983eda984bd95b95a287b0ec5a96e4f4893ccd1
                                                                                                                                                                        • Instruction Fuzzy Hash: C511A120B1C5160BFB6D5D6D649A3792AC1EB98346F24107EF5CBC7292E91998869240
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 6ffc25597a169d5f54041e7456635d6ba90da0527568059da565347f6e4388f2
                                                                                                                                                                        • Instruction ID: db99fa36ed6c1a08a1ef7371ae41af0b01d5f2d165270e04a13f4f10bc44b104
                                                                                                                                                                        • Opcode Fuzzy Hash: 6ffc25597a169d5f54041e7456635d6ba90da0527568059da565347f6e4388f2
                                                                                                                                                                        • Instruction Fuzzy Hash: 8421EA30A08A9D8FEBA5DF1C94557A97BE1FB6C300F50055AF88DC7351CB30A981CB42
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 0dd18252bb7eea541d9be54f2e3556d368ef489871f454f3bc3d8d463b6a4a2e
                                                                                                                                                                        • Instruction ID: 231c97a771cca1bfc726c9b463f6b46f961dbfea7104c18bf49ab35fbb82e0df
                                                                                                                                                                        • Opcode Fuzzy Hash: 0dd18252bb7eea541d9be54f2e3556d368ef489871f454f3bc3d8d463b6a4a2e
                                                                                                                                                                        • Instruction Fuzzy Hash: 581161B0518A4C6FEB94CF08C889BEA7EE0FB49314F94015DF489CB292C7B89915C790
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 1c8ac0afb59631340627bd454beee256c6e1963e242e93a13c162fb569c27b96
                                                                                                                                                                        • Instruction ID: fec0aed13c73015079eb3288f8e93487cacf50a796c166fd96823e63b2935bd4
                                                                                                                                                                        • Opcode Fuzzy Hash: 1c8ac0afb59631340627bd454beee256c6e1963e242e93a13c162fb569c27b96
                                                                                                                                                                        • Instruction Fuzzy Hash: B101A9306048098FDF8CEF18D499E3937E1EFA5306B5515F9F44ACB666CA25DC95CB40
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: cc7dcdb0a39154d42e64aa7f8f2699e34dc92334039a92bee1b6f9daa8ca5367
                                                                                                                                                                        • Instruction ID: 7234db708a6689fc545c07d63332b0adf2c5d54706d951655f6d098fd2a1ae7b
                                                                                                                                                                        • Opcode Fuzzy Hash: cc7dcdb0a39154d42e64aa7f8f2699e34dc92334039a92bee1b6f9daa8ca5367
                                                                                                                                                                        • Instruction Fuzzy Hash: 61018115A2DB894FEB86E73848606587BE19F5B24075A44E7E44CCB2A3E928DC458325
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 832e48059b84ef1a3f1b4cabd4b14a5a61c64492344c2ca866ef41986dcc8e5a
                                                                                                                                                                        • Instruction ID: 5204e12ee393c6113102018badc46ff769bb62e6d7a15754b4b552bd98879d02
                                                                                                                                                                        • Opcode Fuzzy Hash: 832e48059b84ef1a3f1b4cabd4b14a5a61c64492344c2ca866ef41986dcc8e5a
                                                                                                                                                                        • Instruction Fuzzy Hash: 8C019670218A098BEF58DF59D4C8B647BE0FB68305F5511B8E84DCB296CA64D844CB45
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 0f47b1b6bbe9ebac7d1010dc699c36dee697524ef6c18a11376a09dfd87dec25
                                                                                                                                                                        • Instruction ID: bbadbf72d9ea1d568af512cc850b6695021db6aed0cc697bf674a453eee65d2f
                                                                                                                                                                        • Opcode Fuzzy Hash: 0f47b1b6bbe9ebac7d1010dc699c36dee697524ef6c18a11376a09dfd87dec25
                                                                                                                                                                        • Instruction Fuzzy Hash: CAF01D3060540A8FEF8CEE29E499E3937E1EF9531675501B9F44ACB276CA65DC54C780
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: e22b750cf35ae9d115b75f16d8640704d8d8fbf44434381e81a6f3c0bda37d64
                                                                                                                                                                        • Instruction ID: b479ef522e3244a1d3d608476ae58251e99cce010b500a3ca72cd012bb9cf1f0
                                                                                                                                                                        • Opcode Fuzzy Hash: e22b750cf35ae9d115b75f16d8640704d8d8fbf44434381e81a6f3c0bda37d64
                                                                                                                                                                        • Instruction Fuzzy Hash: 70F0E7306094068FEF88EE29E098A793BD1EF9531275404B9E44ACA266CE25EC55C740
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 50ceac3e2ce9eb6c19cb99e06623247ef4423a73c008591aa7fdb49ec4f671f3
                                                                                                                                                                        • Instruction ID: f8676533d8b2f40f25040bbbdd4eb165ab5cb9a1d1c22d4b06f1bb128446e8b7
                                                                                                                                                                        • Opcode Fuzzy Hash: 50ceac3e2ce9eb6c19cb99e06623247ef4423a73c008591aa7fdb49ec4f671f3
                                                                                                                                                                        • Instruction Fuzzy Hash: C4E04815758E0E4BEA545F5C7885378B7C1FFCD311F4445BAF50CC3256CE289845C281
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: ee387779ac6d5f0e8e678e19c74e80d35531438028f4e07af7e327a2c57160df
                                                                                                                                                                        • Instruction ID: e8868ce017216266cc86faafcf49f00d99a32cc3a21c6adaac32fed7d2df6fbb
                                                                                                                                                                        • Opcode Fuzzy Hash: ee387779ac6d5f0e8e678e19c74e80d35531438028f4e07af7e327a2c57160df
                                                                                                                                                                        • Instruction Fuzzy Hash: 7EF0DA7041CB888FD781EF2C804874ABBE0FB99304F50091EF589C2251EB76C1848742
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 0ff6d89ededf603e26d168db3416c0aed1719e72b07b7f03ba0f5010592605ec
                                                                                                                                                                        • Instruction ID: 52c463cc4bf97e842459bc13209e36df8ab13abe68025b26726ed439c2ce673e
                                                                                                                                                                        • Opcode Fuzzy Hash: 0ff6d89ededf603e26d168db3416c0aed1719e72b07b7f03ba0f5010592605ec
                                                                                                                                                                        • Instruction Fuzzy Hash: 77E0D810B58E1B4AFB96DEA958D037825C4EF88352F841075FC4EC62A3CE5CDC81C200
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 1de83ad08bcda85b8474c686df4235b1b88ff435305f36fd16b1ac01912ff283
                                                                                                                                                                        • Instruction ID: 784c071282e3b9a2c3dc927747a13e465539320089da6999f2e971412a0f8d39
                                                                                                                                                                        • Opcode Fuzzy Hash: 1de83ad08bcda85b8474c686df4235b1b88ff435305f36fd16b1ac01912ff283
                                                                                                                                                                        • Instruction Fuzzy Hash: 17E04F21718D4E0BAF89EF2C88D5A7A37E5EFAC31574101B6EC08D7256DE14ECA1C381
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: e50cde5259f9a802497b7bf3de9d0f038ff9b73f328bbd92276cd797ed7ce905
                                                                                                                                                                        • Instruction ID: 0214589eec2a3cb6df0bffdb9f086b7d8d18cbbefbed4265028654d0f61be5b4
                                                                                                                                                                        • Opcode Fuzzy Hash: e50cde5259f9a802497b7bf3de9d0f038ff9b73f328bbd92276cd797ed7ce905
                                                                                                                                                                        • Instruction Fuzzy Hash: 86E0C215A2E7CA0FE347922898652A42FA19F47254B6940FBD09ACB6E7D81C1D098726
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 95aeb7b1a6263ee919768be01bed2be1ce9a93cd6a3425bba16285678609a4ea
                                                                                                                                                                        • Instruction ID: a6228cce0f2eb32b11f8fe4da597e7c14c360d318fb52cd88fd7d496613ffb59
                                                                                                                                                                        • Opcode Fuzzy Hash: 95aeb7b1a6263ee919768be01bed2be1ce9a93cd6a3425bba16285678609a4ea
                                                                                                                                                                        • Instruction Fuzzy Hash: D5E012A451DBC84FD7469B288515B097FF0AF1B394F4A15CAE4C8CB3A3C668C9488726
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 9f27c4fa48cf4221b26f49181512aeccf0d7dfbbb90463ff0595329f07dcbfe1
                                                                                                                                                                        • Instruction ID: c9cb12fc9cd826971c49a6ab125e44f5ea786424f10ba560a43c4e026a1d3ed5
                                                                                                                                                                        • Opcode Fuzzy Hash: 9f27c4fa48cf4221b26f49181512aeccf0d7dfbbb90463ff0595329f07dcbfe1
                                                                                                                                                                        • Instruction Fuzzy Hash: AAE0C21231CB490B9780EA5D8489A7877C1FBD8133B50003FF989C3352CB19E8868391
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: d2506861ff43c9b0232580c916a140079dc826aae685864091535ead8eb65ccc
                                                                                                                                                                        • Instruction ID: 859efae0bbb0dc5d53efeced8968e831c364ff078c10104abb318eeed78427c7
                                                                                                                                                                        • Opcode Fuzzy Hash: d2506861ff43c9b0232580c916a140079dc826aae685864091535ead8eb65ccc
                                                                                                                                                                        • Instruction Fuzzy Hash: 1CD0A711B285080BE3449A5CA8403E443C1F7CC319F50013EF14DC23C3C96D49464205
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 8683b94becc4715cf07ed628cc9c33526d08ae8ce67c043eb0e0f64197c83cda
                                                                                                                                                                        • Instruction ID: bded0113ce2a6bc91eb4500557202af8278b5e97c5c1343b99c5ed930a56f378
                                                                                                                                                                        • Opcode Fuzzy Hash: 8683b94becc4715cf07ed628cc9c33526d08ae8ce67c043eb0e0f64197c83cda
                                                                                                                                                                        • Instruction Fuzzy Hash: 0CD09277A1CA0989FA2C6D48B8031FC2780DF82372E10013BF58B454AB6D1B321690CE
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 89b1c3713544fa11c9fbb60c350c5f8333d483ad5337bc45aaa77a3e15cec3a1
                                                                                                                                                                        • Instruction ID: 613a2f0f803cf3abb3e90a7d7e1f7f7ea6f582190d2b2e286217daa673aa6955
                                                                                                                                                                        • Opcode Fuzzy Hash: 89b1c3713544fa11c9fbb60c350c5f8333d483ad5337bc45aaa77a3e15cec3a1
                                                                                                                                                                        • Instruction Fuzzy Hash: 8FD01742A3DB880EE64A6B390C6516C69D69B9E24135644BBA08ACB2E7DC189C098329
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 6f6f8023d8e152f5632006d80a1345a6d6988d5f04e8bf2c52bc80421447b711
                                                                                                                                                                        • Instruction ID: fb98e630620bab2287d5e575981c3c76db1ace4b49d13186d71f5ce13be03fcf
                                                                                                                                                                        • Opcode Fuzzy Hash: 6f6f8023d8e152f5632006d80a1345a6d6988d5f04e8bf2c52bc80421447b711
                                                                                                                                                                        • Instruction Fuzzy Hash: BAE04F5651DBCA0FD34AD73848701D43FA19F5B19835540EAC1CADB6F3D90A5C09C75A
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 35e918e39a19b61db663428f4cb0fdaa5f52d165499a1477dd1925fc179e7be1
                                                                                                                                                                        • Instruction ID: 500b3f073386d6770e07574d1ec1db57011df78280ecad5bed0ea15f5d8d09b3
                                                                                                                                                                        • Opcode Fuzzy Hash: 35e918e39a19b61db663428f4cb0fdaa5f52d165499a1477dd1925fc179e7be1
                                                                                                                                                                        • Instruction Fuzzy Hash: D5D0220924978E4FC28AA22868B02A47BE0CB471A038100D7C28BCF7A3CC0A1C85C705
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 55db9e537ff00e63615f2fd00db331995bcf469d8bc6f5a03f4ad6b91444e364
                                                                                                                                                                        • Instruction ID: c72e9902c7d2f9fec65cfdee6175fa05ef621ba72f45d21e54edc2c0af3cdda3
                                                                                                                                                                        • Opcode Fuzzy Hash: 55db9e537ff00e63615f2fd00db331995bcf469d8bc6f5a03f4ad6b91444e364
                                                                                                                                                                        • Instruction Fuzzy Hash: 5EC09223754B080B9A0419EEBC8B0F4B3C0D68E47332110B7E209C2A01E69B688652C3
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 13df9a95f5a7b8d8f750089e10d3eb7fa9b7b47a77bc6b757f92cf7967439a40
                                                                                                                                                                        • Instruction ID: 854ad3bc3129b2f2333c32b51562453fa7159ad0daeb7fe5d9b4be5b171d6b36
                                                                                                                                                                        • Opcode Fuzzy Hash: 13df9a95f5a7b8d8f750089e10d3eb7fa9b7b47a77bc6b757f92cf7967439a40
                                                                                                                                                                        • Instruction Fuzzy Hash: 2CC0126260BB880BCB020AB55C89008BFA09E4B02274815FBD144CE263D6AA4889C302
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 64977a5655ba214a34d8f6bb1cad6943303a68ac849da77aac09312f310c5618
                                                                                                                                                                        • Instruction ID: e0b06a19c9ff1b94e51675910266a944bf9c03ad11a2e5783a7d4621195b21ab
                                                                                                                                                                        • Opcode Fuzzy Hash: 64977a5655ba214a34d8f6bb1cad6943303a68ac849da77aac09312f310c5618
                                                                                                                                                                        • Instruction Fuzzy Hash: A8D0A73180F3D14FE743E77558D12843FE08F0622039804DFC0618B553C8143402C396
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: b93fc85374e80d9d17bd96b2ca5ef77a1f0212a7af84598e2fdbad3639f5e527
                                                                                                                                                                        • Instruction ID: d5f8e0ee3fa5ba0142b4cf299ac962d1276d251ee052e203c65fa30e84efa1e2
                                                                                                                                                                        • Opcode Fuzzy Hash: b93fc85374e80d9d17bd96b2ca5ef77a1f0212a7af84598e2fdbad3639f5e527
                                                                                                                                                                        • Instruction Fuzzy Hash: 12D0C946A2D68A0EE249A73848212E85AE2AF4760478544FA904ADB2E3EC1C1C048715
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: f059faac66da9074f65203acb62c1819ca1a00a7a0ca1decd65e2a75af90022a
                                                                                                                                                                        • Instruction ID: 4858b153037168b030cbc3112c0ffb39b6fc10218f490a01faefebd21b3ee465
                                                                                                                                                                        • Opcode Fuzzy Hash: f059faac66da9074f65203acb62c1819ca1a00a7a0ca1decd65e2a75af90022a
                                                                                                                                                                        • Instruction Fuzzy Hash: C3D01251E3DA8A0FE659E73848321F81EE19F4F24579140FA948ED76E3CC0E2D08C315
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 62d23777aebb6fcbc0f685575fca9e490cf6d21e0675fc6c0635629fb7e3fcd4
                                                                                                                                                                        • Instruction ID: ec60c872997ce9cfd37579405f658f378369c22a81739ed6396de80f2d923a7d
                                                                                                                                                                        • Opcode Fuzzy Hash: 62d23777aebb6fcbc0f685575fca9e490cf6d21e0675fc6c0635629fb7e3fcd4
                                                                                                                                                                        • Instruction Fuzzy Hash: 67C0122124D2488FF7064A5868504043B70CF8721535B00D2D544DB173C35959969751
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 5550dde5651244d613b55a6e2baab6b0e12c20d2c7d3b26fa0514d99ab9bee29
                                                                                                                                                                        • Instruction ID: d5d1c327c74312ce3373716064c96c0589c45f7966d0ea8cdb58a2c3ee2aea16
                                                                                                                                                                        • Opcode Fuzzy Hash: 5550dde5651244d613b55a6e2baab6b0e12c20d2c7d3b26fa0514d99ab9bee29
                                                                                                                                                                        • Instruction Fuzzy Hash: EFD0120171DA890FE249D73C49322B81AE19F8F11474144FBD04ED76E3CC0C1C058751
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 94f1f983cb34f112835995e48a8bc7c436b542c22518f42aeb64c0cdee8d847f
                                                                                                                                                                        • Instruction ID: 758e08ffb33b0a8408b9b1a674351dea99dafb59582f198e5027a2e09472ddd7
                                                                                                                                                                        • Opcode Fuzzy Hash: 94f1f983cb34f112835995e48a8bc7c436b542c22518f42aeb64c0cdee8d847f
                                                                                                                                                                        • Instruction Fuzzy Hash: A9D0221281D98E0FC24A97244C230F41BA0DF4B14070700EA880EDBAE3CC082C0A8312
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: b7dab142cc7ae811e4433dd61896f3f49236ef749f599cf001a38e340b220217
                                                                                                                                                                        • Instruction ID: 8a717301c58d34669cdf89470d29635b20fbd4d66e8edfb7809849b5476e5446
                                                                                                                                                                        • Opcode Fuzzy Hash: b7dab142cc7ae811e4433dd61896f3f49236ef749f599cf001a38e340b220217
                                                                                                                                                                        • Instruction Fuzzy Hash: 7EC00265A28A089F8F49FBB8849A59532D2FF6E30471109A5A84FC7296DD64E8008741
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: b4a67841b842bdeceda0eeb2d045d2719fcc908c1c6edf0abee64ed86939f14a
                                                                                                                                                                        • Instruction ID: 73adb45d9050eb430c8501881a602597503f53a579f5c1ae6e92e42be2de19c7
                                                                                                                                                                        • Opcode Fuzzy Hash: b4a67841b842bdeceda0eeb2d045d2719fcc908c1c6edf0abee64ed86939f14a
                                                                                                                                                                        • Instruction Fuzzy Hash: 91B0121378060C07890011E8BC49094B380C58A03334100B3DA08C6110D69B04425181
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 7f7a3823140b73787486afe331efff312c79bf059298c06837f231fe2c9626e6
                                                                                                                                                                        • Instruction ID: 141cac0387eb475c177094b27963b87f7a9b7f65eb1bdedbc92e67b3ef121bd9
                                                                                                                                                                        • Opcode Fuzzy Hash: 7f7a3823140b73787486afe331efff312c79bf059298c06837f231fe2c9626e6
                                                                                                                                                                        • Instruction Fuzzy Hash: E8C08C20728E0A8FFFAC8E6960646BD36A0AF88306F400074B04FC3160CE24E9008340
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 8a3704b53b904c14bd42ba78cd0a2d8c5dcea9fde558a573c6690fd792e31970
                                                                                                                                                                        • Instruction ID: 19032f7269c32003240b3be0876c34edac53c497bae9b5eccd89d6d88b7e6ef8
                                                                                                                                                                        • Opcode Fuzzy Hash: 8a3704b53b904c14bd42ba78cd0a2d8c5dcea9fde558a573c6690fd792e31970
                                                                                                                                                                        • Instruction Fuzzy Hash: E4C04830310A08CF8B80EAA884A9616B3E1EB6D3013164551942ACB214DA60E8408B82
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: bde422273ac1cd0e40b2d929bda289d9b90c8f782b9899d8ad367ba884d3e76d
                                                                                                                                                                        • Instruction ID: f058ec46c9349649805110a1e6f114c8e5785c190149850b319dd9ef6e89c27e
                                                                                                                                                                        • Opcode Fuzzy Hash: bde422273ac1cd0e40b2d929bda289d9b90c8f782b9899d8ad367ba884d3e76d
                                                                                                                                                                        • Instruction Fuzzy Hash: 20C012608092968FF74ADB2888A16A42BA19F8734070A08E6A089CB0A3C8182806C722
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 8e70de5cb085e6f9144c6326bb1a2c6bad4f760101262df209501c7bb9b14792
                                                                                                                                                                        • Instruction ID: b092ccea5ab4be5ae21d1b9e217ffb1f6351d684beda4f9fe9621bca3e8048da
                                                                                                                                                                        • Opcode Fuzzy Hash: 8e70de5cb085e6f9144c6326bb1a2c6bad4f760101262df209501c7bb9b14792
                                                                                                                                                                        • Instruction Fuzzy Hash: 4DA012304454094784009270881109037C05B43100B910068840CC2571C88A19088501
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%

                                                                                                                                                                        Memory Dump Source
                                                                                                                                                                        • Source File: 00000002.00000002.1174413092.00007FFEC92C0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFEC92C0000, based on PE: false
                                                                                                                                                                        Joe Sandbox IDA Plugin
                                                                                                                                                                        • Snapshot File: hcaresult_2_2_7ffec92c0000_NFWCHK.jbxd
                                                                                                                                                                        Similarity
                                                                                                                                                                        • API ID:
                                                                                                                                                                        • String ID:
                                                                                                                                                                        • API String ID:
                                                                                                                                                                        • Opcode ID: 4cd6bc0c6fe7cce099ee522633639a31bdd222a8308319fa60fd6b2bd56e3210
                                                                                                                                                                        • Instruction ID: 6d75819123fb9d27f734314547bceed372e979fd8e0ac40501e64ff6ddd307cc
                                                                                                                                                                        • Opcode Fuzzy Hash: 4cd6bc0c6fe7cce099ee522633639a31bdd222a8308319fa60fd6b2bd56e3210
                                                                                                                                                                        • Instruction Fuzzy Hash: 75A01120B00E088F8A002AEC200A20232C08B2C2003000028A02EC3202C8A0C8808282
                                                                                                                                                                        Uniqueness

                                                                                                                                                                        Uniqueness Score: -1.00%