Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
VZH3bd37Gc.msi

Overview

General Information

Sample name:VZH3bd37Gc.msi
(renamed file extension from none to msi, renamed because original name is a hash value)
Original sample name:0400a87b6100936cdc0a8695c5dc1c7103bb93c0842231efaf7260a795290339
Analysis ID:1431604
MD5:af498bd451f04a1dae63cd61812a3c8b
SHA1:36f54070b8696eaa00ba1ff1d5fcfd5900ddacfa
SHA256:0400a87b6100936cdc0a8695c5dc1c7103bb93c0842231efaf7260a795290339
Infos:

Detection

Score:15
Range:0 - 100
Whitelisted:false
Confidence:40%

Signatures

Yara detected Generic Downloader
Allocates memory with a write watch (potentially for evading sandboxes)
Binary contains a suspicious time stamp
Checks for available system drives (often done to infect USB drives)
Contains capabilities to detect virtual machines
Contains functionality to launch a process as a different user
Contains long sleeps (>= 3 min)
Creates files inside the system directory
Deletes files inside the Windows folder
Detected potential crypto function
Drops PE files
Drops PE files to the windows directory (C:\Windows)
Found dropped PE file which has not been started or loaded
May sleep (evasive loops) to hinder dynamic analysis
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Uses code obfuscation techniques (call, push, ret)

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample is looking for USB drives. Launch the sample with the USB Fake Disk cookbook
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
  • System is w10x64
  • msiexec.exe (PID: 6472 cmdline: "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\VZH3bd37Gc.msi" MD5: E5DA170027542E25EDE42FC54C929077)
  • msiexec.exe (PID: 6612 cmdline: C:\Windows\system32\msiexec.exe /V MD5: E5DA170027542E25EDE42FC54C929077)
    • msiexec.exe (PID: 7148 cmdline: C:\Windows\System32\MsiExec.exe -Embedding 08351F78698DA0C0368A0A0187380C10 E Global\MSI0000 MD5: E5DA170027542E25EDE42FC54C929077)
      • rundll32.exe (PID: 6044 cmdline: rundll32.exe "C:\Windows\Installer\MSI50A5.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5787937 2 AetherPal.Windows.Wix.CustomAction!AetherPal.Windows.Wix.CustomAction.CustomActions.InstallModernApp MD5: EF3179D498793BF4234F708D3BE28633)
        • AetherPal.MSIX.Launcher.exe (PID: 6520 cmdline: "C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe" "install" "C:\Program Files\VMware\Workspace ONE Assist\Resources" MD5: D058E337D5F7E8ADA6BCC28B5114B303)
          • conhost.exe (PID: 6452 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Windows\Installer\MSI50A5.tmp-\netstandard.dllJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
    C:\Program Files\VMware\Workspace ONE Assist\netstandard.dllJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
      SourceRuleDescriptionAuthorStrings
      3.3.rundll32.exe.1320522fe40.1.raw.unpackJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
        No Sigma rule has matched
        No Snort rule has matched

        Click to jump to signature section

        Show All Signature Results
        Source: C:\Windows\System32\msiexec.exeWindow detected: WixUI_Bmp_DialogI &accept the terms in the License Agreement&Print&Back&InstallCancelLicense VMware Workspace ONE AssistPlease read the Workspace ONE Assist Installer License Agreement
        Source: C:\Windows\System32\msiexec.exeWindow detected: WixUI_Bmp_DialogI &accept the terms in the License Agreement&Print&Back&InstallCancelLicense VMware Workspace ONE AssistPlease read the Workspace ONE Assist Installer License Agreement
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMwareJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE AssistJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Cleanup.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\msvcp140.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Numerics.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.TypeConverter.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.VisualC.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Numerics.Vectors.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.PerformanceCounter.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Console.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty-agent.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.ResourceManager.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.AccessControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ServiceProcess.ServiceController.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\netstandard.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.FileManager.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Security.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.EventBasedAsync.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Json.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Permissions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TextWriterTraceListener.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Writer.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Registry.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Bcl.AsyncInterfaces.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\nativeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\libJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windowsJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64Jump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64\libvpx.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty.NET.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\ResourcesJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\AppxJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\AUMIDs.txtJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Expressions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Parallel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.IsolatedStorage.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.RuntimeInformation.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.X509Certificates.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.WPF.CustomControls.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osxJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64Jump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\libvpx.dylibJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\DesktopDuplication.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty-debugserver.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Timer.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140_1.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.Windows.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TraceSource.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Utils.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebHeaderCollection.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.DriveInfo.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tools.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.ZipFile.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.ReaderWriter.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\MPAP_f7529f1a891c4c29afa0bf940c4958e4_001.provxmlJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exe.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.ProtectedData.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.AccessControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NameResolution.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Queryable.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Http.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.MemoryMappedFiles.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Handles.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.EventLog.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.ThreadPool.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Sockets.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Concurrent.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Ping.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Pipes.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Newtonsoft.Json.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ObjectModel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linuxJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\armJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\arm\lib_remote_shell_api.soJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Reader.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Process.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.UnmanagedMemoryStream.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encodings.Web.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Csp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Algorithms.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Requests.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.Unsafe.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.CodeDom.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Buffers.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.AppContext.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.XDocument.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Calendars.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4_License1.xmlJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Drawing.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\lib_remote_shell_api.dylibJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XDocument.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\RemoteLibJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.Client.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Watcher.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Thread.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64Jump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64\lib_remote_shell_api.soJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Debug.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NetworkInformation.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Dynamic.Runtime.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Formatters.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Json.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.SystemEvents.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4.appxbundleJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.StackTrace.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.RegularExpressions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Data.Common.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tracing.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ValueTuple.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.FileVersionInfo.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.NonGeneric.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Overlapped.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlSerializer.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Xml.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Net.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Encoding.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Security.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Specialized.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Net.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Contracts.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Claims.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Memory.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.SecureString.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Parallel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlDocument.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe.configJump to behavior
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Configuration\obj\x64\Release\net462\AetherPal.Configuration.pdbSHA256 source: AetherPal.Configuration.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin\obj\Windows_NT.AnyCPU.Release\System.Runtime.InteropServices.RuntimeInformation\net462\System.Runtime.InteropServices.RuntimeInformation.pdb source: System.Runtime.InteropServices.RuntimeInformation.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Diagnostics\obj\x64\Release\netstandard2.0\AetherPal.Diagnostics.pdbSHA256 source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\agent\_work\66\s\build\ship\x64\SfxCA.pdb source: VZH3bd37Gc.msi, MSI4559.tmp.1.dr, 58426b.msi.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Net\obj\x64\Release\AetherPal.Windows.Net.pdb source: AetherPal.Windows.Net.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ObjectModel\4.0.11.0\System.ObjectModel.pdbX+r+ d+_CorDllMainmscoree.dll source: System.ObjectModel.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Reader\4.0.2.0\System.Resources.Reader.pdb source: System.Resources.Reader.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Tools.RemoteControl.pdbSHA256 source: AetherPal.Tools.RemoteControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Reflection.Primitives\4.0.1.0\System.Reflection.Primitives.pdb source: System.Reflection.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Compression.ZipFile\4.0.3.0\System.IO.Compression.ZipFile.pdb( source: System.IO.Compression.ZipFile.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.NameResolution\4.0.2.0\System.Net.NameResolution.pdb source: System.Net.NameResolution.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.CodeDom/Release/net462/System.CodeDom.pdbSHA256 source: System.CodeDom.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Localization\obj\x64\Release\netstandard2.0\AetherPal.Application.Localization.pdb source: AetherPal.Application.Localization.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem\4.0.3.0\System.IO.FileSystem.pdb8)R) D)_CorDllMainmscoree.dll source: System.IO.FileSystem.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Encoding\4.0.2.0\System.Security.Cryptography.Encoding.pdb source: System.Security.Cryptography.Encoding.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Permissions/Release/net462/System.Security.Permissions.pdbSHA256 source: System.Security.Permissions.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Wix.CustomAction\obj\x64\Release\AetherPal.Windows.Wix.CustomAction.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Windows.Wix.CustomAction.dll.3.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin\obj\Windows_NT.AnyCPU.Release\System.Net.Http\netfx\System.Net.Http.pdb source: System.Net.Http.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Agent\obj\x64\Release\net462\AetherPal.Application.Agent.pdbSHA256 source: AetherPal.Application.Agent.dll.1.dr
        Source: Binary string: C:\projects\assist\pc\platforms\wasm\libvpx_wasm\vcproj\libvpx\x64\Release\libvpx.pdb source: libvpx.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.ResourceManager\4.0.1.0\System.Resources.ResourceManager.pdb source: System.Resources.ResourceManager.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Diagnostics.Tracing/netfx\System.Diagnostics.Tracing.pdb'MAM 3M_CorDllMainmscoree.dll source: System.Diagnostics.Tracing.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Cryptography.ProtectedData/Release/net462/System.Security.Cryptography.ProtectedData.pdb source: System.Security.Cryptography.ProtectedData.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.Process\4.1.2.0\System.Diagnostics.Process.pdb* source: System.Diagnostics.Process.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.RemoteControl.pdb source: AetherPal.Device.Tools.RemoteControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO\4.1.2.0\System.IO.pdb source: System.IO.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.RemoteControl.pdbSHA256r]Hc3C( source: AetherPal.Device.Tools.RemoteControl.dll.1.dr
        Source: Binary string: vcruntime140.amd64.pdbGCTL source: vcruntime140.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Csp\4.0.2.0\System.Security.Cryptography.Csp.pdb4)N) @)_CorDllMainmscoree.dll source: System.Security.Cryptography.Csp.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Linq\4.1.2.0\System.Linq.pdb source: System.Linq.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Utils\obj\x64\Release\netstandard2.0\AetherPal.Utils.pdbSHA256 source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817462846.0000013203552000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817556529.0000013203552000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Utils.dll.3.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.FileManager\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.FileManager.pdb source: AetherPal.Device.Tools.FileManager.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.ServiceProcess.ServiceController/Release/net462/System.ServiceProcess.ServiceController.pdbSHA256) source: System.ServiceProcess.ServiceController.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.pdb source: AetherPal.Device.Tools.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/AnyOS.AnyCPU.Release/System.Data.Common/netfx\System.Data.Common.pdb source: System.Data.Common.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Pipes\4.0.2.0\System.IO.Pipes.pdbh) source: System.IO.Pipes.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Writer\4.0.2.0\System.Resources.Writer.pdb source: System.Resources.Writer.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.WPF.WindowsClient\obj\x64\Release\WorkspaceONE.Assist.Client.pdb source: WorkspaceONE.Assist.Client.exe.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Tools.RemoteControl.pdb source: AetherPal.Tools.RemoteControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Security\4.0.2.0\System.Net.Security.pdbT*n* `*_CorDllMainmscoree.dll source: System.Net.Security.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading.ThreadPool\4.0.12.0\System.Threading.ThreadPool.pdb source: System.Threading.ThreadPool.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\Microsoft.Win32.Primitives\4.0.3.0\Microsoft.Win32.Primitives.pdb|( source: Microsoft.Win32.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Reflection.Primitives\4.0.1.0\System.Reflection.Primitives.pdb$*>* 0*_CorDllMainmscoree.dll source: System.Reflection.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.TraceSource\4.0.2.0\System.Diagnostics.TraceSource.pdb source: System.Diagnostics.TraceSource.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.Tools\4.0.1.0\System.Diagnostics.Tools.pdb source: System.Diagnostics.Tools.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Agent.App\obj\x64\Release\WorkspaceONE.Assist.Agent.pdb source: WorkspaceONE.Assist.Agent.exe.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.Registry/net461-Windows_NT-Release/Microsoft.Win32.Registry.pdb source: Microsoft.Win32.Registry.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Runtime.Serialization.Xml/netfx\System.Runtime.Serialization.Xml.pdb source: System.Runtime.Serialization.Xml.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XmlSerializer\4.0.11.0\System.Xml.XmlSerializer.pdbt+ source: System.Xml.XmlSerializer.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.NameResolution\4.0.2.0\System.Net.NameResolution.pdb|( source: System.Net.NameResolution.dll.1.dr
        Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdbP source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\net461-Release\System.Runtime.CompilerServices.Unsafe.pdbBSJB source: System.Runtime.CompilerServices.Unsafe.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Utils\obj\x64\Release\netstandard2.0\AetherPal.Utils.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817462846.0000013203552000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817556529.0000013203552000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Utils.dll.1.dr, AetherPal.Utils.dll.3.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device\obj\x64\Release\netstandard2.0\AetherPal.Device.pdb source: AetherPal.Device.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Security\4.0.2.0\System.Net.Security.pdb source: System.Net.Security.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XPath\4.0.3.0\System.Xml.XPath.pdb source: System.Xml.XPath.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Utils\obj\x64\Release\net462\AetherPal.Windows.Utils.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.MSIX.Launcher.exe, AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895084039.00000229A6B72000.00000002.00000001.01000000.0000000A.sdmp, AetherPal.Windows.Utils.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime.CompilerServices.VisualC\4.0.2.0\System.Runtime.CompilerServices.VisualC.pdb@*Z* L*_CorDllMainmscoree.dll source: System.Runtime.CompilerServices.VisualC.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Runtime.Serialization.Primitives/netfx\System.Runtime.Serialization.Primitives.pdb source: System.Runtime.Serialization.Primitives.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdb source: System.Text.Json.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdb source: System.Text.Encodings.Web.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Diagnostics.Tracing/netfx\System.Diagnostics.Tracing.pdb source: System.Diagnostics.Tracing.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime\4.1.2.0\System.Runtime.pdb source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895196565.00000229A6BA2000.00000002.00000001.01000000.0000000B.sdmp
        Source: Binary string: /_/artifacts/obj/System.Security.Cryptography.ProtectedData/Release/net462/System.Security.Cryptography.ProtectedData.pdbSHA256C source: System.Security.Cryptography.ProtectedData.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin\obj\Windows_NT.AnyCPU.Release\System.Runtime.InteropServices.RuntimeInformation\net462\System.Runtime.InteropServices.RuntimeInformation.pdbxE source: System.Runtime.InteropServices.RuntimeInformation.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Writer\4.0.2.0\System.Resources.Writer.pdbl( source: System.Resources.Writer.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XmlSerializer\4.0.11.0\System.Xml.XmlSerializer.pdb source: System.Xml.XmlSerializer.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Net\obj\x64\Release\netstandard2.0\AetherPal.Net.pdb source: AetherPal.Net.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Utils\obj\x64\Release\netstandard2.0\AetherPal.Utils.pdbSHA256u source: AetherPal.Utils.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ComponentModel.TypeConverter\4.1.2.0\System.ComponentModel.TypeConverter.pdb source: System.ComponentModel.TypeConverter.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdbSHA256 source: System.Text.Json.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Text.RegularExpressions\4.1.1.0\System.Text.RegularExpressions.pdb source: System.Text.RegularExpressions.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.AccessControl/net461-windows-Release/System.Security.AccessControl.pdb source: System.Security.AccessControl.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.CodeDom/Release/net462/System.CodeDom.pdb source: System.CodeDom.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Utils\obj\x64\Release\net462\AetherPal.Windows.Utils.pdbSHA256 source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895084039.00000229A6B72000.00000002.00000001.01000000.0000000A.sdmp, AetherPal.Windows.Utils.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Localization\obj\x64\Release\netstandard2.0\AetherPal.Application.Localization.pdbSHA25693 source: AetherPal.Application.Localization.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Net\obj\x64\Release\netstandard2.0\AetherPal.Net.pdbSHA256} source: AetherPal.Net.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.NetworkInformation\4.1.2.0\System.Net.NetworkInformation.pdb source: System.Net.NetworkInformation.dll.1.dr
        Source: Binary string: C:\projects\winpty-net\src\winpty.NET\obj\Release\winpty.NET.pdb source: winpty.NET.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Diagnostics\obj\x64\Release\netstandard2.0\AetherPal.Diagnostics.pdbSHA256Pk source: AetherPal.Diagnostics.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdbSHA256 source: System.Text.Encodings.Web.dll.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.SystemEvents/Release/net462/Microsoft.Win32.SystemEvents.pdbSHA256 source: Microsoft.Win32.SystemEvents.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ObjectModel\4.0.11.0\System.ObjectModel.pdb source: System.ObjectModel.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Globalization.Extensions/netfx\System.Globalization.Extensions.pdb source: System.Globalization.Extensions.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.pdbSHA256 source: AetherPal.Device.Tools.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Permissions/Release/net462/System.Security.Permissions.pdb source: System.Security.Permissions.dll.1.dr
        Source: Binary string: C:\projects\assist\pc\platforms\Windows\src\RemoteControl\x64\Release\DesktopDuplication.pdb source: DesktopDuplication.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime.CompilerServices.VisualC\4.0.2.0\System.Runtime.CompilerServices.VisualC.pdb source: System.Runtime.CompilerServices.VisualC.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/AnyOS.AnyCPU.Release/System.Security.SecureString/netfx\System.Security.SecureString.pdbf) source: System.Security.SecureString.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading.Tasks\4.0.11.0\System.Threading.Tasks.pdb source: System.Threading.Tasks.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.TextWriterTraceListener\4.0.2.0\System.Diagnostics.TextWriterTraceListener.pdb source: System.Diagnostics.TextWriterTraceListener.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Reader\4.0.2.0\System.Resources.Reader.pdbl( source: System.Resources.Reader.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.ServiceProcess.ServiceController/Release/net462/System.ServiceProcess.ServiceController.pdb source: System.ServiceProcess.ServiceController.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading.Tasks.Parallel\4.0.1.0\System.Threading.Tasks.Parallel.pdb source: System.Threading.Tasks.Parallel.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Core\obj\x64\Release\netstandard2.0\AetherPal.Core.pdbSHA256) source: AetherPal.Core.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.WebSockets.Client\4.0.2.0\System.Net.WebSockets.Client.pdb source: System.Net.WebSockets.Client.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Core\obj\x64\Release\netstandard2.0\AetherPal.Core.pdb source: AetherPal.Core.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.IsolatedStorage\4.0.2.0\System.IO.IsolatedStorage.pdb source: System.IO.IsolatedStorage.dll.1.dr
        Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools\obj\x64\Release\netstandard2.0\AetherPal.Tools.pdb source: AetherPal.Tools.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Diagnostics\obj\x64\Release\netstandard2.0\AetherPal.Diagnostics.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Diagnostics.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem\4.0.3.0\System.IO.FileSystem.pdb source: System.IO.FileSystem.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.X509Certificates\4.1.2.0\System.Security.Cryptography.X509Certificates.pdb source: System.Security.Cryptography.X509Certificates.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Linq.Expressions\4.1.2.0\System.Linq.Expressions.pdb source: System.Linq.Expressions.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Csp\4.0.2.0\System.Security.Cryptography.Csp.pdb source: System.Security.Cryptography.Csp.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device\obj\x64\Release\netstandard2.0\AetherPal.Device.pdbSHA256 source: AetherPal.Device.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ComponentModel\4.0.1.0\System.ComponentModel.pdb source: System.ComponentModel.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.WPF.CustomControls\obj\x64\Release\AetherPal.WPF.CustomControls.pdb source: AetherPal.WPF.CustomControls.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.FileManager\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.FileManager.pdbSHA256 source: AetherPal.Device.Tools.FileManager.dll.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.SystemEvents/Release/net462/Microsoft.Win32.SystemEvents.pdb source: Microsoft.Win32.SystemEvents.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.AccessControl/net461-windows-Release/System.Security.AccessControl.pdbSHA256 source: System.Security.AccessControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Encoding\4.0.2.0\System.Security.Cryptography.Encoding.pdbT)n) `)_CorDllMainmscoree.dll source: System.Security.Cryptography.Encoding.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Pipes\4.0.2.0\System.IO.Pipes.pdb source: System.IO.Pipes.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.Process\4.1.2.0\System.Diagnostics.Process.pdb source: System.Diagnostics.Process.dll.1.dr
        Source: Binary string: vcruntime140.amd64.pdb source: vcruntime140.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.MSIX.Launcher\obj\x64\Release\AetherPal.MSIX.Launcher.pdb source: AetherPal.MSIX.Launcher.exe, 00000004.00000000.1825414817.00000229A6812000.00000002.00000001.01000000.00000009.sdmp
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Primitives\4.0.11.0\System.Net.Primitives.pdbH,b, T,_CorDllMainmscoree.dll source: System.Net.Primitives.dll.1.dr
        Source: Binary string: C:\agent\_work\66\s\build\ship\x86\uica.pdb source: VZH3bd37Gc.msi, 58426b.msi.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/AnyOS.AnyCPU.Release/System.Security.SecureString/netfx\System.Security.SecureString.pdb source: System.Security.SecureString.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XDocument\4.0.11.0\System.Xml.XDocument.pdb source: System.Xml.XDocument.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Dynamic.Runtime\4.0.11.0\System.Dynamic.Runtime.pdb source: System.Dynamic.Runtime.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading\4.0.11.0\System.Threading.pdb source: System.Threading.dll.1.dr
        Source: Binary string: msvcp140.amd64.pdb source: msvcp140.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Compression.ZipFile\4.0.3.0\System.IO.Compression.ZipFile.pdb source: System.IO.Compression.ZipFile.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\Microsoft.Win32.Primitives\4.0.3.0\Microsoft.Win32.Primitives.pdb source: Microsoft.Win32.Primitives.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Agent\obj\x64\Release\net462\AetherPal.Application.Agent.pdb source: AetherPal.Application.Agent.dll.1.dr
        Source: Binary string: msvcp140.amd64.pdbGCTL source: msvcp140.dll.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\net461-Release\System.Runtime.CompilerServices.Unsafe.pdb source: System.Runtime.CompilerServices.Unsafe.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem.Primitives\4.0.3.0\System.IO.FileSystem.Primitives.pdb source: System.IO.FileSystem.Primitives.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Configuration\obj\x64\Release\net462\AetherPal.Configuration.pdb source: AetherPal.Configuration.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Collections.NonGeneric\4.0.3.0\System.Collections.NonGeneric.pdb source: System.Collections.NonGeneric.dll.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.Registry/net461-Windows_NT-Release/Microsoft.Win32.Registry.pdbSHA256 source: Microsoft.Win32.Registry.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Collections\4.0.11.0\System.Collections.pdb source: System.Collections.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime.Serialization.Json\4.0.1.0\System.Runtime.Serialization.Json.pdb source: System.Runtime.Serialization.Json.dll.1.dr
        Source: Binary string: C:\projects\assist\pc\platforms\Windows\src\RemoteControl\x64\Release\DesktopDuplication.pdb-- source: DesktopDuplication.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools\obj\x64\Release\netstandard2.0\AetherPal.Tools.pdbSHA256 source: AetherPal.Tools.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Primitives\4.0.11.0\System.Net.Primitives.pdb source: System.Net.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem.Watcher\4.0.2.0\System.IO.FileSystem.Watcher.pdb source: System.IO.FileSystem.Watcher.dll.1.dr
        Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: c:Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior

        Networking

        barindex
        Source: Yara matchFile source: 3.3.rundll32.exe.1320522fe40.1.raw.unpack, type: UNPACKEDPE
        Source: Yara matchFile source: C:\Windows\Installer\MSI50A5.tmp-\netstandard.dll, type: DROPPED
        Source: Yara matchFile source: C:\Program Files\VMware\Workspace ONE Assist\netstandard.dll, type: DROPPED
        Source: AetherPal.Device.dll.1.drString found in binary or memory: http://aetherpal.com/XMLSchema/device/DeviceInfo10
        Source: AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.dll.1.drString found in binary or memory: http://aetherpal.com/XMLSchema/device/SecurityPolicy10
        Source: AetherPal.Device.dll.1.drString found in binary or memory: http://aetherpal.com/XMLSchema/device/UserInterfacePolicy10
        Source: AetherPal.Device.dll.1.drString found in binary or memory: http://aetherpal.com/deviceghttp://aetherpal.com/XMLSchema/device/TimerPolicy10
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDCodeSigningCA.crt0
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertSHA2AssuredIDTimestampingCA.crt0
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.dll.1.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://cacerts.digicert.com/NETFoundationProjectsCodeSigningCA.crt0
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.dll.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0P
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl0=
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
        Source: AetherPal.Device.Tools.dll.1.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://crl3.digicert.com/NETFoundationProjectsCodeSigningCA.crl0E
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: http://crl3.digicert.com/sha2-assured-cs-g1.crl05
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://crl3.digicert.com/sha2-assured-ts.crl02
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://crl4.digicert.com/DigiCertAssuredIDRootCA.crl0:
        Source: AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://crl4.digicert.com/NETFoundationProjectsCodeSigningCA.crl0L
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: http://crl4.digicert.com/sha2-assured-cs-g1.crl0L
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://crl4.digicert.com/sha2-assured-ts.crl0
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://ocsp.digicert.com0
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.dll.1.drString found in binary or memory: http://ocsp.digicert.com0A
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, Microsoft.Deployment.WindowsInstaller.dll.3.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.drString found in binary or memory: http://ocsp.digicert.com0C
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://ocsp.digicert.com0K
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.dr, AetherPal.Windows.Net.dll.1.drString found in binary or memory: http://ocsp.digicert.com0N
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://ocsp.digicert.com0O
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://ocsp.digicert.com0X
        Source: rundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: http://sv.symcb.com/sv.crl0a
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: http://sv.symcb.com/sv.crt0
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: http://sv.symcd.com0&
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: http://victoryonemedia.comhttps://github.com/chrismsimpson/Metropolis
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisCopyright
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisExtra
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisLight
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisMedium
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisSemi
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drString found in binary or memory: http://wixtoolset.org
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.drString found in binary or memory: http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/v
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.drString found in binary or memory: http://wixtoolset.org/news/
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.drString found in binary or memory: http://wixtoolset.org/releases/
        Source: VZH3bd37Gc.msi, AetherPal.Tools.dll.1.dr, AetherPal.Net.dll.1.dr, WorkspaceONE.Assist.Client.exe.1.dr, WorkspaceONE.Assist.Agent.exe.1.dr, AetherPal.Utils.dll.1.dr, 58426b.msi.1.dr, AetherPal.WPF.CustomControls.dll.1.dr, AetherPal.Application.Localization.dll.1.dr, AetherPal.Application.Agent.dll.1.dr, AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.Tools.FileManager.dll.1.dr, AetherPal.Device.dll.1.dr, AetherPal.Diagnostics.dll.1.dr, AetherPal.Configuration.dll.1.dr, AetherPal.Windows.Net.dll.1.dr, DesktopDuplication.dll.1.dr, AetherPal.Core.dll.1.dr, AetherPal.Windows.Utils.dll.1.dr, AetherPal.Tools.RemoteControl.dll.1.drString found in binary or memory: http://www.digicert.com/CPS0
        Source: System.Text.Json.dll.1.drString found in binary or memory: https://aka.ms/binaryformatter
        Source: System.Text.Json.dll.1.drString found in binary or memory: https://aka.ms/dotnet-warnings/
        Source: System.Text.Json.dll.1.drString found in binary or memory: https://aka.ms/serializationformat-binary-obsolete
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: https://d.symcb.com/cps0%
        Source: AetherPal.Windows.Net.dll.1.drString found in binary or memory: https://d.symcb.com/rpa0
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: https://github.com/chrismsimpsonhttps://github.com/chrismsimpson/Metropolis
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: https://github.com/chrismsimpsonhttps://github.com/chrismsimpson/MetropolisCopyright
        Source: AetherPal.WPF.CustomControls.dll.1.drString found in binary or memory: https://github.com/chrismsimpsonhttps://github.com/chrismsimpson/MetropolisMetropolisLight
        Source: WorkspaceONE.Assist.Client.exe.1.drString found in binary or memory: https://github.com/dotnet/core/)
        Source: System.Text.Json.dll.1.drString found in binary or memory: https://github.com/dotnet/roslyn/issues/46646
        Source: System.Text.Json.dll.1.drString found in binary or memory: https://github.com/dotnet/roslyn/issues/46646~
        Source: System.Security.Permissions.dll.1.dr, System.ServiceProcess.ServiceController.dll.1.dr, System.Security.AccessControl.dll.1.dr, System.Text.Json.dll.1.dr, System.CodeDom.dll.1.dr, System.Text.Encodings.Web.dll.1.dr, Microsoft.Win32.SystemEvents.dll.1.dr, System.Security.Cryptography.ProtectedData.dll.1.drString found in binary or memory: https://github.com/dotnet/runtime
        Source: System.Security.Permissions.dll.1.dr, System.ServiceProcess.ServiceController.dll.1.dr, System.CodeDom.dll.1.dr, Microsoft.Win32.SystemEvents.dll.1.dr, System.Security.Cryptography.ProtectedData.dll.1.drString found in binary or memory: https://github.com/dotnet/runtime&
        Source: System.Text.Json.dll.1.drString found in binary or memory: https://github.com/dotnet/runtime/issues/73124.
        Source: System.Text.Json.dll.1.drString found in binary or memory: https://github.com/dotnet/runtime8
        Source: WorkspaceONE.Assist.Client.exe.1.drString found in binary or memory: https://www.att.com
        Source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.dr, AetherPal.Windows.Net.dll.1.drString found in binary or memory: https://www.digicert.com/CPS0
        Source: WorkspaceONE.Assist.Client.exe.1.drString found in binary or memory: https://www.gnu.org/licenses
        Source: WorkspaceONE.Assist.Client.exe.1.drString found in binary or memory: https://www.vmware.com/es/help/privacy.html
        Source: WorkspaceONE.Assist.Client.exe.1.drString found in binary or memory: https://www.vmware.com/help/privacy.html
        Source: WorkspaceONE.Assist.Client.exe.1.drString found in binary or memory: https://www.vmware.com/help/privacy.html.
        Source: WorkspaceONE.Assist.Client.exe.1.drString found in binary or memory: https://www.vmware.com/tw/help/privacy.html
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A5D09 CreateProcessAsUserW,3_3_00007FFD9B4A5D09
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\58426b.msiJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\inprogressinstallinfo.ipiJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\SourceHash{2687F608-EC00-4F9A-B6B3-0194BAD168BB}Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI4559.tmpJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI50A5.tmpJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{2687F608-EC00-4F9A-B6B3-0194BAD168BB}Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\{2687F608-EC00-4F9A-B6B3-0194BAD168BB}\icon.icoJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-Jump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Wix.CustomAction.dllJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Utils.dllJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\Microsoft.Deployment.WindowsInstaller.dllJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Diagnostics.dllJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\netstandard.dllJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Utils.dllJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\CustomAction.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile deleted: C:\Windows\Installer\MSI50A5.tmpJump to behavior
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A39B93_3_00007FFD9B4A39B9
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A3F683_3_00007FFD9B4A3F68
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A53243_3_00007FFD9B4A5324
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A12DE3_3_00007FFD9B4A12DE
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A15183_3_00007FFD9B4A1518
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A37513_3_00007FFD9B4A3751
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeCode function: 4_2_00007FFD9B3F13B04_2_00007FFD9B3F13B0
        Source: System.Runtime.CompilerServices.Unsafe.dll.1.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
        Source: System.Numerics.Vectors.dll.1.drStatic PE information: Resource name: RT_VERSION type: Hitachi SH little-endian COFF executable, no relocation info, not stripped, 52 sections, symbol offset=0x5f0053, 4522070 symbols, optional header size 82, created Sat Mar 7 05:34:56 1970
        Source: System.Diagnostics.PerformanceCounter.dll.1.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
        Source: System.Globalization.Extensions.dll.1.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
        Source: winpty-agent.exe.1.drStatic PE information: Number of sections : 22 > 10
        Source: WorkspaceONE.Assist.Cleanup.exe.1.drStatic PE information: No import functions for PE file found
        Source: AetherPal.Channels.AnchorChannel.dll.1.drStatic PE information: No import functions for PE file found
        Source: AetherPal.MSIX.Launcher.exe.1.drStatic PE information: No import functions for PE file found
        Source: AetherPal.Windows.Utils.dll.1.drStatic PE information: No import functions for PE file found
        Source: VZH3bd37Gc.msiBinary or memory string: OriginalFilenameuica.dll\ vs VZH3bd37Gc.msi
        Source: VZH3bd37Gc.msiBinary or memory string: OriginalFilenameAetherPal.Windows.Wix.CustomAction.dll\ vs VZH3bd37Gc.msi
        Source: VZH3bd37Gc.msiBinary or memory string: OriginalFilenameSfxCA.dll\ vs VZH3bd37Gc.msi
        Source: classification engineClassification label: clean15.troj.winMSI@9/191@0/0
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMwareJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Users\user\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\rundll32.exe.logJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeMutant created: NULL
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6452:120:WilError_03
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Users\user\AppData\Local\Temp\MSI82a9f.LOGJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile read: C:\Windows\win.iniJump to behavior
        Source: C:\Windows\System32\msiexec.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\SystemCertificates\CAJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI50A5.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5787937 2 AetherPal.Windows.Wix.CustomAction!AetherPal.Windows.Wix.CustomAction.CustomActions.InstallModernApp
        Source: VZH3bd37Gc.msiStatic file information: TRID: Microsoft Windows Installer (60509/1) 88.31%
        Source: unknownProcess created: C:\Windows\System32\msiexec.exe "C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\VZH3bd37Gc.msi"
        Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
        Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 08351F78698DA0C0368A0A0187380C10 E Global\MSI0000
        Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI50A5.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5787937 2 AetherPal.Windows.Wix.CustomAction!AetherPal.Windows.Wix.CustomAction.CustomActions.InstallModernApp
        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe "C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe" "install" "C:\Program Files\VMware\Workspace ONE Assist\Resources"
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\msiexec.exe C:\Windows\System32\MsiExec.exe -Embedding 08351F78698DA0C0368A0A0187380C10 E Global\MSI0000Jump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess created: C:\Windows\System32\rundll32.exe rundll32.exe "C:\Windows\Installer\MSI50A5.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5787937 2 AetherPal.Windows.Wix.CustomAction!AetherPal.Windows.Wix.CustomAction.CustomActions.InstallModernAppJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe "C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe" "install" "C:\Program Files\VMware\Workspace ONE Assist\Resources"Jump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: srpapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: uxtheme.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: textinputframework.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: coreuicomponents.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: coremessaging.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: ntmarta.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: textshaping.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msihnd.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: dwmapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: windowscodecs.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: oleacc.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: riched20.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: usp10.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msls31.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: userenv.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: profapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sspicli.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: netapi32.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: wkscli.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: netutils.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: srclient.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: spp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: powrprof.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: vssapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: vsstrace.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: umpdc.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: wldp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msasn1.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msisip.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: gpapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: mscoree.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: version.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: rstrtmgr.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: ncrypt.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: ntasn1.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: windows.storage.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: pcacli.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: mpr.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: propsys.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: linkinfo.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: ntshrui.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: srvcli.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: cscapi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: aclayers.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sfc.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: sfc_os.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: msi.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeSection loaded: cabinet.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: mscoree.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: apphelp.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: kernel.appcore.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: version.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: windows.applicationmodel.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: twinapi.appcore.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: wintypes.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: cryptsp.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: rsaenh.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: cryptbase.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: appxdeploymentclient.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeSection loaded: iertutil.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeAutomated click: I accept the terms in the License Agreement
        Source: C:\Windows\System32\msiexec.exeAutomated click: Install
        Source: C:\Windows\System32\msiexec.exeWindow detected: WixUI_Bmp_DialogI &accept the terms in the License Agreement&Print&Back&InstallCancelLicense VMware Workspace ONE AssistPlease read the Workspace ONE Assist Installer License Agreement
        Source: C:\Windows\System32\msiexec.exeWindow detected: WixUI_Bmp_DialogI &accept the terms in the License Agreement&Print&Back&InstallCancelLicense VMware Workspace ONE AssistPlease read the Workspace ONE Assist Installer License Agreement
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMwareJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE AssistJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Cleanup.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\msvcp140.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Numerics.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.TypeConverter.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.VisualC.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Numerics.Vectors.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.PerformanceCounter.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Console.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty-agent.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.ResourceManager.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.AccessControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ServiceProcess.ServiceController.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\netstandard.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.FileManager.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Security.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.EventBasedAsync.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Json.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Permissions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TextWriterTraceListener.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Writer.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Registry.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Bcl.AsyncInterfaces.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\nativeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\libJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windowsJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64Jump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64\libvpx.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty.NET.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\ResourcesJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\AppxJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\AUMIDs.txtJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Expressions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Parallel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.IsolatedStorage.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.RuntimeInformation.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.X509Certificates.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.WPF.CustomControls.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osxJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64Jump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\libvpx.dylibJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\DesktopDuplication.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\winpty-debugserver.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Timer.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140_1.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.Windows.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TraceSource.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Utils.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebHeaderCollection.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.DriveInfo.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tools.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.ZipFile.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.ReaderWriter.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\MPAP_f7529f1a891c4c29afa0bf940c4958e4_001.provxmlJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exe.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.ProtectedData.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.AccessControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NameResolution.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Queryable.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Http.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.MemoryMappedFiles.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Handles.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.EventLog.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.ThreadPool.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Sockets.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Concurrent.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Ping.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Pipes.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Newtonsoft.Json.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ObjectModel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linuxJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\armJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\arm\lib_remote_shell_api.soJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Reader.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Process.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.UnmanagedMemoryStream.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encodings.Web.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Csp.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Algorithms.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Requests.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.Unsafe.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.CodeDom.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Buffers.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.AppContext.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.XDocument.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Calendars.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4_License1.xmlJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Drawing.Primitives.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\lib_remote_shell_api.dylibJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XDocument.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\RemoteLibJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.Client.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Watcher.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Thread.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64Jump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64\lib_remote_shell_api.soJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Debug.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NetworkInformation.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Dynamic.Runtime.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Formatters.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Json.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.SystemEvents.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4.appxbundleJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.StackTrace.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.RegularExpressions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Data.Common.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tracing.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.ValueTuple.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.FileVersionInfo.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.NonGeneric.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Overlapped.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlSerializer.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Xml.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Net.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Encoding.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Security.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Specialized.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Net.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Contracts.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Extensions.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Claims.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Memory.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.SecureString.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Parallel.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlDocument.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeDirectory created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe.configJump to behavior
        Source: VZH3bd37Gc.msiStatic file information: File size 10838016 > 1048576
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Configuration\obj\x64\Release\net462\AetherPal.Configuration.pdbSHA256 source: AetherPal.Configuration.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin\obj\Windows_NT.AnyCPU.Release\System.Runtime.InteropServices.RuntimeInformation\net462\System.Runtime.InteropServices.RuntimeInformation.pdb source: System.Runtime.InteropServices.RuntimeInformation.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Diagnostics\obj\x64\Release\netstandard2.0\AetherPal.Diagnostics.pdbSHA256 source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: C:\agent\_work\66\s\build\ship\x64\SfxCA.pdb source: VZH3bd37Gc.msi, MSI4559.tmp.1.dr, 58426b.msi.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Net\obj\x64\Release\AetherPal.Windows.Net.pdb source: AetherPal.Windows.Net.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ObjectModel\4.0.11.0\System.ObjectModel.pdbX+r+ d+_CorDllMainmscoree.dll source: System.ObjectModel.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Reader\4.0.2.0\System.Resources.Reader.pdb source: System.Resources.Reader.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Tools.RemoteControl.pdbSHA256 source: AetherPal.Tools.RemoteControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Reflection.Primitives\4.0.1.0\System.Reflection.Primitives.pdb source: System.Reflection.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Compression.ZipFile\4.0.3.0\System.IO.Compression.ZipFile.pdb( source: System.IO.Compression.ZipFile.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.NameResolution\4.0.2.0\System.Net.NameResolution.pdb source: System.Net.NameResolution.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.CodeDom/Release/net462/System.CodeDom.pdbSHA256 source: System.CodeDom.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Localization\obj\x64\Release\netstandard2.0\AetherPal.Application.Localization.pdb source: AetherPal.Application.Localization.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem\4.0.3.0\System.IO.FileSystem.pdb8)R) D)_CorDllMainmscoree.dll source: System.IO.FileSystem.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Encoding\4.0.2.0\System.Security.Cryptography.Encoding.pdb source: System.Security.Cryptography.Encoding.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Permissions/Release/net462/System.Security.Permissions.pdbSHA256 source: System.Security.Permissions.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Wix.CustomAction\obj\x64\Release\AetherPal.Windows.Wix.CustomAction.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Windows.Wix.CustomAction.dll.3.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin\obj\Windows_NT.AnyCPU.Release\System.Net.Http\netfx\System.Net.Http.pdb source: System.Net.Http.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Agent\obj\x64\Release\net462\AetherPal.Application.Agent.pdbSHA256 source: AetherPal.Application.Agent.dll.1.dr
        Source: Binary string: C:\projects\assist\pc\platforms\wasm\libvpx_wasm\vcproj\libvpx\x64\Release\libvpx.pdb source: libvpx.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.ResourceManager\4.0.1.0\System.Resources.ResourceManager.pdb source: System.Resources.ResourceManager.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Diagnostics.Tracing/netfx\System.Diagnostics.Tracing.pdb'MAM 3M_CorDllMainmscoree.dll source: System.Diagnostics.Tracing.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Cryptography.ProtectedData/Release/net462/System.Security.Cryptography.ProtectedData.pdb source: System.Security.Cryptography.ProtectedData.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.Process\4.1.2.0\System.Diagnostics.Process.pdb* source: System.Diagnostics.Process.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.RemoteControl.pdb source: AetherPal.Device.Tools.RemoteControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO\4.1.2.0\System.IO.pdb source: System.IO.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.RemoteControl.pdbSHA256r]Hc3C( source: AetherPal.Device.Tools.RemoteControl.dll.1.dr
        Source: Binary string: vcruntime140.amd64.pdbGCTL source: vcruntime140.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Csp\4.0.2.0\System.Security.Cryptography.Csp.pdb4)N) @)_CorDllMainmscoree.dll source: System.Security.Cryptography.Csp.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Linq\4.1.2.0\System.Linq.pdb source: System.Linq.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Utils\obj\x64\Release\netstandard2.0\AetherPal.Utils.pdbSHA256 source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817462846.0000013203552000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817556529.0000013203552000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Utils.dll.3.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.FileManager\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.FileManager.pdb source: AetherPal.Device.Tools.FileManager.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.ServiceProcess.ServiceController/Release/net462/System.ServiceProcess.ServiceController.pdbSHA256) source: System.ServiceProcess.ServiceController.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.pdb source: AetherPal.Device.Tools.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/AnyOS.AnyCPU.Release/System.Data.Common/netfx\System.Data.Common.pdb source: System.Data.Common.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Pipes\4.0.2.0\System.IO.Pipes.pdbh) source: System.IO.Pipes.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Writer\4.0.2.0\System.Resources.Writer.pdb source: System.Resources.Writer.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.WPF.WindowsClient\obj\x64\Release\WorkspaceONE.Assist.Client.pdb source: WorkspaceONE.Assist.Client.exe.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools.RemoteControl\obj\x64\Release\netstandard2.0\AetherPal.Tools.RemoteControl.pdb source: AetherPal.Tools.RemoteControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Security\4.0.2.0\System.Net.Security.pdbT*n* `*_CorDllMainmscoree.dll source: System.Net.Security.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading.ThreadPool\4.0.12.0\System.Threading.ThreadPool.pdb source: System.Threading.ThreadPool.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\Microsoft.Win32.Primitives\4.0.3.0\Microsoft.Win32.Primitives.pdb|( source: Microsoft.Win32.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Reflection.Primitives\4.0.1.0\System.Reflection.Primitives.pdb$*>* 0*_CorDllMainmscoree.dll source: System.Reflection.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.TraceSource\4.0.2.0\System.Diagnostics.TraceSource.pdb source: System.Diagnostics.TraceSource.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.Tools\4.0.1.0\System.Diagnostics.Tools.pdb source: System.Diagnostics.Tools.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Agent.App\obj\x64\Release\WorkspaceONE.Assist.Agent.pdb source: WorkspaceONE.Assist.Agent.exe.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.Registry/net461-Windows_NT-Release/Microsoft.Win32.Registry.pdb source: Microsoft.Win32.Registry.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Runtime.Serialization.Xml/netfx\System.Runtime.Serialization.Xml.pdb source: System.Runtime.Serialization.Xml.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XmlSerializer\4.0.11.0\System.Xml.XmlSerializer.pdbt+ source: System.Xml.XmlSerializer.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.NameResolution\4.0.2.0\System.Net.NameResolution.pdb|( source: System.Net.NameResolution.dll.1.dr
        Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdbP source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\net461-Release\System.Runtime.CompilerServices.Unsafe.pdbBSJB source: System.Runtime.CompilerServices.Unsafe.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Utils\obj\x64\Release\netstandard2.0\AetherPal.Utils.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817462846.0000013203552000.00000004.00000020.00020000.00000000.sdmp, rundll32.exe, 00000003.00000003.1817556529.0000013203552000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Utils.dll.1.dr, AetherPal.Utils.dll.3.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device\obj\x64\Release\netstandard2.0\AetherPal.Device.pdb source: AetherPal.Device.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Security\4.0.2.0\System.Net.Security.pdb source: System.Net.Security.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XPath\4.0.3.0\System.Xml.XPath.pdb source: System.Xml.XPath.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Utils\obj\x64\Release\net462\AetherPal.Windows.Utils.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.MSIX.Launcher.exe, AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895084039.00000229A6B72000.00000002.00000001.01000000.0000000A.sdmp, AetherPal.Windows.Utils.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime.CompilerServices.VisualC\4.0.2.0\System.Runtime.CompilerServices.VisualC.pdb@*Z* L*_CorDllMainmscoree.dll source: System.Runtime.CompilerServices.VisualC.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Runtime.Serialization.Primitives/netfx\System.Runtime.Serialization.Primitives.pdb source: System.Runtime.Serialization.Primitives.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdb source: System.Text.Json.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdb source: System.Text.Encodings.Web.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Diagnostics.Tracing/netfx\System.Diagnostics.Tracing.pdb source: System.Diagnostics.Tracing.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime\4.1.2.0\System.Runtime.pdb source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895196565.00000229A6BA2000.00000002.00000001.01000000.0000000B.sdmp
        Source: Binary string: /_/artifacts/obj/System.Security.Cryptography.ProtectedData/Release/net462/System.Security.Cryptography.ProtectedData.pdbSHA256C source: System.Security.Cryptography.ProtectedData.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin\obj\Windows_NT.AnyCPU.Release\System.Runtime.InteropServices.RuntimeInformation\net462\System.Runtime.InteropServices.RuntimeInformation.pdbxE source: System.Runtime.InteropServices.RuntimeInformation.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Writer\4.0.2.0\System.Resources.Writer.pdbl( source: System.Resources.Writer.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XmlSerializer\4.0.11.0\System.Xml.XmlSerializer.pdb source: System.Xml.XmlSerializer.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Net\obj\x64\Release\netstandard2.0\AetherPal.Net.pdb source: AetherPal.Net.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Utils\obj\x64\Release\netstandard2.0\AetherPal.Utils.pdbSHA256u source: AetherPal.Utils.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ComponentModel.TypeConverter\4.1.2.0\System.ComponentModel.TypeConverter.pdb source: System.ComponentModel.TypeConverter.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Json/Release/net462/System.Text.Json.pdbSHA256 source: System.Text.Json.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Text.RegularExpressions\4.1.1.0\System.Text.RegularExpressions.pdb source: System.Text.RegularExpressions.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.AccessControl/net461-windows-Release/System.Security.AccessControl.pdb source: System.Security.AccessControl.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.CodeDom/Release/net462/System.CodeDom.pdb source: System.CodeDom.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Windows.Utils\obj\x64\Release\net462\AetherPal.Windows.Utils.pdbSHA256 source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895084039.00000229A6B72000.00000002.00000001.01000000.0000000A.sdmp, AetherPal.Windows.Utils.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Localization\obj\x64\Release\netstandard2.0\AetherPal.Application.Localization.pdbSHA25693 source: AetherPal.Application.Localization.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Net\obj\x64\Release\netstandard2.0\AetherPal.Net.pdbSHA256} source: AetherPal.Net.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.NetworkInformation\4.1.2.0\System.Net.NetworkInformation.pdb source: System.Net.NetworkInformation.dll.1.dr
        Source: Binary string: C:\projects\winpty-net\src\winpty.NET\obj\Release\winpty.NET.pdb source: winpty.NET.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Diagnostics\obj\x64\Release\netstandard2.0\AetherPal.Diagnostics.pdbSHA256Pk source: AetherPal.Diagnostics.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Text.Encodings.Web/Release/net462/System.Text.Encodings.Web.pdbSHA256 source: System.Text.Encodings.Web.dll.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.SystemEvents/Release/net462/Microsoft.Win32.SystemEvents.pdbSHA256 source: Microsoft.Win32.SystemEvents.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ObjectModel\4.0.11.0\System.ObjectModel.pdb source: System.ObjectModel.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/Windows_NT.AnyCPU.Release/System.Globalization.Extensions/netfx\System.Globalization.Extensions.pdb source: System.Globalization.Extensions.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.pdbSHA256 source: AetherPal.Device.Tools.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.Permissions/Release/net462/System.Security.Permissions.pdb source: System.Security.Permissions.dll.1.dr
        Source: Binary string: C:\projects\assist\pc\platforms\Windows\src\RemoteControl\x64\Release\DesktopDuplication.pdb source: DesktopDuplication.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime.CompilerServices.VisualC\4.0.2.0\System.Runtime.CompilerServices.VisualC.pdb source: System.Runtime.CompilerServices.VisualC.dll.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/AnyOS.AnyCPU.Release/System.Security.SecureString/netfx\System.Security.SecureString.pdbf) source: System.Security.SecureString.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading.Tasks\4.0.11.0\System.Threading.Tasks.pdb source: System.Threading.Tasks.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.TextWriterTraceListener\4.0.2.0\System.Diagnostics.TextWriterTraceListener.pdb source: System.Diagnostics.TextWriterTraceListener.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Resources.Reader\4.0.2.0\System.Resources.Reader.pdbl( source: System.Resources.Reader.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.ServiceProcess.ServiceController/Release/net462/System.ServiceProcess.ServiceController.pdb source: System.ServiceProcess.ServiceController.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading.Tasks.Parallel\4.0.1.0\System.Threading.Tasks.Parallel.pdb source: System.Threading.Tasks.Parallel.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Core\obj\x64\Release\netstandard2.0\AetherPal.Core.pdbSHA256) source: AetherPal.Core.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.WebSockets.Client\4.0.2.0\System.Net.WebSockets.Client.pdb source: System.Net.WebSockets.Client.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Core\obj\x64\Release\netstandard2.0\AetherPal.Core.pdb source: AetherPal.Core.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.IsolatedStorage\4.0.2.0\System.IO.IsolatedStorage.pdb source: System.IO.IsolatedStorage.dll.1.dr
        Source: Binary string: C:\agent\_work\66\s\build\obj\ship\x86\WindowsInstaller\Microsoft.Deployment.WindowsInstaller.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools\obj\x64\Release\netstandard2.0\AetherPal.Tools.pdb source: AetherPal.Tools.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Diagnostics\obj\x64\Release\netstandard2.0\AetherPal.Diagnostics.pdb source: rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, AetherPal.Diagnostics.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem\4.0.3.0\System.IO.FileSystem.pdb source: System.IO.FileSystem.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.X509Certificates\4.1.2.0\System.Security.Cryptography.X509Certificates.pdb source: System.Security.Cryptography.X509Certificates.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Linq.Expressions\4.1.2.0\System.Linq.Expressions.pdb source: System.Linq.Expressions.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Csp\4.0.2.0\System.Security.Cryptography.Csp.pdb source: System.Security.Cryptography.Csp.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device\obj\x64\Release\netstandard2.0\AetherPal.Device.pdbSHA256 source: AetherPal.Device.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.ComponentModel\4.0.1.0\System.ComponentModel.pdb source: System.ComponentModel.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.WPF.CustomControls\obj\x64\Release\AetherPal.WPF.CustomControls.pdb source: AetherPal.WPF.CustomControls.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Device.Tools.FileManager\obj\x64\Release\netstandard2.0\AetherPal.Device.Tools.FileManager.pdbSHA256 source: AetherPal.Device.Tools.FileManager.dll.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.SystemEvents/Release/net462/Microsoft.Win32.SystemEvents.pdb source: Microsoft.Win32.SystemEvents.dll.1.dr
        Source: Binary string: /_/artifacts/obj/System.Security.AccessControl/net461-windows-Release/System.Security.AccessControl.pdbSHA256 source: System.Security.AccessControl.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Security.Cryptography.Encoding\4.0.2.0\System.Security.Cryptography.Encoding.pdbT)n) `)_CorDllMainmscoree.dll source: System.Security.Cryptography.Encoding.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Pipes\4.0.2.0\System.IO.Pipes.pdb source: System.IO.Pipes.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Diagnostics.Process\4.1.2.0\System.Diagnostics.Process.pdb source: System.Diagnostics.Process.dll.1.dr
        Source: Binary string: vcruntime140.amd64.pdb source: vcruntime140.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.MSIX.Launcher\obj\x64\Release\AetherPal.MSIX.Launcher.pdb source: AetherPal.MSIX.Launcher.exe, 00000004.00000000.1825414817.00000229A6812000.00000002.00000001.01000000.00000009.sdmp
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Primitives\4.0.11.0\System.Net.Primitives.pdbH,b, T,_CorDllMainmscoree.dll source: System.Net.Primitives.dll.1.dr
        Source: Binary string: C:\agent\_work\66\s\build\ship\x86\uica.pdb source: VZH3bd37Gc.msi, 58426b.msi.1.dr
        Source: Binary string: E:\A\_work\1795\s\corefx\bin/obj/AnyOS.AnyCPU.Release/System.Security.SecureString/netfx\System.Security.SecureString.pdb source: System.Security.SecureString.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Xml.XDocument\4.0.11.0\System.Xml.XDocument.pdb source: System.Xml.XDocument.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Dynamic.Runtime\4.0.11.0\System.Dynamic.Runtime.pdb source: System.Dynamic.Runtime.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Threading\4.0.11.0\System.Threading.pdb source: System.Threading.dll.1.dr
        Source: Binary string: msvcp140.amd64.pdb source: msvcp140.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.Compression.ZipFile\4.0.3.0\System.IO.Compression.ZipFile.pdb source: System.IO.Compression.ZipFile.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\Microsoft.Win32.Primitives\4.0.3.0\Microsoft.Win32.Primitives.pdb source: Microsoft.Win32.Primitives.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Application.Agent\obj\x64\Release\net462\AetherPal.Application.Agent.pdb source: AetherPal.Application.Agent.dll.1.dr
        Source: Binary string: msvcp140.amd64.pdbGCTL source: msvcp140.dll.1.dr
        Source: Binary string: D:\a\_work\1\s\artifacts\obj\System.Runtime.CompilerServices.Unsafe\net461-Release\System.Runtime.CompilerServices.Unsafe.pdb source: System.Runtime.CompilerServices.Unsafe.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem.Primitives\4.0.3.0\System.IO.FileSystem.Primitives.pdb source: System.IO.FileSystem.Primitives.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Configuration\obj\x64\Release\net462\AetherPal.Configuration.pdb source: AetherPal.Configuration.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Collections.NonGeneric\4.0.3.0\System.Collections.NonGeneric.pdb source: System.Collections.NonGeneric.dll.1.dr
        Source: Binary string: /_/artifacts/obj/Microsoft.Win32.Registry/net461-Windows_NT-Release/Microsoft.Win32.Registry.pdbSHA256 source: Microsoft.Win32.Registry.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Collections\4.0.11.0\System.Collections.pdb source: System.Collections.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Runtime.Serialization.Json\4.0.1.0\System.Runtime.Serialization.Json.pdb source: System.Runtime.Serialization.Json.dll.1.dr
        Source: Binary string: C:\projects\assist\pc\platforms\Windows\src\RemoteControl\x64\Release\DesktopDuplication.pdb-- source: DesktopDuplication.dll.1.dr
        Source: Binary string: E:\agt01\AS-ASWIN844-BAWPS\AetherPal.Tools\obj\x64\Release\netstandard2.0\AetherPal.Tools.pdbSHA256 source: AetherPal.Tools.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.Net.Primitives\4.0.11.0\System.Net.Primitives.pdb source: System.Net.Primitives.dll.1.dr
        Source: Binary string: E:\A\_work\582\s\bin\obj\ref\System.IO.FileSystem.Watcher\4.0.2.0\System.IO.FileSystem.Watcher.pdb source: System.IO.FileSystem.Watcher.dll.1.dr
        Source: AetherPal.Windows.Utils.dll.1.drStatic PE information: 0xD5389866 [Tue May 11 10:13:58 2083 UTC]
        Source: winpty-agent.exe.1.drStatic PE information: section name: .xdata
        Source: winpty-agent.exe.1.drStatic PE information: section name: /4
        Source: winpty-agent.exe.1.drStatic PE information: section name: /19
        Source: winpty-agent.exe.1.drStatic PE information: section name: /31
        Source: winpty-agent.exe.1.drStatic PE information: section name: /45
        Source: winpty-agent.exe.1.drStatic PE information: section name: /57
        Source: winpty-agent.exe.1.drStatic PE information: section name: /70
        Source: winpty-agent.exe.1.drStatic PE information: section name: /81
        Source: winpty-agent.exe.1.drStatic PE information: section name: /92
        Source: winpty-agent.exe.1.drStatic PE information: section name: /106
        Source: winpty-agent.exe.1.drStatic PE information: section name: /122
        Source: winpty-agent.exe.1.drStatic PE information: section name: /138
        Source: msvcp140.dll.1.drStatic PE information: section name: .didat
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A627E pushad ; retn 5F42h3_3_00007FFD9B4A62CD
        Source: C:\Windows\System32\rundll32.exeCode function: 3_3_00007FFD9B4A61A0 push ds; ret 3_3_00007FFD9B4A620F
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Data.Common.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.FileVersionInfo.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Debug.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.WPF.CustomControls.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.X509Certificates.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.ProtectedData.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Bcl.AsyncInterfaces.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encodings.Web.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.FileManager.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Security.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.Unsafe.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Drawing.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tracing.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.ThreadPool.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.SystemEvents.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Parallel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Reader.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Encoding.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.ReaderWriter.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.AccessControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Claims.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Sockets.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Specialized.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.ObjectModel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140_1.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.EventLog.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Console.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlSerializer.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Cleanup.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Buffers.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Writer.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Concurrent.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebHeaderCollection.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Http.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Wix.CustomAction.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Calendars.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Pipes.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.ServiceProcess.ServiceController.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Numerics.Vectors.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Json.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tools.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TextWriterTraceListener.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Thread.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\winpty-debugserver.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\winpty.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TraceSource.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.PerformanceCounter.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.AppContext.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\winpty-agent.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.SecureString.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.ValueTuple.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Csp.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Memory.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.ResourceManager.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Requests.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.StackTrace.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exeJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Diagnostics.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Process.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Json.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.UnmanagedMemoryStream.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Security.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.CodeDom.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.DriveInfo.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.TypeConverter.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Text.RegularExpressions.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\netstandard.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Numerics.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Ping.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\winpty.NET.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NameResolution.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Handles.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.IsolatedStorage.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\Newtonsoft.Json.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.VisualC.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Queryable.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Timer.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XDocument.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Dynamic.Runtime.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.RuntimeInformation.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\DesktopDuplication.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.Windows.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Contracts.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\msvcp140.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.AccessControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.NonGeneric.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Expressions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64\libvpx.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Xml.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Overlapped.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlDocument.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI50A5.tmpJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Permissions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Net.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Net.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NetworkInformation.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Parallel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.XDocument.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Formatters.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Registry.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.Client.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Watcher.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.MemoryMappedFiles.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.ZipFile.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\netstandard.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.EventBasedAsync.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Algorithms.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\netstandard.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Wix.CustomAction.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Utils.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Diagnostics.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\MSI50A5.tmpJump to dropped file
        Source: C:\Windows\System32\rundll32.exeFile created: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Workspace ONE AssistJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Workspace ONE Assist\Workspace ONE Assist Installer.lnkJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\rundll32.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Windows\System32\conhost.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeMemory allocated: 229A6B40000 memory reserve | memory write watchJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeMemory allocated: 229C0650000 memory reserve | memory write watchJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE.exeJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_resources_appx_c676153d6e65f6c1.cdf-msJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE AssistJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dllJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile opened / queried: C:\Program Files\VMware\Workspace.exeJump to behavior
        Source: C:\Windows\System32\conhost.exeFile opened / queried: C:\Program Files\VMware\SystemResources\AetherPal.MSIX.Launcher.exe.munJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_native_lib_osx_db5bd0859953ed37.cdf-msJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMwareJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exeJump to behavior
        Source: C:\Windows\System32\rundll32.exeFile opened / queried: C:\Program Files\VMware\Workspace ONEJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.INIJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\CRYPTSP.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\Resources\Jump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\arm\Jump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.INIJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_native_lib_osx_x64_ccdf21e9a8dd74b3.cdf-msJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64\Jump to behavior
        Source: C:\Windows\System32\conhost.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\WinTypes.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_native_lib_linux_arm_08ddb92c89110499.cdf-msJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.configJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_775f26ce235dbcad.cdf-msJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_native_lib_linux_x64_08dd878889114c83.cdf-msJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\CRYPTBASE.dllJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dllJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_native_lib_windows_x64_ca18bb33aa32bfda.cdf-msJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\Jump to behavior
        Source: C:\Windows\System32\rundll32.exeFile opened / queried: C:\Program Files\VMware\WorkspaceJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Windows\WinSxS\FileMaps\program_files_vmware_workspace_one_assist_native_lib_windows_cbaaaa13abb66850.cdf-msJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.INIJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\Jump to behavior
        Source: C:\Windows\System32\msiexec.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64\Jump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeFile opened / queried: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.ConfigJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeThread delayed: delay time: 922337203685477Jump to behavior
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Data.Common.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.FileVersionInfo.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Debug.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.WPF.CustomControls.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.ProtectedData.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.X509Certificates.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Bcl.AsyncInterfaces.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encodings.Web.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.FileManager.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Security.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.Unsafe.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Drawing.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tracing.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.ThreadPool.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.SystemEvents.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\MSI50A5.tmp-\Microsoft.Deployment.WindowsInstaller.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Parallel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Reader.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Encoding.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.ReaderWriter.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.AccessControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Sockets.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Claims.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Specialized.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.ObjectModel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140_1.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.EventLog.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Console.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlSerializer.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Cleanup.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Buffers.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Writer.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Concurrent.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebHeaderCollection.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Wix.CustomAction.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Http.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Calendars.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Pipes.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.ServiceProcess.ServiceController.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Numerics.Vectors.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tools.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Json.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TextWriterTraceListener.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Thread.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\winpty-debugserver.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\winpty.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TraceSource.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.PerformanceCounter.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\winpty-agent.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.AppContext.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.SecureString.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.ValueTuple.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Csp.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Memory.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.ResourceManager.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Requests.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.StackTrace.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exeJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Diagnostics.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Process.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Json.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.UnmanagedMemoryStream.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.DriveInfo.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Security.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.CodeDom.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Utils.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.TypeConverter.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Text.RegularExpressions.dllJump to dropped file
        Source: C:\Windows\System32\rundll32.exeDropped PE file which has not been started: C:\Windows\Installer\MSI50A5.tmp-\netstandard.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Numerics.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Ping.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\winpty.NET.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Handles.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NameResolution.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.IsolatedStorage.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\Newtonsoft.Json.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.VisualC.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Queryable.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Timer.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Dynamic.Runtime.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XDocument.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.RuntimeInformation.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\DesktopDuplication.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.Windows.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Contracts.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\msvcp140.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.AccessControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Expressions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.NonGeneric.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64\libvpx.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Xml.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Overlapped.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\Installer\MSI50A5.tmpJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlDocument.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Extensions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Permissions.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Net.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Net.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NetworkInformation.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Parallel.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.XDocument.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Registry.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Formatters.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Watcher.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.Client.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.MemoryMappedFiles.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Primitives.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.ZipFile.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\netstandard.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.EventBasedAsync.dllJump to dropped file
        Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Algorithms.dllJump to dropped file
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe TID: 5968Thread sleep time: -922337203685477s >= -30000sJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeThread delayed: delay time: 922337203685477Jump to behavior
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe.config
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: by VMware Workspace ONE Assist.",
        Source: 58426c.rbs.1.drBinary or memory string: JC:\Program Files\VMware\Workspace ONE Assist\System.IO.IsolatedStorage.dll
        Source: 58426c.rbs.1.drBinary or memory string: FC:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.dll
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895589148.00000229A855E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: /C:/Program%20Files/VMware/Workspace%20ONE%20Assist/Resources/Appx/f7529f1a891c4c29afa0bf940c4958e4.appxbundle
        Source: 58426c.rbs.1.drBinary or memory string: LC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.FileManager.dll
        Source: 58426c.rbs.1.drBinary or memory string: GC:\Program Files\VMware\Workspace ONE Assist\System.Security.Claims.dll
        Source: rundll32.exe, 00000003.00000002.1899311731.0000013203620000.00000004.00000020.00040000.00000000.sdmpBinary or memory string: \??\C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeen-GBenen-USMyApplication.app-----------------------------------------ff7
        Source: 58426c.rbs.1.drBinary or memory string: SC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.FileVersionInfo.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{1E3B0E8F-F007-4D44-8846-17DF5AA2B6FB}MC:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Primitives.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{2AC55CAB-6F2B-44D0-8B04-A6383B0A9A08}RC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Json.dll@
        Source: 58426c.rbs.1.drBinary or memory string: ?C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>VMware Workspace ONE
        Source: 58426c.rbs.1.drBinary or memory string: EC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XDocument.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: https://www.vmware.com/help/privacy.html
        Source: MSI4559.tmp.1.drBinary or memory string: 1\yywlw-zk\yonnbfme\native\lib\windows\x64\|VMware\Workspace ONE Assist\native\lib\windows\x64\
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.ThreadPool.dll
        Source: 58426c.rbs.1.drBinary or memory string: SC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{34A18DED-7817-412F-B485-E6153875008C}?C:\Program Files\VMware\Workspace ONE Assist\vcruntime140_1.dll@
        Source: 58426c.rbs.1.drBinary or memory string: NC:\Program Files\VMware\Workspace ONE Assist\System.Collections.NonGeneric.dll
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895700607.00000229A8651000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 6C:\Program Files\VMware\Workspace ONE Assist\Resources
        Source: rundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CommandArgs: "C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe" "install" "C:\Program Files\VMware\Workspace ONE Assist\Resources"h
        Source: 58426c.rbs.1.drBinary or memory string: @C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Utils.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\MPAP_f7529f1a891c4c29afa0bf940c4958e4_001.provxml
        Source: 58426c.rbs.1.drBinary or memory string: PC:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Extensions.dll
        Source: 58426c.rbs.1.drBinary or memory string: KC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tracing.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.dll
        Source: 58426c.rbs.1.drBinary or memory string: :C:\Program Files\VMware\Workspace ONE Assist\System.IO.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Specialized.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware RemoteHelp
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "More_Information": "Hvis du vil have flere oplysninger om, hvordan VMware h
        Source: MSI4559.tmp.1.drBinary or memory string: &{4CD3D71A-F910-4E85-B04B-EF78D9B40089}AC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dll89:5
        Source: MSI4559.tmp.1.drBinary or memory string: &{D4B27B63-6D38-49CC-BB75-3339345AA8D2}CC:\Program Files\VMware\Workspace ONE Assist\System.Data.Common.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140_1.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "Notification_Title": "VMware Workspace
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>Als u informatie wilt over de data die VMware verzamelt met betrekking tot uw gebruik van deze applicatie ten behoeve van productverbetering en andere analysedoeleinden, raadpleegt u het Trust & Assurance Center en de Privacyverklaringen van VMware.</p>
        Source: 58426c.rbs.1.drBinary or memory string: PC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Parallel.dll
        Source: 58426c.rbs.1.drBinary or memory string: LC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.EventLog.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{033C5492-A6F7-4538-AAB0-0899422BFF02}EC:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.dll@
        Source: 58426c.rbs.1.drBinary or memory string: TC:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.TypeConverter.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{221C9E4D-D9C6-42FA-A0B3-492DAFB5B6DC}@C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Utils.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895241803.00000229A6BC0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Resources
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Console.dll
        Source: 58426c.rbs.1.drBinary or memory string: JC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Extensions.dll
        Source: 58426c.rbs.1.drBinary or memory string: JC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exe
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlSerializer.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "Notification_Title": "VMware Workspace ONE Assist",
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "AGREEMENT": "By selecting & accepting you agree to the VMware Workspace ONE Assist Terms and Conditions for use of this service.",
        Source: MSI4559.tmp.1.drBinary or memory string: &{72A63BF1-2FB3-424B-8CD0-805055F8FA8D}=C:\Program Files\VMware\Workspace ONE Assist\winpty-agent.exe@
        Source: 58426c.rbs.1.drBinary or memory string: FC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Net.dll
        Source: 58426c.rbs.1.drBinary or memory string: ?C:\Program Files\VMware\Workspace ONE Assist\System.Buffers.dll
        Source: 58426c.rbs.1.drBinary or memory string: NC:\Program Files\VMware\Workspace ONE Assist\System.Net.NetworkInformation.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "VMware RemoteHelp sera d
        Source: MSI4559.tmp.1.drBinary or memory string: &{0ADDF2C7-AF58-4687-BD1A-2E505B7BACD9}SC:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.AccessControl.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{63E0EF7F-86A0-4C26-A3D9-EEB9609ED583}[C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TextWriterTraceListener.dll@
        Source: 58426c.rbs.1.drBinary or memory string: SC:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.AccessControl.dll
        Source: 58426c.rbs.1.drBinary or memory string: NC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware Workspace One Assist
        Source: MSI4559.tmp.1.drBinary or memory string: &{E372DF43-9457-4438-AE64-66F0EA22CDE1}GC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.dll@
        Source: 58426c.rbs.1.drBinary or memory string: MC:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Extensions.dll
        Source: 58426c.rbs.1.drBinary or memory string: ?C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{CAE3A7DC-A984-4EB6-8385-05A7F092C6BF}BC:\Program Files\VMware\Workspace ONE Assist\System.Reflection.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{F67B13BD-0210-4B54-A143-CD022B0D3B5C}LC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Overlapped.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{A3073F8C-A5A1-4C2F-B5C1-E6C4F0D36D6B}?C:\Program Files\VMware\Workspace ONE Assist\System.Buffers.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exe
        Source: 58426c.rbs.1.drBinary or memory string: ;C:\Program Files\VMware\Workspace ONE Assist\winpty.NET.dll
        Source: 58426c.rbs.1.drBinary or memory string: IC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tools.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{F514C4CC-87F5-4F69-91DF-99D15C9D8C08}422:\Software\VMware\Workspace ONE Assist\InstallPath@
        Source: MSI4559.tmp.1.drBinary or memory string: &{2DA392E0-6825-4CFA-B7B0-678EE12BFCEC}OC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TraceSource.dll@
        Source: 58426c.rbs.1.drBinary or memory string: ?C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dll
        Source: MSI4559.tmp.1.drBinary or memory string: 1\yywlw-zk\yonnbfme\native\lib\osx\|VMware\Workspace ONE Assist\native\lib\osx\
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69F7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dllW
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tools.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Numerics.Vectors.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Json.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{9F291204-7927-4D65-ACFD-E3367C3EF7ED}RC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Extensions.dll@
        Source: 58426c.rbs.1.drBinary or memory string: RC:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.Windows.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{3ED7DC1C-DB02-4314-B7AB-6F9F1A699A4E}FC:\Program Files\VMware\Workspace ONE Assist\System.Linq.Queryable.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000000.1825439607.00000229A6816000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: 2023 VMware, Inc*
        Source: 58426c.rbs.1.drBinary or memory string: IC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlSerializer.dll
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A6986000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist;C:\Windows\SYSTEM32;C:\Windows\system;C:\Windows;.;C:\Program Files (x86)\Common Files\Oracle\Java\javapath;C:\Windows\system32;C:\Windows;C:\Windows\System32\Wbem;C:\Windows\System32\WindowsPowerShell\v1.0\;C:\Windows\System32\OpenSSH\;C:\Users\user\AppData\Local\Microsoft\WindowsAppsewVersion="4.0ZAw[
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000000.1825414817.00000229A6812000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: 2023 VMware, Inc)
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "VMware RemoteHelp
        Source: MSI4559.tmp.1.drBinary or memory string: &{C4BCAD05-7F50-4A57-A42D-DF8A555335B5}GC:\Program Files\VMware\Workspace ONE Assist\System.Security.Claims.dll@
        Source: 58426c.rbs.1.drBinary or memory string: NC:\Program Files\VMware\Workspace ONE Assist\System.Security.AccessControl.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\winpty.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware Workspace ONE
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>O VMware Workspace ONE coleta informa
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\
        Source: MSI4559.tmp.1.drBinary or memory string: &{44BA2026-E1DF-4422-8683-8CD368BE16E3}SC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{55B89289-E76B-4F50-A62B-D22572F92A7E}AC:\Program Files\VMware\Workspace ONE Assist\System.Threading.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000000.1825414817.00000229A6812000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: VMware Workspace ONE
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.PerformanceCounter.dll
        Source: 58426c.rbs.1.drBinary or memory string: GC:\Program Files\VMware\Workspace ONE Assist\System.Dynamic.Runtime.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Primitives.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: ci VMware.</p>
        Source: 58426c.rbs.1.drBinary or memory string: GC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlDocument.dll
        Source: AetherPal.Windows.Net.dll.1.drBinary or memory string: VMware, Inc.1!0
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\winpty-agent.exe
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>VMware Workspace ONE collects information to provide secure access to your work data and applications. Below you will find an overview of data collected by Workspace ONE and Workspace ONE Assist to provide optimal performance, security and support. For additional information about how your company handles information collected by Workspace ONE, please contact your company.</p>
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.SecureString.dll
        Source: 58426c.rbs.1.drBinary or memory string: FC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.ValueTuple.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.StackTrace.dll
        Source: 58426c.rbs.1.drBinary or memory string: SC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\AUMIDs.txt
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe
        Source: 58426c.rbs.1.drBinary or memory string: XC:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Primitives.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.UnmanagedMemoryStream.dll
        Source: 58426c.rbs.1.drBinary or memory string: ?C:\Program Files\VMware\Workspace ONE Assist\System.CodeDom.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{2FE75A2B-D7BD-4AD2-A0BB-504EB3B759D1}LC:\Program Files\VMware\Workspace ONE Assist\System.IO.MemoryMappedFiles.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{84CDBA99-7BB3-40F3-9F79-BB3084A0624D}GC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Handles.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{92F5E01C-1DA2-48A1-A001-0CEF18E77B06}AC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.TypeConverter.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "Aplikace VMware RemoteHelp bude ze za
        Source: 58426c.rbs.1.drBinary or memory string: QC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exe.config
        Source: 58426b.msi.1.drBinary or memory string: sions.dllcuvmuvfw.dll|System.Text.Encodings.Web.dlloez23nki.dll|System.Text.Json.dlliuck9kln.dll|System.Text.RegularExpressions.dllmdzqixth.dll|System.Threading.dll7uheylij.dll|System.Threading.Overlapped.dllu82mtczq.dll|System.Threading.Tasks.dllsfiz1h0t.dll|System.Threading.Tasks.Extensions.dllxtatt9vt.dll|System.Threading.Tasks.Parallel.dllcpxzgohf.dll|System.Threading.Thread.dllndwlyvjz.dll|System.Threading.ThreadPool.dlla-mv3yrs.dll|System.Threading.Timer.dlljvlrjw9o.dll|System.ValueTuple.dlli4vnoba1.dll|System.Xml.ReaderWriter.dllylyisovf.dll|System.Xml.XDocument.dlloj5g4tua.dll|System.Xml.XmlDocument.dllpklomszb.dll|System.Xml.XmlSerializer.dll2zf1pjlu.dll|System.Xml.XPath.dll2xnicbfq.dll|System.Xml.XPath.XDocument.dllnmisxp2c.dll|vcruntime140.dllodlrilgl.dll|vcruntime140_1.dll14.28.29910.0ei3-tmec.exe|winpty-agent.exeo-ystvpl.exe|winpty-debugserver.exewinpty.dll2hjiihlg.dll|winpty.NET.dll1.0.0.0za-gzgjo.exe|WorkspaceONE.Assist.Agent.exexjmjrbms.con|WorkspaceONE.Assist.Agent.exe.config519gonry.exe|WorkspaceONE.Assist.Client.exejc5bewr0.con|WorkspaceONE.Assist.Client.exe.confignoum54jd.so|lib_remote_shell_api.sowgh9fzbs.so|lib_remote_shell_api.sodame5bap|RemoteLib4mr_fkar.dyl|libvpx.dylibdob0uwwb.dyl|lib_remote_shell_api.dylib5b6v58j6.dll|DesktopDuplication.dlllibvpx.dllAUMIDs.txttz6_wjtg.app|f7529f1a891c4c29afa0bf940c4958e4.appxbundleyygxdbrq.xml|f7529f1a891c4c29afa0bf940c4958e4_License1.xml907amhwg.pro|MPAP_f7529f1a891c4c29afa0bf940c4958e4_001.provxmlicon.icoFindRelatedProductsLaunchConditionsValidateProductIDMigrateFeatureStatesProcessComponentsUnpublishFeaturesStopServicesVersionNTDeleteServicesRemoveRegistryValuesRemoveShortcutsRemoveFilesWriteRegistryValuesInstallServicesStartServicesRegisterUserRegisterProductREMOVE="ALL"RemoveExistingProducts(NOT UPGRADINGPRODUCTCODE) AND (REMOVE="ALL")NOT Installed AND NOT REMOVEAppSearchInstalled AND (RESUME OR Preselected)Installed AND NOT RESUME AND NOT Preselected AND NOT PATCHNOT WIX_DOWNGRADE_DETECTEDA newer version of Workspace ONE Assist is already installed.#cab1.cabARPPRODUCTICONManufacturerVMware, Inc.ProductCode{2687F608-EC00-4F9A-B6B3-0194BAD168BB}ProductLanguageProductNameProductVersion{A064C3A5-9E72-4451-8E85-9883BF43FF84}DefaultUIFontWixUI_Font_NormalWixUI_ModeMinimalErrorDialogUseRMSecureCustomPropertiesWIX_DOWNGRADE_DETECTED;WIX_UPGRADE_DETECTED&Close the applications and attempt to restart them.DontUseRM&Do not close applications. A reboot will be required.Software\VMware\Workspace ONE Assist#1regA6E6BE990A776B3E82A5B55E4E283FA0*InstallPath[INSTALLFOLDER]reg5C682BB8EA335F681D8990C2F5FE9880RemoveStartMenuWorkspace ONE AssistWorkspace_ONE_AssistLocalSystemVMware Workspace ONE
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Numerics.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "VMware RemoteHelp se desinstalar
        Source: MSI4559.tmp.1.drBinary or memory string: &{39346C97-A123-4412-BA35-85409FDE31AF}@C:\Program Files\VMware\Workspace ONE Assist\System.Net.Ping.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Handles.dll
        Source: 58426c.rbs.1.drBinary or memory string: $Software\VMware\Workspace ONE Assist
        Source: MSI4559.tmp.1.drBinary or memory string: &{3CF85474-93F9-43E2-8E5F-DB1190DAE600}121:\Software\VMware\Workspace ONE Assist\Shortcut@
        Source: 58426c.rbs.1.drBinary or memory string: HC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Numerics.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{873F97C7-07B8-4AD2-8777-4855EB1D9882}VC:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\DesktopDuplication.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Linq.Queryable.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{6577A73F-CBDD-4BAE-A741-4105F6A4592E}CC:\Program Files\VMware\Workspace ONE Assist\System.ObjectModel.dll@
        Source: rundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: B"install" "C:\Program Files\VMware\Workspace ONE Assist\Resources"
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895700607.00000229A8651000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: nfile://C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4.appxbundle
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A6986000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exes(x86)%\WindowsPowerShell\Modules;C:\Windows\system32\WindowsPowerShell\v1.0\Modules;C:\Program Files (x86)\AutoIt3\AutoItXPUBLIC=C:\Users\PublicSESSIONNAME=ConsoleSystemDrive=C:Syste
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Primitives.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: r information om de data VMware samlat in i samband med din anv
        Source: MSI4559.tmp.1.drBinary or memory string: &{D2C64D59-9E49-4D77-A0B9-BCC1566010B0}VC:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.EventBasedAsync.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\DesktopDuplication.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>VMware'in bu uygulamay
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "O VMware RemoteHelp ser
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\RemoteLib
        Source: MSI4559.tmp.1.drBinary or memory string: _1\yywlw-zk\yonnbfme\native\lib\windows\x64\|VMware\Workspace ONE Assist\native\lib\windows\x64\
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: es que VMware collecte concernant votre utilisation de cette application pour l'am
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Xml.dll
        Source: 58426c.rbs.1.drBinary or memory string: OC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{79FB1384-359D-47C4-80E7-03EF4D82B29B}?C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{E59A1BA0-4B1B-449F-82B5-E76F2FF96B93}HC:\Program Files\VMware\Workspace ONE Assist\System.Resources.Writer.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895589148.00000229A8549000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: file:///C:/Program%20Files/VMware/Workspace%20ONE%20Assist/Resources/Appx/f7529f1a891c4c29afa0bf940c4958e4.appxbundle
        Source: MSI4559.tmp.1.drBinary or memory string: &{39F56BB8-8805-4DCC-B293-00F4E9708B79}IC:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Registry.dll@
        Source: 58426c.rbs.1.drBinary or memory string: EC:\Program Files\VMware\Workspace ONE Assist\System.Globalization.dll
        Source: 58426c.rbs.1.drBinary or memory string: DC:\Program Files\VMware\Workspace ONE Assist\System.Net.Requests.dll
        Source: 58426c.rbs.1.drBinary or memory string: CC:\Program Files\VMware\Workspace ONE Assist\winpty-debugserver.exe
        Source: AetherPal.Configuration.dll.1.drBinary or memory string: assist.rnu:WorkspaceONE.Assist.Agent.exe4WorkspaceONE.Assist.Client8AetherPal.IPC.Windows.ServerZWorkspaceONE.Assist.IPC.Windows.Agent.Horizon6WorkspaceONE.Assist.Service6VMware Workspace ONE AssistXAirWatchLLC.WorkspaceONEAssist_htcwkw4rx2gx42TaskSchedulerIpcProcessor
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Permissions.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{993CF769-41B3-4CC8-84FB-F6B4EFBCA817}@C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\vcruntime140.dll
        Source: AetherPal.Device.Tools.dll.1.drBinary or memory string: 2020 VMware, Inc)
        Source: 58426c.rbs.1.drBinary or memory string: HC:\Program Files\VMware\Workspace ONE Assist\System.Resources.Writer.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: ce danych zbieranych przez VMware w zwi
        Source: 58426c.rbs.1.drBinary or memory string: LC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{9C0744DA-83AD-4BFF-8402-A1224F8A2F74}XC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.VisualC.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A6980000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: am Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exemonProgramFilesm PlE
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: nost VMware nakl
        Source: AetherPal.Device.Tools.dll.1.drBinary or memory string: 2020 VMware, Inc*
        Source: MSI4559.tmp.1.drBinary or memory string: &{D230B050-572E-4ED9-80BC-A5460BD73B23}NC:\Program Files\VMware\Workspace ONE Assist\System.Collections.Concurrent.dll@
        Source: 58426c.rbs.1.drBinary or memory string: QC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dll
        Source: 58426c.rbs.1.drBinary or memory string: BC:\Program Files\VMware\Workspace ONE Assist\System.ValueTuple.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>VMware Workspace ONE verzamelt informatie om veilige toegang te bieden tot uw zakelijke gegevens en applicaties. Hieronder vindt u een overzicht van gegevens die door Workspace ONE en Workspace ONE Assist worden verzameld om optimale prestaties, beveiliging en ondersteuning te bieden. Neem contact op met uw bedrijf voor meer informatie over de manier waarop uw bedrijf omgaat met informatie die wordt verzameld door Workspace ONE.</p>
        Source: MSI4559.tmp.1.drBinary or memory string: &{5A175A20-EFDC-4367-9B47-452C46D30413}JC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exe@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware Workspace ONE Assist
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Watcher.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: rales de VMware Workspace ONE Assist pour l'utilisation du service Workspace ONE Assist.",
        Source: 58426c.rbs.1.drBinary or memory string: EC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{10BAE074-4F96-4FAC-8ECF-64D2CA7186C5}?C:\Program Files\VMware\Workspace ONE Assist\System.Console.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: 1\yywlw-zk\yonnbfme\native\lib\linux\x64\|VMware\Workspace ONE Assist\native\lib\linux\x64\
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: HOST_CONFIGam Files\VMware
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>For information om data, som VMware indsamler i forbindelse med din anvendelse af denne app til forbedring af produkter, og andre analyser, se Tillids- og Forsikringscenter og VMwares erkl
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{B9994CDC-DF10-40F3-8A8D-EBC972BD61FF}XC:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Primitives.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\
        Source: rundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: o\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe;C:\Program Files\VMware\Workspace ONE Assist\Resources
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69F7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dllnmdL
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.ZipFile.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{54322F77-EB51-44DE-80CA-50D0A347DCCC}FC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dll@
        Source: 58426c.rbs.1.drBinary or memory string: MC:\Program Files\VMware\Workspace ONE Assist\AetherPal.WPF.CustomControls.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: vence Merkezi (Trust & Assurance Center) ve VMware Gizlilik Bildirimlerine bak
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Data.Common.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.FileVersionInfo.dll
        Source: AetherPal.Windows.Net.dll.1.drBinary or memory string: CompanyNameVMware, Inc.`
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dll 5
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dll
        Source: AetherPal.WPF.CustomControls.dll.1.drBinary or memory string: CompanyNameVMware, Inc.b
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Debug.dll
        Source: AetherPal.Tools.RemoteControl.dll.1.drBinary or memory string: CompanyNameVMware, Inc.d
        Source: MSI4559.tmp.1.drBinary or memory string: &{BB6F2335-B7B8-4767-828A-6BF9939D262D};C:\Program Files\VMware\Workspace ONE Assist\winpty.NET.dll@
        Source: 58426c.rbs.1.drBinary or memory string: TC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.ProtectedData.dll
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895700607.00000229A8651000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: CC:\Program Files\VMware\Workspace ONE Assist\Resources\*.appxbundle
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: in VMware Workspace ONE Assist H
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Primitives.dll
        Source: 58426c.rbs.1.drBinary or memory string: LC:\Program Files\VMware\Workspace ONE Assist\System.IO.MemoryMappedFiles.dll
        Source: 58426c.rbs.1.drBinary or memory string: MC:\Program Files\VMware\Workspace ONE Assist\System.Security.SecureString.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{E3639EF2-BEC9-4A1A-96EB-8FC02EEEA670}HC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Numerics.dll@
        Source: 58426c.rbs.1.drBinary or memory string: EC:\Program Files\VMware\Workspace ONE Assist\System.Linq.Parallel.dll
        Source: MSI4559.tmp.1.drBinary or memory string: Workspace ONE AssistN"C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe"@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Security.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{3C5C5395-6745-4A3F-B16A-0387390D8CEE}NC:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.ZipFile.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{9B243A49-C185-44C8-B9BE-3597EB37212E}QC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Xml.dll@
        Source: 58426c.rbs.1.drBinary or memory string: ^C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.X509Certificates.dll
        Source: 58426c.rbs.1.drBinary or memory string: VC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.PerformanceCounter.dll
        Source: MSI4559.tmp.1.drBinary or memory string: 1\yywlw-zk\yonnbfme\native\lib\windows\|VMware\Workspace ONE Assist\native\lib\windows\
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: https://www.vmware.com/help/privacy.html",
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.SystemEvents.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{BA08A3E8-D178-4AB1-8DE1-ED1260F3444E}JC:\Program Files\VMware\Workspace ONE Assist\System.Drawing.Primitives.dll@
        Source: 58426c.rbs.1.drBinary or memory string: XC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Primitives.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{527AF702-D1F0-4147-9BD3-BF6DD2698A6B}EC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "VMware RemoteHelp
        Source: MSI4559.tmp.1.drBinary or memory string: N1\yywlw-zk\yonnbfme\affs8zkc\Appx\|VMware\Workspace ONE Assist\Resources\Appx\
        Source: MSI4559.tmp.1.drBinary or memory string: &{89C194CC-843F-45A1-890E-0E5C9E65FCBC}LC:\Program Files\VMware\Workspace ONE Assist\System.Security.Permissions.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: 22:\Software\VMware\Workspace ONE Assist\InstallPath
        Source: MSI4559.tmp.1.drBinary or memory string: &{6DFDF632-47DC-46DB-86A2-23AA6C0B4656}GC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Timer.dll@
        Source: 58426c.rbs.1.drBinary or memory string: LC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: rminos y condiciones de VMware Workspace ONE Assist para el uso de este servicio.",
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895589148.00000229A855E000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: file://C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4.appxbundle
        Source: MSI4559.tmp.1.drBinary or memory string: &{D9A39F54-BEC0-4328-8B97-50A875AB6300}OC:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Calendars.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{7802E43B-DD0C-43CD-8850-282E676B0BA1}?C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{D7FE1F6C-B8D3-4B5D-9D32-369CD9F4AEE1}IC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Debug.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: 1\yywlw-zk\yonnbfme\native\lib\linux\arm\|VMware\Workspace ONE Assist\native\lib\linux\arm\
        Source: MSI4559.tmp.1.drBinary or memory string: &{EBD61508-73D3-4680-83D9-83A81EAE4A83}AC:\Program Files\VMware\Workspace ONE Assist\System.Text.Json.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Claims.dll
        Source: 58426c.rbs.1.drBinary or memory string: QC:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Csp.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.ObjectModel.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{B44767D6-3C98-436C-AE53-A21F0A71321B}FC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Net.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: 1\yywlw-zk\yonnbfme\native\lib\osx\x64\|VMware\Workspace ONE Assist\native\lib\osx\x64\
        Source: MSI4559.tmp.1.drBinary or memory string: &{89DABC0D-A860-493F-B5F9-931FE8E9DD1E}IC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlSerializer.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64\
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.EventLog.dll
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69F7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: file:///C:/Program Files/VMware/Workspace ONE Assist/System.Runtime.DLL
        Source: MSI4559.tmp.1.drBinary or memory string: &{A7521E54-36E4-4FEC-97E6-CA34CEFFC924}NC:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\x64\libvpx.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{667964BE-37E8-4FB4-B2C9-00F361E4EF22}QC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Agent.exe.config@
        Source: MSI4559.tmp.1.drBinary or memory string: &{6ACAB878-9C05-4103-BC23-B3E288C5FC4D}MC:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Watcher.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{8CBD4132-8BA6-41A8-93BE-17250CCEFCD8}OC:\Program Files\VMware\Workspace ONE Assist\System.Collections.Specialized.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{2CB3C663-14DD-4033-9C74-44BD9F6E3E4D}TC:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.TypeConverter.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: e sicurezza) e l'informativa sulla privacy di VMware.</p>
        Source: 58426c.rbs.1.drBinary or memory string: EC:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Writer.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{7F4F4678-09C9-4BDD-AB84-BAA792BC841D}>C:\Program Files\VMware\Workspace ONE Assist\System.Memory.dll@
        Source: 58426c.rbs.1.drBinary or memory string: OC:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Calendars.dll
        Source: 58426c.rbs.1.drBinary or memory string: NC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.StackTrace.dll
        Source: AetherPal.Windows.Net.dll.1.drBinary or memory string: VMWARE1
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895700607.00000229A8651000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OC:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.Config`_/
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.Concurrent.dll
        Source: 58426c.rbs.1.drBinary or memory string: >C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Net.dll
        Source: 58426c.rbs.1.drBinary or memory string: BC:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64\
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware Workspace ONE Assist for Windows 24.03 GA
        Source: 58426c.rbs.1.drBinary or memory string: PC:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Primitives.dll
        Source: 58426c.rbs.1.drBinary or memory string: 9C:\Program Files\VMware\Workspace ONE Assist\msvcp140.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{6AC94244-5577-4899-B415-F7FDAEC40E77}NC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{B9FB9DA0-9668-45E3-BC37-D4A6E9FBCC5F}JC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Extensions.dll@
        Source: 58426c.rbs.1.drBinary or memory string: YC:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64\lib_remote_shell_api.so
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: nosti VMware.</p>
        Source: 58426c.rbs.1.drBinary or memory string: OC:\Program Files\VMware\Workspace ONE Assist\System.Net.WebHeaderCollection.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.Pipes.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{A7578C1D-3CA9-45CC-8B2E-E98C2E4504D2}DC:\Program Files\VMware\Workspace ONE Assist\System.Net.Requests.dll@
        Source: 58426c.rbs.1.drBinary or memory string: HC:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe
        Source: 58426c.rbs.1.drBinary or memory string: AC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{29E2C520-2ADF-46FB-8105-202DF3008530}CC:\Program Files\VMware\Workspace ONE Assist\System.Net.Sockets.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: til https://www.vmware.com/help/privacy.html",
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: s de este producto, vaya a https://www.vmware.com/es/help/privacy.html",
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.Extensions.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Thread.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{D0DAC1FE-822D-40EA-8498-4D6870CF6F23}GC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XmlDocument.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: 11\yywlw-zk\yonnbfme\|VMware\Workspace ONE Assist\
        Source: rundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: YExecutable Path: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeh
        Source: 58426c.rbs.1.drBinary or memory string: FC:\Program Files\VMware\Workspace ONE Assist\System.Linq.Queryable.dll
        Source: 58426c.rbs.1.drBinary or memory string: KC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe
        Source: MSI4559.tmp.1.drBinary or memory string: &{9E2B0E2B-BEB7-4D7E-928E-D92679C92A9F}SC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dll@
        Source: 58426c.rbs.1.drBinary or memory string: XC:\Program Files\VMware\Workspace ONE Assist\System.ServiceProcess.ServiceController.dll
        Source: 58426b.msi.1.drBinary or memory string: VMware Workspace ONE
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware RemoteHelp
        Source: MSI4559.tmp.1.drBinary or memory string: InstallPath-C:\Program Files\VMware\Workspace ONE Assist\'
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: ber dieses Produkt erfasst werden, finden Sie unter https://www.vmware.com/help/privacy.html",
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "More_Information": "VMware
        Source: MSI4559.tmp.1.drBinary or memory string: &{D525D2C9-9225-4D23-9C13-AFB8E70FA62B}PC:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.Extensions.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "VMware RemoteHelp vil blive afinstalleret fra din enhed.
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "AGREEMENT": "Selezionando e accettando, concordi con i Termini e condizioni di VMware Workspace ONE Assist per l'utilizzo di questo servizio.",
        Source: MSI4559.tmp.1.drBinary or memory string: &{D89B3171-3972-47E7-BEBB-5645DA91477E}WC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.Unsafe.dll@
        Source: 58426c.rbs.1.drBinary or memory string: =C:\Program Files\VMware\Workspace ONE Assist\winpty-agent.exe
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895700607.00000229A8651000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: 8C:\Program Files\VMware\Workspace ONE Assist\Resources\*
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\lib_remote_shell_api.dylib
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Process.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{8A4680ED-66EC-4F54-A066-5EA60E4A88F0}[C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.ProtectedData.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\'
        Source: MSI4559.tmp.1.drBinary or memory string: &{FB6FE1FD-AEF2-4D70-934C-A67C81B0C308}VC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.PerformanceCounter.dll@
        Source: 58426c.rbs.1.drBinary or memory string: GC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Handles.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Text.RegularExpressions.dll
        Source: 58426c.rbs.1.drBinary or memory string: IC:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Registry.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Ping.dll
        Source: MSI4559.tmp.1.drBinary or memory string: "C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe"
        Source: 58426c.rbs.1.drBinary or memory string: MC:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.Client.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: a e os Avisos de privacidade da VMware.</p>
        Source: MSI4559.tmp.1.drBinary or memory string: &{87687F34-E174-4C18-85D7-661B48409DB7}NC:\Program Files\VMware\Workspace ONE Assist\System.Security.AccessControl.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: nner du VMware Workspace ONE Assist-villkoren f
        Source: MSI4559.tmp.1.drBinary or memory string: &{53B6B7E5-8A1E-4D00-9B44-44B41222E013}PC:\Program Files\VMware\Workspace ONE Assist\System.IO.UnmanagedMemoryStream.dll@
        Source: 58426c.rbs.1.drBinary or memory string: GC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: https://www.vmware.com/help/privacy.html
        Source: 58426c.rbs.1.drBinary or memory string: KC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Process.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.VisualC.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{93F3F64A-06F3-4F24-8237-8D54BC2E4B5B}XC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Formatters.dll@
        Source: rundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: FMSIX Directory: C:\Program Files\VMware\Workspace ONE Assist\Resourcesh
        Source: 58426c.rbs.1.drBinary or memory string: @C:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\
        Source: MSI4559.tmp.1.drBinary or memory string: &{69BEDAE8-8356-422B-814E-F2F79E0CF449}EC:\Program Files\VMware\Workspace ONE Assist\System.Linq.Parallel.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "VMware RemoteHelp will be uninstalled from your device. Would you like to continue?",
        Source: 58426c.rbs.1.drBinary or memory string: iC:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4_License1.xml
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Primitives.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.RuntimeInformation.dll
        Source: 58426c.rbs.1.drBinary or memory string: @C:\Program Files\VMware\Workspace ONE Assist\System.Net.Ping.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{4549005F-52CF-4DF2-80AF-AD48335FB45E}mC:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\MPAP_f7529f1a891c4c29afa0bf940c4958e4_001.provxml@
        Source: MSI4559.tmp.1.drBinary or memory string: &{A584A06B-6994-4F27-8184-E8CAD5761495}OC:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.config@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>Informationen dazu, welche Daten VMware zur Produktverbesserung und zu sonstigen Analysezwecken im Zusammenhang mit der Nutzung dieser Anwendung durch Sie erfasst, finden Sie im Bereich
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.AccessControl.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{3F3BA5C1-33D3-41BD-9E94-BD9BA4909227}^C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.X509Certificates.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{82EBBC43-EFE1-4E89-89A1-19218DB8A1EB}FC:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{D7A8AF10-597B-4022-B86B-5BE664053E96}GC:\Program Files\VMware\Workspace ONE Assist\System.Dynamic.Runtime.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Collections.NonGeneric.dll
        Source: 58426c.rbs.1.drBinary or memory string: RC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.Serialization.Json.dll
        Source: 58426c.rbs.1.drBinary or memory string: AC:\Program Files\VMware\Workspace ONE Assist\System.Text.Json.dll
        Source: 58426c.rbs.1.drBinary or memory string: AC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dll
        Source: 58426c.rbs.1.drBinary or memory string: QC:\Program Files\VMware\Workspace ONE Assist\System.Resources.ResourceManager.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\
        Source: MSI4559.tmp.1.drBinary or memory string: &{EF5530BB-8253-4B56-8EC7-E336A255A0F1}NC:\Program Files\VMware\Workspace ONE Assist\Microsoft.Bcl.AsyncInterfaces.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{74973CCB-8E29-4236-AF44-ABC19C9D858B}PC:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Extensions.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: tfen https://www.vmware.com/help/privacy.html adresini ziyaret edin",
        Source: rundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: MArguments: "install" "C:\Program Files\VMware\Workspace ONE Assist\Resources"h
        Source: MSI4559.tmp.1.drBinary or memory string: &{E010BFD9-3010-4968-A829-D3A3BC25CE49}-C:\Program Files\VMware\Workspace ONE Assist\@
        Source: 58426c.rbs.1.drBinary or memory string: VC:\Program Files\VMware\Workspace ONE Assist\native\lib\windows\DesktopDuplication.dll
        Source: rundll32.exe, 00000003.00000003.1897761412.000001320359D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\C:\Program Files\VMware\Workspace ONE.exev&
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Extensions.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{731D273E-43A4-4094-ABCC-3672B3D54B9F}UC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dll@
        Source: 58426c.rbs.1.drBinary or memory string: JC:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "AGREEMENT": "Door accepteren gaat u akkoord met de Algemene Voorwaarden van VMware Workspace ONE Assist voor het gebruik van deze service.",
        Source: AetherPal.Net.dll.1.drBinary or memory string: CompanyNameVMware, Inc.D
        Source: 58426c.rbs.1.drBinary or memory string: IC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Debug.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Net.NetworkInformation.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "More_Information": "Ga naar https://www.vmware.com/help/privacy.html voor meer informatie over de manier waarop VMware omgaat met gegevens die via dit product worden verzameld",
        Source: 58426c.rbs.1.drBinary or memory string: VC:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Encoding.dll
        Source: AetherPal.Core.dll.1.drBinary or memory string: CompanyNameVMware, Inc.F
        Source: MSI4559.tmp.1.drBinary or memory string: &{D96D495D-AC57-4EFB-93CE-A51F71E5ADB1}bC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.InteropServices.RuntimeInformation.dll@
        Source: AetherPal.Utils.dll.3.drBinary or memory string: CompanyNameVMware, Inc.H
        Source: MSI4559.tmp.1.drBinary or memory string: &{2B4FC688-D207-4B5D-8CCA-31EA0C91CC9B}FC:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.dll@
        Source: AetherPal.Device.Tools.dll.1.drBinary or memory string: CompanyNameVMware, Inc.J
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Registry.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{FD510A1F-8129-4932-8F4C-07D9D8A07891}XC:\Program Files\VMware\Workspace ONE Assist\System.ServiceProcess.ServiceController.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\x64\lib_remote_shell_api.so
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "More_Information": "Per ulteriori informazioni circa il modo in cui VMware gestisce i dati raccolti attraverso questo prodotto, visitare il sito web https://www.vmware.com/help/privacy.html",
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.MemoryMappedFiles.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: n acerca de los datos que recopila VMware en conexi
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Primitives.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{A37D5EAD-817D-45B1-A661-B0ACFDEBAF3A}OC:\Program Files\VMware\Workspace ONE Assist\System.Net.WebHeaderCollection.dll@
        Source: AetherPal.Diagnostics.dll.1.drBinary or memory string: CompanyNameVMware, Inc.T
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.config
        Source: AetherPal.Device.Tools.RemoteControl.dll.1.drBinary or memory string: CompanyNameVMware, Inc.V
        Source: AetherPal.Configuration.dll.1.drBinary or memory string: CompanyNameVMware, Inc.X
        Source: MSI4559.tmp.1.drBinary or memory string: &{23AC0DC2-AE1F-4671-BF36-6E8ADBDB49A4}ZC:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\lib_remote_shell_api.dylib@
        Source: 58426c.rbs.1.drBinary or memory string: MC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Contracts.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: de VMware.</p>
        Source: WorkspaceONE.Assist.Agent.exe.1.drBinary or memory string: CompanyNameVMware, Inc.\
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: CompanyNameVMware, Inc.^
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.EventBasedAsync.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Algorithms.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{63792587-EDA1-4625-9AA9-A2151A4CD0D9}SC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{24059BEB-AD58-4255-934B-6C8062C751AA}iC:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4_License1.xml@
        Source: rundll32.exe, 00000003.00000003.1897761412.00000132035EF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\C:\Program Files\VMware\Workspace ONE)O=
        Source: MSI4559.tmp.1.drBinary or memory string: &{5BE65C20-67BB-4200-9063-0D385444C1E7}PC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Parallel.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: https://www.vmware.com/tw/help/privacy.html",
        Source: MSI4559.tmp.1.drBinary or memory string: &{5A684C8E-FF06-4557-AC79-AEDE8935A8F7}MC:\Program Files\VMware\Workspace ONE Assist\System.Net.WebSockets.Client.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69F7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: am Files\VMware\Workspace ONE Assist\Resources
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.dll
        Source: AetherPal.Device.Tools.dll.1.drBinary or memory string: ProductNameVMware Workspace ONE
        Source: 58426c.rbs.1.drBinary or memory string: JC:\Program Files\VMware\Workspace ONE Assist\System.Net.NameResolution.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Microsoft.Bcl.AsyncInterfaces.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{D93EB7EF-2CF6-412E-995D-DFAE3046FA42}HC:\Program Files\VMware\Workspace ONE Assist\System.Resources.Reader.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: -VMware
        Source: 58426c.rbs.1.drBinary or memory string: HC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{CB20CDE9-1B5F-4A59-B043-6A42A96B7273}EC:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\RemoteLib@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.Unsafe.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{BAE15359-1C15-4C7B-BB9F-53C722DAAFC8}HC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Drawing.Primitives.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{20EB5E0E-047A-47F7-9023-427A11E7D509}LC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tracing.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\libvpx.dylib
        Source: 58426c.rbs.1.drBinary or memory string: LC:\Program Files\VMware\Workspace ONE Assist\System.Security.Permissions.dll
        Source: AetherPal.Windows.Net.dll.1.drBinary or memory string: noreply@vmware.com0
        Source: MSI4559.tmp.1.drBinary or memory string: &{F3876345-4471-4A51-8C37-10D3ED62BC09}QC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dll@
        Source: 58426c.rbs.1.drBinary or memory string: RC:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe.config
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware
        Source: MSI4559.tmp.1.drBinary or memory string: &{49DE6BC5-5BB8-427B-AAF0-E39C4451D579}PC:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Primitives.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe
        Source: MSI4559.tmp.1.drBinary or memory string: &{950D71B1-73E3-48AF-8703-8552FF842B53}IC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tools.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.Parallel.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Resources.Reader.dll
        Source: 58426c.rbs.1.drBinary or memory string: OC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.TraceSource.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Xml.ReaderWriter.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Sockets.dll
        Source: 58426c.rbs.1.drBinary or memory string: XC:\Program Files\VMware\Workspace ONE Assist\System.Runtime.CompilerServices.VisualC.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{DA38D1D8-4413-4038-8369-E2E53EA2380D}JC:\Program Files\VMware\Workspace ONE Assist\System.IO.IsolatedStorage.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeB5%
        Source: MSI4559.tmp.1.drBinary or memory string: &{35FC3C5F-44C2-417A-B42D-7D9A5AC0F0EB}DC:\Program Files\VMware\Workspace ONE Assist\System.Net.Security.dll@
        Source: 58426c.rbs.1.drBinary or memory string: GC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "More_Information": "VMware'in bu
        Source: 58426c.rbs.1.drBinary or memory string: @C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.dll
        Source: 58426c.rbs.1.drBinary or memory string: @C:\Program Files\VMware\Workspace ONE Assist\System.Net.Http.dll
        Source: 58426c.rbs.1.drBinary or memory string: FC:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\AUMIDs.txt
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>For information regarding the data VMware collects in connection with your use of this application for product improvement and other analytics purposes, see the Trust & Assurance Center and VMware's Privacy Notices.</p>
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A6980000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Windows\Installer\MSI50A5.tmp-\C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe"C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe" "install" "C:\Program Files\VMware\Workspace ONE Assist\Resources"C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exewinsta0\default
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Globalization.Extensions.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{C17C6D33-7C3D-455C-B8A2-7CC7886DAE60}EC:\Program Files\VMware\Workspace ONE Assist\System.Text.Encoding.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Buffers.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: "UnInstall_PopupDescription": "VMware RemoteHelp kommer att avinstalleras fr
        Source: MSI4559.tmp.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe;C:\Program Files\VMware\Workspace ONE Assist\Resources
        Source: MSI4559.tmp.1.drBinary or memory string: &{FCDBDFC3-EFEE-467B-ACC2-3DAB6CF52B2D}LC:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\libvpx.dylib@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: rene og betingelserne for VMware Workspace ONE Assist i forbindelse med brug af denne tjeneste.",
        Source: MSI4559.tmp.1.drBinary or memory string: &{20CA2246-78C7-46A3-B31B-1108A5D45D10}KC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Tracing.dll@
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeT5?
        Source: MSI4559.tmp.1.drBinary or memory string: O1\yywlw-zk\yonnbfme\native\lib\osx\|VMware\Workspace ONE Assist\native\lib\osx\
        Source: 58426c.rbs.1.drBinary or memory string: FC:\Program Files\VMware\Workspace ONE Assist\System.Net.Primitives.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Http.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{6B88AA3B-CEAC-4317-98C5-A9D41D087F2C}RC:\Program Files\VMware\Workspace ONE Assist\System.Security.Principal.Windows.dll@
        Source: 58426c.rbs.1.drBinary or memory string: AC:\Program Files\VMware\Workspace ONE Assist\System.Threading.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware RemoteHelp
        Source: 58426c.rbs.1.drBinary or memory string: gC:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4.appxbundle
        Source: 58426c.rbs.1.drBinary or memory string: KC:\Program Files\VMware\Workspace ONE Assist\Microsoft.Win32.Primitives.dll
        Source: Workspace ONE Assist Installer.lnk.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exeZ..\..\..\..\..\..\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe-C:\Program Files\VMware\Workspace ONE Assist\DC:\Windows\Installer\{2687F608-EC00-4F9A-B6B3-0194BAD168BB}\icon.ico
        Source: 58426c.rbs.1.drBinary or memory string: JC:\Program Files\VMware\Workspace ONE Assist\System.Text.Encodings.Web.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\f7529f1a891c4c29afa0bf940c4958e4_License1.xml
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: und in den Datenschutzhinweisen von VMware.</p>
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: re dont VMware g
        Source: 58426c.rbs.1.drBinary or memory string: Software\VMware\Workspace ONE Assist
        Source: MSI4559.tmp.1.drBinary or memory string: &{C3D07B00-66F2-4FAF-BC30-91A9BAFF520F}:C:\Program Files\VMware\Workspace ONE Assist\System.IO.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{777B4CD6-0B07-4E9B-B05E-54BD9F1274E7}MC:\Program Files\VMware\Workspace ONE Assist\System.Diagnostics.Contracts.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{03E4863A-4A9C-4F13-BA23-E99E32E623F6}@C:\Program Files\VMware\Workspace ONE Assist\System.IO.Pipes.dll@
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\arm\lib_remote_shell_api.so
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69F7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe.Config
        Source: MSI4559.tmp.1.drBinary or memory string: &{00F72D99-C52D-484F-B12C-BAFBAE267FD4}GC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dll@
        Source: 58426c.rbs.1.drBinary or memory string: BC:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\arm\
        Source: 58426c.rbs.1.drBinary or memory string: @C:\Program Files\VMware\Workspace ONE Assist\System.IO.Pipes.dll
        Source: Workspace ONE Assist Installer.lnk.1.drBinary or memory string: VMware
        Source: MSI4559.tmp.1.drBinary or memory string: 1\yywlw-zk\yonnbfme\affs8zkc\Appx\|VMware\Workspace ONE Assist\Resources\Appx\
        Source: 58426c.rbs.1.drBinary or memory string: MC:\Program Files\VMware\Workspace ONE Assist\System.Reflection.Primitives.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{0366DCCB-37A9-4D7E-8992-6D28F6DA4B0F}LC:\Program Files\VMware\Workspace ONE Assist\System.Threading.ThreadPool.dll@
        Source: MSI4559.tmp.1.drBinary or memory string: &{7F73628A-4519-4612-B499-188C22DA207E}9C:\Program Files\VMware\Workspace ONE Assist\msvcp140.dll@
        Source: 58426c.rbs.1.drBinary or memory string: NC:\Program Files\VMware\Workspace ONE Assist\System.IO.Compression.ZipFile.dll
        Source: 58426c.rbs.1.drBinary or memory string: -C:\Program Files\VMware\Workspace ONE Assist\
        Source: 58426c.rbs.1.drBinary or memory string: HC:\Program Files\VMware\Workspace ONE Assist\System.Threading.Thread.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.AppContext.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Security.Cryptography.Csp.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: ytkowania VMware Workspace ONE Assist, kt
        Source: 58426c.rbs.1.drBinary or memory string: HC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dll
        Source: 58426c.rbs.1.drBinary or memory string: MC:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.Watcher.dll
        Source: 58426c.rbs.1.drBinary or memory string: LC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Net.Requests.dll
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1895700607.00000229A8651000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: ;C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx@C0
        Source: MSI4559.tmp.1.drBinary or memory string: &{AC001B81-5B82-460B-BC49-647D91603DF6}=C:\Program Files\VMware\Workspace ONE Assist\vcruntime140.dll@
        Source: 58426c.rbs.1.drBinary or memory string: <C:\Program Files\VMware\Workspace ONE Assist\System.Linq.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.Threading.Tasks.dll
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>VMware Workspace ONE, i
        Source: 58426c.rbs.1.drBinary or memory string: QC:\Program Files\VMware\Workspace ONE Assist\System.ComponentModel.Primitives.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.IO.FileSystem.DriveInfo.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\System.CodeDom.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{377C9983-C51B-4A4E-9520-F002E81F9B86}HC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dll@
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: VMware.</p>
        Source: WorkspaceONE.Assist.Client.exe.1.drBinary or memory string: <p>VMware Workspace ONE erfasst Informationen, um einen sicheren Zugriff auf Ihre Arbeitsdaten und Anwendungen zu erm
        Source: 58426c.rbs.1.drBinary or memory string: CC:\Program Files\VMware\Workspace ONE Assist\System.Collections.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\native\lib\linux\arm\
        Source: AetherPal.MSIX.Launcher.exe, 00000004.00000002.1893110977.00000229A69F7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: file:///C:/Program Files/VMware/Workspace ONE Assist/
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dll
        Source: 58426c.rbs.1.drBinary or memory string: OC:\Program Files\VMware\Workspace ONE Assist\System.Collections.Specialized.dll
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dll
        Source: 58426c.rbs.1.drBinary or memory string: BC:\Program Files\VMware\Workspace ONE Assist\System.AppContext.dll
        Source: 58426c.rbs.1.drBinary or memory string: ZC:\Program Files\VMware\Workspace ONE Assist\native\lib\osx\x64\lib_remote_shell_api.dylib
        Source: MSI4559.tmp.1.drBinary or memory string: &{22E04EF6-3813-43AC-9343-86A8DB84A1B6}KC:\Program Files\VMware\Workspace ONE Assist\System.Xml.XPath.XDocument.dll@
        Source: 58426c.rbs.1.drBinary or memory string: SC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dll
        Source: 58426c.rbs.1.drBinary or memory string: HC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dll
        Source: 58426c.rbs.1.drBinary or memory string: <C:\Program Files\VMware\Workspace ONE Assist\Resources\Appx\
        Source: 58426c.rbs.1.drBinary or memory string: C:\Program Files\VMware\Workspace ONE Assist\Newtonsoft.Json.dll
        Source: MSI4559.tmp.1.drBinary or memory string: &{63372CBE-AEC1-4301-BDBF-F5CD75F54FCF}LC:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dll@
        Source: C:\Windows\System32\msiexec.exeProcess information queried: ProcessInformationJump to behavior
        Source: C:\Windows\System32\rundll32.exeMemory allocated: page read and write | page guardJump to behavior
        Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformationJump to behavior
        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Windows\Installer\MSI50A5.tmp-\Microsoft.Deployment.WindowsInstaller.dll VolumeInformationJump to behavior
        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Wix.CustomAction.dll VolumeInformationJump to behavior
        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Windows.Utils.dll VolumeInformationJump to behavior
        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Windows\Installer\MSI50A5.tmp-\AetherPal.Diagnostics.dll VolumeInformationJump to behavior
        Source: C:\Windows\System32\rundll32.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\netstandard\v4.0_2.0.0.0__cc7b13ffcd2ddd51\netstandard.dll VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Windows.Utils.dll VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Program Files\VMware\Workspace ONE Assist\System.Runtime.dll VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Management.winmd VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.Foundation.winmd VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\netstandard\v4.0_2.0.0.0__cc7b13ffcd2ddd51\netstandard.dll VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.ApplicationModel.winmd VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Runtime.WindowsRuntime\v4.0_4.0.0.0__b77a5c561934e089\System.Runtime.WindowsRuntime.dll VolumeInformationJump to behavior
        Source: C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exeQueries volume information: C:\Windows\System32\WinMetadata\Windows.System.winmd VolumeInformationJump to behavior
        Source: C:\Windows\System32\rundll32.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
        ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
        Gather Victim Identity InformationAcquire Infrastructure1
        Valid Accounts
        Windows Management Instrumentation1
        Valid Accounts
        1
        Valid Accounts
        23
        Masquerading
        OS Credential Dumping11
        Security Software Discovery
        Remote Services1
        Archive Collected Data
        1
        Encrypted Channel
        Exfiltration Over Other Network MediumAbuse Accessibility Features
        CredentialsDomains1
        Replication Through Removable Media
        Scheduled Task/Job1
        Registry Run Keys / Startup Folder
        1
        Access Token Manipulation
        1
        Valid Accounts
        LSASS Memory1
        Process Discovery
        Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
        Email AddressesDNS ServerDomain AccountsAt1
        DLL Side-Loading
        1
        Process Injection
        1
        Access Token Manipulation
        Security Account Manager41
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
        Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
        Registry Run Keys / Startup Folder
        1
        Disable or Modify Tools
        NTDS11
        Peripheral Device Discovery
        Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
        Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon Script1
        DLL Side-Loading
        41
        Virtualization/Sandbox Evasion
        LSA Secrets1
        File and Directory Discovery
        SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
        Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
        Process Injection
        Cached Domain Credentials13
        System Information Discovery
        VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
        DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
        Obfuscated Files or Information
        DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
        Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
        Rundll32
        Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
        Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt1
        Timestomp
        /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
        IP AddressesCompromise InfrastructureSupply Chain CompromisePowerShellCronCron1
        DLL Side-Loading
        Network SniffingNetwork Service DiscoveryShared WebrootLocal Data StagingFile Transfer ProtocolsExfiltration Over Asymmetric Encrypted Non-C2 ProtocolExternal Defacement
        Network Security AppliancesDomainsCompromise Software Dependencies and Development ToolsAppleScriptLaunchdLaunchd1
        File Deletion
        Input CaptureSystem Network Connections DiscoverySoftware Deployment ToolsRemote Data StagingMail ProtocolsExfiltration Over Unencrypted Non-C2 ProtocolFirmware Corruption
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet
        behaviorgraph top1 signatures2 2 Behavior Graph ID: 1431604 Sample: VZH3bd37Gc Startdate: 25/04/2024 Architecture: WINDOWS Score: 15 39 Yara detected Generic Downloader 2->39 9 msiexec.exe 190 207 2->9         started        12 msiexec.exe 6 2->12         started        process3 file4 31 C:\Windows\Installer\MSI50A5.tmp, PE32+ 9->31 dropped 33 C:\Program Files\VMware\...\winpty.dll, PE32+ 9->33 dropped 35 C:\Program Files\VMware\...\winpty.NET.dll, PE32 9->35 dropped 37 153 other files (none is malicious) 9->37 dropped 14 msiexec.exe 9->14         started        process5 process6 16 rundll32.exe 10 14->16         started        file7 23 C:\Windows\Installer\...\netstandard.dll, PE32 16->23 dropped 25 Microsoft.Deployme...indowsInstaller.dll, PE32 16->25 dropped 27 C:\...\AetherPal.Windows.Wix.CustomAction.dll, PE32+ 16->27 dropped 29 3 other files (none is malicious) 16->29 dropped 19 AetherPal.MSIX.Launcher.exe 2 16->19         started        process8 process9 21 conhost.exe 19->21         started       

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        VZH3bd37Gc.msi0%ReversingLabs
        VZH3bd37Gc.msi0%VirustotalBrowse
        SourceDetectionScannerLabelLink
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Agent.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Communication.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Application.Localization.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Auth.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Channels.AnchorChannel.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Configuration.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Core.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Sys.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.FileManager.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteControl.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.RemoteShell.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.Tools.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Device.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Diagnostics.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Net.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Net.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Security.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Security.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Serialization.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.FileManager.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.FileManager.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteControl.dll0%VirustotalBrowse
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dll0%ReversingLabs
        C:\Program Files\VMware\Workspace ONE Assist\AetherPal.Tools.RemoteShell.dll0%VirustotalBrowse
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisLight0%Avira URL Cloudsafe
        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisCopyright0%Avira URL Cloudsafe
        http://aetherpal.com/deviceghttp://aetherpal.com/XMLSchema/device/TimerPolicy100%Avira URL Cloudsafe
        http://aetherpal.com/XMLSchema/device/DeviceInfo100%Avira URL Cloudsafe
        http://aetherpal.com/deviceghttp://aetherpal.com/XMLSchema/device/TimerPolicy100%VirustotalBrowse
        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisSemi0%Avira URL Cloudsafe
        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisMedium0%Avira URL Cloudsafe
        http://aetherpal.com/XMLSchema/device/SecurityPolicy100%Avira URL Cloudsafe
        http://aetherpal.com/XMLSchema/device/UserInterfacePolicy100%Avira URL Cloudsafe
        http://victoryonemedia.comhttps://github.com/chrismsimpson/Metropolis0%Avira URL Cloudsafe
        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisExtra0%Avira URL Cloudsafe
        http://aetherpal.com/XMLSchema/device/DeviceInfo100%VirustotalBrowse
        http://aetherpal.com/XMLSchema/device/SecurityPolicy100%VirustotalBrowse
        http://aetherpal.com/XMLSchema/device/UserInterfacePolicy100%VirustotalBrowse
        No contacted domains info
        NameSourceMaliciousAntivirus DetectionReputation
        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisSemiAetherPal.WPF.CustomControls.dll.1.drfalse
        • Avira URL Cloud: safe
        unknown
        https://github.com/chrismsimpsonhttps://github.com/chrismsimpson/MetropolisMetropolisLightAetherPal.WPF.CustomControls.dll.1.drfalse
          high
          https://github.com/dotnet/runtime8System.Text.Json.dll.1.drfalse
            high
            http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisCopyrightAetherPal.WPF.CustomControls.dll.1.drfalse
            • Avira URL Cloud: safe
            unknown
            http://aetherpal.com/deviceghttp://aetherpal.com/XMLSchema/device/TimerPolicy10AetherPal.Device.dll.1.drfalse
            • 0%, Virustotal, Browse
            • Avira URL Cloud: safe
            unknown
            https://github.com/dotnet/roslyn/issues/46646~System.Text.Json.dll.1.drfalse
              high
              https://github.com/chrismsimpsonhttps://github.com/chrismsimpson/MetropolisCopyrightAetherPal.WPF.CustomControls.dll.1.drfalse
                high
                http://wixtoolset.org/Whttp://wixtoolset.org/telemetry/vrundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.drfalse
                  high
                  https://www.vmware.com/help/privacy.html.WorkspaceONE.Assist.Client.exe.1.drfalse
                    high
                    https://github.com/dotnet/runtime/issues/73124.System.Text.Json.dll.1.drfalse
                      high
                      https://www.vmware.com/tw/help/privacy.htmlWorkspaceONE.Assist.Client.exe.1.drfalse
                        high
                        http://wixtoolset.org/news/rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.drfalse
                          high
                          https://www.vmware.com/help/privacy.htmlWorkspaceONE.Assist.Client.exe.1.drfalse
                            high
                            http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisLightAetherPal.WPF.CustomControls.dll.1.drfalse
                            • Avira URL Cloud: safe
                            unknown
                            https://github.com/dotnet/core/)WorkspaceONE.Assist.Client.exe.1.drfalse
                              high
                              https://www.att.comWorkspaceONE.Assist.Client.exe.1.drfalse
                                high
                                https://github.com/dotnet/runtimeSystem.Security.Permissions.dll.1.dr, System.ServiceProcess.ServiceController.dll.1.dr, System.Security.AccessControl.dll.1.dr, System.Text.Json.dll.1.dr, System.CodeDom.dll.1.dr, System.Text.Encodings.Web.dll.1.dr, Microsoft.Win32.SystemEvents.dll.1.dr, System.Security.Cryptography.ProtectedData.dll.1.drfalse
                                  high
                                  https://github.com/dotnet/roslyn/issues/46646System.Text.Json.dll.1.drfalse
                                    high
                                    https://www.vmware.com/es/help/privacy.htmlWorkspaceONE.Assist.Client.exe.1.drfalse
                                      high
                                      http://wixtoolset.org/releases/rundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, Microsoft.Deployment.WindowsInstaller.dll.3.drfalse
                                        high
                                        https://github.com/chrismsimpsonhttps://github.com/chrismsimpson/MetropolisAetherPal.WPF.CustomControls.dll.1.drfalse
                                          high
                                          https://aka.ms/dotnet-warnings/System.Text.Json.dll.1.drfalse
                                            high
                                            http://aetherpal.com/XMLSchema/device/DeviceInfo10AetherPal.Device.dll.1.drfalse
                                            • 0%, Virustotal, Browse
                                            • Avira URL Cloud: safe
                                            unknown
                                            http://wixtoolset.orgrundll32.exe, 00000003.00000003.1817301234.0000013205222000.00000004.00000020.00020000.00000000.sdmp, VZH3bd37Gc.msi, Microsoft.Deployment.WindowsInstaller.dll.3.dr, 58426b.msi.1.drfalse
                                              high
                                              http://aetherpal.com/XMLSchema/device/SecurityPolicy10AetherPal.Device.Tools.RemoteControl.dll.1.dr, AetherPal.Device.dll.1.drfalse
                                              • 0%, Virustotal, Browse
                                              • Avira URL Cloud: safe
                                              unknown
                                              https://github.com/dotnet/runtime&System.Security.Permissions.dll.1.dr, System.ServiceProcess.ServiceController.dll.1.dr, System.CodeDom.dll.1.dr, Microsoft.Win32.SystemEvents.dll.1.dr, System.Security.Cryptography.ProtectedData.dll.1.drfalse
                                                high
                                                https://aka.ms/serializationformat-binary-obsoleteSystem.Text.Json.dll.1.drfalse
                                                  high
                                                  https://www.gnu.org/licensesWorkspaceONE.Assist.Client.exe.1.drfalse
                                                    high
                                                    https://aka.ms/binaryformatterSystem.Text.Json.dll.1.drfalse
                                                      high
                                                      http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisMediumAetherPal.WPF.CustomControls.dll.1.drfalse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://aetherpal.com/XMLSchema/device/UserInterfacePolicy10AetherPal.Device.dll.1.drfalse
                                                      • 0%, Virustotal, Browse
                                                      • Avira URL Cloud: safe
                                                      unknown
                                                      http://schemas.xmlsoap.org/ws/2005/05/identity/claims/namerundll32.exe, 00000003.00000002.1899788011.00000132053C1000.00000004.00000800.00020000.00000000.sdmpfalse
                                                        high
                                                        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisAetherPal.WPF.CustomControls.dll.1.drfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        http://victoryonemedia.comhttps://github.com/chrismsimpson/MetropolisMetropolisExtraAetherPal.WPF.CustomControls.dll.1.drfalse
                                                        • Avira URL Cloud: safe
                                                        unknown
                                                        No contacted IP infos
                                                        Joe Sandbox version:40.0.0 Tourmaline
                                                        Analysis ID:1431604
                                                        Start date and time:2024-04-25 14:15:23 +02:00
                                                        Joe Sandbox product:CloudBasic
                                                        Overall analysis duration:0h 6m 43s
                                                        Hypervisor based Inspection enabled:false
                                                        Report type:full
                                                        Cookbook file name:default.jbs
                                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                        Number of analysed new started processes analysed:12
                                                        Number of new started drivers analysed:0
                                                        Number of existing processes analysed:0
                                                        Number of existing drivers analysed:0
                                                        Number of injected processes analysed:0
                                                        Technologies:
                                                        • HCA enabled
                                                        • EGA enabled
                                                        • AMSI enabled
                                                        Analysis Mode:default
                                                        Analysis stop reason:Timeout
                                                        Sample name:VZH3bd37Gc.msi
                                                        (renamed file extension from none to msi, renamed because original name is a hash value)
                                                        Original Sample Name:0400a87b6100936cdc0a8695c5dc1c7103bb93c0842231efaf7260a795290339
                                                        Detection:CLEAN
                                                        Classification:clean15.troj.winMSI@9/191@0/0
                                                        EGA Information:Failed
                                                        HCA Information:
                                                        • Successful, ratio: 96%
                                                        • Number of executed functions: 39
                                                        • Number of non-executed functions: 1
                                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
                                                        • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                        • Execution Graph export aborted for target AetherPal.MSIX.Launcher.exe, PID 6520 because it is empty
                                                        • Execution Graph export aborted for target rundll32.exe, PID 6044 because there are no executed function
                                                        • Not all processes where analyzed, report is missing behavior information
                                                        • Report size getting too big, too many NtSetInformationFile calls found.
                                                        No simulations
                                                        No context
                                                        No context
                                                        No context
                                                        No context
                                                        No context
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):30750
                                                        Entropy (8bit):5.640477030307273
                                                        Encrypted:false
                                                        SSDEEP:768:XNUnfWHhtYNAW4kNUP2Ss7qxcoPHxI9yzQ9T62IamK02iSxsncSYVIT+hV6L13D7:dUnfWHhtYNAW4kNUP2Ss7qxcoPHxI9yh
                                                        MD5:9A949F5B22A5D1D4AACC33367EABBD24
                                                        SHA1:FA9C31F8DC3332A1B63143F4209734BBA005C719
                                                        SHA-256:1E41FDF9570F3A66E6B7B03F34BA6AE468DE7D6F61FF1F70A236BBEF9084FD3E
                                                        SHA-512:00F89E58138339EA2B734B9F2DAACCBEF58A9CFA515520CD64C7B684827F83D97FED7E6B75B4C18BDEE3B891652C122D44F42B1E1EA6A53623754ECD88D2D5A5
                                                        Malicious:false
                                                        Reputation:low
                                                        Preview:...@IXOS.@.....@.r.X.@.....@.....@.....@.....@.....@......&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}..Workspace ONE Assist Installer..VZH3bd37Gc.msi.@.....@.....@.....@......icon.ico..&.{FD0CDE91-FD76-4738-8B40-800BA9713AFC}.....@.....@.....@.....@.......@.....@.....@.......@......Workspace ONE Assist Installer......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]....ProcessComponents..Updating component registration..&.{3CF85474-93F9-43E2-8E5F-DB1190DAE600}&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}.@......&.{F514C4CC-87F5-4F69-91DF-99D15C9D8C08}&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}.@......&.{E010BFD9-3010-4968-A829-D3A3BC25CE49}&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}.@......&.{20EB5E0E-047A-47F7-9023-427A11E7D509}&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}.@......&.{63372CBE-AEC1-4301-BDBF-F5CD75F54FCF}&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}.@......&.{9B5E1039-2250-44BD-B89F-78146919C075}&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}.@......&.{44BA2026-E1
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):211712
                                                        Entropy (8bit):6.067718670093841
                                                        Encrypted:false
                                                        SSDEEP:3072:oj1n8lto91eXhn1pk3gbdYKtSe/0ddy5bQQ41bTcMu7pCbgHPN0W/N:oj1n8/ya1pksYKR/j5E9b4MrbgvNp
                                                        MD5:E5AD37AAA015E8C1BFB4D48A1136D4D1
                                                        SHA1:9EECC43D4E77D9505F7D7E380753923BD31C9427
                                                        SHA-256:96B4C66A5873B9F53315380FBBC0592AB7611FF416E423A0AB957976ECA853C1
                                                        SHA-512:9A8AD0052755F138BD67C5BE7C65E46FB1DDC22CB5428F1BA62984E546D54CF71E5B8047147C825CB84790B4D6EE46E7F7C3206007AA3E677770C397BB75C9DB
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...,e............" ..0.................. ........... .......................`......A.....`...@......@............... ...............................@..<................'..........`*..T............................................................ ..H............text........ ...................... ..`.rsrc...<....@......................@..@........................................H........2..L...........P....#.............................................}.....( .....}......}......}.....s!...}....*..{....*"..}....*..{....*.0..?.........("...}.......}.......}.......}......|......(...+..|....($...*..0.......... Vk...r...pr+..p(%.....}....r...pr+..pr7..p......(&...('....{....%-.&.+.o(...,!r...pr+..pr?..p......(&...()....}.s*...}.....{...........s+...o,....{...........s-...o.....{.....o/...r...pr+..pru..p(0......r...pr+..p.(1.....r...pr+..p(2...*..................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):41728
                                                        Entropy (8bit):6.242264593968292
                                                        Encrypted:false
                                                        SSDEEP:768:DJ7vbaeN4Z7kmKDsFuTjUdzPqLwjtHi7VEpYinAMxymD2:17OBOKhC7O7HxhD2
                                                        MD5:92B8CD364D07849A26BB071105FB2095
                                                        SHA1:30C42317EC365069F50E3BD0002C3BF4BAB6095D
                                                        SHA-256:1F8BE74C0B7B4E75B0D6AF2D15BCDBC123457F648FB19F8D376C7C0CD1950D5D
                                                        SHA-512:B02B84EE0847885DA3C346935C7A513B4F9B9DAC025EB60A9525E122C7D853020D53EABAF3D6A36AED64651AD8FAF992C9C090D94F5E73B24BE88EF817D658F9
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...7............." ..0..t............... ........... ..............................i.....`...@......@............... ..................................l............|...'..............T............................................................ ..H............text...1r... ...t.................. ..`.rsrc...l............v..............@..@........................................H........,..8d..........................................................:.(......(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..(....*..{....*"..}....*..(....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*..{....*"..}....*...0..M.......r...p......%..(.....$....%..(.....%....%..(.....%....%..(.....%..(.....(....*..(....*..{....*"..}....*..(....*6..$.....%...*..{U...*"..}U...*..{V...*"..}V...*..{W...*"..}W...*.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):44800
                                                        Entropy (8bit):6.638648335052158
                                                        Encrypted:false
                                                        SSDEEP:768:qLpV9WSCIjmoB/np70TbkEF9NlF52GvhqB1tEpYinAMxyW3:09W9IjnuTvFxF52pA7Hxh
                                                        MD5:F01597858D6996B5DFEFA48A09C4EA31
                                                        SHA1:07DC8D09FD9A899F17AC6DA037F315FBC534BE74
                                                        SHA-256:E4A76202B3D780284F738A08EF0442B74A9AC3F0D54C3B37BD25191273EA91CE
                                                        SHA-512:42BC89EB586767C769A266FB563E82954C390EB869B1FD2E9EF41317A0CAF980647F6D2CE853617A9E9C08610E4E2600E7BF7E483920E079604A3D037535E84D
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...I>............" ..0.................. ........... ....................................`...@......@............... ...................................................'..............T............................................................ ..H............text........ ...................... ..`.rsrc...............................@..@........................................H.......8,...&..........HR..PM...........................................0..........s'......}....(.......(....,j.o....&.o.......(...s....(...+...o......s........o.......6..,...o......,..o.......r...pr/..p..o....(......~....*..*..(....K..V........C..b..........Pl.......0..6........(......(....-!.(....%-.&.+.o....o....%-.&rM..p*~....*..(....*...0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*..{....*"..}....*F.(....o....(...+*
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):44288
                                                        Entropy (8bit):6.287432631302536
                                                        Encrypted:false
                                                        SSDEEP:768:RrrgVo7O64BpWfZMdOrRyUCf/43e79OGzbrvirC3mycZEpYinAMxytZ:trCYO648e2Nq/43eBOGzHKW3myci7Hx+
                                                        MD5:1182219249FCFEBBC9512C0E52A92DED
                                                        SHA1:579DF9FCECEA2FB07AE6F1411B6112E71BD30EFB
                                                        SHA-256:12F303B122C5491FF8BD5E362AF3599B1390CBDCE158008CF2E54F2334D55CA6
                                                        SHA-512:7C6261D7F3726E6C14910522357B0F2140106EA270F9A7A77E68CE4A4B34D0769DCE676E00A50B322C8B84DA9D8DD13A0A36749A7C65F90A6C738CE8E91931F4
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" ..0.................. ........... ..............................Sk....`...@......@............... ...................................................'..............T............................................................ ..H............text....~... ...................... ..`.rsrc...............................@..@........................................H.......`?..H^..........................................................^.(.....r...p(....(....*..{....*"..}....*..{....*"..}....*...0..[.........(....(.....r...p(....-..r[..p(....-.*..(....%-.&.+..o...+(....*..(....%-.&.+..o...+(....*J.(.....(....o....*B.(........(....*2.(....u....*"..(....*..(....*:.(......(....*2.(....u....*"..(....*..{....*"..}....*V~....%-.&s....%.....*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):62720
                                                        Entropy (8bit):6.1890277735637955
                                                        Encrypted:false
                                                        SSDEEP:1536:av8DKiN7vZwM642OT81Pd6/I5J6hboqlc7HxJ:BDzVJ5T81Pd6/I5QhsqlcD
                                                        MD5:1514872EA0F89D23346C268F0675E88E
                                                        SHA1:2D96A7CD7C04D7BD167FBA5490A8A93D449F0DDA
                                                        SHA-256:FC5E1C0423E64067AF871F964B58EC9D8B4A3146406C07B2DA177F7E8E3538E9
                                                        SHA-512:66EAE20765A4DC50DC04250843289DBF70D882922A3A16852C4C2B5C73FEF57FED31C96583369BCA71D1CCC204A78105859EC1F485EA0A5B1C9D6F3731A64BC6
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...*&m..........." ..0.................. ........... ....................... ............`...@......@............... ..................................`................'..............T............................................................ ..H............text........ ...................... ..`.rsrc...`...........................@..@........................................H........c...s...........................................................0..j.........(....}.......}.......}.......}.......}........}........}........}.......}......|......(...+..|....(....*...0..?.........( ...}+......},......}-......}*.....|+.....(...+..|+...("...*..0..W.......s=....(#.....o$...o%...r...p(&.....('...,..*...((...}&....o$...o%...r...p(&.....('...,..*...((...}'....(...+...>...s*...(...+-..*..(...+...?...s*...(...+}(....{(...-..*..(...+...@...s*...(...+})....{)...-..*.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):34560
                                                        Entropy (8bit):6.189456988613418
                                                        Encrypted:false
                                                        SSDEEP:768:nXPnyx2p85br+bBoYyvXhpEpYinAMxypc:nXPyxNR+bBoPvXhS7HxSc
                                                        MD5:EAA8B1F10B0A673D7097F057F48B9960
                                                        SHA1:0D79A93CFE149F5B69E3748F1EAA0614ACE0E1C4
                                                        SHA-256:20CB79917D1D85600CD6802C9511E3412AC96A06AF51BD445AC1D565EB92C738
                                                        SHA-512:D1D15FEF98F1118F26C8048050408FE9C3D02EC0282F8E3B046E6BC6C587E2C46FA1166ADF82EBD9C9E3294568352B23DAAA62E59F62DCD563C62277A4745A57
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...M............." ..0..X............... ........... ....................................`...@......@............... ..................................$............`...'..........Lu..T............................................................ ..H............text...EV... ...X.................. ..`.rsrc...$............Z..............@..@........................................H........5...?..........................................................Z.(......(......(#...&*..{....*"..}....*..{....*"..}....*..{....*:..}.....o7...*^(....r...p(....%(....&*r(....r...p(....%(....&(....*....0..........(....r...p(......(....,..(....*..0..........r)..p.(....(....,Tr+..p(......(....,/.#(......rI..pr...p(....(....-.(....o....(.....rW..p.(....(....+g( ...(....,;.((....rg..prw..p(......(....-<r...p.r...p(!...r=..p( ...+ .#(......(....-.(....o....(......(....,.(....o....(
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):28416
                                                        Entropy (8bit):6.5573142638358854
                                                        Encrypted:false
                                                        SSDEEP:384:D2sfSEt6/L78cyYoFteKirCdpvlh6jeBybCNyb8E9VF6IYinAM+oXCbauo:DBJ6/LToiKiGds7bCEpYinAMxyS
                                                        MD5:6ABF0C027E1B44F49A57353FA8CC7AD2
                                                        SHA1:2E55BDF32B08E705AC0D44B23072669DA3F106F5
                                                        SHA-256:3E7D4A1064C80EADAFC2C30D2E67E643927B3819AAD336F45F4D5B5E0C8BD617
                                                        SHA-512:932ED5A900CB94E46FEDA3292E41FCA639131A51637A3CFE1802A2AC79F70A291D8D4BFFF05E6A73944B95162C0974E80DC095D723065EB3EDFDF1C691CB3FAE
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....O............" ..0..B............... ........... ....................................`...@......@............... ...............................................H...'...........`..T............................................................ ..H............text....A... ...B.................. ..`.rsrc................D..............@..@........................................H.......l3..D-............................................................**....(....**....(....*..-.r...ps....z...i1.r)..ps....z....o....*..(....*2.o.........*..(....*..-.rg..p*rq..p.(.....-. o....ry..p(....*....0...........-.rg..p*s.........+].....u....,%..u....(......(....r}..p(....o....&+(..,..(....+.rg..p..(....r}..p(....o....&..X....i2..o......#...%...%.. .o....*..%-.&(...+*...*B.{....%-.&~....*..{....*"..}....*N.{....,..{.....i*.*....0..4........-.r...ps....z...&...}......+..{
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):18688
                                                        Entropy (8bit):6.692975570877159
                                                        Encrypted:false
                                                        SSDEEP:384:xhPwReegk8IJNyb8E9VF6IYinAM+oXCbOzvmzI:IoevNEpYinAMxyazezI
                                                        MD5:A0F1CE395D036FCA641BFB3A7415ADEC
                                                        SHA1:CC3DA77A044F619E51E4BB51F72D329D41EC6A79
                                                        SHA-256:690E9278083BFB8B476CA0AF755D1C6F97D5C3D616990565A6028871C3EAF3B2
                                                        SHA-512:83441F4194D745DA9558ACEA0490BED7E22B1825FE8FF794A9A7E16BF64F99E3DAED6B9C688419AD36328521CD9F66742CC8016948D79203F691ACCDDB778CFF
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Reputation:low
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...y............" ..0.................. ........... .......................`............`...@......@............... ...............................@..............."...'...........8..T............................................................ ..H............text........ ...................... ..`.rsrc........@......................@..@........................................H.......P ...............................................................s....z.BSJB............v4.0.30319......l.......#~..@.......#Strings............#US.........#GUID...........#Blob...........W..........3....................L.......................D...E.............................G.......?.........'.@.....@.....@.....@.....@.....@...>.@...............r.@...Y......................... .........................D...E.........-...E.......................k...........................O.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):67328
                                                        Entropy (8bit):6.155743174253633
                                                        Encrypted:false
                                                        SSDEEP:1536:gvAvuN9Ix9SqVL6aKMqn4hk3tWexvZ644AB21rR93q7HxAE:gvS7zTKMVhkdWexh644AB21rRFqKE
                                                        MD5:51CFC5304826105809D659282D402DE9
                                                        SHA1:09207F0320B808AC12F35AE8E168524A693B12DC
                                                        SHA-256:C041479E25B52ECADD120F9F65BFECD6A68C81BB0B91EB2CE974A8BB4E53FEA7
                                                        SHA-512:18D9D360179417AACE2FFC267356709825958A3E4F7E9D95776B4C9F7428D1952A195D16E44A54D6A1F14089585F41B6AC4D53060E3731D19AC22691515C727E
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....]............" ..0.................. ........... ....................... ............`...@......@............... ..................................l................'..........X...T............................................................ ..H............text...o.... ...................... ..`.rsrc...l...........................@..@........................................H.......x....n..........................................................b.r...p}.....(%....(....*J..{....(M...}....*J.(.....{....oL...*^~....-.s.........~....*j.{....-..sE...}.....{....*...0..p........(....oI...op....+..o&.....oV...('...,..oV...((....o....-....,..o........r...pr5..p.().....(....o....oI...oo...*........+<..........HH.......0..$.......sw......},... .......x...s*...(+...*..~,...}.....(%.....s#...}......}......(.....s-...}....*J.{....~.....o....*J.{....~.....o/...*J.{...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):178944
                                                        Entropy (8bit):6.093083329659117
                                                        Encrypted:false
                                                        SSDEEP:3072:ylNVMJgTq1qXMYkxNoe5v42lvyfIAXZ4pEk179sZkF5szYO1ihDn:2NVWqcyi4yv49y1E2
                                                        MD5:9E1574CFBED31D05E22A6FB1CB4A9A40
                                                        SHA1:92BA08343707124B6DBADB536DD33DED032279AF
                                                        SHA-256:40451B9D395DEBBE4440FF294887AA88656F5AFA05077D4A9908ED688EA19626
                                                        SHA-512:BD8A9D10AD673A5D72974D682EA4F4BD96C38E41B65C1A1C4A330FA66D5840F3B0BB4726D3169005BD99E0BBE5C84B33745E3AF24EA67B64CDA516EFCAEFC71E
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..0.................. ........... ....................................`...@......@............... ..................................\................'.............T............................................................ ..H............text...0.... ...................... ..`.rsrc...\...........................@..@........................................H.......p...`.............................................................{'...*..{(...*V.().....}'.....}(...*...0..A........u........4.,/(*....{'....{'...o+...,.(,....{(....{(...o-...*.*.*. Ia. )UU.Z(*....{'...o....X )UU.Z(,....{(...o/...X*...0..b........r...p......%..{'......%q.........-.&.+.......o0....%..{(......%q.........-.&.+.......o0....(1...*..{2...*..{3...*V.().....}2.....}3...*.0..A........u........4.,/(*....{2....{2...o+...,.(,....{3....{3...o-...*.*.*. {S.. )UU.Z(*....{
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):46848
                                                        Entropy (8bit):6.306264073316825
                                                        Encrypted:false
                                                        SSDEEP:768:V/zxkI+ZohgiNJxSY1r4Rn3IpNRwwHiHmIkpVEpYinAMxyPi:Z1kIOyxSM4RONRLwoO7HxD
                                                        MD5:5F4551EB7BA953714B1F2249314513C8
                                                        SHA1:D6F90FA999D61E6016DC43788BDB9230CCBFC024
                                                        SHA-256:0EA27D6F2DDFCDF13D16F480530DDE7DDBB8F98ABAE88B96687A3C45C8B1CDA6
                                                        SHA-512:71486523E89FC6172C8446C093C71755CC006DC836D236E46250CD85DB677FDA55D26A414B71231578CCEB94B6C8DA7F362EFE7DD6B0F4F2DC139C9BD78D76B4
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...p0............" ..0.................. ........... ....................................`...@......@............... ..................................l................'..............T............................................................ ..H............text........ ...................... ..`.rsrc...l...........................@..@........................................H.......<H..\^..............................................................................d......e.....*...0..\........s....}......s....}.....s....}.....s....}.....s....}.....~....}.....(............s....}....*.0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.*....0..)........{.........(....t......|......(...+...3.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):28416
                                                        Entropy (8bit):6.4784404000199824
                                                        Encrypted:false
                                                        SSDEEP:384:CLMigiaTJwgd2ziSt+1CGo8WBFjEDFOpf9at6oNyb8E9VF6IYinAM+oXCbb3CdQ:OMkadwgdqEIV9pf9aIAEpYinAMxy2Q
                                                        MD5:C427D176C52C89F1BE18B80C2F292D6E
                                                        SHA1:D67F6B8D32988437DCC788A223B5BACC5FD06B4E
                                                        SHA-256:BC8C6AEDC04FFC3E3F82CF107EAF3D43D9C5913D6555C2055FC137155AD31615
                                                        SHA-512:8939AC6B58707B04E0CFA5D39CD1766A9D4874EEDC741181A1B8632370AE7E91F0AE62E33D83E39BF7E72FC6088F5B9F6F94F2A06FE65F38DAD9FC05D6787A82
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................." ..0..@............... ........... ..............................*.....`...@......@............... ...............................`...............H...'...........]..T............................................................ ..H............text....>... ...@.................. ..`.rsrc........`.......B..............@..@........................................H........3...*..........................................................V.(......}......}....*..{....*2.{....o....*2.{....o....*J.(....%-.&.*o....*J.(....%-.&.*o....*J.(....%-.&.*o....*>.(....(.......*....0..G.........(....}.......}.......}.......}.......}......|......(...+..|....(....*..0..~.......(....(.....( ...,6(!...%("....s#...($...&..9...(%...(&...&..9....(&...&*('...((...-.('....s#...($...&*(!...%("....s#...($...&*&...(....*..(......}......}.....s)...}......(....&*..{....*..{
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):46848
                                                        Entropy (8bit):6.162419012171159
                                                        Encrypted:false
                                                        SSDEEP:768:N7OiqJOdoL7fCZBefI6FSo+IYneB3vfiP2k3d1GEpYinAMxyBGsc:N7Oi5PDk3Xq3t1n7Hxb7
                                                        MD5:640DEB2D472EDC4CDFB9EB67708C100C
                                                        SHA1:3AD7C9675C23A656A81B39A5225C7E14BE6451E9
                                                        SHA-256:C8F5C694FD5667D67675A43C3351D86DC89BAC0C1A188A86E7DEEB25A8874330
                                                        SHA-512:6A01EB3EFA8B3CAE45DA92998DE8CF62DA74788C6C8B7C28D8C5310CFBBB83531BDD46371E477C8D9444A4CD4E8EF36E6B4865D912FCF349C5596EF902B4C69C
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....37..........." ..0.................. ........... ....................................`...@......@............... ...................................................'..............T............................................................ ..H............text...w.... ...................... ..`.rsrc...............................@..@........................................H........L...Z............................................................{....*:.(......}....*..0..)........u..........,.(.....{.....{....o....*.*.*v .... )UU.Z(.....{....o....X*..0..:........r...p......%..{.......%q.........-.&.+.......o.....(....*..(....*~(....rC..po...+%-.&re..p%(....*F(....rC..p.o...+*.0..:.......(....(......o"...,!.(#...%-.&.+.o$...o....%-.&~%...*~%...*B(....r...po...+*F(....r...p.o...+*..*F(....(.....(&...*B(....r...po...+*F(....r...p.o...+*B(....r...po...+*F(
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):35072
                                                        Entropy (8bit):6.446043411081336
                                                        Encrypted:false
                                                        SSDEEP:768:4cqBae2qA/i5yC3Zjn8eMvEpYinAMxytT:XuubiECJj8eMI7HxQT
                                                        MD5:6612AA970C07F22060DCAE00D3BA5769
                                                        SHA1:5ECEB767F47F41D072385EF7EBC42AE43F628717
                                                        SHA-256:F63BA9919B2340FDA344C1586563C057810EA10C59F0B307F95899293314811C
                                                        SHA-512:932C42219BBEEC27F74EEF4F48A56AD9D39E0703174D664BA1D5019A2CD24800EBCEC1CDF6C14E041C2160148CDBBE0E7F901A5F69878E182D6A902C24D21810
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...$............." ..0..Z............... ........... ..............................Z:....`...@......@............... ...............................................b...'...........x..T............................................................ ..H............text....Y... ...Z.................. ..`.rsrc................\..............@..@........................................H........5...B............................................................{....*..{....*V.(......}......}....*...0..A........u........4.,/(.....{.....{....o ...,.(!....{.....{....o"...*.*.*. ..._ )UU.Z(.....{....o#...X )UU.Z(!....{....o$...X*...0..b........r...p......%..{.......%q.........-.&.+.......o%....%..{.......%q.........-.&.+.......o%....(&...*Bs'........(....*.*..*F.((...()...(....*:(....,..(*...*^.-..*~.....o.....o+...*....0..........~.......o,...._,..o....*2~.....o-...*...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22272
                                                        Entropy (8bit):6.664454537713937
                                                        Encrypted:false
                                                        SSDEEP:384:NnyzWBOoMgvhCSw8LUBzWVRSHx1xTEwysyHCNyb8E9VF6IYinAM+oXCbqyzj8C:Fc47HQHM1CEpYinAMxyH
                                                        MD5:D058E337D5F7E8ADA6BCC28B5114B303
                                                        SHA1:F109FA195433552FE7269D6BBFC898E914F7AF5E
                                                        SHA-256:924BE2F467B6D695430ABD88A914EACAA0E0A8D07017A1E2AB321C0652BC5848
                                                        SHA-512:D8BA53FA35B1B745105758DC48CF6A4432FC71CF640BCC3AAF254FAF01E96B0FCEFE0B6C406D2B0D58A4C9E41FFFF98D68C62CC43AB93315E46E751CDED68AED
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................"...0..&............... .....@..... ..............................sC....`...@......@............... ...............................`..X............0...'...........D..8............................................................ ..H............text...K%... ...&.................. ..`.rsrc...X....`.......(..............@..@........................................H.......H+..T.............................................................(....*.0..7.........(....}.......}.......}......|......(...+..|....(....*..0..7.........(....}.......}.......}......|......(...+..|....(....*..0..7.........(....}.......}.......}......|......(...+..|....(....*..0../.........(....}.......}......|......(...+..|....(....*..0..,.......r...p.#(....~.....(...(......(....,...(....*..(....-..(....-.(...+*.s......o ...*....0..........r!..ps!.....(....-..("...-..*..(#...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):18072
                                                        Entropy (8bit):4.993302880106232
                                                        Encrypted:false
                                                        SSDEEP:96:hrdx0GReGWeGFuGgeKCUDuTeHOTu0U5e3eTOaUmS0SXStuKhubUfSJeZedUabepR:hr3PUDRTHffI3
                                                        MD5:2260AB9C0A196BD452ED5C054913C15A
                                                        SHA1:10E3F9E4E3A618CC7D9C84D7B81063F0303046BB
                                                        SHA-256:27C151986C017AD8821BF02DEFBF16809BDABDC04C06860FA42FBF928B12F2C4
                                                        SHA-512:CE3B0DDCE4BC24078455BB350A30C4CCE6E286AB8EB239A4399C2FDD6504711F814002C64D902C0F6B699F44E613C462F1171551A59997AF2801D49B8807D9A9
                                                        Malicious:false
                                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.6.2" />.. </startup>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Runtime.InteropServices.RuntimeInformation" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.2.0" newVersion="4.0.2.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Collections.Concurrent" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.11.0" newVersion="4.0.11.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):89344
                                                        Entropy (8bit):6.132595461044724
                                                        Encrypted:false
                                                        SSDEEP:1536:i1J8gR6Dhy90Ys9fhi8lMR1cYvHxGBd2Rch4E84pFSk+OMGq8O7HxR:i1SgGy90YAluLRkd2Ch4EZMGq8OT
                                                        MD5:F0849F773C01C34503D9DF6FEDC4418D
                                                        SHA1:750D900DB508DEFC8CB1AF1D134EBC164EFD0D2B
                                                        SHA-256:96C900057624D506B04A41B909B7BCFC6BBDF162DAF4301382BFA25A8F94AC75
                                                        SHA-512:641EA0466BDB8E9E8C96736DA810F8FC8B795602C7686083E4ACD0FE1AAA47944CD2E8F28B3DB34014FE797EAC9BE66F04D51ADEF818FE73661E4ACB0B4271E2
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...w.0..........." ..0..0............... ........... ..............................4u....`...@......@............... ...............................`...............6...'...........M..T............................................................ ..H............text........ ...0.................. ..`.rsrc........`.......2..............@..@........................................H.......p...d..........................................................."..}....*..{....*>..($.....(....*..(%...*.~....*.......*..,.....+..(<...s....*.(<...sC...*........o&...s'...zN........o&...s'...zZ..(......}(.....})...*6.~*....(#...*6.~*....($...*.0..?.........(+...},......}-......}.......}/.....|,.....(...+..|,...(1...*j..(-.....{)....o2...o3...*"..(4...*..0...........~*...(...+%-.&+...o5......r...pr...p.(6.....*...................s7....*...*Vs7........s7........*..{....*"..}..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):20736
                                                        Entropy (8bit):6.695835370502234
                                                        Encrypted:false
                                                        SSDEEP:384:A26au4ZUZKHTuWsXWn7Ki+RNyb8E9VF6IYinAM+oXCbZMUe3X:3SIsG7G1EpYinAMxyCUYX
                                                        MD5:C78A22830FF024AC5B2E3689CE762865
                                                        SHA1:2F383D6F16938E02FCEE12D3F81FCF812396F657
                                                        SHA-256:6254D58785B07415451BF6AFE2C4347752C9CDA3CA00CDA05AC87A4A5EA8A5DC
                                                        SHA-512:10EFE09CD7C8D1DF0891D733B90ECCCDA7A235E5E90DF40651FE7664D6B85A020102C14056201E546E6AE3CECE888C9D24A0D362F6151ACA552A880A926183DF
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...g.C..........." ..0.."............... ........... ..............................}.....`...@......@............... ...............................`...............*...'..........\@..T............................................................ ..H............text...S!... ...".................. ..`.rsrc........`.......$..............@..@........................................H........&...............................................................0..........s....%o.....o....%o......o....%o....(....o......o....o.....o......o....-....S.o.....+4s.......o....}.....o....(...+.......s....(...+-......o....-....,..o .....*.*......../.e........0..........s.......}......(!...-..{....("...,..*.o#..........s$...(...+..("...,..*..o&.....-....4.s'........o(...io)...s*........,...o .....,..o .....*......^..t........O.1.......6.(+....(....*:.u4.....o,...*6.(+....(....*:
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):17152
                                                        Entropy (8bit):6.792599298809396
                                                        Encrypted:false
                                                        SSDEEP:384:roEtjo1SPx2FahNyb8E9VF6IYinAM+oXCbt5f3/w:r1jiSPxqalEpYinAMxyJ5f/w
                                                        MD5:D4C2ED635866035126BF25E499C318FF
                                                        SHA1:E23BD43C58530FD44C15229E6F521E67BB981281
                                                        SHA-256:16660CC586F0D2E1584EFEA5FAE810EE4E2CEF650C2D168876BBDF925CCC8DE9
                                                        SHA-512:DA618759007C11490B66488E84ADAEC6F1759F1ABDCFEF816968F494925D2560D013CAB186C375FCFFC675D25F04043AF8BD8D12211CA2602A6B59659AD20847
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...d............." ..0.................. ........... .......................`.......y....`...@......@............... ...............................@..$................'...........2..T............................................................ ..H............text........ ...................... ..`.rsrc...$....@......................@..@........................................H........$..............................................................Z.....(..........(....*..0..F.......s......s......s......o......j.o....&.o........,..o......,..o.....&...*...(...... -..........17..........AA.......0..%............(.....(......,.......*.........*....0..7.......(.....o....s.......jo.....s.....o........,..o.....&...*..........(..........22......Z.....(..........(....*..0...........(.......&...*...................0..%............(.....(......,.......*.........*...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):46848
                                                        Entropy (8bit):6.0392294644627365
                                                        Encrypted:false
                                                        SSDEEP:768:Rr/1pChKODvwmyR8IuIMIFtBPAc+yyyEpYinAMxyy:R1UfwV8I/FtarLT7Hxv
                                                        MD5:C4E5CA3A57FAF51B187C582E2016AE2D
                                                        SHA1:70901365DEE46FD5DEAC3F17A55157B0EDFBFD6D
                                                        SHA-256:BA72A36075788CE98E2DE070ED86B18A79D13D128131380C2999A4F468C6F08C
                                                        SHA-512:6DCA5D08EDE15CB52FDB3FC5B03DCD324FDB2624E0C2CCE2A236EAA9323BEE2546F73F60CA0F74403396C4C9AB6D03DD3FFD832D360FA2EA1445C331076B665E
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....4X..........." ..0.................. ........... ....................................`...@......@............... ..................................<................'..............T............................................................ ..H............text........ ...................... ..`.rsrc...<...........................@..@........................................H.......h_...F..........................................................>.(.......}....*..*.*n.s....}......(.......}....*....0............*.....{....o......o.....*>.{.......o....*..(....*..s....}.....s....}.....(.......}....*....0../........(.*.....{....o......o.....{....o.......o.....*..{........o.....{.........o....*..s....}.....s....}.....s....}......(.......}....*...0..B........).*.....{....o......o.....{....o.......o.....{....o......(o.....*..{........o.....{.........o.....{....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):155392
                                                        Entropy (8bit):6.054452868104396
                                                        Encrypted:false
                                                        SSDEEP:3072:p59hTo7p2YWjbL/bYAVEx9IHSy3ff6iONqsQe4iFnd76wmWJhAkKuIENdq6ixK6D:j9hTo7p2YWjbL/bYAVEx9IHSy3hw68kF
                                                        MD5:06877FCDFFC1D202EA20422FEA82E08A
                                                        SHA1:65004AA9E4AF445AA847684DF4D24C2D57A3004C
                                                        SHA-256:FBFFC8D84EB5148227D5C515C20EB9673ACA3B8DBFAB64A8B49D672014EBD77B
                                                        SHA-512:4922B8AAFB079954088AF182A0FFF3110AADAAD7C0E419D6E2068E07C3667BB6AD24982806DBC71B6A69DAF3F5C2EDAC8C52C5B7D4FBA8D97C91BB87A22B8940
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....?..........." ..0..0............... ........... ....................................`...@......@............... ...............................`..H............8...'...........N..T............................................................ ..H............text..../... ...0.................. ..`.rsrc...H....`.......2..............@..@........................................H............@............................................................{,...*"..},...*..{....*"..}....*..{-...*"..}-...*..{0...*"..}0...*..{/...*"..}/...*..{1...*"..}1...*..{2...*"..}2...*..{3...*"..}3...*..{4...*"..}4...*..{5...*"..}5...*..{6...*"..}6...*..{7...*"..}7...*..{8...*"..}8...*..{9...*"..}9...*..{:...*"..}:...*..{;...*"..};...*..{>...*"..}>...*..{?...*"..}?...*..{@...*"..}@...*..{A...*"..}A...*..{B...*"..}B...*..{C...*"..}C...*..{=...*"..}=...*..{<...*"..}<...*..{D...*
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):19712
                                                        Entropy (8bit):6.657277663369191
                                                        Encrypted:false
                                                        SSDEEP:384:v2a2tlLlCMstjYNsumHJHJk09ZPNyb8E9VF6IYinAM+oXCbsw5:v2D1l/s6GvzEpYinAMxy9
                                                        MD5:F7148FCD71D29B5604059335BFD7857E
                                                        SHA1:D9D28506C068B4B0CF3E528B4DB25FFDB9897A86
                                                        SHA-256:AE8119F57F2D32DDC2C82A59F003FC76F5577646E4871300F9827E0E79B9B9B2
                                                        SHA-512:B1360EA695F21DC1F796AFC6E9A4AD5E614C1AE3A2D30B9E86EFE7CFCAC1BD3C09E741F51A3B83AA0DEDF68E00C3BDA1C40A8EEB2CCC5E09CAB8C003D5A85AF2
                                                        Malicious:false
                                                        Antivirus:
                                                        • Antivirus: ReversingLabs, Detection: 0%
                                                        • Antivirus: Virustotal, Detection: 0%, Browse
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d....@............" ..0.................. ........... .......................`...........`...@......@............... ...............................@..<............&...'..........D;..T............................................................ ..H............text...M.... ...................... ..`.rsrc...<....@....... ..............@..@........................................H........&..8...........................................................:.(......}....*..*.*j.s....}......(......}....*..0............#.....{....o......o.....*>.{.......o....*..(....*..s....}.....s....}.....(......}....*.0../........(.#.....{....o......o.....{....o.......o.....*..{........o.....{.........o....*..s....}.....s....}.....s....}......(......}....*....0..B........).#.....{....o......o.....{....o.......o.....{....o......(o.....*..{........o.....{.........o.....{......(.o...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):137472
                                                        Entropy (8bit):6.006126753953053
                                                        Encrypted:false
                                                        SSDEEP:3072:KH13g5srGIl9TxmnJ4MRr3JLqHEowJ4888888888b888888888888lV88888888R:Y3Wy2ao
                                                        MD5:2B49CA34C0D6ED282957F12CD5F14D7D
                                                        SHA1:7CA14D904B88846DC56D9F090873D50E4DE03659
                                                        SHA-256:D208B2D377FE8F55390717ADCE4D97B3BBB8ECB527D631252B3C1B2EDA216675
                                                        SHA-512:C0C57B70C5CF7346A94F24DFCD54A070DBA46314C974B8797A978DF69C0FB15B46AE9C64605C2E4BFCE50EE905BF725D2983E4FA4ACF80CFC8603B4D917F226A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...m2..........." ..0.................. ........... .......................@............`...@......@............... ............................... ...................'..............T............................................................ ..H............text........ ...................... ..`.rsrc........ ......................@..@........................................H............7............................................................(%....s&...}......(......}....*J.{....~.....o'...*J.{....~.....o(...*J.{....~.....o'...*J.{....~.....o(...*J.{....~.....o'...*J.{....~.....o(...*J.{....~.....o'...*J.{....~.....o(...*J.{....%-.&.*ov...*..{....*"..}....*..{....*"..}....*...0..?.........()...}.......}.......}.......}......|......(...+..|....(+...*"..(....*"..(....*"..(....*.r...p.{....ov...(,....(-.....(.....o....*.r!..p.{....ov...(,....(-.....(.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):28416
                                                        Entropy (8bit):6.561104795577471
                                                        Encrypted:false
                                                        SSDEEP:768:xtxEi6sUwwskPItslYsZByri0NTqEpYinAMxyM:xtxEipFwscItsykByW0pL7HxB
                                                        MD5:EB725E7553DCDD6287FB4179E16388BC
                                                        SHA1:B1512AE71B343EBA7555610562AF461B8D2E1A74
                                                        SHA-256:BC2AA3A3A3CF3636C69AAC0FDE885FAF3A4B5493EF925602919A28B079DF5C65
                                                        SHA-512:6BAD7E8C47A4425CBC91BAA8284A7373E1B52CF4E018E57091C46E1C19E6186165C3C9957D73D3CF6D4CCDBDD608CF06ECF583D270BFE441C8229E1653503525
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...Zw............" ..0..B............... ........... ....................................`...@......@............... ...............................................H...'..........(`..T............................................................ ..H............text....A... ...B.................. ..`.rsrc................D..............@..@........................................H.......04...+...........................................................0..A.......(....(....,...(....*(....(....,...(....*(....(....,..(....*~....*....0..B.......(....(....,...(....*(....(....,...(....*(....(....,...(....*~....*.(....(....,..(....&*(....(....,..(....&*(....(....,..(....&*..(....*..0..'.......~.........(....t............(...+...3.*..0..'.......~.........(....t............(...+...3.*..(....-&.~....%-.&~......[...s....%.....(...+*.*..(....-&.~....%-.&~......\...s....%
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):794368
                                                        Entropy (8bit):5.805440706166708
                                                        Encrypted:false
                                                        SSDEEP:12288:O5pgVVAGiRv93sxqoQx6XWCrh4j/00qHkUQ+:O5pgLhidRY8UdE/Hkk0
                                                        MD5:13D31B8CB4C4C199B2C07356B4023DF2
                                                        SHA1:2E8A9F50DC50631CFE76868DC151B51CF410CC1A
                                                        SHA-256:DE70F6204E4F920712E10935FB66CBFFAC18FFE368AF642F161DC5770C8B3CB5
                                                        SHA-512:0228E6CD91451B88914597396F58FBD903B3711CF719E557FFD4CC980B96E0829D04829138C3B4EA580556F49F3D4EDFAB9EEF2EA0C508E9EF2A0AE3B4CCA6CA
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................" ..0.................. ........... .......................@......cs....`...@......@............... ............................... ..H................'..............8............................................................ ..H............text........ ...................... ..`.rsrc...H.... ......................@..@........................................H..........D........... ..............................................^.(+.........(,...(-...*F.~....(.........*J.~..........(/...*F.~....(....t....*6.~.....(/...*F.~....(.........*J.~..........(/...*..s....*...0..........r...p.....(,........(,.........s0...(1........r#..p.....(,........(,...(2...s0...(1........r7..p.....(,........(,.........s0...(1........*^.(3.........(,...(-...*F.~....(.........*J.~..........(/...*F.~....(....t....*6.~.....(/...*F.~....(.........*J.~..........(/
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):41216
                                                        Entropy (8bit):6.684561374446608
                                                        Encrypted:false
                                                        SSDEEP:768:edaMlCDjNpenQ9ANYt9IUrdOBGiEpYinAMxy19q:e8MeZwnQOeIMj7Hxsq
                                                        MD5:13829A584B4819D3454F5E33373F152D
                                                        SHA1:3BEA5A25EED6BAB8D2FBDB3ED0CD427AB06EA931
                                                        SHA-256:0ABE332F60E8DCCFF640114B4A8A7C7B1020AFA6D24C2DF8279B4569736CB23A
                                                        SHA-512:F715F6947F410796087E14A64B4342D6D48A5649D2FCD444F2CC33DD10EBBCB7CE37CD1078D79DB617AD61B07DAAC79BB05448DDC5727BF325F8604F217DB762
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d.....S..........." ..0..r............... ........... ....................................`...@......@............... ..................................$............z...'..............8............................................................ ..H............text...kq... ...r.................. ..`.rsrc...$............t..............@..@........................................H........2...9...........k...$...........................................r...pr...pr7..p(.....(....-.(....*.(....o....*.r...pr...pre..p(.....(....,..(.....o....*n.{....~....( ...(!...("...*2.(!...}....*...0..B........{..........(#....(....,!r...pr...pr...p(......}.....(.....{...., r...pr...pr...p(.....{..........r...pr...pr]..p(....($.....o%...-&r...pr...pr...p(.....(.....{.........r...pr...pr...p(....(&.......,.....('...-#r...pr...prK..p(.....(.....{......I....r...pr...pr...p(.....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):55040
                                                        Entropy (8bit):6.352367501234968
                                                        Encrypted:false
                                                        SSDEEP:768:O67ktKzuJjYyNiCXFFa548Ld0uXQ7XhFAb7Prr8uxoJ7PVOcEpYinAMxyeQ:J7kUzuJjYyw0OyhGb7DrmP017HxC
                                                        MD5:A769FB7DC1C5F92D356E22482BE43782
                                                        SHA1:BDF5DFA96FA7E7D78FB2BA56CE0084125FF1F871
                                                        SHA-256:8D58A6BAC0D5788F847386BAD721E133BAE7B0D1990D78F16F8EC819FE2CBB8C
                                                        SHA-512:02203716F48AC89CA87ED03A6C8735AC9E1693A36027C26BFFCB27AD350C3ECD70144B549ECF802EFFC4B266DED4E268567AF3E327EF90EE335F345113FF114B
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...f.8..........." ..0.................. ........... ..............................[.....`...@......@............... ...................................................'..........T...T............................................................ ..H............text...M.... ...................... ..`.rsrc...............................@..@........................................H........B..............................................................6.{.....o....*...0..1.......sy......}.....{.....o....%-.&.*...z...s....(...+*....0..1.......s{......}.....{.....o....%-.&.*...|...s....(...+*....0..1.......s}......}.....{.....o....%-.&.*...~...s....(...+*....0..........~......-.r...ps....z.o....o.......(......,.r...pr3..prW..p( ....s!...zr...pr3..pr...p("...........(.......@............(......,.r...pr3..pr...p( ....s!...zr...pr3..pr...p("...(#.....($....Z.($....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):26752
                                                        Entropy (8bit):6.512503595653532
                                                        Encrypted:false
                                                        SSDEEP:768:DulwnBhYlTVv2wK5idcgF4of1n6K9zUYJ:ywHYFtKYdcg/f1nXzUYJ
                                                        MD5:970B6E6478AE3AB699F277D77DE0CD19
                                                        SHA1:5475CB28998D419B4714343FFA9511FF46322AC2
                                                        SHA-256:5DC372A10F345B1F00EC6A8FA1A2CE569F7E5D63E4F1F8631BE367E46BFA34F4
                                                        SHA-512:F3AD2088C5D3FCB770C6D8212650EED95507E107A34F9468CA9DB99DEFD8838443A95E0B59A5A6CB65A18EBBC529110C5348513A321B44223F537096C6D7D6E0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...$:............" ..0..4...........S... ...`....... ....................................`..................................S..O....`...............@...(...........R..T............................................ ............... ..H............text....3... ...4.................. ..`.rsrc........`.......6..............@..@.reloc...............>..............@..B.................S......H........'..P*..................,R........................................(....*..(....*^.(.......1...%...}....*:.(......}....*:.(......}....*:.(......}....*:.(......}....*..(....*..(....*..(....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*..(....*:.(......}....*..{....*^.(.......2...%...}....*:.(......}....*..{....*z.(......}.......2...%...}....*V.(......}......}....*..{....*..{....*:.(......}....*..{....*..{....*"..}....*..{....*"..}....*..{
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21216
                                                        Entropy (8bit):6.900655456226697
                                                        Encrypted:false
                                                        SSDEEP:384:/N9VWhX3WsQBm0GftpBjvmaQHRN7YlgaGn7rJd0:1GmViYL0Gff0
                                                        MD5:76B8D417C2F6416FA81EACC45977CEA2
                                                        SHA1:7B249C6390DFC90EF33F9A697174E363080091EF
                                                        SHA-256:5EAA2E82A26B0B302280D08F54DC9DA25165DD0E286BE52440A271285D63F695
                                                        SHA-512:3B510CDC45C94BE383C91687C2CB01A501BA34E3FBB66346214FC576D6F0E63C77D1D09C6419FC907F5B083387A7046C0670377AD2E00C3EC2E731275739F9C7
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?..Y.........." ..0..............(... ...@....... ....................................@.................................T(..O....@..0................>...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc...0....@......................@..@.reloc.......`......................@..B.................(......H.......P ..L....................&......................................BSJB............v4.0.30319......l...|...#~......<...#Strings....$.......#US.(.......#GUID...8.......#Blob......................3......................................................\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.7...K.W...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):26496
                                                        Entropy (8bit):6.147606968484159
                                                        Encrypted:false
                                                        SSDEEP:384:j4nLpSumfSQrlHViaCZYvLPQmlJLfjnWn6GWfdHRN76+fVlGsa9h:j4QVrxViR9mlxd96lv
                                                        MD5:59C48AACB1C413C108161AFE13FDBED9
                                                        SHA1:31ACE4B26D8A069C84AAD6001E06C2A5483806F3
                                                        SHA-256:E9A9D281C1A708AAAE366F82FD6A1742F65DA2918CC4FA5EAAAADA0BE24277D9
                                                        SHA-512:8252ABE64C67863D9E4C70E820F0C69C517B8678A4B4C13A436118BC276E5F21E84522B93566C0BC009EFFCB251ED67BDBC60E4907ABEA2F33B6BE3764E28D1D
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....j............" ..0..:..........jX... ...`....... ..............................a.....`..................................X..O....`...............D...#..........$W..T............................................ ............... ..H............text...p8... ...:.................. ..`.rsrc........`.......<..............@..@.reloc...............B..............@..B................LX......H........$..8"...........G.......V.......................................~....*..0..1.......(....,..%-.&.*..(.....o.......&...,...o....,..*.*....................(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%...%...%...(....*....(....*.(....,"r...p......%...%...%...%....(....*......(
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):24704
                                                        Entropy (8bit):6.51349660965756
                                                        Encrypted:false
                                                        SSDEEP:384:xMI6w0w2PYDtSJNnNFfWr6JWsK/WyRIHRN7NVOQGR9zEzC:axw2QDt0FxDKuo0NVOQ69z1
                                                        MD5:1ADB721381E8CD1995DF10011B151A5D
                                                        SHA1:FE370431132004A69214297C326121F7CEF67522
                                                        SHA-256:661062F43BF973E2714BF63312590DF327143489F8E049D9D450D3BE21FFD372
                                                        SHA-512:A24198696D4431C6DA910A91833401E5CAE0A088834508C68F8147DE3FC1D0E4BADADEF6F1ECA9DB3EDCC90065D119DC01E801CBDA04D23CB2D556591FA062FD
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..............M... ...`....... ....................................`.................................AM..O....`..d............8...(..........PL..T............................................ ............... ..H............text....-... ...................... ..`.rsrc...d....`.......0..............@..@.reloc...............6..............@..B................uM......H........$..h"...........G.......K........................................(....*:.(......}....*.~....*...0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%...%...%...(....*....( ...*.(....,"r.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):711952
                                                        Entropy (8bit):5.967185619483575
                                                        Encrypted:false
                                                        SSDEEP:12288:GBja5bBvR8Q0TE2HB0WLmvXbsVG1Gw03RzxNHgKhwFBkjSHXP36RMGy1NqTUO:GBjk38WuBcAbwoA/BkjSHXP36RMG/
                                                        MD5:195FFB7167DB3219B217C4FD439EEDD6
                                                        SHA1:1E76E6099570EDE620B76ED47CF8D03A936D49F8
                                                        SHA-256:E1E27AF7B07EEEDF5CE71A9255F0422816A6FC5849A483C6714E1B472044FA9D
                                                        SHA-512:56EB7F070929B239642DAB729537DDE2C2287BDB852AD9E80B5358C74B14BC2B2DDED910D0E3B6304EA27EB587E5F19DB0A92E1CBAE6A70FB20B4EF05057E4AC
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...p$?..........." ..0.............B.... ........... ....................... ............`....................................O......................../.......... ...T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B................$.......H.......x...(9............................................................(....*..(....*^.(...........%...}....*:.(......}....*:.(......}....*..(....*:.(......}....*..{....*..(....*..(....*:.(......}....*..{....*.(.........*....}.....(......{.....X.....}....*..0...........-.~....*.~....X....b...aX...X...X..+....b....aX....X.....2.....cY.....cY....cY..|....(......._..{........+,..{|....3...{{......(....,...{{...*..{}.......-..*...0...........-.r...ps....z.o......-.~....*.~....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):50
                                                        Entropy (8bit):4.648367439558377
                                                        Encrypted:false
                                                        SSDEEP:3:FX4GdeWu6UymXOSRNSIkq:tjdeWuJymeS5
                                                        MD5:9DD05BC401CC062A617ED4D8A9F01968
                                                        SHA1:B176600648B3E0955031F7656E22DAC3FC3C10A5
                                                        SHA-256:785ACBF7A80B3A191508DE2EE4CA600CE48A1ABD4FDA387872A2FE79726E6E49
                                                        SHA-512:B659FD3D6FFEC4389F95B2A073EEC095D4AB129A848F68B7C5841216F5DBCAA59EF974576B13F9E529211E2CAE461A2F942E4FDCBA78EE0DCBE46A2D9D1D9BFA
                                                        Malicious:false
                                                        Preview:AirWatchLLC.WorkspaceONEAssist_htcwkw4rx2gx4!App..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):859
                                                        Entropy (8bit):3.5175377128041263
                                                        Encrypted:false
                                                        SSDEEP:12:TMHd4f5zi3ysxsDiOOhQlynseTQOTQlynsmfVFuNFuazim:2dY3yxhd3TVTdZr2Nd
                                                        MD5:2571EBD0D6200D1E4E0B3B7A5480AA51
                                                        SHA1:08A44B3C72B6386D6271D3AE69BEA3C35B37ABCA
                                                        SHA-256:24F5FE6EE910B15BEC15721F9C1C18911B93DA2A1B12DF93017581EC095BD36C
                                                        SHA-512:E8A3EF4C48846FCA3C23FB3D9EC9823BD9C47DCE11EB487EF2713D7A4A07C371413453FC6F77294866582EB8704652ADC642C1C09DAB542FFA12A3FE496C2F4E
                                                        Malicious:false
                                                        Preview:<?xml version="1.0" encoding="utf-8" ?>.. <wap-provisioningdoc>.. <characteristic type="AppInstall"> .. <characteristic type="AppxPackage">.. <parm name="AppXPath" value="C:\PROGRAMS\CommonFiles\Xaps\f7529f1a891c4c29afa0bf940c4958e4.appxbundle" />.. <parm name="LicensePath" value="C:\PROGRAMS\CommonFiles\Xaps\f7529f1a891c4c29afa0bf940c4958e4_License1.xml" />.. </characteristic>.. </characteristic>.. </wap-provisioningdoc>
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Zip archive data, at least v4.5 to extract, compression method=store
                                                        Category:dropped
                                                        Size (bytes):2602535
                                                        Entropy (8bit):7.976304419953961
                                                        Encrypted:false
                                                        SSDEEP:49152:0ctA6gk+iCKo/o8ePRm/v2bbB6+3p4nuGUF1HhRTIMWU3:0a+ViCBQ8e8/UB6EpzBWMWs
                                                        MD5:0A8FC8C63DAEDF561B6CC448974FD857
                                                        SHA1:58ADFE3FFACFB211283A684A26199E879ABEF74D
                                                        SHA-256:9B1D2AF876F78E2E7398F141EE5346E601FA4D405DD17D54BD635B2CC486189E
                                                        SHA-512:13B8AE554887AB14C4CD17BB01B18734DAE6890C3664EC78F2FDF00742426AA859CFF49877A3330EC1777D4609959949BFB9CF0D410E9298D913EEC57F38C6F9
                                                        Malicious:false
                                                        Preview:PK..-.....#.]X............&...AetherPal.MSIX_24.3.0.0_scale-100.appxPK..-.......]X................Assets/LargeTile.scale-100.png.PNG........IHDR...6...6...........pHYs..........o.d..-.IDATx.....\U./..9..^.wg....C.... .2...P.Q.qTT\x....q....#"....2.YT..$!tge'.$$......;.....I....]'..V.k.u.I.r.....b..>...RC...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......(.....A...r.l......m.5.;....V.4....]..HMa.V.......s...1...eI.X.kz......]...dYo.........d.P.6(o.6.?...o.m...qc..V.O,6I......%.6...|..C........~..>.....LD[2IF"....z{.].5.....E.^.........w......2...?m|.aY...Jn?&
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:ASCII text, with very long lines (2693), with no line terminators
                                                        Category:dropped
                                                        Size (bytes):2693
                                                        Entropy (8bit):5.935569350364311
                                                        Encrypted:false
                                                        SSDEEP:48:l8dmLkq+Hz3R6RY20rLYMsLmczH6Lh6QvL3+m5z5Gv8+L+XnnDaD6SCG5:ImYNTEp0rhsiWHsLFzVFXnDOKG5
                                                        MD5:0443B3EF83B24487EAD3FE85935628F6
                                                        SHA1:AB9F20708881483B8884A0FF0E024EF48D07F1F6
                                                        SHA-256:05DDB89B045DC2B67316963AE970AD1B95682C1312D665BC76458F1EC85B46AD
                                                        SHA-512:4F924DD24C71BE690841934F05E4CE4C3F20A42AA1389F162ADCB254D6D4A472F1AF1B4F81A4AEBAFECF61BF2D181BB30ADF92BFC32056FFE74C338CE5FBF9DE
                                                        Malicious:false
                                                        Preview:<License xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" ID="5ce96754-68f2-4b38-908b-220f1a2273ba" LicenseID="b84ed2f1-264b-6290-35d1-007301d5f9d5" ContentID="1f0a1a56-6cd3-5be8-eaef-3d6f996926d7" Version="3" xmlns="urn:schemas-microsoft-com:windows:store:licensing:ls"><Binding Binding_Type="Machine"><ProductID>9P65VD6QM68L</ProductID><PFM>airwatchllc.workspaceoneassist_htcwkw4rx2gx4</PFM><LicenseInstanceID>66d36c14-111e-4866-9baa-532e0e67de15</LicenseInstanceID><RequestorID>f0c9998e-e898-d2a1-0759-7534fb1c8a43</RequestorID><LeaseRequired>False</LeaseRequired></Binding><LicenseInfo Type="Full" LicenseUsage="Offline" LicenseCategory="OEM"><IssuedDate>2024-03-01T01:52:56.3500036Z</IssuedDate><LastUpdateDate>2024-03-01T01:52:56.3165233Z</LastUpdateDate><BeginDate>2024-03-01T01:52:56.3165215Z</BeginDate></LicenseInfo><SPLicenseBlock>FAAAAMIAAADJAAAACgAAAAMAAQD4NOFlAgDLAAAAEAAAAPHSTrhLJpBiNdEAcwHV+dXOAAAAWgAAAGEAaQByAHcAYQB0AGMAaABsAGwAYwAu
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21176
                                                        Entropy (8bit):6.887075475210058
                                                        Encrypted:false
                                                        SSDEEP:384:uDNxWQFW5+109m0GftpBj9yaQHRN7SAl78oSwDnu/L:uDNV+Vi+LSyaw6L
                                                        MD5:8CC4C7DFEB41B6C227488CE52D1A8E74
                                                        SHA1:93702135DB0646B893BABE030BD8DC15549FF0C2
                                                        SHA-256:9DC115AC4AADD6A94D87C7A8A3F61803CC25A3D73501D7534867DF6B0D8A0D39
                                                        SHA-512:E4DA7E3AE5CA31E566EA0475E83D69D998253FB6D689970703A5AD354A2AAD1BB78D49A2C038F0A3C84A188D091696191B04E4A39253DEB3B6CB310B72F02F97
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?..Y.........." ..0.............f(... ...@....... ..............................ZY....@..................................(..O....@...................>...`.......&............................................... ............... ..H............text...l.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................H(......H.......P ......................\&......................................BSJB............v4.0.30319......l...|...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................z...............\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.....K.N...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):20856
                                                        Entropy (8bit):6.425485073687783
                                                        Encrypted:false
                                                        SSDEEP:384:/rMdp9yXOfPfAxR5zwWvYW8a2cyHRN7vCvlbLg:/rMcXP6N6e
                                                        MD5:ECDFE8EDE869D2CCC6BF99981EA96400
                                                        SHA1:2F410A0396BC148ED533AD49B6415FB58DD4D641
                                                        SHA-256:ACCCCFBE45D9F08FFEED9916E37B33E98C65BE012CFFF6E7FA7B67210CE1FEFB
                                                        SHA-512:5FC7FEE5C25CB2EEE19737068968E00A00961C257271B420F594E5A0DA0559502D04EE6BA2D8D2AAD77F3769622F6743A5EE8DAE23F8F993F33FB09ED8DB2741
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....jM^.........." ..0..$..........BC... ...`....... ....................................@..................................B..O....`..@...............x#...........A............................................... ............... ..H............text...H#... ...$.................. ..`.rsrc...@....`.......&..............@..@.reloc...............,..............@..B................$C......H........'...............?..X...8A......................................j~....%-.&(....s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*.~....*2r...p.(....*B.....(.........*R.....(...+%-.&(!...*^.....("....(...+&~....*.s$...*"..s%...*..(&...*.*....0......................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):32384
                                                        Entropy (8bit):6.250631046498082
                                                        Encrypted:false
                                                        SSDEEP:768:/ccaU602gaB3EqYChzZpXc2uo0hGJm9zWAw:EcaGsYCh1pX0o0PzWAw
                                                        MD5:BCD6DAAE1022CBE0C86DA778CB874B6C
                                                        SHA1:0C696CA7F7A0AE7F6C749C6376D61F79A56BF82C
                                                        SHA-256:D4047CDC0C372B06AFC9CBED39B717FAC18DCED723E5851806A19F1BF42DE1A3
                                                        SHA-512:EAB2278FFAC26B21DF01FAD86EB7747BAE59706F854E4BC86EFE536904210258BFDD79AAE1090D25DE40FA8852C23844CF8DDEA6C487CD6221E30BF8174083B2
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..J...........i... ........... ..............................QX....`.................................yi..O....................V...(...........h..T............................................ ............... ..H............text....I... ...J.................. ..`.rsrc................L..............@..@.reloc...............T..............@..B.................i......H.......t%...4..........dZ......$h........................................(....*:.(......}....*.~....*...0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%...%...%...(....*....( ...*.(....,"r.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21224
                                                        Entropy (8bit):6.941945190587086
                                                        Encrypted:false
                                                        SSDEEP:384:Jm2igOWnW8rWwvT1Dm0GftpBjVjaQHRN70lxBGDD:5t/1DVinjLSMD
                                                        MD5:559C98EB9633C7BA1BC813F8E6E0E9A5
                                                        SHA1:311F52B31611E6DC5FD4C0159BFA452C22980CA7
                                                        SHA-256:CC62F3B867D50083C2932061F20662C698D2E1A741C4D2F9DF1FD2D435E3EF3C
                                                        SHA-512:E241C16869D1CDBB2C6482A7C5B2AF93DE4BA0CEF8185B8826EEE35ECB174F35F7585C8AE0320F7F4F6B80F3BB5B3EDAE2383760F2F35637F03C3A0E38E0875C
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?..Y.........." ..0..............)... ...@....... ..............................X.....@.................................t)..O....@..D................>...`......<(............................................... ............... ..H............text........ ...................... ..`.rsrc...D....@......................@..@.reloc.......`......................@..B.................)......H.......P ..l....................'......................................BSJB............v4.0.30319......l.......#~..d.......#Strings....@.......#US.D.......#GUID...T.......#Blob......................3................................................n.o.....o.....\...........8...3.8...P.8.....8.....8.....8.....8.....8.....1.....8.................V.....V.....V...).V...1.V...9.V...A.V...I.V...Q.V...Y.V...a.V...i.V...q.V.......................#.....+.....3.....;.....C.:...K.Z...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21224
                                                        Entropy (8bit):6.939816403058967
                                                        Encrypted:false
                                                        SSDEEP:384:2napn1iwwPWcGWNhvT1Dm0GftpBj/aQHRN7oIBldBoQAY0GP:lDuF91DVi1LoIzoJYR
                                                        MD5:45FF71114047DBF934C90E17677FA994
                                                        SHA1:526C688E71A7D7410007AD5AA6EA8B83CACE76C5
                                                        SHA-256:529943C0CDF24F57E94BF03FAC5F40B94A638625027A02DF79E1E8CB5D9BC696
                                                        SHA-512:29684AC5391268EAA276196A6249364F6D23ABFE59BDC304A561CF326CEA6CD662FA04C05E15924FD6D3F9E9D1607992B8DCAD3F817CFE891580F9D9462FE9B7
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............)... ...@....... ...............................>....@.................................p)..O....@..@................>...`......8(............................................... ............... ..H............text........ ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B.................)......H.......P ..h....................'......................................BSJB............v4.0.30319......l.......#~..t.......#Strings....<.......#US.@.......#GUID...P.......#Blob......................3................................................F.o.....o.....\...........,.....,...(.,.....,...f.,.....,.....,.....,.....%.....,.................V.....V.....V...).V...1.V...9.V...A.V...I.V...Q.V...Y.V...a.V...i.V...q.V.......................#.....+.....3.....;.....C.:...K.Z...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21224
                                                        Entropy (8bit):6.942827969586567
                                                        Encrypted:false
                                                        SSDEEP:384:2ZHLaEav5aaUa6arWVLWOvT1Dm0GftpBjq1xFaQHRN71mldBoQAYu:rPv5t/NOF1DViQ1xFLcoJYu
                                                        MD5:B52C339601CB264F83DF72D802E98687
                                                        SHA1:8BBB7BADAAA912C1F17775E9ACDCAB389704C772
                                                        SHA-256:938DA38561DA54793944E95E94B6E11CF83AACD667487297D428FBCE1C06DC9C
                                                        SHA-512:287F08AB07827570F9F3EF48A6D7E5C186899A2704FB3DBAF36975F6BE7B29FB6695A69FAB85A6F09BDDEFB60C79052C3A33CF862651F892EB9D773D880B3AF8
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?..Y.........." ..0..............)... ...@....... ....................................@..................................)..O....@..P................>...`......P(............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..........#Strings....T.......#US.X.......#GUID...h.......#Blob......................3..................................................`.....`...t.M.................................=.....V.................q.....Z...................G.....G.....G...).G...1.G...9.G...A.G...I.G...Q.G...Y.G...a.G...i.G...q.G.......................#.....+.....3.....;. ...C.;...K.[...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21696
                                                        Entropy (8bit):6.848992181946284
                                                        Encrypted:false
                                                        SSDEEP:384:h6iIJq56dOuWSKeWkvT1Dm0GftpBj0RaQHRN7T7lxBGDto:viAw1DViKRLTxMi
                                                        MD5:1D8AAFECA1EA565B257384D3F64864B0
                                                        SHA1:4D923B100142AFA2E0A8B7ACDB3A6DE6FEB91148
                                                        SHA-256:C2250E9E51B44D8AB8C5B892592766925F6580EE00B95026621D0AFB037C2707
                                                        SHA-512:99E4A226E1FABB348E7EF7C6FA56AD0CE4E4CF5D8569CE21881703DCA8D83A1C113FD5F440A4FC9E9B99A04AE8CF4490E17D62FFC09CFAC5A45678A4419EFDBB
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...?..Y.........." ..0..............*... ...@....... ..............................J.....@..................................*..O....@...................>...`......L)............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ..|....................(......................................BSJB............v4.0.30319......l.......#~..|.......#Strings....\.......#US.`.......#GUID...p.......#Blob......................3................................................k.~.....~.....k...........*...0.*...M.*.....*.....*.....*.....*.....*.....#.....*.....x...........e.....e.....e...).e...1.e...9.e...A.e...I.e...Q.e...Y.e...a.e...i.e...q.e.......................#.....+.....3.....;.....C./...K.O...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21768
                                                        Entropy (8bit):6.880530414500754
                                                        Encrypted:false
                                                        SSDEEP:384:/nzz+MpSaLWW0+WNC7Bm0GftpBjsY1xaDaQHRN7RlTZVkRzQ:npuAViVxaDLHZV+Q
                                                        MD5:6067ECBAB3C6DDDB6BF7C49C7948CAA8
                                                        SHA1:5F3DA777AF01DBC159BD8D9D97D5DC105918AFC5
                                                        SHA-256:22108E32E0B6E42F5F52A4CB17B9B6FA3DFD547ECD9EEF9C67226DBEC54D23E5
                                                        SHA-512:9F3E834B8342E0C7AA5CCC993B520D664B03F1F0091066C66067923E1D4991EFA03F63908552538C05F423AA2B696DE7C76993F71A7564F3E87662CB0FC00726
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0.............B*... ...@....... ....................................@..................................)..O....@...................?...`.......(............................................... ............... ..H............text...H.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................$*......H.......P ......................8(......................................BSJB............v4.0.30319......l.......#~..t...@...#Strings............#US.........#GUID....... ...#Blob......................3............................................................V...........j.................i...........8.................S.....<...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.'...C.B...K.b...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21752
                                                        Entropy (8bit):6.916008128976572
                                                        Encrypted:false
                                                        SSDEEP:384:fGhr+YUfyHxsW/HWiC7Bm0GftpBjoEKaQHRN7VlO62gHcXn2d:MkmyViaLEg832d
                                                        MD5:2F39655CCFC010E32A7240D9BF5D0852
                                                        SHA1:20AEAED12DFB8D71E39687350EB12BC0DE372AF0
                                                        SHA-256:BFCD867F71C887429DFE008D7EC5D1853D15B3932D4CE8991694293477B5BE37
                                                        SHA-512:9769E59279A32F29C2F2C6970C81D3ED76FE3421B819DDFFC8FA98329F1B45300C737FDF71956672F80F69B3A75727D184F8C421E00B84E94163A86CB744A991
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............+... ...@....... ...................................@.................................<+..O....@..`................>...`.......*............................................... ............... ..H............text........ ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B................p+......H.......P ..4....................)......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................................Y.]...{.]...6.J...}.....r........... .............................................................D.....D.....D...).D...1.D...9.D...A.D...I.D...Q.D...Y.D...a.D...i.D...q.D.......................#.....+.....3.....;."...C.=...K.]...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22784
                                                        Entropy (8bit):6.859096700065679
                                                        Encrypted:false
                                                        SSDEEP:384:BRE+ruiA5vzWeNWnvT1Dm0GftpBj94aQHRN7N+ql78oSwDnuQM:BS9bW1DVib4L5awfM
                                                        MD5:D1699287934DA769FC31E07F80762511
                                                        SHA1:BFE2384A92B385665689AD5A72F23ABC8C022D82
                                                        SHA-256:0DBB92ECD5DFA7FC258BC6DEED4CECF1B37F895457FD06976496926ABDB317BB
                                                        SHA-512:4FEF3E1535F546FFDDE0683F32A069BEEFFE89096524C7068F1F5CE8377824F82AE530D3990C9DD51BCCAA9E53FDED5613FA1174013325808059276DEE771187
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0............../... ...@....... ..............................:.....@................................../..O....@..p................?...`......T................................................ ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B................./......H.......P .......................-......................................BSJB............v4.0.30319......l.......#~......@...#Strings....T.......#US.X.......#GUID...h.......#Blob......................3................................;.....Y.........8...........<...........P.......................X.....q.....g................."...................I.....I.....I...).I...1.I...9.I...A.I...I.I...Q.I...Y.I...a.I...i.I...q.I.......................#.....+.....3.....;.%...C.@...K.`...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21192
                                                        Entropy (8bit):6.910097922783346
                                                        Encrypted:false
                                                        SSDEEP:384:HT+6ywnVvW0LWqvT1Dm0GftpBj+XaQHRN7qn0lTZVk0N:H9911DViYLqeZVdN
                                                        MD5:632CC8AD69B76FD9BB5847DE1E1439F7
                                                        SHA1:2E32D50EC33EC6635681485B754F4E58D434A5EE
                                                        SHA-256:5E61D755616CB10524F5F31E9B70C65A7FFF8E30E25CE711AC8B354D657AB479
                                                        SHA-512:9BA5CC82573308E5D995BA05BC660FC1C087EB91D8BD7EFCA6FF838A3C47BD6118D9C92919B2E0DAC11A5A27977318C5C819499DC19CD5D6E57122A0749858C6
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............)... ...@....... ....................................@..................................(..O....@...................>...`......|'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~.. ...h...#Strings............#US.........#GUID...........#Blob......................3......................................................\.....0.....7.....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.2...K.R...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21160
                                                        Entropy (8bit):6.908265030965905
                                                        Encrypted:false
                                                        SSDEEP:384:iRbzriaXT+WlEWLC7Bm0GftpBjXUNZiTaQHRN7hldBoQAYv8:A7icYVisiTLToJYU
                                                        MD5:EA9376C17EE0148F0503028AD4501A92
                                                        SHA1:9D5686CBF45E90DF5E11D87E7B90173A1A64B1A0
                                                        SHA-256:B537313413F80105F143CC144FEEAE2AC93F44747727DE309A71D57D2650034A
                                                        SHA-512:18D1BB2D5C469644078D75766DBF04ADDF7D0C543F7ED15FF522CEEAEF960900DD8EC68172F5D684B76B0AA6946BB38D641F021EC04C70AD66A6062C10412E0A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0.............6)... ...@....... ...............................U....@..................................(..O....@...................>...`.......'............................................... ............... ..H............text...<.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ......................,'......................................BSJB............v4.0.30319......l.......#~..H...x...#Strings............#US.........#GUID...........#Blob......................3......................................................k.....?.....$.....S.................R...........!.....j...........<.....%...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.+...K.K...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):154448
                                                        Entropy (8bit):5.513799122521585
                                                        Encrypted:false
                                                        SSDEEP:3072:wdYO+3m9R6e1x03BZ6bDSzZ8B0uAP+Pch:i+2jv1x0ebezWiumh
                                                        MD5:D712A5A82A446086443CE00B610D8A5D
                                                        SHA1:7ADD96BAA123DB819F2F3D5AA62D6F872CE8FE14
                                                        SHA-256:1C7BFF6F16BB618648E699B723AEAFE511515CD6AAD699C25FAAE2A507E22811
                                                        SHA-512:225128E58E2F01B5CAADA6FE54B1D32FF6A700542CE22B425649AB22DA2944F796F04D1A2428C542BCAB5348A161CF73F5F9A1E7BBF1F6417C4D507217FE3FD0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..............,... ...@....... ..............................DR....@..................................,..O....@..................P?...`.......+............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H........A...............?..h...t+......................................j~....%-.&(....s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*2r;..p.(....*2ro..p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2rK..p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2rM..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21736
                                                        Entropy (8bit):6.879068263314492
                                                        Encrypted:false
                                                        SSDEEP:384:8RtRWjYWYvT1Dm0GftpBjaGaQHRN77TlgaGn73:+i61DViUGLHG7
                                                        MD5:99373AB10858746AAD424F28B48277F5
                                                        SHA1:5042EE630A6C7C2986E8323A14D052C1D83B6F61
                                                        SHA-256:9C4AE61E0E8365762EFE3D34C5595029F2C12E0079E6070720E2CEF0882C84E5
                                                        SHA-512:E96F8FDD6FFB702D344746CE82DE576BBA8636EDE3E39A7DA18CCF8A0178B8346FD31140760B864F1487D7804D931FF1A18DE07A4CAFA0CF79BDB340421FC03F
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............*... ...@....... ..............................mG....@.................................x*..O....@..@................>...`......@)............................................... ............... ..H............text........ ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B.................*......H.......P ..p....................(......................................BSJB............v4.0.30319......l...@...#~..........#Strings....H.......#US.L.......#GUID...\.......#Blob......................3..................................................-.....-.........M...........[.................'.....@.................[.....*...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.9...K.Y...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21208
                                                        Entropy (8bit):6.940882019021464
                                                        Encrypted:false
                                                        SSDEEP:384:IeWnoWMC7Bm0GftpBjVwaaQHRN7g20lgaGn771Y:InTViMaLnYGtY
                                                        MD5:8B8C402311D7AB87E588675E736414FD
                                                        SHA1:EB8C010A35B461402C1C33133F1B61C78BE8425A
                                                        SHA-256:55A30D92D163CF1807BEA6DC13B4C13E70AEBBB034DC77EAEF4F4394730DCD8E
                                                        SHA-512:D03F450A3A19320DE71145E48CD7C088D9B50D0A683CC9A79D8967DCE085A6F63CBE537FCA1C6208865EB52EAFB10189613C7233047318CAEB2FB2C23C34A269
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............)... ...@....... ....................................@.................................X)..O....@..$................>...`...... (............................................... ............... ..H............text........ ...................... ..`.rsrc...$....@......................@..@.reloc.......`......................@..B.................)......H.......P ..P....................'......................................BSJB............v4.0.30319......l.......#~..X.......#Strings....,.......#US.0.......#GUID...@.......#Blob......................3......................................K.........]...........d.............o...".o...?.o.....o...}.o.....o.....o.....o.....h...-.o.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.5...K.U...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):35456
                                                        Entropy (8bit):6.252306254622891
                                                        Encrypted:false
                                                        SSDEEP:768:IUnjYQng2w3yhGfmAXOaYbEVnuo0xfOQ69zh:IUnPCGLbEko0Mzh
                                                        MD5:376F3147F713A0C46A6C83498A8DBF26
                                                        SHA1:44050D05EA2C3362965884E836D3748EC62A8BE0
                                                        SHA-256:7E451AD27D83C4A82786842BF3D068EE581F43468A811986916B2FCD460804D8
                                                        SHA-512:C2DC91CE490E9C5254C9209B6E677685DA2BFE8AB19364C50888511EDE3913DA1881F6E0E28C78E49FC084B1853AE1933D0597153671226C281C707E6D84D32A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...C............" ..0..X..........Fw... ........... ..............................9.....`..................................v..O....................b...(...........v..T............................................ ............... ..H............text...LW... ...X.................. ..`.rsrc................Z..............@..@.reloc...............`..............@..B................'w......H........&..|7..........T^..0....u........................................(....*:.(......}....*.~....*...0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...( ...*.(....,.r...p......%...%...%...(....*....(!...*.(....,"r.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21248
                                                        Entropy (8bit):6.908174280383857
                                                        Encrypted:false
                                                        SSDEEP:384:m6oWJjWlC7Bm0GftpBjJeiaQHRN7t2H9lO62gHcXq:m6vpVi+iLtecg8a
                                                        MD5:0D9A641105098D642567B22101A4DE0B
                                                        SHA1:12419C25D1C2EB706A4E4E649EE353CEDA7446A9
                                                        SHA-256:7C25A74772E135257235640A0264DDC05235E14F3627896CFE735E9955155F83
                                                        SHA-512:FD4560CDF01DE237DDF797A33C5DBC220D3FCAE07EDE17D43C39F5562E36E03646676A87E20699D7603FCA6D84F66C8756EB863DD4727B7E1A499619BB88DDE1
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............(... ...@....... ..............................@.....@.................................H(..O....@..p................?...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc...p....@......................@..@.reloc.......`......................@..B................|(......H.......P ..@....................&......................................BSJB............v4.0.30319......l...|...#~......(...#Strings............#US.........#GUID...$.......#Blob......................3......................................z...............\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.$...C.?...K._...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):44672
                                                        Entropy (8bit):5.933764820619879
                                                        Encrypted:false
                                                        SSDEEP:768:U5QXOoy47Gm2RG32rLMnnnkarAB8uo0NCOQ69zGT:U5vz2HGrkADo0Fz+
                                                        MD5:FEF8FA2ED7568A6C16CDA1F2270C3734
                                                        SHA1:E2F1FB213EFC86EE80F8BB15C67D7600AFB6116F
                                                        SHA-256:28491784CF9E26F697EE7DB054EA1DDA2265BB0D3B405A9DA2C31ACB53F412AE
                                                        SHA-512:BD502DBAFB70C117B463914691B04C92B64DE687365F649469F7BE17C4DAEDAADC43B0E95B0B032141D88DCC612BF5D7BF3B6F57B634B6C17F37670402273CF1
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....O..........." ..0..z.............. ........... ....................................`.....................................O........................(..............T............................................ ............... ..H............text....x... ...z.................. ..`.rsrc................|..............@..@.reloc..............................@..B........................H........'...@...........h..8.............................................(....*:.(......}....*.~....*...0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%...%...%...(....*....( ...*.(....,"r.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21728
                                                        Entropy (8bit):6.856791185052111
                                                        Encrypted:false
                                                        SSDEEP:384:Gqk53/hW3fZ+zWQC7Bm0GftpBj6dlwaQHRN7q5blgaGn7i:Gqk53MpViywLGbGu
                                                        MD5:D86B0ACA05321569D9383DC7C4E9E934
                                                        SHA1:2EF7D0A222C3A3E564B3C72D5B71A5BE40A7ADEA
                                                        SHA-256:28B165CDDB82A2507114394AE398995EF8A50C549214F8678AA66054F6927754
                                                        SHA-512:5959E1129C983825233A07869DD1B2B1DB32830D2B5F6B7F8D869C39A76A241F88F76D37341FDFBF56F000FC6ACBA19AEB36A7EFB94721494B41B65BF4978651
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0.............**... ...@....... ..............................vC....@..................................)..O....@..0................>...`.......(............................................... ............... ..H............text...0.... ...................... ..`.rsrc...0....@......................@..@.reloc.......`......................@..B.................*......H.......P ...................... (......................................BSJB............v4.0.30319......l...$...#~..........#Strings............#US.........#GUID...........#Blob......................3............................................................j.q.........~.................}.....3.....L.................g.....P...................k.....k.....k...).k...1.k...9.k...A.k...I.k...Q.k...Y.k...a.k...i.k...q.k.......................#.....+.....3.....;.....C.7...K.W...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):23936
                                                        Entropy (8bit):6.756576538241564
                                                        Encrypted:false
                                                        SSDEEP:384:TFCc4Y4OJWfOWqWWOWYDzDm0GftpBjnZaQHRN7IlDggA:RCcyCSVifLeLA
                                                        MD5:FA98A0F020248C2BE1DD40C07092F22A
                                                        SHA1:EF6B3CCFF90BEDDAB5CE6F60B4CC23F75EDFD009
                                                        SHA-256:CAE99F910874288AFBF810968D13B79D755CD4B2006609EC036EA4934181CBA5
                                                        SHA-512:554A25C761102DC41A9E421621E329868D1162AB29F47E59754C8FCFAE0C12BBE8200E1B5975ABF926F1DE0977A5407C43202AC8A2801C69A7F01D95B6A1E959
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0.............N.... ...@....... ....................................@..................................-..O....@...................?...`......L-............................................... ............... ..H............text...T.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................0.......H........ ..4....................,......................................F.(....~....(....*6.o.....(....*6.o..........**.o.......*.~....*.~....*.BSJB............v4.0.30319......l.......#~..<.......#Strings.... .......#US.(.......#GUID...8.......#Blob...........GU.........3..................................................8.........*.h...m.h.....Z.....$...........Z...+.|.....Z...1.Z.....$.....$.......3.D.......|...F.|...c.|.....|.....|.....|.....|.....|.....Z...I.|...}.Z.....Z.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21280
                                                        Entropy (8bit):6.9260824081196715
                                                        Encrypted:false
                                                        SSDEEP:384:EAWxMW3QvT1Dm0GftpBj1ROaQHRN7gIlBLY6fc8:Evxs1DVidOLgEYA
                                                        MD5:A964808487E671BB369DBC0E4DC5A947
                                                        SHA1:C3848473E42E2F9B4D0A00180EA9ADE654432587
                                                        SHA-256:63EAB38EE9F4DCD686C8E6A4F01E1E2A9BB91E52B20AB4DDE0C28061E9261860
                                                        SHA-512:7352368B68835ECC9C5943AE2F2BD5CAB775A7FBB018AF7683E74FAD1731A9738AE14EBE0BCCD854A223AB762FCA7EC11411FDAE865C5C6DDD034900FA55CFD0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............(... ...@....... ...............................G....@..................................(..O....@.................. ?...`......L'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ..|....................&......................................BSJB............v4.0.30319......l.......#~......P...#Strings....D.......#US.H.......#GUID...X...$...#Blob......................3......................................z...........!...\.!...0.....A.....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.,...C.G...K.g...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21208
                                                        Entropy (8bit):6.915565842835677
                                                        Encrypted:false
                                                        SSDEEP:384:UUAlcWHaWlvT1Dm0GftpBjXGIRaQHRN7/lBLY6fIi:29N1DVihGIRL/Yni
                                                        MD5:27C7D752C11C3F43F28EB31968E73E2B
                                                        SHA1:51E466218025126C5E524AFD2086F4AB0BF3660A
                                                        SHA-256:260C6250EF9B57DCA99B4CECC533F9A34857B5A32B5351202F776163841200AA
                                                        SHA-512:393D1747911A7F91F4C4F4F363A3782F24E00431478088DA454823A223A4E75E51D9B010FC5D9746E2BF0185BE90071B6CB70C777337D718B39151EEF6B486AA
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............(... ...@....... ...............................C....@..................................(..O....@.. ................>...`......d'............................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......|...#Strings....p.......#US.t.......#GUID...........#Blob......................3............................................................`.....1.....t.................s.....).....B.................].........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.5...K.U...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21744
                                                        Entropy (8bit):6.857834679374035
                                                        Encrypted:false
                                                        SSDEEP:384:K8IZnWlNWM+109m0GftpBjBPaQHRN7401lTZVkAa:xUynViXPLrbZVs
                                                        MD5:37BE4CCE0ED037F8D9A7A3940BD2A2E1
                                                        SHA1:96314EC1A59E4BB53C5B609BF79AD4C998A7A988
                                                        SHA-256:C81A57D0634C462A6CF49844059E9B170F650CCDF0789519FFD4AE7D28E2718D
                                                        SHA-512:CEDAC24F414CCE5053FDF10779DBD153FCEBAD69B3960F75A5AB1110DA18799C79DC01B30269641022FCD874A331BC2DC7CE1A7D1A60DC90E109DD55B58665DB
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0.............2*... ...@....... ....................................@..................................)..O....@..P................>...`.......(............................................... ............... ..H............text...8.... ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................*......H.......P ......................((......................................BSJB............v4.0.30319......l...\...#~..........#Strings............#US.........#GUID...........#Blob......................3............................................................t...................................=.....V.................q.....Z...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;. ...C.;...K.[...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):31608
                                                        Entropy (8bit):6.6075135088084505
                                                        Encrypted:false
                                                        SSDEEP:384:GlQnCMi33333333kj8xe+5PTYM3zUy+CezHjzgKj0uRWOdWmWJdWo3szm0GftpBp:8Qq33333333kX+TBi8P8zViDdsLHH0D
                                                        MD5:60F59659DB517C2F4DD4C5C583D43097
                                                        SHA1:87ED79D195D8D93AE1155AF08857F751A7ECA245
                                                        SHA-256:B84B93BE455CC7D14EC0C88CE08DAFAC7B6AAC2E549C969E7126EB48C31F8B1C
                                                        SHA-512:90BCEA3BAA04146F08013A832633957C6D511D5EB52270575EF9A571153384B5A02C5026361B70940775907B5BC710B2C91627EEACE432744F3B9E5E1ED509D6
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0.............RM... ...`....... ....................................@..................................L..O....`..x............<..x?..........PL............................................... ............... ..H............text...X-... ...................... ..`.rsrc...x....`.......0..............@..@.reloc...............:..............@..B................3M......H.......8*...!...................K.......................................0..H........(.....-.r...ps....z.-.r...ps....z.(......}......(#...}.....{.....o....*"..(....*....0..Z.............%.r#..p.%..{.....%.rA..p.%..{..........%.rS..p.%..{....l.{....l[...ra..p(.....(....*&...{....*.0..4.................}......+....{.....".......X.....{.....i2.*.0..k..........{........{..........."....(.......X....{.....i.0%.(..........(.....(.......,..(........"....3.....}....*.......=..M......
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21208
                                                        Entropy (8bit):6.910934602645047
                                                        Encrypted:false
                                                        SSDEEP:384:R28YFlXulWY/W1+109m0GftpBjIaQHRN7T/8ldBoQAYBS:R0qMViaLTwoJYBS
                                                        MD5:29B0A1554E54611EBBA7911049F26FD3
                                                        SHA1:D707745E72D2F39374F2D28AF52AAAB7888B93AB
                                                        SHA-256:2805A18724A24034AD6ACB315DAC516E479CECC5F3753204052657E560932D5D
                                                        SHA-512:17558306A611BFAC6982D5650335B05EA407191290B653C028896142EBEE2ABCEB22F7D71926FBBCC3FAB8227C61A5FDA0E770ABFCA021AC7F891C9C7EE42E81
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............(... ...@....... ...............................n....@..................................(..O....@.. ................>...`......t'............................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~..,...P...#Strings....|.......#US.........#GUID...........#Blob......................3......................................................~.....R..... .....f.................e...........4.....}...........O.....8...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.6...K.V...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22224
                                                        Entropy (8bit):6.827241992748525
                                                        Encrypted:false
                                                        SSDEEP:384:puMLcdQ5MW9MWf+109m0GftpBjMR5aQHRN7Ljl78oSwDnuB3:AOcSpxVi2Lhawi
                                                        MD5:C5CADB1409F25B6A1C7A6DD4C2DF236B
                                                        SHA1:A994C87352486D433A06943C01329DD721AB343F
                                                        SHA-256:F600ACC811720183C639CEBE5618BAF9C8135B85B9CBDC0758BC9B2DCC6DD7A9
                                                        SHA-512:6BD6E482533B9FF8FFF8823F84CDE7191A0FD5575F76891A95E99CD1F5C1122EF92B436745EC9583089445FD5EAC795181759080B1D83CCFA1EED31D9CCE3AF0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............,... ...@....... ..............................`.....@..................................+..O....@...................>...`.......*............................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H.......P .......................*......................................BSJB............v4.0.30319......l.......#~..p...0...#Strings............#US.........#GUID...........#Blob......................3................................................;.........................$.....$.....$.....$...[.$...t.$.....$.....$.........g.$.....#...........e.....e.....e...).e...1.e...9.e...A.e...I.e...Q.e...Y.e...a.e...i.e...q.e.......................#.....+.....3.....;.....C.3...K.S...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21744
                                                        Entropy (8bit):6.8850738754620915
                                                        Encrypted:false
                                                        SSDEEP:384:3Z7RqXWDRqlRqj0RqFWX5Twm0GftpBjGRqazmHaQHRN76RqIil3uVogC:J9qKqjqjuq0wViGqRLoqItV7C
                                                        MD5:AC2F4B435DDF0600D7A866F42F3B40D9
                                                        SHA1:0564FF7F7E6084BD6D02D8E6A4127D1C878B3FA6
                                                        SHA-256:B56FFB65B842DAAE13F3020B0B04646DB92F89801D2A2F89087D145A996D43F7
                                                        SHA-512:DC3E9C3B4D732801DCF43CFD6CDD2672F01E03CB99D804A3F4803FDDB9CA9817BCFD2F96FD94B7B33DB0994F5478CE200C048DB5DBB78D3B24E950262EBF4D28
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............*... ...@....... ....................................@.................................X*..O....@..P................>...`...... )............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................*......H.......P ..P....................(......................................BSJB............v4.0.30319......l...L...#~......l...#Strings....$.......#US.(.......#GUID...8.......#Blob......................3......................................z...............\.....0.....%.....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;. ...C.;...K.[...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):25992
                                                        Entropy (8bit):6.72175242984799
                                                        Encrypted:false
                                                        SSDEEP:384:MNBMbljRC+lgfS1RPWYR1Rw0R9WYRPWYRDRj0R9WQDzDm0GftpBjeXRsTUbaQHR/:MvMhF2SzNzwu/Nlju/ViCLLsBy
                                                        MD5:C7C93DE0627833900B8379FD181B7351
                                                        SHA1:2CB98F9622F57A0A9E037A378519AA6A271302F6
                                                        SHA-256:C7E91BD148ED22EE1FF8EBD3E58B199A30AF90AA37499BCF8DA34409672F2ED9
                                                        SHA-512:1067BACC4495EACBC27937B54780B97DA62FED1AF66158E2FA492FC82B068D49BB49BC20C3C82C22D8EDD300BD7B097E14AA1E317F1789744E188BCA15D22B4D
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..............6... ...@....... ...............................x....@.................................a6..O....@...............&...?...`.......5............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`.......$..............@..B.................6......H........"..H............4......(5........................................o....*"..o....*..o....*"..o....*j~....%-.&(....s....%.....*..*.0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*......(....*...0..K........-.r1..ps....z. ...@3.(....*. ....3.(....*. ...._,.(....rI..ps..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21192
                                                        Entropy (8bit):6.947656997583423
                                                        Encrypted:false
                                                        SSDEEP:384:gZ4RLWdRfRJ0RZWw+109m0GftpBjPWR+HaQHRN71RNl78oSwDnud:gZK0pJujViFc6LzrawS
                                                        MD5:AE023BB0BEEE5189A07C7FD4E0CF3FCA
                                                        SHA1:846711D4161A3950FACDEF97037898A71F4EFDA1
                                                        SHA-256:56BD0C02C734ABF4D7FD1EF2E8B6A9E4BF5E4BAB4E606CD1023D63B02852FA61
                                                        SHA-512:62305027AE8BB5B830630FE54F2CF9E607F9B97FFE28912C2CB15D429252668F17EAF2D7CEECF5601C889D5EA52E0B9100F115173BB11B5D6208171792833C85
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............)... ...@....... ..............................PI....@..................................)..O....@...................>...`......h(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l...0...#~..........#Strings....x.......#US.|.......#GUID...........#Blob......................3......................................................m.....A.{.........U.................T...........#.....l...........>.....'...................u.....u.....u...).u...1.u...9.u...A.u...I.u...Q.u...Y.u...a.u...i.u...q.u.......................#.....+.....3.....;.....C.1...K.Q...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21224
                                                        Entropy (8bit):6.866908604521752
                                                        Encrypted:false
                                                        SSDEEP:384:OYWsmWs+109m0GftpBjncaQHRN7QlgaGn7G7:O28ViGLMGG
                                                        MD5:BB1A520F25BB93ACE4DD0A060FBA677D
                                                        SHA1:92BF07CCF32EB9FDF06F446A256E0271C4028BF0
                                                        SHA-256:7720EE13405EA8A3C204703A181E67DC6D66835E9DF263C09D04D8B48B41EB26
                                                        SHA-512:9288148EC879EBEAFD53C225854EE3BD3768BA5C7B829D6AF1251D20AC301FC27A04BEBB603FE2CDE6949BC5968FDE717E8B747337C1AD872450D26F7C36F515
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0.............*(... ...@....... ..............................'.....@..................................'..O....@..@................>...`.......&............................................... ............... ..H............text...0.... ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B.................(......H.......P ...................... &......................................BSJB............v4.0.30319......l.......#~......D...#Strings....8.......#US.<.......#GUID...L.......#Blob......................3......................................................z.....N.....".....b.................a...........0.....y...........K.....4...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........:.....C.....b...#.k...+.k...3.k...;.....C.....K.....S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):110944
                                                        Entropy (8bit):6.427912093819953
                                                        Encrypted:false
                                                        SSDEEP:1536:lvc/U5yNq2oS4Zd0LE3YigSFvhoZO2K3aAYH2TfXmNoJXrVDCa8:Jgk1tiLMYiDFvxqrWDWNoJXJ2p
                                                        MD5:33B8972FA6B00B8922210CA95E5745D1
                                                        SHA1:609F31B98831327677E89E08BFF7D7322BA0F4A4
                                                        SHA-256:DA18D61BB6B7D35C56CB4F392FAE0844CCA73F72A043A08994BECCB531FF3B77
                                                        SHA-512:F85F03E20C8CE40BCF28D883CCD80CED755BF75D515FA66986963F0F4F5AD00BB1823D8C100A75323147B28A4916DD6C598102B18999AEB7B358C196AF4206DA
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..d...........W... ........... ...................................@.................................5W..O....................r..`?...........V............................................... ............... ..H............text....b... ...d.................. ..`.rsrc................f..............@..@.reloc...............p..............@..B................iW......H........................9.......V......................................j~....%-.&(I...s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*2r7..p.(....*2rs..p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2r=..p.(....*2r_..p.(....*2r...p.(....*2r...p.(....*2r...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):28552
                                                        Entropy (8bit):6.173353710620323
                                                        Encrypted:false
                                                        SSDEEP:384:nmjoB5y+MLi9VYp/OiRc715ZkSAcE1l2Yd5zqNz8TWgVbWqdHRN7NfVlGsa9x:yCN9VYp/OiRcnZIfk8PpET
                                                        MD5:3409C581F0C5083F0C2A93A7A5AC9790
                                                        SHA1:18EA7BD41D31247148ABF184527C9368A26F39E7
                                                        SHA-256:E6026501AD4056FF2F1655B0AFDFE8923BC6E8FBAD67E1E9EF56E3002F49FBB9
                                                        SHA-512:AE877C6FDDAD0E4133274E6372D783EAA4DD6BDCBBF40AB66302FB89BD2F76B215130001186B5C9A135ABD16336C5BFD4D414177704D7D359539DA91918E82ED
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...._............" ..0..B...........`... ........... ...............................P....`.................................t`..O....................L...#..........l_..T............................................ ............... ..H............text....@... ...B.................. ..`.rsrc................D..............@..@.reloc...............J..............@..B.................`......H........&..t)...........P.......^........................................(....*^.(.......(...%...}....*:.(......}....*:.(......}....*:.(......}....*.~....*.0..1.......(....,..%-.&.*..(.....o.......&...,...o....,..*.*....................(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.918416126337718
                                                        Encrypted:false
                                                        SSDEEP:384:uKcuz1W1cWW+109m0GftpBjFGAaQHRN7PlBLY6fJ:6u8AVi5LvYc
                                                        MD5:2FCB2158FC41D97E2BB71953664B99B9
                                                        SHA1:16EB49AFCA84C9E6160B4E5B36F1EC5C98470C86
                                                        SHA-256:984575C44CAB17D46587AF6CC8C22C409B79BEC280FD771E6AF93A0A0C20E5B0
                                                        SHA-512:1527A426F8EC9931573468929966E102012B630EC4AA370C196B2B87472BCEE696B00355ADAEB39B4151B986470F7DADA415E3F930D9678B68D3C531C8AC9B52
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............(... ...@....... ....................................@..................................(..O....@..P................>...`......H'............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................(......H.......P ..x....................&......................................BSJB............v4.0.30319......l.......#~......H...#Strings....L.......#US.P.......#GUID...`.......#Blob......................3......................................................p.....D.....9.....X.................W...........&.....o...........A.....*...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;. ...C.;...K.[...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.918387036071988
                                                        Encrypted:false
                                                        SSDEEP:384:W+SWikWL+109m0GftpBjqaQHRN7Dh6l3uVogJ:W+e1ViILDHV7J
                                                        MD5:51B07204081BDE29A1F84A3B48554186
                                                        SHA1:FCA2F72C039937357099CA6E167330E540F8335D
                                                        SHA-256:5C84DD40D67C0E59906511D2B09DA8E28C454B5979EB5FDE74213F9D4BDBC564
                                                        SHA-512:099EC1B84FCF6BF07142AD8CD34307C80F19A64C754ADE505AB55707075A764FBE7BFA4CE2FBAEAA09B3E61EBDB6E3D116608DF0CF77BC076C7B3119DB37A324
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............(... ...@....... ...................................@..................................(..O....@..P................>...`......d'............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......X...#Strings....h.......#US.l.......#GUID...|.......#Blob......................3......................................................y.....M...........a.................`.........../.....x...........J.....3...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.!...C.<...K.\...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21224
                                                        Entropy (8bit):6.9502839815242545
                                                        Encrypted:false
                                                        SSDEEP:384:fAWzgWw+109m0GftpBjeQKaQHRN7Z0lO62gHcXC:ftCVisdLzg8S
                                                        MD5:3772A3A7E55178EC90ECB607ABA28511
                                                        SHA1:68C240D1A43DE1678EF13107B9300C544E9D5E4E
                                                        SHA-256:C9E2562F1A1B86ACDB6957CF916ACED9C4F8B71EBB16DFA0050252146205AD37
                                                        SHA-512:245F12B4926114EBDB39A54628A1DF2501C4A27ABD531172CC63BC96298EE0F4BE5658AE95FE730C063EADFB1B664C7D201C69C2246CFBA23ED5A4FE7EF3D14E
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............)... ...@....... ....................................@.................................p)..O....@..@................>...`......8(............................................... ............... ..H............text........ ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B.................)......H.......P ..h....................'......................................BSJB............v4.0.30319......l.......#~..d.......#Strings....@.......#US.D.......#GUID...T.......#Blob......................3..................................................C...f.C...:.0...c.....N.................M.................e...........7..... ...................*.....*.....*...).*...1.*...9.*...A.*...I.*...Q.*...Y.*...a.*...i.*...q.*.......................#.....+.....3.....;.....C.9...K.Y...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21192
                                                        Entropy (8bit):6.922388458113732
                                                        Encrypted:false
                                                        SSDEEP:384:9BLRWbYW+f+109m0GftpBjPIuaQHRN7RlgaGn7c:9B20zViFIuLxGQ
                                                        MD5:BFCEB4FACA75681137455CD70F8038B6
                                                        SHA1:BFA0E27BE1D56BA48918A9B7CA7090AF7779A10E
                                                        SHA-256:9A4595DBB128E2D8F373B3AC45478E7131F4D181B50EC821EC8CB88BD46BD5B8
                                                        SHA-512:58D7E8D6FA237A6EAC018C0A88D6BF76AD9EE49B6A6790B64E68C33EBF80AFCB4223881AAC6821132B877E7D848BC917EB9490590CDB297F362C9B43143D6713
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0.............b)... ...@....... ...................................@..................................)..O....@...................>...`.......'............................................... ............... ..H............text...h.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................D)......H.......P ......................X'......................................BSJB............v4.0.30319......l.......#~..X.......#Strings............#US.........#GUID...........#Blob......................3................................................../...z./...N.....O.....b.................a...........0.....y...........K.....4...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.1...K.Q...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21208
                                                        Entropy (8bit):6.911523435668273
                                                        Encrypted:false
                                                        SSDEEP:384:2HW4/WJvT1Dm0GftpBjE3aQHRN76RlTZVkuu:2ry1DViu3L6HZVC
                                                        MD5:AB8D293BCD7A13E83565B4AFA8438988
                                                        SHA1:48F227C62B2001C441BCBC5B570911F096DDF421
                                                        SHA-256:0E80A2E256D16E487BC847D1857ED7CD088F176254BA2A385D675338B836B0FC
                                                        SHA-512:443DD75234C043DE736423466C1FC2FF2BD9B6B9FE753521C3C225DE99F5A7D3828A470CF8EA54678A86681949E5DCD1DE1EAB35BF0F348F758FA099A9092F54
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ....................................@..................................(..O....@.. ................>...`......X'............................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......\...#Strings....`.......#US.d.......#GUID...t.......#Blob......................3..................................................+.....+...^.....K.....r.................q.....'.....@.................[.....D...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.6...K.V...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21216
                                                        Entropy (8bit):6.952503401221548
                                                        Encrypted:false
                                                        SSDEEP:384:Gvk7hWmCWXC7Bm0GftpBjyuGaaQHRN70EflO62gHcXm:Gs7/+Vi1GaLIg82
                                                        MD5:34E21101FAF71A27C6819CC051DEBC9D
                                                        SHA1:D9DF77B4993418337894FF04C6B813224B9F8543
                                                        SHA-256:81B6527AC2D18782AC24AE463C11DD1D70AB1BC89F626B7347A592229B371A1D
                                                        SHA-512:AA339F2489CA9BC9EF7F6121C9586DBD8F5AD2CA5A160A3BCAC74B908570EC2FC0BC24E0EC33AE9DE9D6A6C3557EC2816FE8E89FFCA93E310503F6F83A691F6D
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............)... ...@....... ..............................!.....@.................................h)..O....@..0................>...`......0(............................................... ............... ..H............text........ ...................... ..`.rsrc...0....@......................@..@.reloc.......`......................@..B.................)......H.......P ..`....................'......................................BSJB............v4.0.30319......l.......#~..H.......#Strings....8.......#US.<.......#GUID...L.......#Blob......................3................................................ .C.....C...w.0...c.............................@.....Y.................t.....]...................*.....*.....*...).*...1.*...9.*...A.*...I.*...Q.*...Y.*...a.*...i.*...q.*.......................#.....+.....3.....;.....C.8...K.X...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21168
                                                        Entropy (8bit):6.934271103866825
                                                        Encrypted:false
                                                        SSDEEP:384:3GMWCUWm+109m0GftpBjG6VVaQHRN7Utl3uVog4a:33cVi0OVLUOV73
                                                        MD5:58A2E5AC0510B9223236B9317C505B58
                                                        SHA1:A00954217CA326C54A863D451820263A6D7EE1AF
                                                        SHA-256:80A229B2917FC3A5D941FF9745A6BE0065028AFDF9509300410D2721C71F1198
                                                        SHA-512:18736ECFE0EF0C477BF64F89CA97AF4578DEFC996F0A5BAD33D7A29AF6E09745E4B10D6D543243B9664E40169EE550C996E783C5FFBB0FC767DA7FFC63E13FB6
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............)... ...@....... ..............................P.....@.................................@)..O....@...................>...`.......(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................t)......H.......P ..8....................'......................................BSJB............v4.0.30319......l.......#~..X.......#Strings............#US. .......#GUID...0.......#Blob......................3..................................................].....]...T.J...}.....h.$.....$.....$...g.$.....$...6.$.....$.....$...Q.....:.$.................D.....D.....D...).D...1.D...9.D...A.D...I.D...Q.D...Y.D...a.D...i.D...q.D.......................#.....+.....3.....;.....C.,...K.L...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.909892409390874
                                                        Encrypted:false
                                                        SSDEEP:384:sBhwI7WSQWfTwm0GftpBjGaQHRN7SRalgaGn7x:sDwIBxwVi0L3Gd
                                                        MD5:D74405753F829E75E89BBA5EBC296112
                                                        SHA1:474944856DB781A34796BFCCE18ECD4580275AD1
                                                        SHA-256:86F1F12E47F260985B08BB966598123578EB5E48BEF9BB086F04E16E9D53BB32
                                                        SHA-512:CDC5D49FCF0249C539E45C9917C152F130C8FEE975D97C2F62526F474CB779B2BF273195F4AA7A64F76DD2496528C0D021B56E60AAE2635606F9F55092CB47F4
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ..............................1W....@.................................l(..O....@..P................>...`......4'............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................(......H.......P ..d....................&......................................BSJB............v4.0.30319......l.......#~......D...#Strings....8.......#US.<.......#GUID...L.......#Blob......................3......................................................f.....:.....2.....N.................M.................e...........7..... ...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.!...C.<...K.\...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21144
                                                        Entropy (8bit):6.936275464847822
                                                        Encrypted:false
                                                        SSDEEP:384:iyvPRW4lWkTwm0GftpBj8w0aQHRN7y3lBLY6f4:H39VwViGw0L0Yh
                                                        MD5:809FDBD7422A3E02C89244DC530A3367
                                                        SHA1:A6999C04B243B034F8EE7AD0D79F3CE24DF9A9D0
                                                        SHA-256:C191A43029EDD4EB8EEE003356F1FE79AA45071C25433A7A3589590E9089EED9
                                                        SHA-512:5232B7EF2B60A99BE2B027112078A7DEBF58BFA4308F4AE53DD9A96FA7BCCBB0927BEB7148E7A3944173F7820F9F519767539D1FDFEF848B6F1D6668BE11FC15
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...@..Y.........." ..0..............)... ...@....... ..............................A.....@..................................)..O....@...................>...`......l(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l...L...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................................f.....:...........N.................M.................e...........7..... ...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.&...K.F...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22224
                                                        Entropy (8bit):6.8873536206529895
                                                        Encrypted:false
                                                        SSDEEP:384:j6RW6eW++109m0GftpBjeLUaQHRN7es2lGinGEx:j67aVi8ULzSN
                                                        MD5:3B49BF361F3116DE28176B40845BC199
                                                        SHA1:5627E53D15E56868DC9082EDCAE5A653B96B9AF1
                                                        SHA-256:BF97F67165231C2A42B95F11D80337B082E2B2BE54351DA44C8A10C06194B369
                                                        SHA-512:0FE87438ACD6C14401523987BE617A83DDFD2B42938FC52E0DA5F941F7DC70686CC6436EDD41C4998FD56D5F52D64ACFAB5010B96B1E80C084C4AB9F546202A8
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............-... ...@....... ....................................@..................................-..O....@...................>...`......P,............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................-......H.......P .......................+......................................BSJB............v4.0.30319......l.......#~..\.......#Strings....\.......#US.`.......#GUID...p.......#Blob......................3......................................5.........c.............z...............(.....E.....................................Q.........../...........b.....b.....b...).b...1.b...9.b...A.b...I.b...Q.b...Y.b...a.b...i.b...q.b.......................#.....+.....3.....;.....C.4...K.T...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21192
                                                        Entropy (8bit):6.913851684806603
                                                        Encrypted:false
                                                        SSDEEP:384:ISUP9W70WuvT1Dm0GftpBjluHJaQHRN7alxBGD0F:NUek1DViTupLMMc
                                                        MD5:8BE0CAA60074176FA1E7E63C0AEB6C01
                                                        SHA1:4D4AE0D2664025327F28400D917CC59AFD69F33A
                                                        SHA-256:30A49D16436E3A05569C99A0C2D21755C2FA323C5B925F9F21C10287CC97D9C9
                                                        SHA-512:057F21A7E7496343C06CC497A24E46E59218EAE1838885EEEF7391285CDE243AFE853155F52933959B40F40AA7028A289D15D279833208BBA42BF853D4DF91C6
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............)... ...@....... ..............................S.....@..................................(..O....@...................>...`.......'............................................... ............... ..H............text...$.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..,...x...#Strings............#US.........#GUID...........#Blob......................3..................................................&.....&...p.....F.............................9.....R.................m.....V...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.1...K.Q...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21192
                                                        Entropy (8bit):6.914858816124373
                                                        Encrypted:false
                                                        SSDEEP:384:m8yg07W0/WGC7Bm0GftpBj8xPoaQHRN7WE1l78oSwDnuaPJL:mBH2ViyoLW4awFRL
                                                        MD5:E04CDB6229D83768285ACB08D870F23A
                                                        SHA1:A181F5CC93E9273D9169A9954A74D73BC1852980
                                                        SHA-256:719AC73BB261E0A13574F5A198126CCF40352264958DEFB555280D005134C704
                                                        SHA-512:257FB07C0D86E292FE6FA88E03B29994CB9864C17A535CE7B366A728EAA4B3A803D88A23157CAA457D0B681A2C0D97DD7D9A2754300B73030D9A09C4E9004772
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............)... ...@....... ...............................F....@..................................(..O....@...................>...`......x'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~.. ...d...#Strings............#US.........#GUID...........#Blob......................3.................................................."....."...m.....B.............................6.....O.................j.....S.......(...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.2...K.R...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21152
                                                        Entropy (8bit):6.8927140284137165
                                                        Encrypted:false
                                                        SSDEEP:384:De1WmRWk+109m0GftpBjBpcQaQHRN7MAlgaGn7hw:Dej/ViOQL/Glw
                                                        MD5:5E33930FE2E0867CB1F9FABEDDFBD7B1
                                                        SHA1:4D93C7D7E6315CA2195ED73716996ADE8E17FBB2
                                                        SHA-256:349C7FBE9AE2B78C2F90239BDDFCEA5B16A0FAAC1FE83553A816C50C3E9089B1
                                                        SHA-512:8F87B5013E0CF3A776BFB1F1A68F316A28AF3CB6C74F0ADF3EAD6D5063525C6668B42C077549F66267130959A9CB986BF5F8E4242FC4EF36C356D6927F587A0F
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ..............................~.....@.................................p(..O....@...................>...`......8'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ..h....................&......................................BSJB............v4.0.30319......l.......#~.. ...0...#Strings....P.......#US.T.......#GUID...d.......#Blob......................3............................................................f...........z.................y...../.....H.................c.....L.......,...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.(...K.H...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):142240
                                                        Entropy (8bit):6.142019016866883
                                                        Encrypted:false
                                                        SSDEEP:3072:nUGrszKKLB8a9DvrJeeesIf3amN32AW/rcyw/s:OB8l3/aK32qU
                                                        MD5:F09441A1EE47FB3E6571A3A448E05BAF
                                                        SHA1:3C5C5DF5F8F8DB3F0A35C5ED8D357313A54E3CDE
                                                        SHA-256:BF3FB84664F4097F1A8A9BC71A51DCF8CF1A905D4080A4D290DA1730866E856F
                                                        SHA-512:0199AE0633BCCFEAEFBB5AED20832A4379C7AD73461D41A9DA3D6DC044093CC319670E67C4EFBF830308CBD9A48FB40D4A6C7E472DCC42EB745C6BA813E8E7C6
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....6wb.........." ..0.................. ... ....... .......................`.......>....@.................................`...O.... ..@................'...@......(................................................ ............... ..H............text........ ...................... ..`.rsrc...@.... ......................@..@.reloc.......@......................@..B........................H........,................................................................('...*>..}......}....*..{....*..{....*..{.....{....3..{.....{....((...*.*..0...........%.u....,..........(....*.*z.{....%-.&.+.o)....{....(a...*..(....zN........o*...s+...*.(....z.s,...*..(....zF(U....(O...s-...*.(....z.(V...s-...*.(....z.s....*.(....z.s/...*..(....zN........o*...s0...*.(....zrr...p(\....c.K...(O...s1...*.(....zBr...p(Y...s1...*.(....z.s2...*.(....z.(X...s3...*.(!...z.(_...s3...*.(#...z
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):198472
                                                        Entropy (8bit):6.150725701658664
                                                        Encrypted:false
                                                        SSDEEP:3072:HeruQlNGOhYq0AQcTvankc+8lbKta4FUPAT8xpRI454I/Kv6RpZ8dwPSgEQ4:aW60VcTvakcXcApOW4
                                                        MD5:665E355CBED5FE5F7BEBC3CB23E68649
                                                        SHA1:1C2CEFAFBA48BA7AAAB746F660DEBD34F2F4B14C
                                                        SHA-256:B5D20736F84F335EF4C918A5BA41C3A0D7189397C71B166CCC6C342427A94ECE
                                                        SHA-512:5300D39365E84A67010AE4C282D7E05172563119AFB84DC1B0610217683C7D110803AEF02945034A939262F6A7ECF629B52C0E93C1CD63D52CA7A3B3E607BB7D
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0.................. ........... ....................... ............@.....................................O.......h...............H?........................................................... ............... ..H............text...D.... ...................... ..`.rsrc...h...........................@..@.reloc..............................@..B........................H........$..H...........$....,...........................................0..,........ ....1.r...ps0...z.............(.....s1...*.0..l........J.2..J.o2...2.r...ps0...z..Jo3....%36.o2....JY.2*..J.Xo3.....J.Xo3...(...... ........J.XT.*...J...XT.o3...*..o2....Y./..*..o3....%3 ...Xo3......Xo3...(.... .......*.*..0..=..........J...XT..%....J...XT.~..... ...._.c.....J...XT.~......._..*....0............02...91...A2...F1...a2...f1. ....*..91...F1...aY+...AY..X+...0Y...02...91...A2...F
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21208
                                                        Entropy (8bit):6.9009750652396775
                                                        Encrypted:false
                                                        SSDEEP:384:R6ZWYLWfQBm0GftpBjf6xTaQHRN76IzlTZVkH:R6lNViBCTL6GZVU
                                                        MD5:2EEC710DBAACD32BEDFCA09ECA8DE52D
                                                        SHA1:2CB934305D3648FF29FDBC7D92485003F8458848
                                                        SHA-256:222BD77C5692C2961E8C3638F6511D6F7CBEB9E0977E2D5C3BCA6739A5311F37
                                                        SHA-512:03F132E1BAC629A394A093D59550B22D5FD4C4D6F244697173229282741A9CD6669C4256C024467CE94293C74F304560066711C35620AB4750621502AA67B5B1
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ..............................f.....@.................................T(..O....@.. ................>...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................(......H.......P ..L....................&......................................BSJB............v4.0.30319......l.......#~......0...#Strings....$.......#US.(.......#GUID...8.......#Blob......................3......................................z...............\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.6...K.V...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22248
                                                        Entropy (8bit):6.861480146265617
                                                        Encrypted:false
                                                        SSDEEP:384:B1W1WMQW5R4Xm0GftpBjNY1aQHRN7ZKl3uVogY:O154XVij2LZVV7Y
                                                        MD5:F39A35095CFD0019D6D4BB8461750BF0
                                                        SHA1:AD55AF22E5479A5ADDF01D698138E5149270E3CF
                                                        SHA-256:2E2D28A0802D8C8C08C0D422F48733AD8BF1DFAE75F5682A4A3DF8898E7E819F
                                                        SHA-512:25FC9D4254DE0AFAB9AE3E19B8B225E1D875DCACE6CA2C83F768B62C0E2B331CC9DD2988DFF7994B5819FB0DD7A89A49FD19E653FC2E4EE656182E08A969A93D
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............,... ...@....... ...............................u....@..................................,..O....@..@................>...`......p+............................................... ............... ..H............text........ ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B.................,......H.......P .......................*......................................BSJB............v4.0.30319......l...<...#~..........#Strings....t.......#US.x.......#GUID...........#Blob......................3................................!...............E.................%.................'...........e.....~...........................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.:...K.Z...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21168
                                                        Entropy (8bit):6.898664332146086
                                                        Encrypted:false
                                                        SSDEEP:384:AdSWSKW5R4Xm0GftpBjBaQHRN77OlGinGEwK:+Of4XViHL7asK
                                                        MD5:2A459C2C395F54352A16DE4AA0E5407F
                                                        SHA1:1BA9ECC598E170D779CEB290163AC88E6993935F
                                                        SHA-256:4D97E8481B9A27042BB903245625735D82FF627C66797DE619303C1E705D0D6A
                                                        SHA-512:28DCB8B6E306015D2004EC00443652CE986AB8E09FB09EB82193BFB0604268CA63C527FF64B6364F63C3ADBCDAF5FCDF4D1494243BFC8F6BB629BD213073BD7C
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ..............................|.....@..................................(..O....@...................>...`......X'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~.. ...L...#Strings....l.......#US.p.......#GUID...........#Blob......................3......................................................\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.,...K.L...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22216
                                                        Entropy (8bit):6.840714789582829
                                                        Encrypted:false
                                                        SSDEEP:384:CJEYA2WkIWVvT1Dm0GftpBj/WaQHRN7glBLY6fI:CyYA8r1DViVWL8YF
                                                        MD5:562F67001889CDBC2531947636418EE5
                                                        SHA1:B219DD45550762B54DAB46533D489C4755F55E0E
                                                        SHA-256:9A8BA725F8E953C933285065228A9409036F9137D03016B127CCEA8A19452466
                                                        SHA-512:FDE868018D24FD72177EDE58952325B52561F9D44AE02A4A2268E445F47ABF3B81B809F443D362DF83BD6667B5988AC2CA15242B9F76A0B5FB5B444FADA1BF26
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0.............r,... ...@....... ..............................0c....@................................. ,..O....@...................>...`.......*............................................... ............... ..H............text...x.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................T,......H.......P ......................h*......................................BSJB............v4.0.30319......l.......#~..|...x...#Strings............#US.........#GUID...........#Blob......................3......................................$.........N.U.....U.....-...u.................0...........n.........................>.......................'.....'.....'...).'...1.'...9.'...A.'...I.'...Q.'...Y.'...a.'...i.'...q.'.......................#.....+.....3.....;.....C.2...K.R...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21184
                                                        Entropy (8bit):6.933179959460408
                                                        Encrypted:false
                                                        SSDEEP:384:OJGWe4WG80um0GftpBjTaQHRN7xAlTZVk+:ymhViRLxaZV1
                                                        MD5:28141960A88365DF6A60B0C6FF831B0B
                                                        SHA1:B56C3D2E270B1C793A2EE17CAC9C98B178258E94
                                                        SHA-256:F2E74A3EC2DC753C9A48FA9A677775F949EB1E02FC1BB8BF38C39E8D2AB147EB
                                                        SHA-512:CD44E789A6C04E2BC3B07810B57CC83787F06530065FDCE069D89E42557F40770923CC705E73B7699731166F19FD7133FBDD8EDD578D308A4F72CBB29E76939F
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............)... ...@....... ..............................d.....@.................................0)..O....@...................>...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................d)......H.......P ..(...................x'......................................BSJB............v4.0.30319......l.......#~..d.......#Strings............#US.........#GUID...........#Blob......................3..................................................4...~.4...R.!...T.....f.................e...........4.....}...........O.....8...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.0...K.P...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21696
                                                        Entropy (8bit):6.870719034523618
                                                        Encrypted:false
                                                        SSDEEP:384:KdW1w3WesWoC7Bm0GftpBjWG1aQHRN7sl78oSwDnujJ:f1wxvVi11LWawS
                                                        MD5:8D00682E84D1D773D2160B63C0380BA6
                                                        SHA1:5E4158533532A27E03D0CCC9A0AF5E89FFFD8637
                                                        SHA-256:D0D90152136A0ACF340FB345098F2E5C718BB13F3B5A809D7BE4D9948B8574D4
                                                        SHA-512:991FC952B452446255963AEB4F11C74E7116E15B666924452F3C0D15517322EF1D925DC44BC1F003E8483B5C0B34AD71D54ECAEE360FD9E942664FDEC4E37E99
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0.............~*... ...@....... ..............................X~....@.................................,*..O....@...................>...`.......(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`*......H.......P ..$...................t(......................................BSJB............v4.0.30319......l...$...#~......t...#Strings............#US.........#GUID...........#Blob......................3......................................................\.....0...........D.<.....<.....<...C.<.....<.....<...[.<...x.<...-.......<.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.0...K.P...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):30544
                                                        Entropy (8bit):6.684598614993447
                                                        Encrypted:false
                                                        SSDEEP:384:mylNGlfdqj5531HJTABhf8g2MkO1ICMbmiT2Y4Y3ocWS9sWvW8YsW6vm0GftpBj5:myp12Bhkg3qnV/s2ViaBL0HhR
                                                        MD5:8C9D9F45B85526E491F6555B1566A41C
                                                        SHA1:1420EF91F6E0F6954F373F1AC4079064398AB455
                                                        SHA-256:694F4C61B6BAE0AEFAC07A1E861C12C03CB6002F30091E4C8B05BB9C8CCF0D3D
                                                        SHA-512:38890886C641D7E6E76A3D4D984215C680F5DCF12129BA2EBD560644EDA793335B01C637C1F6744C249DAB1FEFD5AEB8D1B212475221C03DF3CA82413F6670C0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..*...........I... ...`....... ...............................[....@.................................gI..O....`...............8..P?...........H............................................... ............... ..H............text....)... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............6..............@..B.................I......H.......H(... ..................HH.......................................0..J.......(....~....%-.&~..........s....%.....~....%-.&~..........s....%......o....*...0..L.......(....~....%-.&~..........s....%.....~....%-.&~..........s....%........o...+*.0..K.......(....~....%-.&~..........s....%.....~....%-.&~..........s....%.......o...+*..0..L.......(....~....%-.&~..........s....%.....~....%-.&~..........s....%........o...+*.0..L.......(....~....%-.&~..........s....%.....~....%-.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.910950453979084
                                                        Encrypted:false
                                                        SSDEEP:384:5HPAW1bW4QBm0GftpBjzuGRaQHRN7dlxBGD:1rmViFL3M
                                                        MD5:7DA1FEE108A0750F47B70F25FE2CC55A
                                                        SHA1:6523838EF4AAB39D0D3C0DF11C28ADA449EDD592
                                                        SHA-256:69B48FF8E6F40B84CDDDB95BCDBB34E1184A2E29CB4CCC0FC9F1A2493648EE37
                                                        SHA-512:9C0E69C07B2ED6CAA9BB3FFD9EBA6C82A0B763F2DFB06341F6343C54DBC254505CC0350B96B79DC4062D8D28D47C79824E98BB293C8C85203E827164AF862B5A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ...................................@..................................(..O....@..P................>...`......P'............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......P...#Strings....T.......#US.X.......#GUID...h.......#Blob......................3......................................z...............\.....0.....3.....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;. ...C.;...K.[...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21224
                                                        Entropy (8bit):6.91070814532456
                                                        Encrypted:false
                                                        SSDEEP:384:MNoqWD7W6QBm0GftpBjig+aQHRN7Ml3uVogS/:MNofkViOLXV7S/
                                                        MD5:E06BAE626965FBDB0BAE5437498B5155
                                                        SHA1:49392F58BE6F5C97C5DE59BFC44F9CFCBE1E5DD7
                                                        SHA-256:19766A20B62B038ABC3E863F2D6E7B55FABEE4D9CBCAD3EB1D7BD3EBFE8D023A
                                                        SHA-512:69C6D8D5F8835DA31D36940F0AE793BD00D87E9CB9380C3A7B21FE3E315F192F95B8E63C8F9D0A3737C73673A0AEAC41FC728FB7B236F12453A953066F9E53E7
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ....................................@.................................|(..O....@..@................>...`......D'............................................... ............... ..H............text........ ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B.................(......H.......P ..t....................&......................................BSJB............v4.0.30319......l.......#~......X...#Strings....L.......#US.P.......#GUID...`.......#Blob......................3......................................z...............\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.9...K.Y...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21192
                                                        Entropy (8bit):6.92602478259668
                                                        Encrypted:false
                                                        SSDEEP:384:YGETSAWUEWB+109m0GftpBjkOaQHRN7El3uVogD5R:OT1TViCOLvV7D3
                                                        MD5:2E6378FEAEEE2F745417FC025C7850F9
                                                        SHA1:E0FAD5EF75676B2ED7CF155AF6602B867FCED041
                                                        SHA-256:99920CE34A01A0C07EFD86D6E134BB401993515D001B7567A4116AD222993A63
                                                        SHA-512:5A8C41F32598BCF8C8E315B18AD5F1BBC377D7B638DC05CAA3CC47E988536AA0EBE4718D73AEE39ED5004328BE3A9DE9722D8759E5DFD500038E7139DADF9638
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0.............B)... ...@....... ....................................@..................................(..O....@...................>...`.......'............................................... ............... ..H............text...H.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................$)......H.......P ......................8'......................................BSJB............v4.0.30319......l.......#~..<.......#Strings............#US.........#GUID...........#Blob......................3............................................................T.....,.....h.................g...........6.................Q.....:...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.2...K.R...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):115856
                                                        Entropy (8bit):5.631610124521223
                                                        Encrypted:false
                                                        SSDEEP:1536:nPOw0SUUKw+GbgjMV+fCY1UiiGZ6qetMXIAMZ2zstK/hV+sUwS:nWw0SUUKBM8aOUiiGw7qa9tK/bJS
                                                        MD5:AAA2CBF14E06E9D3586D8A4ED455DB33
                                                        SHA1:3D216458740AD5CB05BC5F7C3491CDE44A1E5DF0
                                                        SHA-256:1D3EF8698281E7CF7371D1554AFEF5872B39F96C26DA772210A33DA041BA1183
                                                        SHA-512:0B14A039CA67982794A2BB69974EF04A7FBEE3686D7364F8F4DB70EA6259D29640CBB83D5B544D92FA1D3676C7619CD580FF45671A2BB4753ED8B383597C6DA8
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....?.Z.........." ..0..v............... ........... ..............................DF....@.................................f...O........................>.......................................................... ............... ..H............text....u... ...v.................. ..`.rsrc................x..............@..@.reloc..............................@..B........................H........Q..|?..........$... ...D.........................................(....*&.l(....k*&.l(....k*..l.l(....k*..l.l(....k*&.l(....k*&.l(....k*&.l(....k*j~....%-.&(....s....%.....*..*.0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*.~....*2r...p.(....*2rG..p.(....*2r...p.(....*2r...p.(.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21696
                                                        Entropy (8bit):6.907185647363724
                                                        Encrypted:false
                                                        SSDEEP:384:icDagtDApWSKJWsQBm0GftpBjwaQHRN7ptXl3uVog4:iPKBEVi2LAV74
                                                        MD5:55D9528D161567A19DBB71244B3AE3CE
                                                        SHA1:8A2FB74CF11719708774FC378D8B5BFCC541C986
                                                        SHA-256:870EE1141CB61ABFCE44507E39BFDD734F2335E34D89ECFFFB13838195A6B936
                                                        SHA-512:5338B067297B8CB157C5389D79D0440A6492841C85794EA15B805B5F71CFED445EFA9099C95E5BDEF8CF3902A6B10F032BFC356B0598DDE4F89FA5B349737907
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............+... ...@....... ...............................L....@.................................0+..O....@...................>...`.......)............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................d+......H.......P ..(...................x)......................................BSJB............v4.0.30319......l...x...#~......$...#Strings............#US.........#GUID...........#Blob......................3......................................x.........w.o.....o.....\...............<.....Y.................................................G...........V.....V.....V...).V...1.V...9.V...A.V...I.V...Q.V...Y.V...a.V...i.V...q.V.......................#.....+.....3.....;.....C./...K.O...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21224
                                                        Entropy (8bit):6.911906528800318
                                                        Encrypted:false
                                                        SSDEEP:384:rIWD4WwC7Bm0GftpBjkKgnaQHRN75lgaGn7v:r13ViYnL5GD
                                                        MD5:DEFAADD4A92D4D348B0827AB8159D2FE
                                                        SHA1:F3BD9B4108ACD42ABFB99A3A4760BFFCB84F6C28
                                                        SHA-256:3D2551D6458B84566025FDDFE5DAD479CAB5785428EFD6814860D36AD1811C9A
                                                        SHA-512:1B13C70F05D56871008D5C8752BC93C8FB590D5F89B4E97264F592CDFD772CBBCCE8380D255F8BB305BC25BCDDEA21E422617FA614DFFD3DDCC9A1D4BE6C54A5
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ...................................@..................................(..O....@..@................>...`......\'............................................... ............... ..H............text........ ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......`...#Strings....d.......#US.h.......#GUID...x.......#Blob......................3......................................................\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.9...K.Y...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21736
                                                        Entropy (8bit):6.863412750707488
                                                        Encrypted:false
                                                        SSDEEP:384:AMWzQWsvT1Dm0GftpBjF2i4aQHRN7Del3uVogM:A561DVijuLD5V7M
                                                        MD5:CF318475E6A7A56789ABB0F98C37ABE1
                                                        SHA1:33D1EBD7212D747C8723CFB9E4292C99A641B964
                                                        SHA-256:0383DC02FDF0B5D4612D8CAAAD13D594CAC1609C8240B73DFD6EA5803F5E17EA
                                                        SHA-512:5C67456A65FD051147281E14041F5165C1852FD6519DFC8DFCF9C86F20217CDAD9E2D26F815B557B99E2DB3500AF47B2DF8A1225A659FA1069815CD62302458F
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0.............N*... ...@....... ....................................@..................................)..O....@..@................>...`.......(............................................... ............... ..H............text...T.... ...................... ..`.rsrc...@....@......................@..@.reloc.......`......................@..B................0*......H.......P ......................D(......................................BSJB............v4.0.30319......l...L...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................................z.....N.....:.....b.................a...........0.....y...........K.....4...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.9...K.Y...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22200
                                                        Entropy (8bit):6.818690002285853
                                                        Encrypted:false
                                                        SSDEEP:384:oxDHKWAMWU+109m0GftpBjyi/aszaQHRN7RldBoQAY1:QD8GVirBzLDoJY1
                                                        MD5:1A3DA139180E9FAB380033D8D1FE3995
                                                        SHA1:3CA31DE7F0F0784559E5A73EBD0EFB42C34D18FC
                                                        SHA-256:63AAF632EE7F3BC852C4D71C742CF1D26F18F784F6C89113E056B2599BA8F514
                                                        SHA-512:D991298419FB5290D6906A1F9FCCEF56BB3E17506E235C85B4D979EBC49ABD4F4B3123697E675346B57829C3EFDEED6291A155D69348CD55B8B6B2EEC9F804A1
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0.............r,... ...@....... ..............................Z4....@................................. ,..O....@...................>...`.......*............................................... ............... ..H............text...x.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................T,......H.......P ......................h*......................................BSJB............v4.0.30319......l...H...#~......D...#Strings............#US.........#GUID...........#Blob......................3................................"...............1.............{.................................Q.....j.......................n...................u.....u.....u...).u...1.u...9.u...A.u...I.u...Q.u...Y.u...a.u...i.u...q.u.......................#.....+.....3.....;.....C.....K.N...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21200
                                                        Entropy (8bit):6.897645601910542
                                                        Encrypted:false
                                                        SSDEEP:384:WLNBEW6pWgQBm0GftpBjFaQHRN7GQlGinGEIJl:WbMIVi/LRU
                                                        MD5:F1CC91D25B52C7504DC5BEAB5D0F498C
                                                        SHA1:498F0FBBD2712F4F637BDB7370B2302FCC4966F3
                                                        SHA-256:E3036362506D96C9C00ED6393A2AFCACD9F2E71CD2A35C1D638A61E85D2FB040
                                                        SHA-512:4C931389035DF21AE67810D8C8E95CB613D9495E2392B11E34D84F624F90C78C541B14FB0D6FE7F0F89799AAD4B34E91FB6F73978AE38231840F047915E6EB5B
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ...............................q....@.................................D(..O....@...................>...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................x(......H.......P ..<....................&......................................BSJB............v4.0.30319......l...|...#~......0...#Strings............#US.........#GUID...,.......#Blob......................3......................................z...............\.....0..... .....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.4...K.T...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.926543977764199
                                                        Encrypted:false
                                                        SSDEEP:384:2KkHKW/tWXC7Bm0GftpBjcR3raQHRN7T0ldBoQAYNI:7uNViydLTgoJYW
                                                        MD5:9E71DFCE86F14BEEB8F3E9F00D0A472E
                                                        SHA1:BF83A7E98418BDE907DEAE8C0C0F3FB0F6C9DB1A
                                                        SHA-256:62DCE4679E33C079E11F41B096BC803B30B1D963A1EA79EFA84187CEBBC06AFE
                                                        SHA-512:FF8CDC0287E510F859F46C1E35F9B0FB42EAD907B1EAA42C90C84B31CF6C2D4638CF682777F359B8611DD22062C1A5FA71F7FB667B7A3903783673E678098515
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............)... ...@....... ....................................@..................................(..O....@..`................>...`.......'............................................... ............... ..H............text...4.... ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B.................)......H.......P ......................$'......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3..................................................W.....W...R.D.........f.......................=.....V.....}...........q.........................>.....>.....>...).>...1.>...9.>...A.>...I.>...Q.>...Y.>...a.>...i.>...q.>.......................#.....+.....3.....;."...C.=...K.]...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21200
                                                        Entropy (8bit):6.904224159979604
                                                        Encrypted:false
                                                        SSDEEP:384:XLnfIWqrW0QBm0GftpBjTUFSNaQHRN7G1lBLY6f5vB:XDf4WVih8OLGNYIvB
                                                        MD5:05D1B950C470EA8B0AA357F9A59CF264
                                                        SHA1:B1756DC750ED5CFD5D0BFC70CB899FD590867A0C
                                                        SHA-256:DAAABD07F1B94BE19D72913360286E469F454886850AFCC603506EAAB03150E4
                                                        SHA-512:8E65FF1909AC8D65F599062E61AC935A919D43404C357DBC6AD628923B0C7ED7158862DDD272CFC1C2A8CEC393D48A57BC4D69CE7706EEF1BB6838826B1AFAE3
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............(... ...@....... ....................................@.................................D(..O....@...................>...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................x(......H.......P ..<....................&......................................BSJB............v4.0.30319......l...|...#~......0...#Strings............#US.........#GUID...,.......#Blob......................3......................................z...............\.....0..... .....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.4...K.T...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):18024
                                                        Entropy (8bit):6.343772893394079
                                                        Encrypted:false
                                                        SSDEEP:384:EybU8ndrbbT9NWB2WL/uPHRN7bhlsQVryo:Ey5ndvWbMPVryo
                                                        MD5:C610E828B54001574D86DD2ED730E392
                                                        SHA1:180A7BAAFBC820A838BBACA434032D9D33CCEEBE
                                                        SHA-256:37768488E8EF45729BC7D9A2677633C6450042975BB96516E186DA6CB9CD0DCF
                                                        SHA-512:441610D2B9F841D25494D7C82222D07E1D443B0DA07F0CF735C25EC82F6CCE99A3F3236872AEC38CC4DF779E615D22469666066CCEFED7FE75982EEFADA46396
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....Ksa...........!.................6... ...@....@.. ....................................@..................................6..K....@..............."..h$...`.......$............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B.................6......H.......D%..<...................P ......................................_...+.'g.......x2..}}...B.O....T...e..?.M..R"M.~pg..c..LD#..y.....y....:u.v*...#.;.-.h.......0..#.....a5|T%W...].!.%'..9.0...........q....*..0..............q....*...0..............q....*...0.................*.0....................*..0....................*..0............q.........*....0............q.........*....0............*..0..........*....0................*..0...............*...0..............
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21784
                                                        Entropy (8bit):6.872325269765102
                                                        Encrypted:false
                                                        SSDEEP:384:vna8WK1W6QBm0GftpBjBxRaQHRN73clxBGD:vna0+VinL36M
                                                        MD5:9F31B6954FD453F13B5F39DA36F2E8EB
                                                        SHA1:7A6276348D85EAF00AE6958117797045929078CB
                                                        SHA-256:18A610B8BAD43CF784CDE4D4902A238F2281C2A677DAAE790CAB55F6DA915979
                                                        SHA-512:D3696D4D60CFC5AA5834F60A0B97A4F3A3F8EC3FB05BEB3C3D927426B72B3E5463C628C7DF950E43FF1344823B8C2D39730BA47BA0F2FEC7A0CFCDC237A5BCC6
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0.............j*... ...@....... ...............................R....@..................................*..O....@...................?...`.......(............................................... ............... ..H............text...p.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................L*......H.......P ......................`(......................................BSJB............v4.0.30319......l...@...#~......0...#Strings............#US.........#GUID....... ...#Blob......................3................................................w.................!...........<.....Y.............................................................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.)...C.D...K.d...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21720
                                                        Entropy (8bit):6.851248273705748
                                                        Encrypted:false
                                                        SSDEEP:384:2BSWITW5+109m0GftpBj4+19aQHRN76hlO62gHcXAJ:26oVi6+19L64g8QJ
                                                        MD5:B0346A4C5FA0FAC135509A0E7D3C4449
                                                        SHA1:7D71B46BB9A28289384AA1EDF5CB03D64B3BCFF0
                                                        SHA-256:F9FEB277F86241F55425182A26DECF50A210675D4F040EC542AF3FB3DD287DE6
                                                        SHA-512:916A465236F11FF6E421800961B20CB80A320176DA8C58002F6742040CE33C5207D378667A584C5D8E35CF8CFC19AC54504B3F6129E489EEABD86A5B4E7D8C77
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..............*... ...@....... ...............................Y....@..................................)..O....@.. ................>...`.......(............................................... ............... ..H............text...$.... ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...@...#~..........#Strings............#US.........#GUID...........#Blob......................3..................................................|.....|...S.i.........g.................f...........5.....~...........P.....9...................c.....c.....c...).c...1.c...9.c...A.c...I.c...Q.c...Y.c...a.c...i.c...q.c.......................#.....+.....3.....;.....C.6...K.V...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21200
                                                        Entropy (8bit):6.924980445039345
                                                        Encrypted:false
                                                        SSDEEP:384:t88cIIWNoWRQBm0GftpBjsP9SaQHRN7f7l78oSwDnuC6:t9cUoViM9SLftaw4
                                                        MD5:65FBBA7A86B3E175200AE44727AB40E5
                                                        SHA1:584B8683943A8E0AE98B10F452C94F6109D1C4EA
                                                        SHA-256:7A81D2A001B543B2A55C9AFFC845A5DF7EDAB1FD308C6979BBD982B1B826B57C
                                                        SHA-512:43607AEBBB0A3F2D437C7DE77785CD6C9F49411E1D4EFE41ECCD93D7FCCA197DABD4E15F45FBC4FBFF27C202FEC96B79F82202AFC88B59C20ED5E7912BCDC6D3
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0.............V)... ...@....... ...............................d....@..................................)..O....@...................>...`.......'............................................... ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................8)......H.......P ......................L'......................................BSJB............v4.0.30319......l.......#~.. .......#Strings............#US.........#GUID...........#Blob......................3..................................................*.....*...c.....J.....w.................v.....,.....E.................`.....I...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.3...K.S...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):28624
                                                        Entropy (8bit):6.700175270481286
                                                        Encrypted:false
                                                        SSDEEP:384:OkUwx9rm5go1fWKmmW6oqN5eWjaWsFm0GftpBjZNaQHRN7ZtnlJCxJ:lrmoFmWdOMViLNLZhCb
                                                        MD5:568B53398BFC0E54AAF448B68F5C77C2
                                                        SHA1:76B0B6E65E38A90A4ECDB3F6DFE16D5A803081E9
                                                        SHA-256:8BB9D52BA5C67F05C8F632DEB1E7E98A909318B10E1388B47E919515FDD42CBF
                                                        SHA-512:6052EE3664FD2095DE3338CF6D24DF022DC13D00B4BF14C57572F2A34AC078E07BD1F634A50028DB0952AE8067FFCF19079177FA534240D9526F33AE1E1459AC
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..&...........E... ...`....... ...............................V....@.................................PE..O....`..x............0...?...........D............................................... ............... ..H............text....%... ...&.................. ..`.rsrc...x....`.......(..............@..@.reloc..............................@..B.................E......H........$...............A.......C......................................j~....%-.&(....s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*2r/..p.(....*......(....*2(.....(....*^~....-.(.........~....*.0..........~..........(.........(....-Y..(!....{/......5..,
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):24296
                                                        Entropy (8bit):6.780229572480669
                                                        Encrypted:false
                                                        SSDEEP:384:N09bOAghbsDCyVnVc3p/i2fBVlAO/BRU+psbC984vmJHrE1dtx66aI2sU52RWVsX:MOAghbsDCyVnVc3p/i2fBVlAO/BRU+pJ
                                                        MD5:D7E74EA95786A02687CE43C356ABDC95
                                                        SHA1:2E6A3047BD3BCEE01F55D139A3C03E6D4D2DB14A
                                                        SHA-256:383A1F9DAC655C6805C24D4A03BC5FBEB9ABD1536DE5510F5756259EEFCB4871
                                                        SHA-512:B7E76B65406904F092FE96DED558A94EA53FA40BEC500EFCDCDEBF124921F4526DE2F239CD25BAE1801692DD6DFE5652FFD46B2AA4325133C7127D27F626BB9B
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0.............r5... ...@....... ...............................k....@................................. 5..O....@..P............ ...>...`.......3............................................... ............... ..H............text...x.... ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B................T5......H.......P ......................h3......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3................................r.....................e...........4.................3.....L...................................R...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;. ...C.;...K.[...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21200
                                                        Entropy (8bit):6.898006718463938
                                                        Encrypted:false
                                                        SSDEEP:384:27W6RWDvT1Dm0GftpBjhvPaQHRN7VwXldBoQAYd:25K1DViXHLVyoJYd
                                                        MD5:6CCCA0BA6A7B9CAF8B8D3B0287DBED8B
                                                        SHA1:B81FF87B407578EFBF184BDC10D0F101610379DB
                                                        SHA-256:16E7EFD6C19B2E3E516AE1BC7B3175D0E22F1AD357701F229E353DA348EEE182
                                                        SHA-512:8505479031A0A5CAEEEE1A8A60AA35D7E0C332BBFDDE61193B615E242C127780E55F404289F26930E9EC9E53FCCF436B1A991BA2C8A9177163B41AAAF6BE0D32
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............(... ...@....... ....................................@.................................T(..O....@...................>...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ..L....................&......................................BSJB............v4.0.30319......l.......#~......4...#Strings....(.......#US.,.......#GUID...<.......#Blob......................3......................................z...............\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.4...K.T...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21264
                                                        Entropy (8bit):6.950539566613158
                                                        Encrypted:false
                                                        SSDEEP:384:uI5HeWFwTBsWbvT1Dm0GftpBjW0hZraQHRN7ZflZ3j:uI5HFwTB91DVism5LZzz
                                                        MD5:A42C32F4E98A9656FC2FED72D30E9380
                                                        SHA1:B6B8986FC1B5140817DE262AE4102499E37DAFFD
                                                        SHA-256:C343F7BF08A4C97A90BA607A492C721533333173FA63F65F6E5DE9CEEE65FC16
                                                        SHA-512:5C2DE8F18CB9B367D7DE88A2AF8A7FD538486B9FFB393972FBDFF42CD2899D6679FD8D7076FE37954D5E8EAB6C5041F19EDAD32659C5CCEEC1C2BA35E6F8982A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............)... ...@....... ....................................@.................................|)..O....@...................?...`......D(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P ..t....................'......................................BSJB............v4.0.30319......l.......#~..H.......#Strings....@.......#US.D.......#GUID...T... ...#Blob......................3............................................................U.x...........................~.....4.....M.................h.....$...................r.....r.....r...).r...1.r...9.r...A.r...I.r...Q.r...Y.r...a.r...i.r...q.r.......................#.....+.....3.....;.)...C.D...K.d...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21240
                                                        Entropy (8bit):6.93694523950017
                                                        Encrypted:false
                                                        SSDEEP:384:YAJpVWbfkBnWyC7Bm0GftpBjV1raQHRN7RyV0lTZVkvq:YAJpWfkBSVi31LRyAZVZ
                                                        MD5:E1E2239979B853157BA75310FEA7E65D
                                                        SHA1:EE1AE416570911282ABDD3745674E58F9D469C9E
                                                        SHA-256:E8D531F0AAA674F794B7F43EC76E4E32AD93F3C136020CF4B6E3433832F9C0DF
                                                        SHA-512:DDF9D6E05D9566C9E02295A061756FF164C408EA211D016023EDBFA91BBA4D0D7DFF293D2BF4D87C25FE923500C7535E4A21B6A8D4B18FD9505F8E5C635F9C95
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0.............>)... ...@....... ...............................#....@..................................(..O....@..`................>...`.......'............................................... ............... ..H............text...D.... ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B................ )......H.......P ......................4'......................................BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob......................3......................................z...........@...\.@...0.-...`.....D.................C.................[.....x.....-.........................'.....'.....'...).'...1.'...9.'...A.'...I.'...Q.'...Y.'...a.'...i.'...q.'.......................#.....+.....3.....;.#...C.>...K.^...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):27048
                                                        Entropy (8bit):6.661112158879877
                                                        Encrypted:false
                                                        SSDEEP:384:c8R71h7yzt94dHWFgQBVWeHWFyTBVW/4wm0GftpBj1AipaQHRN7E5AN/lD7DDN:d1dyAqgQBfqyTB+FVizAGLE5AXHDN
                                                        MD5:3373A24450373CAF0CBB756E10097FD4
                                                        SHA1:87C352153804FF5BD4F8AEF8851546F3CF22461E
                                                        SHA-256:575E26A455892F1FD77B730E6928F70B760E76094AFE5BCB677D854DAF869AC5
                                                        SHA-512:85E005B5BEB7C14BA34C62C38DA635962D1AA4740F91549B8659910EDD10F0FDE1734064B19567BF5BC63DBBBB62399F6CBE0AA323193DA599232DCE22B14A01
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..............8... ...@....... ..............................Ag....@..................................8..O....@..8............*...?...`.......7............................................... ............... ..H............text........ ...................... ..`.rsrc...8....@......................@..@.reloc.......`.......(..............@..B.................8......H.......|!..l............1..p...X7......................................j~....%-.&(....s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*......(....*..BSJB............v4.0.30319......l.......#~..h.......#Strings....\...4...#US.........#GUID...........#Blob...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):24816
                                                        Entropy (8bit):6.774158289322937
                                                        Encrypted:false
                                                        SSDEEP:768:EsPMQMI8COYyi4oBNw4tB8ngViK+QLc7LGS:vPMQMxCO4xJV86+GS
                                                        MD5:9087373EEE85190DAF8915E614B1E4BD
                                                        SHA1:F434AF8CE30EAF5511E28C0230211F0D8ED4A154
                                                        SHA-256:557858E44A51A74646AD07A85CBA56AF1DA13AD26AC2F74EE5D8C3E8A171C221
                                                        SHA-512:F728238FA567457D7977FEA667FCCB56C2EFE718A9A362E294934CC752E506E05C5D20C0BE2A309DE2A984DD60C3AE4EA03054185B96C9B5F5F5DE827AF9CEAF
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..............3... ...@....... ..............................6~....@..................................3..O....@..............."...>...`.......2............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`....... ..............@..B.................3......H........!..0...................L2.......................................s....*..s....*..0...........o....u......,..o....*.*.0..%........s..........(....r...p.$o......o....*:.(......}....*..{....*.(....z.(....z6.{.....o....*:.{......o....*.(....z:.{......o....*.(....z.(....z.BSJB............v4.0.30319......l.......#~.. .......#Strings....$...0...#US.T.......#GUID...d.......#Blob...........W..........3............................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):29360
                                                        Entropy (8bit):6.504362287456874
                                                        Encrypted:false
                                                        SSDEEP:384:fbhigwLAuZtM66g/Id7WVXWbC7Bm0GftpBjyV8aQHRN7mT1lO62gHcX2:fbhzkKsrVi48Lpg8m
                                                        MD5:0E35085C130D2D91E5241334BE7EF0DA
                                                        SHA1:FD622ADE5CAE26353A22B6FA50A83669B72B6C41
                                                        SHA-256:50AD612D4CF6113DE26B2870DA099C4817F59E64A2DA98F05803B4A2E2304919
                                                        SHA-512:2498811F4AAC308CDC55C3406BEA4FEF5DC9E6F23559B09FB181F7447474EF586F00038282DDC39C241490B5DC2BCA7F41F19BD3E1BB00890DA29DF6489BB151
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...A..Y.........." ..0..*.........."H... ...`....... ..............................7.....@..................................G..O....`...............4...>...........F............................................... ............... ..H............text...((... ...*.................. ..`.rsrc........`.......,..............@..@.reloc...............2..............@..B.................H......H.......P ...%...................F......................................BSJB............v4.0.30319......l.......#~..........#Strings.....#......#US..#......#GUID....#......#Blob......................3................................................_.........................8.....8...*.8.....8.....8.....8.....8.....8.........*.8.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.+...K.K...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):35952
                                                        Entropy (8bit):5.895371991419636
                                                        Encrypted:false
                                                        SSDEEP:384:zdlIF91FhktexyvaMAdB+w3G5h9MF4YfzMfpcrqmf9wEJqIxVRvFNgfBkyN17xWI:ZlM7Ke5/WBkyN1hhMPS
                                                        MD5:527595C86AD17045A101D567D7D3279F
                                                        SHA1:83014E2A98F7597B9A26E424A0759E5A3D2ECFF1
                                                        SHA-256:FF14C5F628B9A6798D173AEFBBA0A43D61E66F715108E2576AC0D3DFAB9071D0
                                                        SHA-512:9EBAACA1623BC8E2FC8DF158F338B5E415670FA53E212BB38771E7E25AF9688301CC4AEE055C5B64E33F8AA24729ED896E0BE8E2DBCE54386583C660476C5DDA
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................." ..0..Z...........x... ........... ....................................`..................................x..O....................h..p$...........w..T............................................ ............... ..H............text....X... ...Z.................. ..`.rsrc................\..............@..@.reloc...............f..............@..B.................x......H........%..p5..........P[.......w.......................................~....*..0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%...%...%...(....*....(....*.(....,"r...p......%...%...%...%..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21200
                                                        Entropy (8bit):6.921540746927502
                                                        Encrypted:false
                                                        SSDEEP:384:2UcX6W9aW2EC7Bm0GftpBj3ZYvSaQHRN7tMlgaGn7Vy:2UchixVi9LtQGJy
                                                        MD5:99604779C668D9B8EF913854B9A24F9D
                                                        SHA1:97B62A3DBE2465B4C995E082AD6FF183F6267F59
                                                        SHA-256:8270D1248950EE8AEE5C2AC2E321DF07E65C7A94004AE03C857DEACD231A5542
                                                        SHA-512:BE6DEE6E7030B400EAC68AC289EC9B74BFE0140EE59AF5E68BF43A63A821C6F6AD9CA03C501896A6C92464BF8116D7996FFE640AB51BD9FA96673D9794AC82CD
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0.............B)... ...@....... ....................................@..................................(..O....@...................>...`.......'............................................... ............... ..H............text...H.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................$)......H.......P ......................8'......................................BSJB............v4.0.30319......l.......#~..<.......#Strings............#US.........#GUID...........#Blob......................3......................................................\.....0.....(.....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.3...K.S...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):47016
                                                        Entropy (8bit):6.126380612996906
                                                        Encrypted:false
                                                        SSDEEP:768:yoBj7kS+8mjvHTeaWKs0Sd4eeVngVixLVH:hPmb9WKs0Pee6VEVH
                                                        MD5:E4A1681E09AEC6EFB00FB2A9355A1296
                                                        SHA1:95699D187BF150D319CC64F90064301CAC57F338
                                                        SHA-256:967DDDBFE7F1CEB933B5875D65C59CDB835BB063F287A361E8B35DD814A9B14D
                                                        SHA-512:49299C773A4C7CCC235C54A91FD07A000CF547B3EE55272E2EE8B2AA40281DC0AF3C3B5A9EDF5CAEE4BEB3AD0DE5A0DEA07159ACEBA582911B78A6B85DB793B0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..h.............. ........... ..............................I.....@.................................u...O.......8............x...?........................................................... ............... ..H............text....f... ...h.................. ..`.rsrc...8............j..............@..@.reloc...............v..............@..B........................H.......P'..\8..........._...%..,.......................................j~....%-.&(F...s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*2rI..p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2r...p.(....*2r9..p.(....*2rm..p.(....*2r...p.(....*2r...p.(....*2r=..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21240
                                                        Entropy (8bit):6.935501042478791
                                                        Encrypted:false
                                                        SSDEEP:384:pTI2pWPzW8vT1Dm0GftpBjFQaQHRN7vlgaGn7s:pE3L1DViEL3G4
                                                        MD5:F554762FC38F81CB22D1DC8AB5CD40D5
                                                        SHA1:A67FDACEB10E828805A9E24FE0C59E1D73D19A7C
                                                        SHA-256:566775F5502C3C1FA70ACADE145293DF5D02C1A9F031820D429605E9B4584B44
                                                        SHA-512:BD23571BF9D0FE62BBF5FDDCAFF6B8F383CCC728AFBCEEBCAD8404D68C02EA1F55D4A22306BFC86C30172E70C6CF5425F2FF8877AAA8758A51C48CF4303BD2AB
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0.............^)... ...@....... ....................................@..................................)..O....@..`................>...`.......'............................................... ............... ..H............text...d.... ...................... ..`.rsrc...`....@......................@..@.reloc.......`......................@..B................@)......H.......P ......................T'......................................BSJB............v4.0.30319......l.......#~..,.......#Strings............#US.........#GUID...........#Blob......................3......................................z...........A...\.A...0.....a.....D.................C.................[.....x.....-.........................(.....(.....(...).(...1.(...9.(...A.(...I.(...Q.(...Y.(...a.(...i.(...q.(.......................#.....+.....3.....;."...C.=...K.]...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21256
                                                        Entropy (8bit):6.945812678642078
                                                        Encrypted:false
                                                        SSDEEP:384:d1cezoy4W04WDvT1Dm0GftpBjEUvCMuaQHRN71xlZ3VRw:PBzoy+F1DVivQLjjw
                                                        MD5:7AB10B31C5CE290672B319D403751E95
                                                        SHA1:ED23E654968B3704A82F613B06BE5829E0CAAD70
                                                        SHA-256:1F5C1ABE1B2720680170388569354D8CDA9D558B53AFF7CAF175CE0F7E3733E5
                                                        SHA-512:65ED3AFF2424E7560FCC44380DC719BF200D444F9B06AF7F916D52152C330D55A7F4B96D0C1D2B291B07D82805C71DD9850F2F5F612F00ADFCA1CDF117C6B14A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0.............~)... ...@....... ....................................@.................................,)..O....@...................?...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................`)......H.......P ..$...................t'......................................BSJB............v4.0.30319......l.......#~..<.......#Strings............#US.........#GUID....... ...#Blob......................3..................................................f...o.f...C.S.........W.................V...........%.....n...........@.....)...................M.....M.....M...).M...1.M...9.M...A.M...I.M...Q.M...Y.M...a.M...i.M...q.M.......................#.....+.....3.....;.'...C.B...K.b...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21784
                                                        Entropy (8bit):6.863777213641518
                                                        Encrypted:false
                                                        SSDEEP:384:jQH/JWKpWNvT1Dm0GftpBjjaQHRN7/lO62gHcXv:jQH/jw1DVilLeg8f
                                                        MD5:A60084F9988C7907F7092C143C8D3818
                                                        SHA1:A69238054BEE26063D32B85B797BC4E0C49F79D4
                                                        SHA-256:B755D0B55A465D07C9DD3FC11822487D1E649B684AEF91A4CE9B935B416A01B9
                                                        SHA-512:6147F18BD9C49727251CBEA7A3168E3B19F34056DE5A9898571ECDEC85D424627A72968072449C81F97F95330BAED7E2ED0F6FDBA7E2F79B59B9352AB11003CF
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0............."*... ...@....... ....................................@..................................)..O....@...................?...`.......(............................................... ............... ..H............text...(.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l...$...#~..........#Strings............#US.........#GUID....... ...#Blob......................3............................................................o.s...........D.....D.....D.....D...8.D...Q.D.....D.....D...l.....U.D.................m.....m.....m...).m...1.m...9.m...A.m...I.m...Q.m...Y.m...a.m...i.m...q.m.......................#.....+.....3.....;.)...C.D...K.d...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21648
                                                        Entropy (8bit):6.57237392280082
                                                        Encrypted:false
                                                        SSDEEP:384:/LoCClk2P9vGMCxvcFHWAR6jDWn/WyRIHRN7er+leLR9zusBvjv:Dofk2Fvaxki6uo0eked9zuY
                                                        MD5:E52A7A4ED5621744ECF2D8E8121BAC97
                                                        SHA1:59220619E2239E707A5E3CFF042EED85D8473EE3
                                                        SHA-256:F48944813063E301668B25DC7EDECC4839FD45668EA154EA67493D1E43411C18
                                                        SHA-512:02FA15F50C16E6C787987D4091822C7E10DEE35B6D7788278EBA3C86D787DD8D1FE968E632B7F347E501B08DF9C596D3C2D46E325E9DD43E55B0B74E3FEDF03F
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...u.0..........." ..0.. ...........?... ...@....... ....................................`.................................u?..O....@..(............,...(...`......h>..T............................................ ............... ..H............text........ ... .................. ..`.rsrc...(....@......."..............@..@.reloc.......`.......*..............@..B.................?......H.......H"..p............;..0....=........................................(....*:.(......}....*..(....*..(....*..(....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*..(....*:.(......}....*..{....*^.(...........%...}....*:.(......}....*..{....*z.(......}...........%...}....*V.(......}......}....*..{....*..{....*:.(......}....*..{....*"..(....*"..(....*"..(....*>..(......}....*..{....*"..(....*>..(......}....*..{....*..{....*"..}....*"..(....*"..(
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22832
                                                        Entropy (8bit):6.823696761227228
                                                        Encrypted:false
                                                        SSDEEP:384:3TjbocNsWMhWqvT1Dm0GftpBjAB8O9aQHRN7FswlO62gHcXpe:fboYyf1DViyB8O9LFAg88
                                                        MD5:06D000552ED6785988AE188FC35D1B86
                                                        SHA1:B0A8868D459FE0AF34D16C263CFE0202C414DC53
                                                        SHA-256:3C8630ACB43C12A6A317227FF2922056ECD991FE945464FDF7EA81F1293A479F
                                                        SHA-512:F3E5E97AAF3D26EA62C64787198CCE6DF703EA3A4EBB389BEBC84B424C8129A0181142A4FA5D965CA3106758A047D0E1A723F181AD293FD389C4F1B8D290B5A5
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0.................. ...@....... ..............................j.....@..................................-..O....@..................0?...`.......,............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................-......H.......P .......................,......................................BSJB............v4.0.30319......l.......#~......|...#Strings....x.......#US.|.......#GUID.......(...#Blob......................3................................'.....).........u.................=......."...:."...W.".....".....".....".....".....".....[.....".................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;./...C.J...K.j...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):30328
                                                        Entropy (8bit):6.239972992007481
                                                        Encrypted:false
                                                        SSDEEP:384:pS3NEDzTPs/9L7s4La7w2JpmxjP/h9+WzlWskiXvHRN7jWsVOY/wR9z1VBQ:E3YzTM9s37w26xjP/7Tfkofjx/M9zi
                                                        MD5:18346946D34E3A77B2733EC3809FD27B
                                                        SHA1:5B43C123B7176765450C1969B42C8EB63931302A
                                                        SHA-256:347555F8600C3171EBD53B3034683BAD125ACE59F1491EC58EDB08AA54C4AA8E
                                                        SHA-512:AE20F1DB6EDCE893ABAF0557FC5F7414A09D1B704845D902887FC385D85D97F650BCA3E3102E1BFB0575CEF6CD9B534F938ECA5CAC567D671FE28875B73E96A2
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L.....|..........." ..0..D...........c... ........... ..............................,.....`..................................c..O....................N..x(...........b..T............................................ ............... ..H............text....C... ...D.................. ..`.rsrc................F..............@..@.reloc...............L..............@..B.................c......H........#...7...........[..x....b........................................(....*:.(......}....*.~....*...0..........(....,..*..(.....o.......&...*...................0...........(.......(....-..,..*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*..,&(....,..r...pr...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*...(....*.(....,.r...p......%...%...%...(....*....(....*.(....,"r.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):18312
                                                        Entropy (8bit):6.439506871486808
                                                        Encrypted:false
                                                        SSDEEP:384:cEwo6eTs14YY4cWpOW6dHRN7FYpJAlGspU:VwDdT463
                                                        MD5:BE2962225B441CC23575456F32A9CF6A
                                                        SHA1:9A5BE1FCF410FE5934D720329D36A2377E83747E
                                                        SHA-256:B4D8E15ADC235D0E858E39B5133E5D00A4BAA8C94F4F39E3B5E791B0F9C0C806
                                                        SHA-512:3F7692E94419BFFE3465D54C0E25C207330CD1368FCDFAD71DBEED1EE842474B5ABCB03DBA5BC124BD10033263F22DC9F462F12C20F866AEBC5C91EB151AF2E6
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....r..........." ..0.............V8... ...@....... ..............................!.....`..................................8..O....@...............$...#...`.......6..T............................................ ............... ..H............text...\.... ...................... ..`.rsrc........@......................@..@.reloc.......`......."..............@..B................68......H.......|!..............\4.. ...|6......................................:.(......}....*..{....*"..(....*"..(....*"..(....*..(....*..(....*..(....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*..(....*:.(......}....*..{....*^.(...........%...}....*:.(......}....*..{....*z.(......}...........%...}....*V.(......}......}....*..{....*..{....*..BSJB............v4.0.30319......l.......#~..@.......#Strings....8.......#US.<.......#GUID...L.......#Blob...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21208
                                                        Entropy (8bit):6.913262967781329
                                                        Encrypted:false
                                                        SSDEEP:384:+SKiWIhWdC7Bm0GftpBjtQaQHRN76fl3uVogL:+SK8DVicL6wV7L
                                                        MD5:6DCD91B6A029794728F4EDEB2BF2E42D
                                                        SHA1:82BA1313448B431893C14D866F46D47B620514A9
                                                        SHA-256:02416BC542BE82002B8B81ADBBBCDCC8D098104020D09B571DC674B5BC19A177
                                                        SHA-512:2566F369EDEE9313E823AA2667CB95977F0DB57B4B47DA62F44850811F524D0598FDE6F5BB082BB3325789E4B256E970603B4297D3586F1C435498430723A38B
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............(... ...@....... ...............................s....@.................................t(..O....@.. ................>...`......<'............................................... ............... ..H............text........ ...................... ..`.rsrc... ....@......................@..@.reloc.......`......................@..B.................(......H.......P ..l....................&......................................BSJB............v4.0.30319......l.......#~......@...#Strings....D.......#US.H.......#GUID...X.......#Blob......................3......................................................\.....0.....'.....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.6...K.V...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22392
                                                        Entropy (8bit):6.85070945929809
                                                        Encrypted:false
                                                        SSDEEP:384:n0KbZWApWmWTpWWFm0GftpBjNaTaQHRN7vnl4aRISeS:0KRybViaTLSAl
                                                        MD5:4523F60270149BAD67F6AE63375D2CDB
                                                        SHA1:FF6E6BCD83A11D40BF53DABD0480A67AECFDCF50
                                                        SHA-256:18032D190D0D599823E59C8DD8B588909BEF8888B8BF304723A138B61F1B911F
                                                        SHA-512:025E33F6927E634FE187491F40D96B36B2DDAF2ACDE97B340C8705BAE58BDED6C02B8BF9199A1B9D4AC75884C69DC665DC03B34571B1BD178CA1784C5F0D5451
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..............)... ...@....... ..............................#.....@.................................>)..O....@..................x?...`.......(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B................r)......H.......p .......................(........................................(....*..(....*..(....*..(....*BSJB............v4.0.30319......l.......#~..........#Strings....`.......#US.h.......#GUID...x...(...#Blob...........G..........3.............................................."...........C...........u...............m.b...........J.....J.....J.....J...6.J...O.J.....J.....J...j.C...S.J.............................P ............X ............` ......4.....h ....................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22136
                                                        Entropy (8bit):6.553435177736525
                                                        Encrypted:false
                                                        SSDEEP:384:ERiNrM5s2PuLGMcrt18VKWiWV1upaWuiXvHRN7TyAdVUB3R9zeZ:ERiNIs22LYtT4ofT9VUP9zg
                                                        MD5:57309E02D50092A1D8AF78F0E0E18E70
                                                        SHA1:87CFB2BE5BB611DCE9EA29170EF535C5FC24A595
                                                        SHA-256:9AC1FD35AE5EB148B23B41CACEC6E09F1B83FD8E8270B8A79E9C401B284F5D8F
                                                        SHA-512:FCAE08EA95858E69BF89D7430395732CE1F79F772BEEBF4ECFC9AADF796282869C89493F4460249980E22065C83BA0A4AAB1736D36D84F76CCE3674BA3150791
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....EI..........." ..0.."..........VA... ...`....... ..............................U.....`..................................A..O....`..4...............x(...........?..T............................................ ............... ..H............text...\!... ...".................. ..`.rsrc...4....`.......$..............@..@.reloc...............,..............@..B................7A......H.......H"..............L=..0...|?........................................(....*:.(......}....*..(....*..(....*..(....*..(....*:.(......}....*..{....*:.(......}....*..{....*:.(......}....*..{....*..(....*:.(......}....*..{....*^.(...........%...}....*:.(......}....*..{....*z.(......}...........%...}....*V.(......}......}....*..{....*..{....*:.(......}....*..{....*"..(....*"..(....*"..(....*>..(......}....*..{....*"..(....*>..(......}....*..{....*..{....*"..}....*"..(....*"..(
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.925439366434707
                                                        Encrypted:false
                                                        SSDEEP:384:rb1nWCXWBC7Bm0GftpBjEYdgaQHRN7pC7lZ3atK9N:37RVioLpCf/9N
                                                        MD5:D40515A84448B91315F956E6D1A6C64B
                                                        SHA1:7FE773332D0461A252E52BE720A7794FCAAC7BFB
                                                        SHA-256:CBE29672CD2B6A0EA97B55F3844FBEDE3E591996F39C3AA1F829F2FA50551FA9
                                                        SHA-512:322F82AEB9EB9DA22257AC9FE835BF1C54C1BB268D37F0F97A4CA52BB42F6ACCCA9C8DBDB96D6D695FA69C24F5069978A4B6F1E960EE81D9EA671CCD30A348D3
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............)... ...@....... ..............................iR....@..................................(..O....@..T................>...`.......'............................................... ............... ..H............text... .... ...................... ..`.rsrc...T....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~.. ...t...#Strings............#US.........#GUID...........#Blob......................3......................................................\.....0.....6.....D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.!...C.<...K.\...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21696
                                                        Entropy (8bit):6.85763123423511
                                                        Encrypted:false
                                                        SSDEEP:384:UNyW7TWpvT1Dm0GftpBj6jaQHRN7hlGinGErW:ufi1DViGLpfW
                                                        MD5:7F65CCBF58C39F3853BB8DC4137DFD12
                                                        SHA1:3946DFF0B68F0CA01689BD44C348559ADF548258
                                                        SHA-256:0AB1F7F87B7C2AFCA57D394E4F4E262C82BA3209CB0A750CD66401FB33F21ECA
                                                        SHA-512:FF7D953EC4B82C10E64FC85D3AFC8A1A58582170EF1752D4688FA1D48EFC490DBA5F0A784E748F7902E96FD885EA868B1A84DE44F48CF071975F3CD3F8E52C6A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0.............2*... ...@....... ..............................'.....@..................................)..O....@...................>...`.......(............................................... ............... ..H............text...8.... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ......................((......................................BSJB............v4.0.30319......l...0...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................................\.....0...........D.7.....7.....7...C.7.....7.....7...[.7...x.7...-.0.....7.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.1...K.Q...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):78976
                                                        Entropy (8bit):6.105061710610473
                                                        Encrypted:false
                                                        SSDEEP:1536:4OO7OOOc2yIDmBkKQh3rt7jUGyRG/mz4CRLf8ocVW4t72bfQZHzp:fyMmXQh3rNjUFG/mk8f8owW4s0ZHF
                                                        MD5:C77AE3414D78C1F082C65415FAE69661
                                                        SHA1:3B35461D86A774535AC226CA9706FB50332DE20A
                                                        SHA-256:C792BFE3F43C894E20339252D159A96A20CCC6E13322B2D382570FF97939E501
                                                        SHA-512:08941BA8BE5031CC4E363A916525437C62B409576C91C10FC72795FAA10BC989F0D1797B576802E208DFE4305A4447C0299E2755BA92F97F531DE1F56FD5865A
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....u............" ..0.................. ... ....... .......................`......<.....`.....................................O.... ...................(...@..........T............................................ ............... ..H............text...0.... ...................... ..`.rsrc........ ......................@..@.reloc.......@......................@..B........................H........m......................H.........................................('...*..('...*..('...*^.('......8...%...}....*:.('.....}....*:.('.....}....*:.('.....}....*^.('......9...%...}....*:.('.....}....*:.('.....}....*..0..E........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X((.....R...((.....d.R*....0..K........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X().... ...._.S...().....d.S*..0..&.........+....(*...G...Z.(......X....(+...2.*...0............(+.....1...(+....Z.:..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):582320
                                                        Entropy (8bit):5.99177382417674
                                                        Encrypted:false
                                                        SSDEEP:12288:Bo+rY8ZyAVNXL1VPGSEiWqJHsiEg2A9fLF:BhxXXrPGS6A7h
                                                        MD5:B7083FFD5D2BBBE83C6B439196838D78
                                                        SHA1:17B58D7F1CFFE4C1DD8E8246E127C949F4066D85
                                                        SHA-256:D14DBC34F6824757E6F6AE758B05F76C447F96F8D75BE3C4B8286FCC5A388B30
                                                        SHA-512:6C82D0F3B8E65DB99AA6F3973A6CB69CC9D02EFD3C3CC55AF03F01D5318360054E004EA4BCB53A2A7CF5DC1C0D77DC9183B479654CF88BBAC7B263FC68C61B16
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L................" ..0.................. ........... ....................... ......+.....`.................................i...O........................(..............T............................................ ............... ..H............text........ ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................H........S..............`O...w............................................(J...*..(J...*..(J...*..(J...*^.(J..........%...}....*:.(J.....}....*:.(J.....}....*:.(J.....}....*..(J...*:.(J.....}....*.0..E........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X(K.....R...(K.....d.R*....0..K........ ...._.b..._X ....Y..e pp.._.d.X ....X.`.....X(L.... ...._.S...(L.....d.S*..0..&.........+....(M...G...Z.(......X....(N...2.*...0............(N.....1...(N....Z.....(...+.+...(N....Z......
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.952743264834991
                                                        Encrypted:false
                                                        SSDEEP:384:i6Rb32WVzWIvT1Dm0GftpBj2gaQHRN7EBlBLY6fG:NRb3dH1DViIgLEhYj
                                                        MD5:7D317D88F9860A18ECF7FB90B33995D3
                                                        SHA1:C2E4B19CB9A0B48E899512CD121FFE6657D41072
                                                        SHA-256:C98A52BD017DF01AEA7B955E6F219537D391A62C2C2B976684DA282F9CD7CACF
                                                        SHA-512:79ED01C6D1CEA3DBA6B3566E03D05A971745E221BE9330F6800A249D1B239E092D3FF704E7403E7ECD6B7709B24B0CDD7E518F2EE5DA38019E7139D80594173E
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............)... ...@....... ...............................Y....@.................................t)..O....@..P................>...`......<(............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................)......H.......P ..l....................'......................................BSJB............v4.0.30319......l.......#~..........#Strings....@.......#US.D.......#GUID...T.......#Blob......................3..................................................K...d.K...8.8...k.....L.................K.................c...........5.........................2.....2.....2...).2...1.2...9.2...A.2...I.2...Q.2...Y.2...a.2...i.2...q.2.......................#.....+.....3.....;. ...C.;...K.[...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):37752
                                                        Entropy (8bit):6.646566139863202
                                                        Encrypted:false
                                                        SSDEEP:768:ou5I+sqOylryry8qqIfUc7a5oUVi1vLFss:oYIVBpry8qqIfUcm5vVgDSs
                                                        MD5:1A890C488CF2ECD406B804E7E3C5B7F0
                                                        SHA1:BF2C1287F0EC04223CD17FE20AB2ECFFF18579E3
                                                        SHA-256:F17FF442B77A6CFE9C118D2F8FAE1AB6C814A0D4F35C5844996BE84F3FCC8592
                                                        SHA-512:4EEC61F9245DFF3D468818D6D6CBB8E12A5172658F1027A9AB0ECE03CC1377499833056A0DD4FF20B83B9FF9E47BB2E7F8DC7B641BC63AD78FF96C54BE01F524
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..F...........d... ........... ....................................@..................................c..O.......x............T..x?...........c............................................... ............... ..H............text....D... ...F.................. ..`.rsrc...x............H..............@..@.reloc...............R..............@..B.................c......H........&...7...........^.......b......................................j~....%-.&(....s....%.....*..*...0..$.........(.....o.......&...,....o....,..*.*..................,!(....,..r...p.(....(....*..(....*.*.(....,.r...p......%...%...(....*..(....*.(....,.r...p......%...%...%...(....*...(....*.(....,!r...p......%...%...%...%...(....*....(....*2r...p.(....*2rK..p.(....*2ry..p.(....*2r...p.(....*2r...p.(....*2rc..p.(....*......(....*..0..;........|....(......./......(....o....s
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):25984
                                                        Entropy (8bit):6.291520154015514
                                                        Encrypted:false
                                                        SSDEEP:384:1R973o62/KqcAnb05J3w0I5eUGef8s72XBWdvVW2JW8aJcyHRN7WEimpplex:1RZ4nNxnYTb6Blha
                                                        MD5:E1E9D7D46E5CD9525C5927DC98D9ECC7
                                                        SHA1:2242627282F9E07E37B274EA36FAC2D3CD9C9110
                                                        SHA-256:4F81FFD0DC7204DB75AFC35EA4291769B07C440592F28894260EEA76626A23C6
                                                        SHA-512:DA7AB8C0100E7D074F0E680B28D241940733860DFBDC5B8C78428B76E807F27E44D1C5EC95EE80C0B5098E8C5D5DA4D48BCE86800164F9734A05035220C3FF11
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....jM^.........." ..0..8...........V... ...`....... ....................................@..................................V..O....`...............B...#..........PU............................................... ............... ..H............text....6... ...8.................. ..`.rsrc........`.......:..............@..@.reloc...............@..............@..B.................V......H........0...$...................T........................................(....*..(....z..(....z2.(....s....*2.(....s....*:........o....*.~....*~.-..(......}......}......}....*~.-..(......}......}......}....*Z..}......}......}....*J.{....%-.&.*o....*^.u....,........(....*.*~.{.....{....3..{.....{......*.*&...(....*2...(.......*....0..'........{......,..u....%-.&..(...+(....*(....*n.{....,..(....s....*.q....*..0..a.........{....o0.....,;..{....o2...(......;...3.~.......s......
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21232
                                                        Entropy (8bit):6.924199325151996
                                                        Encrypted:false
                                                        SSDEEP:384:Wvn4HREpWiQWBTwm0GftpBjtSaQHRN7BlGinGEb:pS7wVifSLJ/
                                                        MD5:9088029E38B2A393F22AFD9E576CE86E
                                                        SHA1:05E65EE95F647F38C717C73A0399870912DD374A
                                                        SHA-256:3468E0C875DB94A8F45D56AB76BBCC677B942CA51A23649BA3C5AD1B20E391F1
                                                        SHA-512:23DCF5819996EE0F0C8FE044D6642A12E98A40309CE1F3F74688CF8E3DD6F6ED230AEC391FE7E511E15FBBBF14BFF09F976E923F22F2D68AD816D8FFAD17F101
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............)... ...@....... ..............................d.....@..................................(..O....@..P................>...`......x'............................................... ............... ..H............text........ ...................... ..`.rsrc...P....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......l...#Strings....|.......#US.........#GUID...........#Blob......................3......................................................n.....B.....".....V.................U...........$.....m...........?.....(...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.!...C.<...K.\...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22224
                                                        Entropy (8bit):6.854915516686979
                                                        Encrypted:false
                                                        SSDEEP:384:G8MjKb47T3UCcqFMkJ59WdtWe+109m0GftpBjPRaQHRN7LKlgaGn7ce:jMjKb4vcGdOdVilRLLeG4e
                                                        MD5:0AD301EE2B7282B87DCD0D862EFE14DC
                                                        SHA1:F720109A38846E358BDE7C47D9C946A79D2B6B1C
                                                        SHA-256:0110616DFE870B8BCF25DF8F6CE38EF5AAC39E728DDAA3420EA199F5A7E80A16
                                                        SHA-512:C66FC92435C399804D8A8C1C836E5648725DDA8A55D7ACD897AE719CA231D89251A0D9A293A67F079E345709CFDA83DCC693AD41A28D13661A55459F94FE33E0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............,... ...@....... ..............................k.....@.................................`,..O....@...................>...`......(+............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................,......H.......P ..X....................*......................................BSJB............v4.0.30319......l...<...#~..........#Strings....4.......#US.8.......#GUID...H.......#Blob......................3................................!.....O.......................................].....z.............................7.......j...........n...........................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.3...K.S...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21200
                                                        Entropy (8bit):6.917303618941186
                                                        Encrypted:false
                                                        SSDEEP:384:RzyNXd4+BW6FW9vT1Dm0GftpBjJtaQHRN73hYlO62gHcXb:szA1DViHtLxRg8L
                                                        MD5:FDB3A743B2DAE5924CBA88A5C865128D
                                                        SHA1:C53132EC95A7211C1BB6DCD5AD21CCB150A7B923
                                                        SHA-256:9D4FAEA9892D4ECFABF61986687FC6CB30F5F51A6B62819B9571FF58E04C4DD5
                                                        SHA-512:CBD8370F3CB84CB9EB8BF3A7392245D6A90CE1A324971EA96170974DA092BDFC3DB2196F66958CA5D5000F13B18AFAB44FF82D50C5B9A625AA1B7A4AF17717DE
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............)... ...@....... ...................................@..................................(..O....@...................>...`.......'............................................... ............... ..H............text... .... ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P .......................'......................................BSJB............v4.0.30319......l.......#~..,...p...#Strings............#US.........#GUID...........#Blob......................3..................................................'.....'...T.....G.....h.................g...........6.................Q.....:...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.4...K.T...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21216
                                                        Entropy (8bit):6.913880291057063
                                                        Encrypted:false
                                                        SSDEEP:384:Bvs2Q3HKJNrWWRW8KvT1Dm0GftpBjb/aQHRN765EldBoQAYY9:BuMg1DViJ/L65woJYi
                                                        MD5:18CE4ECC42FC8D999EF091D812472CF0
                                                        SHA1:F874903CEA9F08F1A0887949B47722E6BA81B789
                                                        SHA-256:3D9EBC81B1BD3234666C8CE403A5F17A726867C68FFA5DE4EC8EE92599335658
                                                        SHA-512:0C027440EF6F6C105B0BF9319F4E0EA421FD310699028AF0A159300145C662E74B4B5D969663E3B52CDA7F9934A6AB93BBAE9BCD1BD39AAAC24FCBA7EC451156
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............(... ...@....... ..............................L.....@..................................(..O....@..4................>...`......h'............................................... ............... ..H............text........ ...................... ..`.rsrc...4....@......................@..@.reloc.......`......................@..B.................(......H.......P .......................&......................................BSJB............v4.0.30319......l.......#~......`...#Strings....p.......#US.t.......#GUID...........#Blob......................3................................................../...q./...E.....O.....Y.................X...........'.....p...........B.....+...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.8...K.X...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21200
                                                        Entropy (8bit):6.897588144752097
                                                        Encrypted:false
                                                        SSDEEP:384:FFz0Q6gcqRhcsMWdMWwvT1Dm0GftpBjZ/AoaQHRN7plxBGDO:FFz1c6u1DViHBLTMO
                                                        MD5:824053272B268C577E9ADF17ED398142
                                                        SHA1:5EA3F290ECDE1BAB983CEEE2417A688B7ED9B7F5
                                                        SHA-256:04B9235F64C9C846F8A767230714895DA87C7AE2CD0105E9D14835AE46F0FED8
                                                        SHA-512:F475DCD2CC23FDFB017688713170FCAF8FEA05869A680613EA4AD84CB358ED0F2442DB0FF0DCBD739E3CC3DB7128A8F4A568AE8E5AF6A8840319B02630E420B9
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............(... ...@....... ....................................@.................................L(..O....@...................>...`.......'............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................(......H.......P ..D....................&......................................BSJB............v4.0.30319......l.......#~......,...#Strings.... .......#US.$.......#GUID...4.......#Blob......................3......................................................\.....0...........D.................C.................[.....x.....-.........................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.3...K.S...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22192
                                                        Entropy (8bit):6.821272653310105
                                                        Encrypted:false
                                                        SSDEEP:384:E6xWA3W4aW/NWtvT1Dm0GftpBjHaQHRN7TqidlZ30F:EaBk1DViFLTquO
                                                        MD5:11D674CFC81B7102C0BC6FFE58F6AC5E
                                                        SHA1:DDDA49572D112944EC9AB62B31959AA93A386618
                                                        SHA-256:4DC8D588EC63641C28422D648E8DE5E2C030EB7AFEC2071A99DD3BD9A204557F
                                                        SHA-512:FB7C628B796A321AD9ECBF01D165E24F151C99D7E60A65D0AF52F779AD60A3203F47B247D44FC47044A68790D1EA4EE458A7BC8DF7EBE9D42C2275A9C11BC324
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............,... ...@....... ..............................).....@..................................+..O....@...................>...`.......*............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H.......P .......................*......................................BSJB............v4.0.30319......l... ...#~..........#Strings............#US.........#GUID...........#Blob......................3......................................-.........O.k.....k.....X.....................1...........o.........................B...........9...........J.....J.....J...).J...1.J...9.J...A.J...I.J...Q.J...Y.J...a.J...i.J...q.J.......................#.....+.....3.....;.....C.-...K.M...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):78992
                                                        Entropy (8bit):6.056589052139225
                                                        Encrypted:false
                                                        SSDEEP:1536:6784YWau8lqubx6WxXLA+o2SLFyEdux136ytgHo0AuresehSAPVGHMc:67NV8v36tI0XCKAt6
                                                        MD5:8C9424E37A28DB7D70E7D52F0DF33CF8
                                                        SHA1:81CD1ACB53D493C54C8D56F379D790A901A355AC
                                                        SHA-256:E4774AEAD2793F440E0CED6C097048423D118E0B6ED238C6FE5B456ACB07817F
                                                        SHA-512:CB6364C136F9D07191CF89EA2D3B89E08DB0CD5911BF835C32AE81E4D51E0789DDC92D47E80B7FF7E24985890ED29A00B0A391834B43CF11DB303CD980D834F4
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....>.Z.........." ..0.................. ... ....... .......................`............@.....................................O.... ..P................>...@......x................................................ ............... ..H............text........ ...................... ..`.rsrc...P.... ......................@..@.reloc.......@......................@..B........................H......................................................................6..o.........*f..o...........o.........*...o...........o...........o.........*...o...........o ..........o!...........o"........*...o#..........o$..........o%...........o&...........o'........*....0..L.........o(..........o)..........o*...........o+...........o,...........o-........*.0..Y.........o...........o/..........o0...........o1...........o2...........o3...........o4.... ...*....0..k.........o5....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21712
                                                        Entropy (8bit):6.911176710124494
                                                        Encrypted:false
                                                        SSDEEP:384:mr97WquWk+109m0GftpBjNWVaQHRN7u90lgaGn7a:mRJcVifWVLbGW
                                                        MD5:090FF56C4FE2EEFF2E16F03099AD71E1
                                                        SHA1:EF317CACC230A58A3B2FCC6CC079CC763AFCC7C5
                                                        SHA-256:5F560E1DD529BB2529D7052E04008449F58D0439C2BB43437D7B5D39F84F949F
                                                        SHA-512:FDAC43D0A18D9158DB4438349A7A550557A36E6ED0665EFCB65A046A5BEB5C38181996CBF6D860B8AD01C19E35315BB61AE766CAF06B23985E046484DAB45256
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............+... ...@....... ..............................W.....@.................................\+..O....@...................>...`......$*............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................+......H.......P ..T....................)......................................BSJB............v4.0.30319......l.......#~..T.......#Strings....0.......#US.4.......#GUID...D.......#Blob......................3......................................z...........j.....j.....W...............B.....z.............................................................Q.....Q.....Q...).Q...1.Q...9.Q...A.Q...I.Q...Q.Q...Y.Q...a.Q...i.Q...q.Q.......................#.....+.....3.....;.....C.4...K.T...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21696
                                                        Entropy (8bit):6.875690583921479
                                                        Encrypted:false
                                                        SSDEEP:384:O16eWLDWevT1Dm0GftpBjAAYaQHRN7N9lZ3w:q6L91DViqTLXA
                                                        MD5:37E21B63959F243A157534133F85C5AF
                                                        SHA1:DFAD52A9990B2FAFCE7098CEBB174927E8E0BA00
                                                        SHA-256:4F6A14E4BA2A2B26B8B8433D5F82F75A96AF5A4F036D9447373B07271493917B
                                                        SHA-512:F59FAA6319FE2AFEBCCBD643E20C1EDB75DB74E9271354BD86DAC3BEA2CC59452EE024DC26B517AE88254A7C90DBE0E6C19A7B5AB3BFE9159D986D6C53CA5521
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............*... ...@....... ..............................#F....@.................................|*..O....@...................>...`......D)............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P ..t....................(......................................BSJB............v4.0.30319......l.......#~......8...#Strings....T.......#US.X.......#GUID...h.......#Blob......................3..................................................z.....z...u.g.................................>.....W.................r.....[...................a.....a.....a...).a...1.a...9.a...A.a...I.a...Q.a...Y.a...a.a...i.a...q.a.......................#.....+.....3.....;.....C.1...K.Q...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):22904
                                                        Entropy (8bit):6.8552351968066105
                                                        Encrypted:false
                                                        SSDEEP:384:58G4YC2W+wW8WpwWOFm0GftpBjBdDcaQHRN78lgCovnt/:2GZ5QVipgLzH/h
                                                        MD5:A5F541655A9EDC24F4B5184A40E40227
                                                        SHA1:90E196DCD76168F770ABE30098399BC5866ADF1B
                                                        SHA-256:B33D08149A756A401628D11BFDDFEEACA1F03C0578395BB061DAE44F8A12CE5D
                                                        SHA-512:C4D13E95114E232300B36ED7B7A72CE786F66D0F68B0ED9D54FEF788A831B39C893DAA3C2DE982B376A56A539C23E8F314CE8552ED7094E6826D5F70BFBE2D4B
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L......Z.........." ..0..............+... ...@....... ...............................+....@.................................z+..O....@..x...............x?...`.......*............................................... ............... ..H............text........ ...................... ..`.rsrc...x....@......................@..@.reloc.......`......................@..B.................+......H.......t ......................P*........................................s....*:.(......}....*2.{....(....*BSJB............v4.0.30319......l.......#~..0.......#Strings............#US.........#GUID...........#Blob...........WW.........3..............................................................L.........4.H...}.H...u.v...........;...........;...=.;.................../.%...........P.....m.....................................v...S.......v...d.v...........v...m...............
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21176
                                                        Entropy (8bit):6.950543834803339
                                                        Encrypted:false
                                                        SSDEEP:384:z6ziqTEkGWvRWtvT1Dm0GftpBjqK4aQHRN7FMlBLY6fMf:zYT1E1DViaLFgYnf
                                                        MD5:415E3AB72F17F10D646B3E2C7A76F612
                                                        SHA1:ED25E94D4E88293345A0F28A5B975159C393B050
                                                        SHA-256:24DAA1FAEE0478BA58FEBE8EE789EB88BE0A14D350B57AD8B10690C55976B2E1
                                                        SHA-512:55B5C22B87F21DF89D0514AE05C9433B65A3C7532845FDFC4C2C5C5E2C3929D70143D84698FDB4DC13EC01895B1022CF0E5E76E12102739530B54150932A7B07
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...B..Y.........." ..0..............)... ...@....... ..............................x.....@..................................)..O....@...................>...`......d(............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................)......H.......P .......................'......................................BSJB............v4.0.30319......l...0...#~..........#Strings....x.......#US.|.......#GUID...........#Blob......................3................................................'...........~...................................G.....`.................{.....d...................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.-...K.M...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21712
                                                        Entropy (8bit):6.8884260737638385
                                                        Encrypted:false
                                                        SSDEEP:384:jUv7c7iWNCWxvT1Dm0GftpBjvaQHRN7KlBLY6fmV:jM7c1R1DVi5LeYpV
                                                        MD5:328D12AF9613B0F3F25320B85DCCCBF4
                                                        SHA1:09D02B85A094E925AC3C5D8B1ACA096B730C160F
                                                        SHA-256:8957F0BCEA6AB8A011A53AE62466505199F11A228F87F3809931D974F87078CE
                                                        SHA-512:16569ECB727ADA36811E72FFC925F07AA21B8A627BE45F1EDA18CF2B759939591DCAFCB2D087596EE903C5ABFFAF19F56F25E9710EF22874C934CAD19537B798
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...C..Y.........." ..0..............*... ...@....... ..............................\.....@..................................*..O....@...................>...`......`)............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................*......H.......P .......................(......................................BSJB............v4.0.30319......l.......#~......l...#Strings....l.......#US.p.......#GUID...........#Blob......................3................................................4...........~.............H.....H.....H.....H...T.H...m.H.....H.....H.........d.H.................................).....1.....9.....A.....I.....Q.....Y.....a.....i.....q.........................#.....+.....3.....;.....C.3...K.S...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):21712
                                                        Entropy (8bit):6.916807633540711
                                                        Encrypted:false
                                                        SSDEEP:192:3+vxmNWnRW52bivT1CCjdks/nGfe4pBjSrl1WAaAXcrMHnhWgN7aMW2Mqnaj87Xf:GSWnRWDvT1Dm0GftpBjy7aQHRN7IlZ3U
                                                        MD5:D9F02D9F7DA653F82E75112A2AB99CE6
                                                        SHA1:BBBB4C2C3911AE1F5BA7FAF1D632ED0F14D9B6AC
                                                        SHA-256:21493F7F615A099E795F7FAE7ECCE6082414D1D427790BDF4B103623A3AB34EB
                                                        SHA-512:DE5546FF103CCC6AA38E254039A372697A193F9C44D0A44F0BE3B242D9EEF63023DC3FD0C6E8E0D2363177F9230A4E7200D4C32591B398269A1CEE9BC47A99FC
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...C..Y.........." ..0..............+... ...@....... ....................................@.................................L+..O....@..$................>...`.......*............................................... ............... ..H............text........ ...................... ..`.rsrc...$....@......................@..@.reloc.......`......................@..B.................+......H.......P ..D....................)......................................BSJB............v4.0.30319......l.......#~..........#Strings.... .......#US.$.......#GUID...4.......#Blob......................3..................................................k.....k...U.@.........i.....=.........................................&.....'...................:.....:.....:...).:...1.:...9.:...A.:...I.:...Q.:...Y.:...a.:...i.:...q.:.......................#.....+.....3.....;.....C.5...K.U...S.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):78080
                                                        Entropy (8bit):6.045714767198294
                                                        Encrypted:false
                                                        SSDEEP:1536:Fq/+0G+b5yxxJ6q4S7SVrdtwbmAiJyrKclP7HxqMkU:qG+1yxqqRSBdtwbWyOYPM9U
                                                        MD5:B967900C197C07A4A71514054FD6F99B
                                                        SHA1:6AEAF84C7FCFF57FDD157655DD1D161D04F384D3
                                                        SHA-256:CC4935FF9435998AC4CF453ECE83619F1C51A469134809E4B125A8D07D00701D
                                                        SHA-512:4121908E71A5D7D89B04514E84437CC5DBB99226174F290A1C4503CABE4DAB1BB80278005E5D50C96A87F40E7AA7D617C04F4EF56B069EDCE01512910C84842B
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...k............."...0.................. .....@..... .......................@......b.....`...@......@............... ............................... ...................'..............8............................................................ ..H............text........ ...................... ..`.rsrc........ ......................@..@........................................H........}..........F.....................................................{....*.0..|.........}......}.....r...p.#(....~.....n...(....}.......(...........s....(...........s....(....(.....( ....o!...o"......,..o#....*......_..q.......0..,..............s....($..........s....(%......(.....*........$$.......0..3.........(&...}E......}G......}F......}D.....|E.....(...+*.( ...o(...*..0...........r!..po)...r-..prG..pro..p..t...(*...(+.......s,...%r...po-....(....,;. ....("...%-.&.+.(......,
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):19803
                                                        Entropy (8bit):5.001270994061144
                                                        Encrypted:false
                                                        SSDEEP:96:NmhruVMkubUwfx0GReGWeGFuGgeKCUDuTeHOTu0U5e3eTOaUmS0SXStuKhubUfSy:NmhruU5PUDRTHffIz
                                                        MD5:9EB8EB5B95A24D24F410DEAA400A2308
                                                        SHA1:CC6512BA800D56B450F1CAA1D6F545AD1C8054E7
                                                        SHA-256:6098E9EC019C71D3EC97B3F556FA4CB12AAB13A41AC6C921DD6ED4D60344020A
                                                        SHA-512:0BCBEBB191F0909AA1DA959BFCABD2318ED356B39C758C8AEBDF90DA9C63ED9A867A7D6F422BB9548D890AD3F13962CC16ECFE1265038A8D51482DB8026868C7
                                                        Malicious:false
                                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="debug" value="false" />.. Verbose = 0, Information = 1, Warning = 2, Error = 3, Critical = 4-->.. <add key="loglevel" value="2" />.. set this flag to true if enrollment sync is enabled-->.. <add key="registrationSyncEnabled" value="true" />.. how many times Assist should try to connect to Hub before it fails -->.. <add key="registrationSyncHubRetry" value="3" />.. 12h default enrollment syncup interval-->.. <add key="registrationSyncIntervalMinutes" value="720" />.. </appSettings>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.6.2" />.. </startup>.. <system.net>.. <defaultProxy>.. <module type="AetherPal.Windows.Net.CachedWebProxy, AetherPal.Windows.Net" />.. </defaultProxy>.. </system.net>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyI
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):18688
                                                        Entropy (8bit):6.6530295717862895
                                                        Encrypted:false
                                                        SSDEEP:384:PiFp2CEM4emAQZZNyb8E9VF6IYinAM+oXCbZuA:02tMTY9EpYinAMxyV
                                                        MD5:C7239FFE59A3C868C1B5E93737FF1C18
                                                        SHA1:EE02BCDEB29D504292275E81420A8B9EBC8E10F7
                                                        SHA-256:9E99BFFEBD73F231B320C47F113B4E6725C5CA3764EC1200A929295D00B71CA7
                                                        SHA-512:93CEC97354FAEB2554D793DE520855AA614E6C26C5A470557367E8552218397996473D3BD9FBF8D99AD98CF7C2FD862115FAD6FAFDB3550E6F6B7FC863B0B1C0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...\............"...0.................. .....@..... .......................`......,c....`...@......@............... ...............................@..p............"...'...........5..8............................................................ ..H............text...Q.... ...................... ..`.rsrc...p....@......................@..@........................................H........%...............................................................0............r...p......%.(.....(.....s....(....&r...pr-..pr7..p(....r_..p.rm..p.~......o......-..+...(....,O.o.........+:...........o....,"....o....%r...po....o......o....+....X.......i2....,..o.....~......o........-..+....(....,R..o.........+<...........o....,$.....o....%r...po....o.......o....+....X.......i2.....,...o.........r...pr-..p..(.......r...p .'..(....(....(........r...pr-..p..(....... ....(....r...p
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):1603328
                                                        Entropy (8bit):6.8628318302326345
                                                        Encrypted:false
                                                        SSDEEP:12288:U37H1pN3fXl3qxS+HHBQdNiWpJ0jM30rCGU48DMeKmb2+HVuzJrR:uNR+HHBWiWpJ0jM30rCG58DMeKg2zL
                                                        MD5:DD9D6E62E343139A4AA744EA55DC5FD5
                                                        SHA1:C66D1F9BC83D24105BFC5ED85894B862436139FD
                                                        SHA-256:63077A1873CC6325D96E591D43DE4E653D422F881FCD758A5EC75BEBD99D5BE6
                                                        SHA-512:61BDCD29039CCA1F24F3139C5ED96191292EAEB5C53FFFC125D4B5D7384A1A22715B9570814ED42739442C448ECAFA085373C51A35452FE01045C31AAB9CBFCC
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d................."...0......t........... .....@..... ..............................;X....`...@......@............... ...................................r...........P...'..........x...8............................................................ ..H............text........ ...................... ..`.rsrc....r.......t..................@..@........................................H........=..d.......,...@...88..........................................V~....%-.&s....%.....*"..}....*..{....*"..}....*..{....*.0...........#.......?}.......}.....(....r...pr...pr...p(.....('....(....(............s....(...........s....(.....#.......?( .......%...s!....("...s#...}.....{....o$....~%...(r...rS..p~&...ro..p('...((...&(....,"(....o)...,.(...........s*...o+...*"..}....*.0..2.......s.......}......}.....("..........s,...(...+o....&*...0..........r...pr...pr...p.o/...(0...(.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):20533
                                                        Entropy (8bit):5.026848715712913
                                                        Encrypted:false
                                                        SSDEEP:96:3vprKKS4YpyMrsJ+J4YqJyMfowUkubUwfx0GReGWeGFuGgeKCUDuTeHOTu0U5e3q:3vprKKS/pvrsJ+J/qJvbO5PUDRTHffIz
                                                        MD5:64E7AAB4DC17F56E599D252A7B00B57D
                                                        SHA1:8A16203DA3DAAD841EDEDFEFA18D1160BDB68035
                                                        SHA-256:BE25F35B80E0A683A5A5BA0BA5A065A29AB88324FBDCC32AC61BD4F7E4E94161
                                                        SHA-512:D16E86DF5EDE3E37CF7D3EADE388862B293FAF159C2F4206F93DE89330EF544707BDADBAF2AB98B916AD0E634194F68390C13C82C50FAA8B4AEC96CDB8BAC5FC
                                                        Malicious:false
                                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. <add key="debug" value="false" />.. <add key="loglevel" value="2" />.. Verbose = 0, Information = 1, Warning = 2, Error = 3, Critical = 4-->.. <add key="ClientSettingsProvider.ServiceUri" value="" />.. <add key="supportedlanguage" value="ar-AE, cs-CZ, da-DK, de-DE, en-US, es-ES, fr-FR, he-IL, it-IT, ja-JP, ko-KR, nl-NL, pl-PL, pt-BR, ru-RU, sv-SE, tr-TR, zh-CN, zh-TW" />.. </appSettings>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.6.2" />.. </startup>.. <system.web>.. <membership defaultProvider="ClientAuthenticationMembershipProvider">.. <providers>.. <add name="ClientAuthenticationMembershipProvider" type="System.Web.ClientServices.Providers.ClientFormsAuthenticationMembershipProvider, System.Web.Extensions, Version=4.0.0.0, Culture=neutral, PublicKeyToken=31bf3856ad364e35" serviceUri="" />.. </providers>.. </membership>.. <ro
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):68352
                                                        Entropy (8bit):6.038708912856335
                                                        Encrypted:false
                                                        SSDEEP:768:7mx/URky8q95QfDNo+ShLFR074iG7cqoVXEb89tNjHLCTHXHvMEpYinAMxy5r7E:7m3iWfDSfhLf0NqmXzrCTHXPF7HxYrY
                                                        MD5:D7868E470ECA7ADE4DF6B53D8F25527C
                                                        SHA1:DB4C753CFA582DD32E05DDAE3BEB515BCBB5FD1B
                                                        SHA-256:4A95415C648941E5B351385BDBF03EDA92F699D11C8C0674FE0670A1ED06AF86
                                                        SHA-512:6243B0579FD633F1A249C7E29386CB1A7CB1A900647931C94BD8534F4BE713A2201A13D462AB3E157E3C2D9F41FDE2FDB5B1CD00F0D5CDFAAD8AFA1C16EB48B0
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.........."...0.................. .....@..... ....................... ......}.....`...@......@............... ..................................p................'........................................................................... ..H............text........ ...................... ..`.rsrc...p...........................@..@........................................H.......`^..L.......%.....................................................(....(.....(.....r...p(......(....r9..pr9..prW..p(....*....0..x.......(\...oa...r...p.(...........s....(....&.......s....(....&.(\...ob...}....(\...oh....".r9..pr...pr...p.o ...(!...(".....*........UU.".....0..........( ...(\...o_...(\...o`...(O...oR...(8...o;...(,..........s(...o....(,...o2....{....%-.&+.(#...&.{....%-.&+.o$....".r9..pr...pr...p.o ...(!...(".....*...........rr.".....0..3.........(%...}=......}
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):18296
                                                        Entropy (8bit):4.998731775001215
                                                        Encrypted:false
                                                        SSDEEP:96:irdx0GReGWeGFuGgeKCUDuTeHOTu0U5e3eTOaUmS0SXStuKhubUfSJeZedUabepW:ir3PUDRTHffIw
                                                        MD5:64045A9C557916EE1D7307A289191991
                                                        SHA1:41B4B399168B95F2D651737F0479BAFC0D840AF3
                                                        SHA-256:7AEDAB220A00D2CE7BB5BB83C2ABEC3688CF17502BB37B5F08D86998B71DB001
                                                        SHA-512:56A07453FAA079F77C244C8E23A7EA802B25B51F581DEAE96954BD8C67B770FB18FB2E7AE83194B338DDF420097433A1B55AB94FDCD4BAE854CAB5F1D567E8AD
                                                        Malicious:false
                                                        Preview:<?xml version="1.0" encoding="utf-8"?>..<configuration>.. <appSettings>.. Verbose = 0, Information = 1, Warning = 2, Error = 3, Critical = 4-->.. <add key="loglevel" value="1" />.. <add key="ShowConsoleWindow" value="false" />.. </appSettings>.. <startup>.. <supportedRuntime version="v4.0" sku=".NETFramework,Version=v4.6.2" />.. </startup>.. <runtime>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Runtime.InteropServices.RuntimeInformation" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.2.0" newVersion="4.0.2.0" />.. </dependentAssembly>.. </assemblyBinding>.. <assemblyBinding xmlns="urn:schemas-microsoft-com:asm.v1">.. <dependentAssembly>.. <assemblyIdentity name="System.Collections.Concurrent" publicKeyToken="b03f5f7f11d50a3a" culture="neutral" />.. <bindingRedirect oldVersion="0.0.0.0-4.0.11.0
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):633152
                                                        Entropy (8bit):6.344861237666909
                                                        Encrypted:false
                                                        SSDEEP:12288:eNQSZJrC30ovvjPo9E/YZt4QEKZm+jWodEEV2qwcg5MpccRwLM:0Z2jPo96QEKZm+jWodEEYqwcg5Mpck9
                                                        MD5:9FF712C25312821B8AEC84C4F8782A34
                                                        SHA1:1A7A250D92A59C3AF72A9573CFFEC2FCFA525F33
                                                        SHA-256:517CD3AAC2177A357CCA6032F07AD7360EE8CA212A02DD6E1301BF6CFADE2094
                                                        SHA-512:5A65DA337E64EA42BCC461B411AE622CE4DEC1036638B1E5DE4757B366875D7F13C1290F2EE345F358994F648C5941DB35AA5D2313F547605508FD2BCC047E33
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........`....}...}...}.......}..y...}.._|...}...|...}.._~...}.._y...}.._x...}.._u...}.._}...}.._....}.._....}.Rich..}.........................PE..d....LZW.........." ................@.....................................................`A............................................h...h...,............P...B...j..@?..............8...........................` ......................,...@....................text............................... ..`.rdata..............................@..@.data...L9..........................@....pdata...B...P...D..................@..@.didat..h............X..............@....rsrc................Z..............@..@.reloc...............^..............@..B................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:ELF 32-bit LSB shared object, ARM, EABI5 version 1 (SYSV), dynamically linked, BuildID[sha1]=db03b84a1b67d183b44f55e9194d7a7b2b7bed1f, not stripped
                                                        Category:dropped
                                                        Size (bytes):12988
                                                        Entropy (8bit):4.529268633466909
                                                        Encrypted:false
                                                        SSDEEP:96:FbWlfiRyuGODBWBvRmy/387WtzsFcT5JpqH8mfKiuGMMd/OZ7kzXTCvLXw/w7ei4:Qng86y/bsFgCHl/MM4zAoRqTjw
                                                        MD5:83BEDF0E3FE5509AAEC52698E9EB34ED
                                                        SHA1:7FCD78F34D220163B12AE41A2BE90B5F2F214967
                                                        SHA-256:1B6338CD6C66AA02F4B45E0A44D872FCC6DC94DFA07B3D4FE4F47E20FAA30CE5
                                                        SHA-512:AD55E391CFDE59899590E793956A8248A6C2D3FBC699A5923B1E9A3DEAE21F5C354E7F2604FF10D7503C6E6959AF14BC6CCA2F856B01AC7B89CEF040A160BBB9
                                                        Malicious:false
                                                        Preview:.ELF..............(.....T...4...........4. ...(.....................H...H............................................... ... ... ...................................$...$...........Q.td............................R.td........................................GNU....J.g..OU..Mz{+{......"..............t.@ C..\....."...............$.......&.......*...+...,...............0...1...2....D..r..._......Ia.H.......#r......9?..J..|97MoZyY.Iz.S.J....]*..c*..................................... ..........F..........."............... ...................................<...............................+...............................................C...............6...............................!........................................................... .................................../...............................................................j...............................................................................,........... ...................................................p.......
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:ELF 64-bit LSB shared object, x86-64, version 1 (SYSV), dynamically linked, BuildID[sha1]=3f1a63a925512b784b7ce7e5ee0b8b07f26fabd6, not stripped
                                                        Category:dropped
                                                        Size (bytes):18192
                                                        Entropy (8bit):3.4063403227399283
                                                        Encrypted:false
                                                        SSDEEP:384:fkNuxYnE8Xvn/3PHfXvn/3PHfXvn/3PHfXgY70SkycfVBpCxSx:fkHnE8Xvn/3PHfXvn/3PHfXvn/3PHfXu
                                                        MD5:D48A3146DBE28BDEC845134FFF74CF68
                                                        SHA1:927EAD159175303D2F50490EC71BEF0E53BAED14
                                                        SHA-256:A485AB47E9B68F27FF96237FB66D4C5890331BF70BBBA5644E76FBBB08D59271
                                                        SHA-512:8DEB25E4E6C8D9A7B023801A33FF964DE7811F9AC7F89A901A4BB61CC28655BECB0D9B922230C376EEF06C0DAE9FDEFBEF9C39F1FE749B0D1BFBA95D9474F877
                                                        Malicious:false
                                                        Preview:.ELF..............>.............@........?..........@.8...@.....................................h.......h...............................................A.......A........................ ....... ....... ......$.......$........................-.......=.......=......h................................-.......=.......=.............................................................. ....... ...............................................$.......$...............S.td............................ ....... ...............P.td.....!.......!.......!......T.......T...............Q.td....................................................R.td.....-.......=.......=......X.......X...........................GNU.............................GNU.?.c.%Q+xK|.......o..........!............."4.P$C......\.!...............#.......%.......)...*...+...-.........../...0...1....D..r..._......Ia.H.......#r......9?..J..|97MoZyY.Iz.S.J....]*..c*............................................................................ ...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Mach-O universal binary with 2 architectures: [x86_64:Mach-O 64-bit x86_64 dynamically linked shared library, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|NO_REEXPORTED_DYLIBS>] [arm64:Mach-O 64-bit arm64 dynamically linked shared library, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|NO_REEXPORTED_DYLIBS>]
                                                        Category:dropped
                                                        Size (bytes):529488
                                                        Entropy (8bit):5.019146318202435
                                                        Encrypted:false
                                                        SSDEEP:12288:2RJLW5ACOUbS+h5ACOUbSM+k2mX5ACOUbSE5ACOUbS:2Re+/
                                                        MD5:ADA1C497760FDA4EA7E4E8828A78D49A
                                                        SHA1:1421A8E31D96F414311B7167383C5DFAB7436374
                                                        SHA-256:72F3DA9FFE5ADD01E8324C9A523A65B3ABB985A3AAC3420FBCB67FB713A4D87E
                                                        SHA-512:E5C69E1ADA7CDFC18A2555B8755A6F49E50A3247DADE2269C6F0301520B43CE9CF51AC4740406020B563533400926A2E2661C958369DECCD9A27D4DCA607B52E
                                                        Malicious:false
                                                        Preview:..................@..................@....P............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Mach-O 64-bit x86_64 dynamically linked shared library, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|NO_REEXPORTED_DYLIBS>
                                                        Category:dropped
                                                        Size (bytes):51608
                                                        Entropy (8bit):1.0369335952185468
                                                        Encrypted:false
                                                        SSDEEP:96:xtefmvdw45yA+Q2F/wG16dr++H8Wx6QJIyJU+G2O1kohO7EcosKAfLA8V80Pya:X/dw2IQVbdrVvG2icowMEpya
                                                        MD5:BDF19AD33B7B78E0729D5C48F9AABDF1
                                                        SHA1:267D05EC3B7B384C8AC6B866EC6C28903B604B4F
                                                        SHA-256:04C0DDB32AF8922435940847EBC4C8B0E1BF0B96734149585296061F14D10E7A
                                                        SHA-512:3EA933863E4A7D71625C23C1753F2A6F2E5D660FFB2C1E79D1E3CE6CDA2E1A534EB32159585BED4DBFED793268CCCF7ED7DC4965057C2F1629B2C45B2910AFC1
                                                        Malicious:false
                                                        Preview:........................................__TEXT...................@...............@......................__text..........__TEXT.......... 2......(....... 2..............................__stubs.........__TEXT..........H<..............H<..............................__stub_helper...__TEXT...........<......(........<..............................__cstring.......__TEXT...........>...............>..............................__unwind_info...__TEXT...........?......H........?......................................__DATA_CONST.....@.......@.......@.......@......................__got...........__DATA_CONST.....@...... ........@......................................__DATA...................@...............@......................__la_symbol_ptr.__DATA.............................................. ...........__data..........__DATA..........................................................__common........__DATA..................0.......................................__bss...........__DATA..........
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Mach-O 64-bit x86_64 dynamically linked shared library, flags:<NOUNDEFS|DYLDLINK|TWOLEVEL|WEAK_DEFINES|BINDS_TO_WEAK|NO_REEXPORTED_DYLIBS>
                                                        Category:dropped
                                                        Size (bytes):1364688
                                                        Entropy (8bit):6.387660308589572
                                                        Encrypted:false
                                                        SSDEEP:24576:rFRRWex6q5v8KZk79jEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEEkEEEEEEEEEEEEEk:rFRN5v8KO79jEEEEEEEEEEEEEEEEEEEM
                                                        MD5:D387176235EC976413BD9850EF75DA70
                                                        SHA1:B959F2E000A780B4181CEB6BE05018C2AAACA459
                                                        SHA-256:E0EF09B0A831820107AD13F77FCC01678062BD38CD340262046F550AE85F0C78
                                                        SHA-512:B5981699AF893E2AD763EF305D931FD5759D3462DF0C9980A9512C66F5212A35E45075C15339A27BF1D35FECB8E81ED7576E7FEA4F07290A93378C536A9663AB
                                                        Malicious:false
                                                        Preview:....................`...............x...__TEXT..........................................................__text..........__TEXT........... ............... ..............................__stubs.........__TEXT..........v...............v...............................__init_offsets..__TEXT..........4...............4...............................__const.........__TEXT..........@...............@...............................__cstring.......__TEXT...................%......................................__gcc_except_tab__TEXT..........................................................__unwind_info...__TEXT..................h...............................................__DATA_CONST.............@...............@......................__got...........__DATA_CONST........................................J...........__const.........__DATA_CONST........................................................8...__DATA...........@.......@.......@.......@......................__data..........__DATA..........
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):60672
                                                        Entropy (8bit):6.262762109027057
                                                        Encrypted:false
                                                        SSDEEP:768:wnTiAz9Qh/gaoHwe1c5dl7Wt995Pk876VSQiogkMDIDqhMAEpYinAMxy1:wnmAzii5FOl4kU/T2qW7Hxs
                                                        MD5:C916DA84AB98C6868C92AC661248715C
                                                        SHA1:253B6C31FA25710D3DB51FDC359CE3283F13309E
                                                        SHA-256:FE1D705CB119B3071086353323A611F042E2E415F8822037C10409769F7432FD
                                                        SHA-512:9DCB493E384506DC162B88028F67465FB606286EF1ABD0CE3BB98440ECF6D4BA8C148387274D990272673B6712BE1AF0FE9D00142F02DCC3AC8F583C62805063
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........l..f?..f?..f?..?..f?..b>..f?..e>..f?.c>..f?..c>..f?..c>..f?..g>..f?..g>..f?..g?S.f?B.o>..f?B.f>..f?B..?..f?B.d>..f?Rich..f?........................PE..d.....e.........." .....j...`.......k....................................................`..............................................................................'......`... ...p............................................................................text...`i.......j.................. ..`.rdata...K.......L...n..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..`...........................@..B........................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):471040
                                                        Entropy (8bit):6.478904777947634
                                                        Encrypted:false
                                                        SSDEEP:12288:rgDUcMGRqADEvXfcvxoO+uFHGxDGmRZhZMZolF:8D+GRqADEvXJACZ3+olF
                                                        MD5:A4CB043C78D6351C3027370FFE7577E5
                                                        SHA1:1715C20925BA07E315EB0D91FC0C2FA2F562E07D
                                                        SHA-256:3800392446A663726D77903AB63F189E5191E5A759E2399368AA96861CF6E70D
                                                        SHA-512:F3592FF5CA8BF0B97558FD1C3B9F6C1B7639FEED771FCD7E5265B6ACE6F7B8EF1C77517B403684C968BF59A97DEABF58CF15EA0FEC5CCC54AD1A0E4608B42C38
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............X...X...X..UX...X...Y...X.;X...X...Y...X...Y...X...Y...X..Y...X...X...X...X...Xm..Y...Xb..Y...Xb..Y...Xb.9X...Xb..Y...XRich...X........PE..d.....e.........." .........f...............................................p............`.............................................H...H........P....... ...............`..........p...............................8...............x............................text............................... ..`.rdata..`,..........................@..@.data...............................@....pdata....... ... ..................@..@.rodata......@......."..............@..@.rsrc........P.......,..............@..@.reloc.......`......................@..B........................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):98616
                                                        Entropy (8bit):5.627990537858435
                                                        Encrypted:false
                                                        SSDEEP:1536:Q2Ec05j4eAH64rh5fSt5T9nFcI94WiVQTjpu:nlK4eA7mDmWqQXpu
                                                        MD5:0ADF6F32F4D14F9B0BE9AA94F7EFB279
                                                        SHA1:68E1AF02CDDD57B5581708984C2B4A35074982A3
                                                        SHA-256:8BE4A2270F8B2BEA40F33F79869FDCCA34E07BB764E63B81DED49D90D2B720DD
                                                        SHA-512:F81AC2895048333AC50E550D2B03E90003865F18058CE4A1DFBA9455A5BDA2485A2D31B0FDC77F6CBDFB1BB2E32D9F8AB81B3201D96D56E060E4A440719502D6
                                                        Malicious:false
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_GenericDownloader_1, Description: Yara detected Generic Downloader, Source: C:\Program Files\VMware\Workspace ONE Assist\netstandard.dll, Author: Joe Security
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...M..Z.........." ..0..8...........U... ...`....... ..............................v.....@..................................U..O....`..,............B..8?........................................................... ............... ..H............text....6... ...8.................. ..`.rsrc...,....`.......:..............@..@.reloc...............@..............@..B.................U......H.......P ...4..................,U......................................BSJB............v4.0.30319......l...|...#~.....d...#Strings....L3......#US.T3......#GUID...d3..x...#Blob......................3................................q.....2B........e$.M...,.M.....M...4.M...1.M...1.M..v..M...*.M...*.M....p...........................!.....).....1.....9.....A.....I.................................#.......+.......3.......;.J.....C.f.....K.f...................2.....................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):87888
                                                        Entropy (8bit):6.509817790363228
                                                        Encrypted:false
                                                        SSDEEP:1536:6iOTTyN9d/mqN5fomseOpLZ5UP4nlf9ecbtGgcvg9EBIN:6DIVzgx5UAecbt4g9EuN
                                                        MD5:EDF9D5C18111D82CF10EC99F6AFA6B47
                                                        SHA1:D247F5B9D4D3061E3D421E0E623595AA40D9493C
                                                        SHA-256:D89C7B863FC1AC3A179D45D5FE1B9FD35FB6FBD45171CA68D0D68AB1C1AD04FB
                                                        SHA-512:BF017AA8275C5B6D064984A606C5D40852AA70047759468395FE520F7F68B5452BEFC3145EFAA7C51F8EC3BF71D9E32DBD5633637F040D58FF9A4B6953BF1CBF
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......).uym~.*m~.*m~.*...*o~.*d..*f~.*m~.*F~.*V .+n~.*V .+g~.*V .+f~.*V .+s~.*V .+l~.*V .*l~.*V .+l~.*Richm~.*........PE..d....LZW.........." .........T......@........................................p......-.....`A........................................0...4...d........P.......0..........P?...`..p...p...8............................................................................text...'........................... ..`.rdata..f5.......6..................@..@.data........ ......................@....pdata.......0......................@..@_RDATA.......@......................@..@.rsrc........P......................@..@.reloc..p....`......................@..B........................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):36728
                                                        Entropy (8bit):6.338644648247156
                                                        Encrypted:false
                                                        SSDEEP:384:Ln62MCmWEnhUcSLt5a9Y6v4HOE5fY/ntz5BBW0O3+XfaWuncS7Q2pWr8KWSdHRN8:udCm5nhUcxgHY/ntXBzxvaN7dc/p+
                                                        MD5:33D84A4FBD00450F781AAEE90ABFAB3D
                                                        SHA1:BB4D63385A1B157ACB2685CFACCEF8463AEBC081
                                                        SHA-256:721831B56CBC8531802B036044610F7442397D02A58EBE82AA82FC7F9D99B2D8
                                                        SHA-512:8D589B69DB1C7E44EE847CE3B48BD82D5869A38315882CA050BD4C60E92DB055E5047D47C96FB964AFA7A4A556C154EB0A1F13F1CC926D79A62640A89E5712B3
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........@..@..@.....B..,..B..I._.K..@..q..,..E..,..G..,..Z..,..A..,.3.A..,..A..Rich@..........................PE..d....x$`.........." .....:...4......`A..............................................X.....`A.........................................k......<l..x....................l..x#......<...(b..T............................b..8............P..X............................text...u9.......:.................. ..`.rdata..P!...P..."...>..............@..@.data... ............`..............@....pdata...............b..............@..@.rsrc................f..............@..@.reloc..<............j..............@..B................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (console) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):3052745
                                                        Entropy (8bit):5.834379139502269
                                                        Encrypted:false
                                                        SSDEEP:49152:h5hbbylCSWhnhDgTvrI/DZMvXWqyUTqkY:XhilCnnJqvrIlMvX8UTqkY
                                                        MD5:D27DC1B0A20FBC6F6528F832BFA41F51
                                                        SHA1:9A3C7ED581E0923716A3B498F73AB9BD12760AD6
                                                        SHA-256:345CF7E3EB3446DD039FF1574E136BFF12C55C7EA484E09F88E7A2001738834E
                                                        SHA-512:60A3574E840B67AF3BC6D9ED1215B086635ADB940223DDC0C7993016944F5BC2019573B6A276D0901F88B76889216AB89A295585C9CD4A892097C457B32B186D
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...;|.b.~'.?0....&....%.&.....................@.............................`(......4/....... .................................................<................A..............................................(....................... ............................text...($.......&..................`..`.data........@.......,..............@....rdata..P....P.......0..............@..@.pdata...A.......B..................@..@.xdata...G...P...H..................@..@.bss.....................................idata..<............f..............@....CRT....p...........................@....tls................................@....rsrc...............................@....reloc..............................@..B/4......0@.......B..................@..B/19......s...`...t..................@..B/31.....-!......."...J..............@..B/45.....Lg.......h...l..............@..B/57.....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (console) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):2826293
                                                        Entropy (8bit):5.776085648707069
                                                        Encrypted:false
                                                        SSDEEP:49152:jLR7nnGrsSBkwTDEVwhIfhn9nSBrZY7N1++vYy+GQtn:jLR7nnGrsSBkE8GAn5urZYh1++p+GQtn
                                                        MD5:721496E500C8526382B0AA91FB9129EA
                                                        SHA1:6B150A3B0082C24E5379EEAC9FC33E7302048D10
                                                        SHA-256:DC5037FFF382687EFDAE941A7E773F94CAA3049AB31ECDCE04A1747517FE6E2D
                                                        SHA-512:D8A27FE8FC9CB876CA9A95ED98FB7A13F30482E1C5E3D3D25D37DCFB36F547F231D539441DBA49B8E2BC9C49D27E3EE11BFA2CA3BE7423E8D24380AADAD0847F
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...B|.b..$..)....&....%.......................@..............................%.......+....... ......................................................0.......`.. 7...........@..............................`/..(.......................P............................text...............................`..`.data...P...........................@....rdata...d.......f..................@..@.pdata.. 7...`...8...:..............@..@.xdata...3.......4...r..............@..@.bss....`................................idata..............................@....CRT....p...........................@....tls......... ......................@....rsrc........0......................@....reloc.......@......................@..B/4......0>...P...@..................@..B/19.................................@..B/31.................................@..B/45.....mR.......T..."..............@..B/57.....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):6656
                                                        Entropy (8bit):4.466554375620127
                                                        Encrypted:false
                                                        SSDEEP:96:YWBpEU1WPk3fulCAk30EmGC+dTaSefECjuF0eeQtmlj:9BpEU0Wful00PGC+dTaNwF5twj
                                                        MD5:28CFBE48D22D3CE0D8C4B1A30898E9B1
                                                        SHA1:0D287CF6FD128D14070EE93504701717877BEE3F
                                                        SHA-256:BA5D4C81011D74A6EA15A47820C72D2B02C6B262CC95F34E62A21A809275A7DE
                                                        SHA-512:C067D6B463CF78D934B9706C23E4EB51F5B3B7EED3A8E12B806947A95D7EF0D60B55AD91C73EE764750E1BE4A7DB833FD451E936094B7B662493AB3C2B2D0E85
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...=..X.........." ..0..............0... ...@....... ....................................@.................................|0..O....@.......................`......D/............................................... ............... ..H............text........ ...................... ..`.rsrc........@......................@..@.reloc.......`......................@..B.................0......H.......| ...............................................................~....*..(....*.*.s....z..(....*.s.........*BSJB............v4.0.30319......l.......#~..........#Strings............#US.........#GUID...........#Blob...........W?.........3........................).........................................i.........5.L.....L...i.....l.............................U.....n...........}.-...[.-.......................-...a.-.............................A.............A.....1...{.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):2860490
                                                        Entropy (8bit):5.837026916223675
                                                        Encrypted:false
                                                        SSDEEP:49152:M2lv4hM/f2srzwunGQkSeIO2XZ1++tWyu1q7n:zlNXVpnPHeIOO1++Bu1q7n
                                                        MD5:5E2B8753613DE18F534C1A78F5702C02
                                                        SHA1:A1C94B5DAEDC69F3C9BC5BA85F4FDC5AD8CE0A39
                                                        SHA-256:053CDBDAA0EDF6187D51B2B603C755DD34D59827C6AB630972FDCF6186D970F3
                                                        SHA-512:DE8503F5C465D7B4ED4956DCE9EC5534375E3CB57B482D9D274A4867F574D77DB6EE7E6CFB22ED7629C8E7DF1AA124E8784D2905D01F273FAA44FA1CD2021F45
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...M|.b.R%..)....& ...%.,...P......P..........r..............................&.....jr,....... ......................................p..z.......................h:..........................................@...(......................x............................text...X*.......,..................`..`.data........@.......2..............@....rdata.......P.......6..............@..@.pdata..h:.......<..................@..@.xdata...:... ...<..................@..@.bss.........`...........................edata..z....p.......2..............@..@.idata...............6..............@....CRT....`............L..............@....tls.................N..............@....reloc...............P..............@..B/4.......<.......>...V..............@..B/19.....1...........................@..B/31.....C............|..............@..B/45......L.......N..................@..B/57.....
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has Working directory, Icon number=0, Archive, ctime=Wed Mar 27 14:55:22 2024, mtime=Thu Apr 25 11:16:28 2024, atime=Wed Mar 27 14:55:22 2024, length=1603328, window=hide
                                                        Category:dropped
                                                        Size (bytes):2201
                                                        Entropy (8bit):3.7095960478800096
                                                        Encrypted:false
                                                        SSDEEP:24:8FdjzlkFXmD76iA1+ydSV4Ff76QdSV4Fg+MUNkeSHp4WUN0JNzWyfm:8Fd/wmQ1+ydSVadSVN5SkeSWWSe
                                                        MD5:208583A1ED742A57DCAD024A47539371
                                                        SHA1:EFA708FBE8B0A0AE776842388C048C6ADDC2ED08
                                                        SHA-256:870C403A1F1B4919D11B4D93C16349B7A5DE76877113791644B0524E2D3AACA6
                                                        SHA-512:B00306132F44F800FFFD0FAA053174F7BD4C538886E1540C02B5BECE5E2F170033AAED81BE94013386422DFDC1952FDF6D5FCE4896500C5748F9DC6D0934EA3A
                                                        Malicious:false
                                                        Preview:L..................F.@.. ....Q.,_...>.Pf.....Q.,_....w...........................P.O. .:i.....+00.../C:\.....................1......X.b..PROGRA~1..t......O.I.X.b....B...............J.......).P.r.o.g.r.a.m. .F.i.l.e.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.7.8.1.....T.1......X.b..VMware..>......X.b.X.b....")......................).V.M.w.a.r.e.....r.1......X.b..WORKSP~1..Z......X.b.X.b....d+....................M...W.o.r.k.s.p.a.c.e. .O.N.E. .A.s.s.i.s.t.......2..w..{X.~ .WORKSP~3.EXE..n......{X.~.X.b.....G........................W.o.r.k.s.p.a.c.e.O.N.E...A.s.s.i.s.t...C.l.i.e.n.t...e.x.e.......z...............-.......y............J>w.....C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Client.exe..Z.....\.....\.....\.....\.....\.....\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.M.w.a.r.e.\.W.o.r.k.s.p.a.c.e. .O.N.E. .A.s.s.i.s.t.\.W.o.r.k.s.p.a.c.e.O.N.E...A.s.s.i.s.t...C.l.i.e.n.t...e.x.e.-.C.:.\.P.r.o.g.r.a.m. .F.i.l.e.s.\.V.M.w.a.r.e.\.W.o.r.k.s.p.a.c.e. .O.N.E. .A.s.s.i.s.t.\.D.C
                                                        Process:C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):873
                                                        Entropy (8bit):5.334794687457023
                                                        Encrypted:false
                                                        SSDEEP:12:Q3La/KDLI4MWuPXcp1OKbbDLI4MWuPOKfSSI6Kha3xaaoWoyge4MYfoE1DLI4MWZ:ML9E4KQwKDE4KGKZI6KhnXyr4PrE4Km
                                                        MD5:6FF075077359996839BB99D4547BBB0F
                                                        SHA1:310C570D802D40371BC0D877E0D86D0D355A92DF
                                                        SHA-256:FB60E87C6824BC2FF9ACE88EF5B3B298FE5590C021F671C4DF92D6FA6AD3C5C6
                                                        SHA-512:D3B782D12F3A58134FF4855DECB0F54A14E1269D67C7A60373EEDE085CEF6CC9FD05744D4140AFB01B770CB08733FBB4880860ECACACAA76E6485C1770F884C2
                                                        Malicious:false
                                                        Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni.dll",0..2,"C:\Windows\system32\WinMetadata\Windows.Management.winmd",1..2,"C:\Windows\system32\WinMetadata\Windows.Foundation.winmd",1..2,"netstandard, Version=2.0.0.0, Culture=neutral, PublicKeyToken=cc7b13ffcd2ddd51",0..2,"C:\Windows\system32\WinMetadata\Windows.ApplicationModel.winmd",1..2,"System.Runtime.WindowsRuntime, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089",0..2,"C:\Windows\system32\WinMetadata\Windows.System.winmd",1..
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):737
                                                        Entropy (8bit):5.34973518043042
                                                        Encrypted:false
                                                        SSDEEP:12:Q3La/KDLI4MWuPXcp1OKbbDLI4MWuPOKfSSI6KhaOK9eDLI4MNOK9XGK9yiyWoyD:ML9E4KQwKDE4KGKZI6KhPKIE4TKBGKoU
                                                        MD5:82F8048F931D8F7FFF5D774529C4D756
                                                        SHA1:4116C9A0451C97B50E5AF140D25E1A44310BB58C
                                                        SHA-256:9A3E43E664EC44B17C4B8B580F0644A640DEE40D9051D85CA3FED8157B525C36
                                                        SHA-512:E5ED3F758A9C8AEBE13F257F4C0B82035AEABFC7011E43DCE5EC91A56B4C3BD17F26473A1621F064D72A526A227AF3BCE0C0A7784AC2243447766A8EBEF14E12
                                                        Malicious:false
                                                        Preview:1,"fusion","GAC",0..1,"WinRT","NotApp",1..3,"System, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System\b187b7f31cee3e87b56c8edca55324e0\System.ni.dll",0..3,"System.Core, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Core\31326613607f69254f3284ec964796c8\System.Core.ni.dll",0..3,"System.Configuration, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a","C:\Windows\assembly\NativeImages_v4.0.30319_64\System.Configuration\915c1ee906bd8dfc15398a4bab4acb48\System.Configuration.ni.dll",0..2,"netstandard, Version=2.0.0.0, Culture=neutral, PublicKeyToken=cc7b13ffcd2ddd51",0..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Unicode text, UTF-16, little-endian text, with no line terminators
                                                        Category:dropped
                                                        Size (bytes):2
                                                        Entropy (8bit):1.0
                                                        Encrypted:false
                                                        SSDEEP:3:Qn:Qn
                                                        MD5:F3B25701FE362EC84616A93A45CE9998
                                                        SHA1:D62636D8CAEC13F04E28442A0A6FA1AFEB024BBB
                                                        SHA-256:B3D510EF04275CA8E698E5B3CBB0ECE3949EF9252F0CDC839E9EE347409A2209
                                                        SHA-512:98C5F56F3DE340690C139E58EB7DAC111979F0D4DFFE9C4B24FF849510F4B6FFA9FD608C0A3DE9AC3C9FD2190F0EFAF715309061490F9755A9BFDF1C54CA0D84
                                                        Malicious:false
                                                        Preview:..
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: VMware Workspace ONE Assist, Author: VMware, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Workspace ONE Assist Installer., Template: x64;1033, Revision Number: {FD0CDE91-FD76-4738-8B40-800BA9713AFC}, Create Time/Date: Wed Mar 27 21:55:34 2024, Last Saved Time/Date: Wed Mar 27 21:55:34 2024, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                        Category:dropped
                                                        Size (bytes):10838016
                                                        Entropy (8bit):7.8547122848696205
                                                        Encrypted:false
                                                        SSDEEP:196608:Oidybl3zkehEaHKc7wV9J9y5JKdmyg9KAtVVEDZLmZ2HHq8YLQL40fqV/d/r8ScO:OO4RzBqc7wXEsg9KWVWSZ2HK8nLTydI0
                                                        MD5:AF498BD451F04A1DAE63CD61812A3C8B
                                                        SHA1:36F54070B8696EAA00BA1FF1D5FCFD5900DDACFA
                                                        SHA-256:0400A87B6100936CDC0A8695C5DC1C7103BB93C0842231EFAF7260A795290339
                                                        SHA-512:80A4B5F8DBB1B4E1BFAF60FC6DC6AB8D0828A117168D87B1E6F802A8FDF1AFA81752BEE6D6C10E9CCC3DB857F960B68A0F46742471A7A127E1E0DC9D987CD794
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):605563
                                                        Entropy (8bit):6.367056125292695
                                                        Encrypted:false
                                                        SSDEEP:12288:6wHL0Dt97G21pQwAWW3GIp7fFk5USiqWfLf0LzyMWOWUXMRe:bHL0RpQ5B7EUSiqWfLf0LzyMWOWUXMRe
                                                        MD5:C66432022910846CBF84B2BBB6C8B72C
                                                        SHA1:85D169A38B9AE3C5D32EA61BA110B9BEB81BA046
                                                        SHA-256:EA42CA216DF80DFC442ABE80F99737051AAD9DCDE8DFF487A1B8517F583EF5B6
                                                        SHA-512:ABBFC2D7D9D6C2F7B81310E1B6E39CCF16C165B6A132DE53D9DB74F02D564AED890E18DF0BBEA477200A282F89D389E5A34E9E7A4A09EBCC201744A59D7691CC
                                                        Malicious:false
                                                        Preview:...@IXOS.@.....@.r.X.@.....@.....@.....@.....@.....@......&.{2687F608-EC00-4F9A-B6B3-0194BAD168BB}..Workspace ONE Assist Installer..VZH3bd37Gc.msi.@.....@.....@.....@......icon.ico..&.{FD0CDE91-FD76-4738-8B40-800BA9713AFC}.....@.....@.....@.....@.......@.....@.....@.......@......Workspace ONE Assist Installer......Rollback..Rolling back action:..[1]..RollbackCleanup..Removing backup files..File: [1]...@.......@........ProcessComponents..Updating component registration.....@.....@.....@.]....&.{3CF85474-93F9-43E2-8E5F-DB1190DAE600}1.21:\Software\VMware\Workspace ONE Assist\Shortcut.@.......@.....@.....@......&.{F514C4CC-87F5-4F69-91DF-99D15C9D8C08}4.22:\Software\VMware\Workspace ONE Assist\InstallPath.@.......@.....@.....@......&.{E010BFD9-3010-4968-A829-D3A3BC25CE49}-.C:\Program Files\VMware\Workspace ONE Assist\.@.......@.....@.....@......&.{20EB5E0E-047A-47F7-9023-427A11E7D509}L.C:\Program Files\VMware\Workspace ONE Assist\WorkspaceONE.Assist.Service.exe.@.......@.....@.....@......&.
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows, InstallShield self-extracting archive
                                                        Category:dropped
                                                        Size (bytes):338223
                                                        Entropy (8bit):6.525133709241373
                                                        Encrypted:false
                                                        SSDEEP:6144:c8XqvLwHL0otXjsGeqG1AmG21pQwOzeCqH8+O3EXIbhD7fYaKP5Cto:6wHL0Dt97G21pQwAWW3GIp7fFk55
                                                        MD5:7536672693DAE593A461B8932EBD3B3A
                                                        SHA1:C83434EE79204FE7B103F323D77A74C694CB00A1
                                                        SHA-256:5E91D63A2722EADAEDC50D94A1B96CCB63ADFD4A5EE738B317A34896C161CAB4
                                                        SHA-512:F1A33282AAE203C02AACA7A31AA5E41FDA7C2C5A5BBE523E358B8847216C09574CA4CB2720F42D8B05305B10B0D86BE0D5394A35B371766E1FEECDA668065C02
                                                        Malicious:true
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........_.>..>..>....w.>....u..>....t.>...V..>...V..>...V..>..F..>..>...>..>W..>..>W..>..>Wy.>..>..>..>W..>..Rich.>..........................PE..d....o.].........." .....R...........U.......................................p............`.........................................P....*......x....P.......0...............`..X......T...........................0................p...............................text....Q.......R.................. ..`.rdata.......p.......V..............@..@.data...............................@....pdata.......0......................@..@.rsrc........P......................@..@.reloc..X....`......................@..B........................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):25088
                                                        Entropy (8bit):5.656476520669442
                                                        Encrypted:false
                                                        SSDEEP:384:V6BscqBH6R4YzqLjhzQfUyniJTeViz3ZLvH3HhnkVrMowykjvDxJtKT3:rcqBae2qA/i5yC3ZjnZeb
                                                        MD5:4AF1FFB80B114439B6E599D5A066B3AF
                                                        SHA1:293B44FAEBB0EFDA5837BA8ED948FB20DD05D8FF
                                                        SHA-256:1978E094CB8EB183122AE05775EF854AF5A6B9E295AE0D10C6A72B4C311D12DD
                                                        SHA-512:C8848ADDB92CE7AA2F873C1A183747E186920BEA2ACF3AE96763E36F3173D78D59B494F95519249B9C670E3AB4ABDA15174F3B4499A4CB09F4A8B66F769FAA17
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...U............." ..0..Z............... ........... ....................................`...@......@............... ...............................................................x..T............................................................ ..H............text....Y... ...Z.................. ..`.rsrc................\..............@..@........................................H........5...B............................................................{....*..{....*V.(......}......}....*...0..A........u........4.,/(.....{.....{....o ...,.(!....{.....{....o"...*.*.*. ..._ )UU.Z(.....{....o#...X )UU.Z(!....{....o$...X*...0..b........r...p......%..{.......%q.........-.&.+.......o%....%..{.......%q.........-.&.+.......o%....(&...*Bs'........(....*.*..*F.((...()...(....*:(....,..(*...*^.-..*~.....o.....o+...*....0..........~.......o,...._,..o....*2~.....o-...*...
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):18432
                                                        Entropy (8bit):5.614236404174859
                                                        Encrypted:false
                                                        SSDEEP:384:1hMtA4sQEi6aAATUGVaA9slCGsZBnpvr0EQTp1Zw8hIt:YtxEi6aew9sl3sZBVri+8y
                                                        MD5:BA18FE948ACAA586AB8AC5B3EF0813F9
                                                        SHA1:D233BE51B2380F265E94DA558841F887409496B5
                                                        SHA-256:E7ED080458520D691E8BDA87CB56A64742841B6ED7512407AC366D01DFC1B1C9
                                                        SHA-512:ABC8EAF8FB30B7B2684CAC51A52AE63F11F8DF2442CA81686ACBE32EC71A514DBDF1D41E65BB8824905A3731649490680C50BCD9C112F7BEDDA167858149FE75
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...S.d..........." ..0..B............... ........... ....................................`...@......@............... ...............................................................a..T............................................................ ..H............text....A... ...B.................. ..`.rsrc................D..............@..@........................................H.......T4...,...........................................................0..A.......(....(....,...(....*(....(....,...(....*(....(....,..(....*~....*....0..B.......(....(....,...(....*(....(....,...(....*(....(....,...(....*~....*.(....(....,..(....&*(....(....,..(....&*(....(....,..(....&*..(....*..0..'.......~.........(....t............(...+...3.*..0..'.......~.........(....t............(...+...3.*..(....-&.~....%-.&~......[...s....%.....(...+*.*..(....-&.~....%-.&~......\...s....%
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):45056
                                                        Entropy (8bit):5.879739872576788
                                                        Encrypted:false
                                                        SSDEEP:768:Q67ktKzuJjYyNiCXFFa548Ld0uXQ7XhFAb7Prr8uxoJ71VP:b7kUzuJjYyw0OyhGb7Drm11
                                                        MD5:92B3761745E0D97B95C0BA7511052013
                                                        SHA1:675FDF5C6230F5BEA39CE628A85D25DF28443E7B
                                                        SHA-256:82802BEC944BE7B215409AC543B65F1C23CE2D78A302E3493FC941947E362D88
                                                        SHA-512:12280935FA594A288268C411B3D18FB0F0B682D6F2C114E75E7A3F81AFB7DE39D90A7364A7153A802D8F9F2B39E57444116888EDF33B9DAF1C1E77A4B3BEE1A8
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...V............." ..0.................. ........... ....................................`...@......@............... ..............................................................T...T............................................................ ..H............text...M.... ...................... ..`.rsrc...............................@..@........................................H........B..............................................................6.{.....o....*...0..1.......sy......}.....{.....o....%-.&.*...z...s....(...+*....0..1.......s{......}.....{.....o....%-.&.*...|...s....(...+*....0..1.......s}......}.....{.....o....%-.&.*...~...s....(...+*....0..........~......-.r...ps....z.o....o.......(......,.r...pr3..prW..p( ....s!...zr...pr3..pr...p("...........(.......@............(......,.r...pr3..pr...p( ....s!...zr...pr3..pr...p("...(#.....($....Z.($....
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:PE32+ executable (DLL) (console) x86-64 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):11776
                                                        Entropy (8bit):4.571473182754461
                                                        Encrypted:false
                                                        SSDEEP:192:lN+t8kLSBH5rxqVd76c8JbZFipI2fqCuhZLqAsZaboNu2:it8kLSw6bfGImqvfLqc0u
                                                        MD5:6365204B7C1BFD3348EA1C606FFC47F2
                                                        SHA1:75ACBBA9BD3199E2FF4BAFDA0CA793A8DD5DC67A
                                                        SHA-256:443A3F1FCB0FE0DA212DD8369FFD257F7388B0D4705F6E5D75D99DD217B8D8D1
                                                        SHA-512:3A7641234083B628CC28A55C3ACC47D0D5BF5AEA2E3F25763799C943F451F666A74B415BCA9D0130F65C82B5B24C9FF74811A5C978F966F653972E511BC64E30
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d......f.........." ..0..&............... ........... ....................................`...@......@............... ...............................`..`............................C............................................................... ..H............text...$%... ...&.................. ..`.rsrc...`....`.......(..............@..@........................................H.......d(................................................................r...po.....(......(.....rA..po.....*..r}..po.....(......(.....r...po.....*.0...........r...po.....s......l(......o.....r...po.......o.....r...po.....rA..p.o.........(....o.......,..o.........ri..p.o....(....o.......r...po....*........I[..........\g.......0...........r...po....r...p(.......+.....r...po....o......X....i2.r...p(.......+.....r...po....o......X....i2.....r...p.o....(....o.......r...po....*..........
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:XML 1.0 document, ASCII text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):1493
                                                        Entropy (8bit):4.732294656481805
                                                        Encrypted:false
                                                        SSDEEP:24:2dhmhx0PY6Iee7LfKhT06XWslTh17jJB7ZtG9jDqRp:c0nd5t7q7WsFD7tztG96n
                                                        MD5:01C01D040563A55E0FD31CC8DAA5F155
                                                        SHA1:3C1C229703198F9772D7721357F1B90281917842
                                                        SHA-256:33D947C04A10E3AFF3DCA3B779393FA56CE5F02251C8CBAE5076A125FDEA081F
                                                        SHA-512:9C3F0CC17868479575090E1949E31A688B8C1CDFA56AC4A08CBE661466BB40ECFC94EA512DC4B64D5FF14A563F96F1E71C03B6EEACC42992455BD4F1C91F17D5
                                                        Malicious:false
                                                        Preview:<?xml version="1.0" encoding="utf-8" ?>..<configuration>.. <startup useLegacyV2RuntimeActivationPolicy="true">.... .. Use supportedRuntime tags to explicitly specify the version(s) of the .NET Framework runtime that.. the custom action should run on. If no versions are specified, the chosen version of the runtime.. will be the "best" match to what Microsoft.Deployment.WindowsInstaller.dll was built against..... WARNING: leaving the version unspecified is dangerous as it introduces a risk of compatibility.. problems with future versions of the .NET Framework runtime. It is highly recommended that you specify.. only the version(s) of the .NET Framework runtime that you have tested against..... Note for .NET Framework v3.0 and v3.5, the runtime version is still v2.0..... In order to enable .NET Framework version 2.0 runtime activation policy, which is to load all assemblies.. by using the latest
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):184240
                                                        Entropy (8bit):5.876033362692288
                                                        Encrypted:false
                                                        SSDEEP:3072:BGfZS7hUuK3PcbFeRRLxyR69UgoCaf8+aCnfKlRUjW01KymkO:9zMRLkR6joxfRPW
                                                        MD5:1A5CAEA6734FDD07CAA514C3F3FB75DA
                                                        SHA1:F070AC0D91BD337D7952ABD1DDF19A737B94510C
                                                        SHA-256:CF06D4ED4A8BAF88C82D6C9AE0EFC81C469DE6DA8788AB35F373B350A4B4CDCA
                                                        SHA-512:A22DD3B7CF1C2EDCF5B540F3DAA482268D8038D468B8F00CA623D1C254AFFBBC1446E5BD42ADC3D8E274BE3BA776B0034E179FACCD9AC8612CCD75186D1E3BF1
                                                        Malicious:false
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....o.].........." ..0...... ......z.... ........... ....................................@.................................(...O................................................................................... ............... ..H............text....w... ...................... ..`.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\rundll32.exe
                                                        File Type:PE32 executable (DLL) (console) Intel 80386 Mono/.Net assembly, for MS Windows
                                                        Category:dropped
                                                        Size (bytes):98616
                                                        Entropy (8bit):5.627990537858435
                                                        Encrypted:false
                                                        SSDEEP:1536:Q2Ec05j4eAH64rh5fSt5T9nFcI94WiVQTjpu:nlK4eA7mDmWqQXpu
                                                        MD5:0ADF6F32F4D14F9B0BE9AA94F7EFB279
                                                        SHA1:68E1AF02CDDD57B5581708984C2B4A35074982A3
                                                        SHA-256:8BE4A2270F8B2BEA40F33F79869FDCCA34E07BB764E63B81DED49D90D2B720DD
                                                        SHA-512:F81AC2895048333AC50E550D2B03E90003865F18058CE4A1DFBA9455A5BDA2485A2D31B0FDC77F6CBDFB1BB2E32D9F8AB81B3201D96D56E060E4A440719502D6
                                                        Malicious:false
                                                        Yara Hits:
                                                        • Rule: JoeSecurity_GenericDownloader_1, Description: Yara detected Generic Downloader, Source: C:\Windows\Installer\MSI50A5.tmp-\netstandard.dll, Author: Joe Security
                                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L...M..Z.........." ..0..8...........U... ...`....... ..............................v.....@..................................U..O....`..,............B..8?........................................................... ............... ..H............text....6... ...8.................. ..`.rsrc...,....`.......:..............@..@.reloc...............@..............@..B.................U......H.......P ...4..................,U......................................BSJB............v4.0.30319......l...|...#~.....d...#Strings....L3......#US.T3......#GUID...d3..x...#Blob......................3................................q.....2B........e$.M...,.M.....M...4.M...1.M...1.M..v..M...*.M...*.M....p...........................!.....).....1.....9.....A.....I.................................#.......+.......3.......;.J.....C.f.....K.f...................2.....................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Composite Document File V2 Document, Cannot read section info
                                                        Category:dropped
                                                        Size (bytes):49152
                                                        Entropy (8bit):0.7689268857658604
                                                        Encrypted:false
                                                        SSDEEP:12:JSbX72FjhXiAGiLIlHVRpZh/7777777777777777777777777vDHFk3pKjsit/lN:JmQI5tW54piF
                                                        MD5:D14DFCFDC385AFA326EF95BB3E38615E
                                                        SHA1:60C50DE11AF487B99D5C8380DA15561A4B428CA0
                                                        SHA-256:13BCDF6998A4C468D08F8720AE23F014EFA094EB56681BAA94A0F268ACE9D5BA
                                                        SHA-512:14CFE6CE07ECBC1C8109ABC512B5728FCC6200F14FD7F988A3442D71EBC0AC997685D4C949A64BE80D7C2623CDF2663057615F5CA28D8A236DF6BA961500372A
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Composite Document File V2 Document, Cannot read section info
                                                        Category:dropped
                                                        Size (bytes):32768
                                                        Entropy (8bit):1.307517046927086
                                                        Encrypted:false
                                                        SSDEEP:48:b2iquKBJveFXJPT5hVyyicUdSVlSNdSVCdSVmAdSUoKrydSVlSCdSVCdSVmAdSIP:RqK3TPV3icrV
                                                        MD5:C964C656A25FCA25B06A10120911CCE9
                                                        SHA1:3A49BDE4CF12FE3D651A829241AEEA07CAB31070
                                                        SHA-256:B2F6951CDF5443C9FABF0593D7DF32DBD9A2E95A7D51B1A9B5BC4C89C5257A99
                                                        SHA-512:CAC3B798FFA58849619625ECDFD1A101DD0B1ED295FE15A9B7C6564A72A2908096D6E9D02C73800A7CCC79FF400B1C346944B03DC74192C0A0B58E57C07A8822
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:MS Windows icon resource - 4 icons, 32x32, 32 bits/pixel, 48x48, 32 bits/pixel
                                                        Category:dropped
                                                        Size (bytes):204134
                                                        Entropy (8bit):4.978599072849292
                                                        Encrypted:false
                                                        SSDEEP:3072:BDKF8ZSiazvedANnon+e8yFBxalEQcFfLf0GQN6fnp58kizyMWOWUXMk:UMSiaz96RFfLf0GBpwzyMWOWUXMk
                                                        MD5:95D8356A328B69E36C6198158078CB7F
                                                        SHA1:32845CB99FFCBAA102AA57C79CE011B9202B3861
                                                        SHA-256:6A6D555E6990F036D83C238889C269824751FAC4CFB72CC5AFDFA1D281CC28FB
                                                        SHA-512:9C3B928A5915E230114CF1EEBA2F90BBAB33DC648423AA23A8B0042F72DD00DDFF473137C854586FC5CD2E817E6ED4A7183D00CF8D5181B8CED9EE759C6B6BEF
                                                        Malicious:false
                                                        Preview:...... .... .....F...00.... ..%......``.... ......6........ .(R..>...(... ...@..... ...........................................................6...6...5'..5d..6...6...6...6...6...6...6...6...5m..5-..3...5...........................................................3...0...56..6...6...6...6...6...6...6...6...6...6...6...6...6...6...5:..6...6...........................................4...6...5...5...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...5...7...............................6...j...64..6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...57.$...3......................./...W...2B..5...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...6...5C..6...5..............)...0..-6..0...3...5...6...6...6...6...5...5...4...3...3...3...3...4...5...5...6...6...6...6...6...6...6...68..7...5..........)..(..+..-...0...3...4...4...3...7...>...I...Z...f...k...l...g...^...L...@...8...3...4...5...6...6...6...6...6...
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
                                                        Category:dropped
                                                        Size (bytes):432221
                                                        Entropy (8bit):5.375173116947815
                                                        Encrypted:false
                                                        SSDEEP:1536:6qELG7gK+RaOOp3LCCpfmLgYI66xgFF9Sq8K6MAS2OMUHl6Gin327D22A26Kgau9:zTtbmkExhMJCIpErA
                                                        MD5:7A5F014A37D56E56CC7937607C5AFF71
                                                        SHA1:C74D7449E3C8EB64187EA6845F30A25EF55F9AD2
                                                        SHA-256:0333E9AFA655DD8F7ED67B7F98343CB7D490D24BFEA5A0A16C607243EFA71744
                                                        SHA-512:51E3E427E45E99135F8EACD741197C20BAA4A0BD49ACF0C563C367D6AEDA75FB89FE9820DE35099D0E982FED92B533F3C23455523118AB95721C02F7446F3E2E
                                                        Malicious:false
                                                        Preview:.To learn about increasing the verbosity of the NGen log files please see http://go.microsoft.com/fwlink/?linkid=210113..12/07/2019 14:54:22.458 [5488]: Command line: D:\wd\compilerTemp\BMT.200yuild.1bk\Windows\Microsoft.NET\Framework64\v4.0.30319\ngen.exe executeQueuedItems /nologo ..12/07/2019 14:54:22.473 [5488]: Executing command from offline queue: install "System.Runtime.WindowsRuntime.UI.Xaml, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=b77a5c561934e089, processorArchitecture=msil" /NoDependencies /queue:1..12/07/2019 14:54:22.490 [5488]: Executing command from offline queue: install "System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil" /NoDependencies /queue:3..12/07/2019 14:54:22.490 [5488]: Exclusion list entry found for System.Web.ApplicationServices, Version=4.0.0.0, Culture=Neutral, PublicKeyToken=31bf3856ad364e35, processorArchitecture=msil; it will not be installed..12/07/2019 14:54:22.490 [
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):32768
                                                        Entropy (8bit):0.07144308198257465
                                                        Encrypted:false
                                                        SSDEEP:6:2/9LG7iVCnLG7iVrKOzPLHKOkZ3pKju8tZltgVky6lit/:2F0i8n0itFzDHFk3pKjfit/
                                                        MD5:141FC7148BE4B075D7D8BB7C430D369F
                                                        SHA1:0CD947136CDD5CC82A665D359B53A179C2745BE9
                                                        SHA-256:C3657697C9F465829CCA3D65AC2F9BB6B140CA93078A1451A6E4C2146738742B
                                                        SHA-512:F6D18F9B62F763920DAEC6A07FBF27AE9DA5DD756FB3019BB3D886F99ADBB7A5326477FDD6B0A50BD9F6DE013E65AA4E83D3CE25065F6AD9C6DC5719288ABB6B
                                                        Malicious:false
                                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:data
                                                        Category:modified
                                                        Size (bytes):512
                                                        Entropy (8bit):0.0
                                                        Encrypted:false
                                                        SSDEEP:3::
                                                        MD5:BF619EAC0CDF3F68D496EA9344137E8B
                                                        SHA1:5C3EB80066420002BC3DCC7CA4AB6EFAD7ED4AE5
                                                        SHA-256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
                                                        SHA-512:DF40D4A774E0B453A5B87C00D6F0EF5D753143454E88EE5F7B607134598294C7905CCBCF94BBC46E474DB6EB44E56A6DBB6D9A1BE9D4FB5D1B5F2D0C6ED34BFE
                                                        Malicious:false
                                                        Preview:................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:data
                                                        Category:dropped
                                                        Size (bytes):81920
                                                        Entropy (8bit):0.1506426855999441
                                                        Encrypted:false
                                                        SSDEEP:48:0JrxdSVlSCdSVCdSVmAdScdSVlSNdSVCdSVmAdSUoKrLoyi:t/zJi
                                                        MD5:1D0958E9D9438BFAE74E59CF56D51D56
                                                        SHA1:020720AD93C0463254D754A4DEE4F5EB1372A107
                                                        SHA-256:8C5CF907FCD57E85986BF6046D0AA976CD31ACD27158D7004CFD3B7A05A43666
                                                        SHA-512:4FFA1462A04B6D8EC51FC8F32F3174218FA6FC1E80BD9FBF043DDE0E9EABC5050C810B9FEAFD9FBD63C88160F5147BC30766E2FD5DF792B9AC2334C33AE7F44C
                                                        Malicious:false
                                                        Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        Process:C:\Windows\System32\msiexec.exe
                                                        File Type:Composite Document File V2 Document, Cannot read section info
                                                        Category:dropped
                                                        Size (bytes):32768
                                                        Entropy (8bit):1.307517046927086
                                                        Encrypted:false
                                                        SSDEEP:48:b2iquKBJveFXJPT5hVyyicUdSVlSNdSVCdSVmAdSUoKrydSVlSCdSVCdSVmAdSIP:RqK3TPV3icrV
                                                        MD5:C964C656A25FCA25B06A10120911CCE9
                                                        SHA1:3A49BDE4CF12FE3D651A829241AEEA07CAB31070
                                                        SHA-256:B2F6951CDF5443C9FABF0593D7DF32DBD9A2E95A7D51B1A9B5BC4C89C5257A99
                                                        SHA-512:CAC3B798FFA58849619625ECDFD1A101DD0B1ED295FE15A9B7C6564A72A2908096D6E9D02C73800A7CCC79FF400B1C346944B03DC74192C0A0B58E57C07A8822
                                                        Malicious:false
                                                        Preview:......................>...............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                        File type:Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, MSI Installer, Code page: 1252, Title: Installation Database, Subject: VMware Workspace ONE Assist, Author: VMware, Inc., Keywords: Installer, Comments: This installer database contains the logic and data required to install Workspace ONE Assist Installer., Template: x64;1033, Revision Number: {FD0CDE91-FD76-4738-8B40-800BA9713AFC}, Create Time/Date: Wed Mar 27 21:55:34 2024, Last Saved Time/Date: Wed Mar 27 21:55:34 2024, Number of Pages: 200, Number of Words: 2, Name of Creating Application: Windows Installer XML Toolset (3.11.2.4516), Security: 2
                                                        Entropy (8bit):7.8547122848696205
                                                        TrID:
                                                        • Microsoft Windows Installer (60509/1) 88.31%
                                                        • Generic OLE2 / Multistream Compound File (8008/1) 11.69%
                                                        File name:VZH3bd37Gc.msi
                                                        File size:10'838'016 bytes
                                                        MD5:af498bd451f04a1dae63cd61812a3c8b
                                                        SHA1:36f54070b8696eaa00ba1ff1d5fcfd5900ddacfa
                                                        SHA256:0400a87b6100936cdc0a8695c5dc1c7103bb93c0842231efaf7260a795290339
                                                        SHA512:80a4b5f8dbb1b4e1bfaf60fc6dc6ab8d0828a117168d87b1e6f802a8fdf1afa81752bee6d6c10e9ccc3db857f960b68a0f46742471a7a127e1e0dc9d987cd794
                                                        SSDEEP:196608:Oidybl3zkehEaHKc7wV9J9y5JKdmyg9KAtVVEDZLmZ2HHq8YLQL40fqV/d/r8ScO:OO4RzBqc7wXEsg9KWVWSZ2HK8nLTydI0
                                                        TLSH:E9B601513DC24873E5E1293675D2720C12E7BCF64AA34B5D2984F2693E3F293D4EAB42
                                                        File Content Preview:........................>......................................................................................................................................................................................................................................
                                                        Icon Hash:2d2e3797b32b2b99
                                                        No network behavior found

                                                        Click to jump to process

                                                        Click to jump to process

                                                        Click to dive into process behavior distribution

                                                        Click to jump to process

                                                        Target ID:0
                                                        Start time:14:16:18
                                                        Start date:25/04/2024
                                                        Path:C:\Windows\System32\msiexec.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:"C:\Windows\System32\msiexec.exe" /i "C:\Users\user\Desktop\VZH3bd37Gc.msi"
                                                        Imagebase:0x7ff7b0ad0000
                                                        File size:69'632 bytes
                                                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:false

                                                        Target ID:1
                                                        Start time:14:16:18
                                                        Start date:25/04/2024
                                                        Path:C:\Windows\System32\msiexec.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:C:\Windows\system32\msiexec.exe /V
                                                        Imagebase:0x7ff7b0ad0000
                                                        File size:69'632 bytes
                                                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:false

                                                        Target ID:2
                                                        Start time:14:16:28
                                                        Start date:25/04/2024
                                                        Path:C:\Windows\System32\msiexec.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:C:\Windows\System32\MsiExec.exe -Embedding 08351F78698DA0C0368A0A0187380C10 E Global\MSI0000
                                                        Imagebase:0x7ff7b0ad0000
                                                        File size:69'632 bytes
                                                        MD5 hash:E5DA170027542E25EDE42FC54C929077
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:false

                                                        Target ID:3
                                                        Start time:14:16:28
                                                        Start date:25/04/2024
                                                        Path:C:\Windows\System32\rundll32.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:rundll32.exe "C:\Windows\Installer\MSI50A5.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_5787937 2 AetherPal.Windows.Wix.CustomAction!AetherPal.Windows.Wix.CustomAction.CustomActions.InstallModernApp
                                                        Imagebase:0x7ff7beb40000
                                                        File size:71'680 bytes
                                                        MD5 hash:EF3179D498793BF4234F708D3BE28633
                                                        Has elevated privileges:true
                                                        Has administrator privileges:true
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:true

                                                        Target ID:4
                                                        Start time:14:16:29
                                                        Start date:25/04/2024
                                                        Path:C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:"C:\Program Files\VMware\Workspace ONE Assist\AetherPal.MSIX.Launcher.exe" "install" "C:\Program Files\VMware\Workspace ONE Assist\Resources"
                                                        Imagebase:0x229a6810000
                                                        File size:22'272 bytes
                                                        MD5 hash:D058E337D5F7E8ADA6BCC28B5114B303
                                                        Has elevated privileges:false
                                                        Has administrator privileges:false
                                                        Programmed in:C, C++ or other language
                                                        Antivirus matches:
                                                        • Detection: 0%, ReversingLabs
                                                        • Detection: 0%, Virustotal, Browse
                                                        Reputation:low
                                                        Has exited:true

                                                        Target ID:5
                                                        Start time:14:16:29
                                                        Start date:25/04/2024
                                                        Path:C:\Windows\System32\conhost.exe
                                                        Wow64 process (32bit):false
                                                        Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                        Imagebase:0x7ff7699e0000
                                                        File size:862'208 bytes
                                                        MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                        Has elevated privileges:false
                                                        Has administrator privileges:false
                                                        Programmed in:C, C++ or other language
                                                        Reputation:high
                                                        Has exited:true

                                                        Reset < >
                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: 2C_I
                                                          • API String ID: 0-999908352
                                                          • Opcode ID: 1b5a50a658cb6161c76adbed0a7e25b7b03a6719e611f67b4b7428912ce48a96
                                                          • Instruction ID: a1d284bcbe61a454bfead542201173e31dd0bc0f6762babf792fcf1db18b25e5
                                                          • Opcode Fuzzy Hash: 1b5a50a658cb6161c76adbed0a7e25b7b03a6719e611f67b4b7428912ce48a96
                                                          • Instruction Fuzzy Hash: F9222DA3B0F6C44FFB3545AC18641296F92EF976A871901FBD0D8871FBE854AE06E341
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          APIs
                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID: CreateProcessUser
                                                          • String ID:
                                                          • API String ID: 2217836671-0
                                                          • Opcode ID: 3f91aaf0f4d0787014fda94006da887cf0b6f1aeac5af99a0097924c4e13b134
                                                          • Instruction ID: e1e08de4371851c6a357f7c6d7c57671a12120ff691b99ea078ff911bd7087f2
                                                          • Opcode Fuzzy Hash: 3f91aaf0f4d0787014fda94006da887cf0b6f1aeac5af99a0097924c4e13b134
                                                          • Instruction Fuzzy Hash: 20B18C31D18A6C8FDB65DF58D845AE9BBF0FF58310F0042AAD40DE3291DB30AA858B81
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: KI_H
                                                          • API String ID: 0-1463696982
                                                          • Opcode ID: d6713661f630b72a48c6b393d2d65049d0d7718fdcfb0f2ed669e0c41f0553be
                                                          • Instruction ID: af7c0d228849033489a2163660d5438eec24cb66d97ce09a2adf800a40f49373
                                                          • Opcode Fuzzy Hash: d6713661f630b72a48c6b393d2d65049d0d7718fdcfb0f2ed669e0c41f0553be
                                                          • Instruction Fuzzy Hash: 37E12631B1DA4D4FEBA8DB6C84617B973E2EF99304F5501BAD44DC72E2DE24AD029780
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: H
                                                          • API String ID: 0-2852464175
                                                          • Opcode ID: e8fbb52700e61dbd9544e04620377d19d841aac66b7068c74b29f1c3144e6431
                                                          • Instruction ID: ae7d2baed68f66f9774e1a86ac97d231f918f50d61a096ed2f0cf28d4d232e5d
                                                          • Opcode Fuzzy Hash: e8fbb52700e61dbd9544e04620377d19d841aac66b7068c74b29f1c3144e6431
                                                          • Instruction Fuzzy Hash: 94C1F430B09A8D4FDB99EB3884616B97BE2EF4A304B5500FAD45DCB2E7DD25AE019740
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: b3fefc31559a3c0649c222886b8b62a8cbd85f3a75f9e1debf76f412833c6222
                                                          • Instruction ID: fefdcdfc15ed2f309cfcff84e01f1d9b1eb41a9c7f1d1c8359259aecd4ebfdf8
                                                          • Opcode Fuzzy Hash: b3fefc31559a3c0649c222886b8b62a8cbd85f3a75f9e1debf76f412833c6222
                                                          • Instruction Fuzzy Hash: 9CD16B62B0F6C90FE77946AC18691786B92EF9A268B0901FBD099C71FBEC14AD01D341
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 2386409b99d80c8b598b5b9f74bc732bdbc9234a7d73df6ac03cb431d0335f7c
                                                          • Instruction ID: 17f6d9c18620cd939be2154714243e99bf346a1c775096ec4d74a3eb89f71673
                                                          • Opcode Fuzzy Hash: 2386409b99d80c8b598b5b9f74bc732bdbc9234a7d73df6ac03cb431d0335f7c
                                                          • Instruction Fuzzy Hash: FAA12631A0DA4C4FEB58DB6C88666B97BF0EF5A304F1540BFC44DC72A2D921BD429B81
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          APIs
                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID: CodeExitProcess
                                                          • String ID:
                                                          • API String ID: 3861947596-0
                                                          • Opcode ID: 88222ff61ec59a4055880bc87f74849591601ab4be4136510c0ea398e8a3bd3e
                                                          • Instruction ID: 44ef370e05ee4c00b6f7f4fe7bc7ca6d0b12aeb501cc0874ea9bce58f062f50b
                                                          • Opcode Fuzzy Hash: 88222ff61ec59a4055880bc87f74849591601ab4be4136510c0ea398e8a3bd3e
                                                          • Instruction Fuzzy Hash: 8F51C630A09A4C8FDB54DFA8C859BED7BF1EF55310F0441ABD04DD7296DA349846CB41
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          APIs
                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID: ChangeCloseFindNotification
                                                          • String ID:
                                                          • API String ID: 2591292051-0
                                                          • Opcode ID: 9b5ca85dcc713b8c551b77c1f601f6e7fafb3a16042651cae8636b5f8760a474
                                                          • Instruction ID: ce6236146d1f71c7c1b997e12043d48f3d58247fbf6dde4a1fea9420e0f48186
                                                          • Opcode Fuzzy Hash: 9b5ca85dcc713b8c551b77c1f601f6e7fafb3a16042651cae8636b5f8760a474
                                                          • Instruction Fuzzy Hash: 26313830A0CA4C8FDB58DBA8C855BF9BBE0EF56320F00426FD049D3192CB74A855CB91
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000003.00000003.1897510107.00007FFD9B4A0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B4A0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_3_3_7ffd9b4a0000_rundll32.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: ea7bd06a76b14bdd2c809294a6787474b2d24d12b77a4576b9c20d9720851f80
                                                          • Instruction ID: bf99ca30a153d80e2e3b5fe76f2e6f33816ed7723b1e5ed86e876a9bd44a1cee
                                                          • Opcode Fuzzy Hash: ea7bd06a76b14bdd2c809294a6787474b2d24d12b77a4576b9c20d9720851f80
                                                          • Instruction Fuzzy Hash: A481362160F6CA0FE76697B858755B17FE4EF43328B1901FED0D9C70A3E9096946C742
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 174dfeee211c727fd456112664730dc328697a6d79711537ffd7ae9374cd2886
                                                          • Instruction ID: fda06fc63ccb37c6558e22159f37d681abd61804e0c01817ec5f7c175bece92f
                                                          • Opcode Fuzzy Hash: 174dfeee211c727fd456112664730dc328697a6d79711537ffd7ae9374cd2886
                                                          • Instruction Fuzzy Hash: 29E1F862B0FEC90BF761DB98A8B42297F91EF45250B0901BFD499C72FBD855AD01C381
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: >N_^$;@N_^
                                                          • API String ID: 0-347589474
                                                          • Opcode ID: cbbf9da561eca99c360dae61fec0608d6e76a36abaabfe0fcb8267720cddb786
                                                          • Instruction ID: 8d0edc4020fa7100b95511a3922df6a99da2a90e22f740b571b06a45f1dca13b
                                                          • Opcode Fuzzy Hash: cbbf9da561eca99c360dae61fec0608d6e76a36abaabfe0fcb8267720cddb786
                                                          • Instruction Fuzzy Hash: 7BB11B43B0FAC51FF7359ADC7CA41685F91EF91AA070902FFD4D8CA0FBA8556A068391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: >N_^$;@N_^
                                                          • API String ID: 0-347589474
                                                          • Opcode ID: 9434bd84dab992c6411b8ad4b276ddf19b7bd778e1f6bf66e12e6389fe0932ad
                                                          • Instruction ID: 454ef603440f16c019794bde336d7c0fe52cbe5da3204d784a33ec4db942bb29
                                                          • Opcode Fuzzy Hash: 9434bd84dab992c6411b8ad4b276ddf19b7bd778e1f6bf66e12e6389fe0932ad
                                                          • Instruction Fuzzy Hash: 7CB12F43B0FAC51FF7359ADC3CA51685F51EF916A070901FFD4D8CA0FBA8556A068391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: >N_^$;@N_^
                                                          • API String ID: 0-347589474
                                                          • Opcode ID: 3668c6a74d50b737005c8bcc162c63bd2ddd2fa85071eb43dd532bedf636e3df
                                                          • Instruction ID: 04dce669090a3f966a87b10ac0c7790c82c4a9c013eb33254a5a024fc92b38c8
                                                          • Opcode Fuzzy Hash: 3668c6a74d50b737005c8bcc162c63bd2ddd2fa85071eb43dd532bedf636e3df
                                                          • Instruction Fuzzy Hash: A9A1DA43B0FAC51FF7359ADC3CA51685F91EF91AA070901FFD4D8CA0FBA855AA068391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: >N_^$;@N_^
                                                          • API String ID: 0-347589474
                                                          • Opcode ID: 1c26ce7da617f7d7bd6317fe2d8b283c99a633d293059126d6bb875d7f26ab60
                                                          • Instruction ID: 535f6003433f227e017ebc3182aa3da7c0eed4b55cacefb06b097c8375ae6fd2
                                                          • Opcode Fuzzy Hash: 1c26ce7da617f7d7bd6317fe2d8b283c99a633d293059126d6bb875d7f26ab60
                                                          • Instruction Fuzzy Hash: DDA1D983B0FAC51FF73599DC3CA51685F91EF91AA070901FFD4D8CA0FBA855AA068391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: >N_^$;@N_^
                                                          • API String ID: 0-347589474
                                                          • Opcode ID: 713f61dffe3845559295a23398cd5c92ca4696436f6a5cd0c92cd37a0458611f
                                                          • Instruction ID: ff4fee8a4f982c464fe88d6a3150294fb1f5a3bc88aa0311be595feb74fbfd09
                                                          • Opcode Fuzzy Hash: 713f61dffe3845559295a23398cd5c92ca4696436f6a5cd0c92cd37a0458611f
                                                          • Instruction Fuzzy Hash: 08A1D783B0FAC51FF77599DC3CA41685F91EF91AA070901FFD4D8CA0FBA855AA068391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: 4N_I$5N_I
                                                          • API String ID: 0-4019850855
                                                          • Opcode ID: a5fbf3829115e142e9fef001ba52cef99ed6be6a26421b3d905cd863abcc2105
                                                          • Instruction ID: 2f7abfb5df96a31799a17702eccfc8d02e287e9bb4c88436c91a27169db14e06
                                                          • Opcode Fuzzy Hash: a5fbf3829115e142e9fef001ba52cef99ed6be6a26421b3d905cd863abcc2105
                                                          • Instruction Fuzzy Hash: CF51B543B0FFD51EF772D7E82C391296E91AF5266074942FFD1D48A1BBE804AA068352
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: %N_I
                                                          • API String ID: 0-4270823541
                                                          • Opcode ID: 2b5c72573f03064408fe80ac3cc865d18175934a990ecf8cfbb1f8fa13ea359a
                                                          • Instruction ID: 2b54e75bae08298a92d9e747d8ef50ea438acbf34a1d96acf26e732a9abf10cc
                                                          • Opcode Fuzzy Hash: 2b5c72573f03064408fe80ac3cc865d18175934a990ecf8cfbb1f8fa13ea359a
                                                          • Instruction Fuzzy Hash: DE12C543B0FBD50BF77597EC2C34128AF91EF522A075902FFE194861FBE455AA058391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: ^
                                                          • API String ID: 0-1590793086
                                                          • Opcode ID: 4a1762c9866e7e0760c2b2007f10371499c8110805c885cddf1c71213aa2bedd
                                                          • Instruction ID: 5193e72ab8d57e2f07629afd52ac8267d194d653e225126c3b91b346ae329c87
                                                          • Opcode Fuzzy Hash: 4a1762c9866e7e0760c2b2007f10371499c8110805c885cddf1c71213aa2bedd
                                                          • Instruction Fuzzy Hash: 4AB12822B0E6D94FE715A7AC98656E57FA0EF42310F0942FBD098C70E7DD5869468381
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Strings
                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID: ;@N_^
                                                          • API String ID: 0-3383401294
                                                          • Opcode ID: 2e59356d7888c3644c8e7ccb740669aa9133cfeeb38a43d5215f75b27cfc3caf
                                                          • Instruction ID: b9769909fdebfb2ad664d3f4e9a5dd13324e754d51ec1a0e4d79a01f5fa16568
                                                          • Opcode Fuzzy Hash: 2e59356d7888c3644c8e7ccb740669aa9133cfeeb38a43d5215f75b27cfc3caf
                                                          • Instruction Fuzzy Hash: B991B583B0FAC51FF77599DC3CA41685F91EB91AA070901FFD4D8CA0FBA855AA068391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 9159cee7c4291def8bbb3ac17b22f7edffa3ce77b57fea0648f9120760c8e1a8
                                                          • Instruction ID: 4ba77272fc8f3b53c480034f840249cdfde72dadfb3a5d446b48e46004ba508d
                                                          • Opcode Fuzzy Hash: 9159cee7c4291def8bbb3ac17b22f7edffa3ce77b57fea0648f9120760c8e1a8
                                                          • Instruction Fuzzy Hash: 8AD12A22B0EA4E0FF769B6AD68655F93BD1EF85320B0542BFD04DC31E7ED1868468391
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 7ec061dfa073252876c1c8d38243cec4c2c66baa7fd1a15257ec59b00ff3e426
                                                          • Instruction ID: 29cd6d0fd69302cb91c79cd5ee813587a3c7f5a8f66ef9a4303d5403952a0b37
                                                          • Opcode Fuzzy Hash: 7ec061dfa073252876c1c8d38243cec4c2c66baa7fd1a15257ec59b00ff3e426
                                                          • Instruction Fuzzy Hash: A9D13922B1E6D60EE312B7B868315E47F60EF42235B0942FBD1DDCB0E7DD1825498392
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: abb9cb2072ba6ca97851b50dad67a1f1ca4d66c84d4493013e47ca8fbbdf9d99
                                                          • Instruction ID: 88239d7ada8cd7571ee74ef0aa91c520b865197e61f2835bef18f963137e6f87
                                                          • Opcode Fuzzy Hash: abb9cb2072ba6ca97851b50dad67a1f1ca4d66c84d4493013e47ca8fbbdf9d99
                                                          • Instruction Fuzzy Hash: EBE11A30B0964E8FEBA4EF68C461AEA7BA1FF45310F0141BDD41DC72E6DA34A946C781
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 39439573bb02fb7271f12b3b8f8c66e5bdfc8173de2b6fbbc1f1a2863cdecc4b
                                                          • Instruction ID: 71a7f67884638e4f240824610e434a17af9ac276ff4f2c4be1a6c375fc8502b1
                                                          • Opcode Fuzzy Hash: 39439573bb02fb7271f12b3b8f8c66e5bdfc8173de2b6fbbc1f1a2863cdecc4b
                                                          • Instruction Fuzzy Hash: C671FA31A4E7CD1FE362ABB848259E57FE1DF43650B0A02FBD498CB0E3D91C554A8352
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: c91826548c143ceb32d3f8bbe4e7045a73e734ecf6d648d930a6124c486340f1
                                                          • Instruction ID: 2c5f5c10bc4e6eae27e03eef8f6db9efac08a7324001f33bfcfc6da4ea47b3e4
                                                          • Opcode Fuzzy Hash: c91826548c143ceb32d3f8bbe4e7045a73e734ecf6d648d930a6124c486340f1
                                                          • Instruction Fuzzy Hash: DD513A31B1DA8E4FFB98EB6858265B57BE1EF9535070141BEE45DC31A3DD25AD01C340
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: e3f32474203c8f150beb8aaa69427a1c5abe063b887860643ea0a30749afd85f
                                                          • Instruction ID: b3d62512d2973bb2dd9ff859f3b1ab8334fa91de0e6e1f1988f2441a59021cc6
                                                          • Opcode Fuzzy Hash: e3f32474203c8f150beb8aaa69427a1c5abe063b887860643ea0a30749afd85f
                                                          • Instruction Fuzzy Hash: AF619071A08B4C4FEB94EBA89859BEDBBE1EB59310F0041AED00DD72A2DA749845CB41
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 1fe6d4b5ebe787a430b37246396ed1699d080a8f1163ceaea6eda5f5f9dd3eed
                                                          • Instruction ID: b8b974b8560c3b433a674b3dc47bbe445c19675b3eb4a412dc97fc8ff2c4c6c9
                                                          • Opcode Fuzzy Hash: 1fe6d4b5ebe787a430b37246396ed1699d080a8f1163ceaea6eda5f5f9dd3eed
                                                          • Instruction Fuzzy Hash: 4D511921B1D90D4FE788EBAD9869674B7D2EF98310B1502BFF40DC32E6DD599C428341
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: d13bdf203e2c715e0f850a8da620d8e5cf6a13b6bbe42fe6ff5478177c828235
                                                          • Instruction ID: 6f7251bdf45236497ddcff4db8d4548d90c68533411962a09878b30f1837242c
                                                          • Opcode Fuzzy Hash: d13bdf203e2c715e0f850a8da620d8e5cf6a13b6bbe42fe6ff5478177c828235
                                                          • Instruction Fuzzy Hash: CF512831F0DB884FE759E7689819AA93FE0EF46310F0541BEE48DD71A3CD6828428781
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 924b3c4fa3b7de4bc53e1e7cd36647e29c0ca1c7e49b4ddd5430f4c6a5497c5e
                                                          • Instruction ID: 18f01e893f5547a6bdc2c17a121773d2b91fd4e52571a0b46c4f599bfcb7b0ce
                                                          • Opcode Fuzzy Hash: 924b3c4fa3b7de4bc53e1e7cd36647e29c0ca1c7e49b4ddd5430f4c6a5497c5e
                                                          • Instruction Fuzzy Hash: 0751A230A1D68C8FEB55EFA8CC55AE9BFF0EF16310F0441AAD449D71A2DE746845CB41
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: d8ad4ebf41229771acbf8642479cccb992c1381fcfadf1cc48b142baa027a0bb
                                                          • Instruction ID: 4c8fc9e15c60c645e2400aecb6ba072d63f4482639909487be45dd3a51cfd002
                                                          • Opcode Fuzzy Hash: d8ad4ebf41229771acbf8642479cccb992c1381fcfadf1cc48b142baa027a0bb
                                                          • Instruction Fuzzy Hash: D9517170A08A5C8FEBA4EFA8D849BEDBBF1FF55310F0041AAD00DD3252DB7499858B41
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: d1492c10e6bcc02fcc5c8df4a9ef478c0c658fec1073414fd52af4f1fc6e7a1e
                                                          • Instruction ID: 19b25dceda3ec43a3f820d13f1c16b0aa1b646b3956e9497d2373d4270ebea5b
                                                          • Opcode Fuzzy Hash: d1492c10e6bcc02fcc5c8df4a9ef478c0c658fec1073414fd52af4f1fc6e7a1e
                                                          • Instruction Fuzzy Hash: F5418130A08A4C8FEB98EFA8D859BEDBBF0FF55310F10416AD00DD7256DA705945CB41
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: c1a4f1ecbc8943535db7ec99a72efbaf22b3ba9074c6debbea96e5b1e41589ba
                                                          • Instruction ID: 2ea9978ea487e322c796f5918bd1494d4c95d91f52c41e51814b28a723a8a743
                                                          • Opcode Fuzzy Hash: c1a4f1ecbc8943535db7ec99a72efbaf22b3ba9074c6debbea96e5b1e41589ba
                                                          • Instruction Fuzzy Hash: C1517530609A4D8FDF98EF58C494EAA7BF1FF58304F5045ADE41AC7296CA31E991CB40
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: d99b717140d105c19882656230641e751d98b943e171f5a2f5b80c6f2cef3e01
                                                          • Instruction ID: 08af8ca1331764cd825c23ce0cc3161fefbd97e4b42fbbc84038c1e2fc0142dd
                                                          • Opcode Fuzzy Hash: d99b717140d105c19882656230641e751d98b943e171f5a2f5b80c6f2cef3e01
                                                          • Instruction Fuzzy Hash: 56214762B0FC8E4FF7A4E6AD9C549647B81DFA426130502FFE048C71A7EC01AD468340
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 79344b89e7283d3e3e73c7c9cba5c64d023704ad370d01a64eb37843425ddd4e
                                                          • Instruction ID: 635d79710e9104d3f6c0279354179ab2a7e87ec68f79b53707053b86069482fb
                                                          • Opcode Fuzzy Hash: 79344b89e7283d3e3e73c7c9cba5c64d023704ad370d01a64eb37843425ddd4e
                                                          • Instruction Fuzzy Hash: 0421C822B1EA0E0EFA78F59E646127967C2EFC4760F55427FE40DC21A5EE18A9420185
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: ac8db0d6a9d52e274f22254865b077bfe163a2a2eb69cea2223f0d493e0aa761
                                                          • Instruction ID: 2a847ffc6315c6a6e35e95ad295e802ee78799a402e3e28d32707b03c5a68b13
                                                          • Opcode Fuzzy Hash: ac8db0d6a9d52e274f22254865b077bfe163a2a2eb69cea2223f0d493e0aa761
                                                          • Instruction Fuzzy Hash: 4121B826F1A59D19FBB0FAAC48316BA3ED0DF45710F4501B9D45CC34E3ED182A1A4681
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 54e0d838eab837603545073da73e9274ef1127c068a5051e8a6d96055b2bd0f6
                                                          • Instruction ID: f5d5e30bed61709893fcf0ee519aa1285fb3aae7492d6fd223fa79182bf49f32
                                                          • Opcode Fuzzy Hash: 54e0d838eab837603545073da73e9274ef1127c068a5051e8a6d96055b2bd0f6
                                                          • Instruction Fuzzy Hash: 77210822F8E84E09F7B6F6A858312F87ED0EF44320F46017ED41CC34E2DD186A0A0281
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 938e702d4c342038c74e217bf07715992f86c0b13e443d576f393babc1905dbc
                                                          • Instruction ID: 4b660e548d6842d24247c04f236a2dee84e83d8606423da5b454cbe46bd2ba2e
                                                          • Opcode Fuzzy Hash: 938e702d4c342038c74e217bf07715992f86c0b13e443d576f393babc1905dbc
                                                          • Instruction Fuzzy Hash: F721F536F1E99E5AF7B0FAAC48316B93AD1EF55710F46017ED41CC34E3DD282A190281
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: 78964c8ab06c8d293e351af92b24a96f70a05b87b67bf668e387a76e44369888
                                                          • Instruction ID: eea35965f3cfda7ddb9f7f0e23f549818283185073b859a35908962206b81bac
                                                          • Opcode Fuzzy Hash: 78964c8ab06c8d293e351af92b24a96f70a05b87b67bf668e387a76e44369888
                                                          • Instruction Fuzzy Hash: 29110430A0D6C54FE756E739C865A207FE0EF5721170A02DAD095CB1F3D999AC86C311
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: d3f3506e4604126268643072c1d16ede8c011973b3a78cd2b9001e61740c16d1
                                                          • Instruction ID: 442cef0c86ef540716cea0205c5b04b8ad30179965774851920546c5ad00239f
                                                          • Opcode Fuzzy Hash: d3f3506e4604126268643072c1d16ede8c011973b3a78cd2b9001e61740c16d1
                                                          • Instruction Fuzzy Hash: 95E01732F2841D4F8B94EAACAC102FEB3E2EB8C212B000176E22DE3240DA20991147A1
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: ce7c290792f14a245ccc1a0812071de7eafbf633612bac8cecc2fa0ebe904132
                                                          • Instruction ID: 9a5b3aac0c376387570a26125c8997b537822b07b93ed03bd839f7f2071db810
                                                          • Opcode Fuzzy Hash: ce7c290792f14a245ccc1a0812071de7eafbf633612bac8cecc2fa0ebe904132
                                                          • Instruction Fuzzy Hash: C0D0EA30A4880DDFDF94EF58C494EA97BA1FF68344B164269E40ED72A1DB34E955CB80
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%

                                                          Memory Dump Source
                                                          • Source File: 00000004.00000002.1896395171.00007FFD9B3F0000.00000040.00000800.00020000.00000000.sdmp, Offset: 00007FFD9B3F0000, based on PE: false
                                                          Joe Sandbox IDA Plugin
                                                          • Snapshot File: hcaresult_4_2_7ffd9b3f0000_AetherPal.jbxd
                                                          Similarity
                                                          • API ID:
                                                          • String ID:
                                                          • API String ID:
                                                          • Opcode ID: a0858a5492f3134227adf094816f36f849e534df0f9226b20fbd3d9a7620c1c9
                                                          • Instruction ID: b8226e88cb1c8b87544789355825d0e6dbca99917f2867cbccb83404f82926ef
                                                          • Opcode Fuzzy Hash: a0858a5492f3134227adf094816f36f849e534df0f9226b20fbd3d9a7620c1c9
                                                          • Instruction Fuzzy Hash: 92A02232A8200C82EF30888038020FA3300EB00200F028222E80E020A0CA22A3308880
                                                          Uniqueness

                                                          Uniqueness Score: -1.00%