Windows Analysis Report
ndp48-web.exe

Overview

General Information

Sample name: ndp48-web.exe
Analysis ID: 1431611
MD5: 34a5c76979563918b953e66e0d39c7ef
SHA1: 4181398aa1fd5190155ac3a388434e5f7ea0b667
SHA256: 0bba3094588c4bfec301939985222a20b340bf03431563dec8b2b4478b06fffa
Infos:

Detection

Score: 3
Range: 0 - 100
Whitelisted: false
Confidence: 20%

Compliance

Score: 48
Range: 0 - 100

Signatures

Creates a process in suspended mode (likely to inject code)
Creates or modifies windows services
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

Compliance

barindex
Source: ndp48-web.exe Static PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1033\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1030\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1043\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1040\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1031\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1035\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1036\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1038\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1045\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1029\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1028\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1037\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1025\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1032\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1042\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1041\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1044\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1053\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\3082\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1046\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\2070\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1055\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\2052\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1049\eula.rtf Jump to behavior
Source: ndp48-web.exe Static PE information: certificate valid
Source: ndp48-web.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: sqmapi.pdb source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643088661.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1642873053.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643183335.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097119067.000000006CA81000.00000020.00000001.01000000.00000006.sdmp, sqmapi.dll.0.dr
Source: Binary string: SetupEngine.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097226411.000000006CAC1000.00000020.00000001.01000000.00000005.sdmp, SetupEngine.dll.0.dr
Source: Binary string: SetupUtility.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: SetupUtility.pdb5 source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: Setup.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4094321813.0000000000EE1000.00000020.00000001.01000000.00000004.sdmp, Setup.exe.0.dr
Source: Binary string: -C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: SetupResources.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097511959.000000006E321000.00000020.00000001.01000000.0000000C.sdmp, SetupResources.dll20.0.dr, SetupResources.dll10.0.dr, SetupResources.dll4.0.dr, SetupResources.dll11.0.dr, SetupResources.dll5.0.dr, SetupResources.dll2.0.dr, SetupResources.dll13.0.dr, SetupResources.dll7.0.dr, SetupResources.dll12.0.dr, SetupResources.dll16.0.dr, SetupResources.dll14.0.dr, SetupResources.dll18.0.dr, SetupResources.dll19.0.dr, SetupResources.dll3.0.dr, SetupResources.dll17.0.dr, SetupResources.dll1.0.dr, SetupResources.dll9.0.dr, SetupResources.dll22.0.dr, SetupResources.dll6.0.dr, SetupResources.dll0.0.dr, SetupResources.dll15.0.dr, SetupResources.dll21.0.dr, SetupResources.dll.0.dr, SetupResources.dll8.0.dr
Source: Binary string: SetupUi.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4096935660.000000006C631000.00000020.00000001.01000000.0000000B.sdmp, SetupUi.dll.0.dr
Source: winword.exe Memory has grown: Private usage: 1MB later: 42MB
Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD4157.2.dr String found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab
Source: Setup.exe, 00000001.00000003.1674388120.00000000005BF000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.1674301361.00000000005B7000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://go.mic
Source: SetupResources.dll10.0.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: SetupResources.dll10.0.dr Static PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: SetupResources.dll7.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll1.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll11.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll4.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll22.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll14.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll17.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll16.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll19.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll13.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll5.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll8.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll9.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll10.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll21.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll2.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll18.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll0.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll3.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll15.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll6.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll12.0.dr Static PE information: No import functions for PE file found
Source: SetupResources.dll20.0.dr Static PE information: No import functions for PE file found
Source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1623425541.0000000000C6D000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000C98000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000002.4086062566.00000000000FD000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1642980054.0000000000D20000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSetupUI.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSetupUtility.exe\ vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSetupEngine.dllT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSetupResources.dllT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSetupResources.dllX vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSetupResources.dll\ vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenameSetup.dllT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000000.1622920091.00000000000FD000.00000002.00000001.01000000.00000003.sdmp Binary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1643183335.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe Binary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exe Static PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: classification engine Classification label: clean3.winEXE@14/132@0/0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE File created: C:\Users\user\AppData\Roaming\Microsoft\Office Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Mutant created: \Sessions\1\BaseNamedObjects\Global\NetFxSetupMutex
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\Users\user\AppData\Local\Temp\dd_ndp48-web_decompression_log.txt Jump to behavior
Source: ndp48-web.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe File read: C:\Windows\win.ini Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File read: C:\Users\user\Desktop\ndp48-web.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\ndp48-web.exe "C:\Users\user\Desktop\ndp48-web.exe"
Source: C:\Users\user\Desktop\ndp48-web.exe Process created: C:\5478d9557b6298dc63ac5974e1\Setup.exe C:\5478d9557b6298dc63ac5974e1\\Setup.exe /x86 /x64 /web
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Users\user\Desktop\ndp48-web.exe Process created: C:\5478d9557b6298dc63ac5974e1\Setup.exe C:\5478d9557b6298dc63ac5974e1\\Setup.exe /x86 /x64 /web Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf" Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf" Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288 Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process created: unknown unknown Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: cabinet.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: cryptdll.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: cryptsp.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: clusapi.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: rsaenh.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: cryptbase.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: feclient.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: winmm.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: samcli.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: version.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: userenv.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: mpr.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: netutils.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: setupengine.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msi.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: secur32.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: sqmapi.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: netapi32.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: wkscli.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msasn1.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: wldp.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: profapi.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: setupui.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msxml6.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: riched20.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: usp10.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msls31.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: atlthunk.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: dataexchange.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: d3d11.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: dcomp.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: dxgi.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: twinapi.appcore.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: propsys.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: edputil.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: windows.staterepositoryps.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: policymanager.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: msvcp110_win.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: appresolver.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: bcp47langs.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: slc.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: sppc.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: onecorecommonproxystub.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Section loaded: onecoreuapcommonproxystub.dll Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InProcServer32 Jump to behavior
Source: Templates.LNK.2.dr LNK file: ..\..\Templates
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE File opened: C:\Windows\SysWOW64\MsftEdit.dll Jump to behavior
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Window detected: Number of UI elements: 15
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Key opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Common Jump to behavior
Source: ndp48-web.exe Static PE information: certificate valid
Source: initial sample Static PE information: Valid certificate with Microsoft Issuer
Source: ndp48-web.exe Static file information: File size 1439328 > 1048576
Source: ndp48-web.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: ndp48-web.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: ndp48-web.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: ndp48-web.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: ndp48-web.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: ndp48-web.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: ndp48-web.exe Static PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: ndp48-web.exe Static PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: sqmapi.pdb source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643088661.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1642873053.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643183335.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097119067.000000006CA81000.00000020.00000001.01000000.00000006.sdmp, sqmapi.dll.0.dr
Source: Binary string: SetupEngine.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097226411.000000006CAC1000.00000020.00000001.01000000.00000005.sdmp, SetupEngine.dll.0.dr
Source: Binary string: SetupUtility.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: SetupUtility.pdb5 source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: Setup.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4094321813.0000000000EE1000.00000020.00000001.01000000.00000004.sdmp, Setup.exe.0.dr
Source: Binary string: -C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: SetupResources.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097511959.000000006E321000.00000020.00000001.01000000.0000000C.sdmp, SetupResources.dll20.0.dr, SetupResources.dll10.0.dr, SetupResources.dll4.0.dr, SetupResources.dll11.0.dr, SetupResources.dll5.0.dr, SetupResources.dll2.0.dr, SetupResources.dll13.0.dr, SetupResources.dll7.0.dr, SetupResources.dll12.0.dr, SetupResources.dll16.0.dr, SetupResources.dll14.0.dr, SetupResources.dll18.0.dr, SetupResources.dll19.0.dr, SetupResources.dll3.0.dr, SetupResources.dll17.0.dr, SetupResources.dll1.0.dr, SetupResources.dll9.0.dr, SetupResources.dll22.0.dr, SetupResources.dll6.0.dr, SetupResources.dll0.0.dr, SetupResources.dll15.0.dr, SetupResources.dll21.0.dr, SetupResources.dll.0.dr, SetupResources.dll8.0.dr
Source: Binary string: SetupUi.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4096935660.000000006C631000.00000020.00000001.01000000.0000000B.sdmp, SetupUi.dll.0.dr
Source: SetupResources.dll7.0.dr Static PE information: real checksum: 0x85b6 should be: 0x11869
Source: SetupResources.dll.0.dr Static PE information: real checksum: 0x6ea5 should be: 0x14bba
Source: SetupResources.dll1.0.dr Static PE information: real checksum: 0xeaf1 should be: 0xf9e7
Source: SetupResources.dll11.0.dr Static PE information: real checksum: 0x152f3 should be: 0xfcfd
Source: SetupUi.dll.0.dr Static PE information: real checksum: 0x5bb56 should be: 0x580a0
Source: SetupResources.dll4.0.dr Static PE information: real checksum: 0x15ab2 should be: 0x11a19
Source: SetupResources.dll22.0.dr Static PE information: real checksum: 0x79e2 should be: 0x14200
Source: SetupResources.dll14.0.dr Static PE information: real checksum: 0xb54d should be: 0xe4b6
Source: SetupResources.dll17.0.dr Static PE information: real checksum: 0x74cf should be: 0xed2c
Source: SetupResources.dll16.0.dr Static PE information: real checksum: 0x133a7 should be: 0x11cfc
Source: SetupResources.dll19.0.dr Static PE information: real checksum: 0x664a should be: 0x6bd6
Source: SetupResources.dll13.0.dr Static PE information: real checksum: 0xe0f8 should be: 0x12f83
Source: SetupResources.dll5.0.dr Static PE information: real checksum: 0xff36 should be: 0x92e3
Source: SetupResources.dll8.0.dr Static PE information: real checksum: 0x8bd9 should be: 0x12d34
Source: SetupResources.dll9.0.dr Static PE information: real checksum: 0xda87 should be: 0x11fd2
Source: SetupResources.dll10.0.dr Static PE information: real checksum: 0xccb2 should be: 0x10498
Source: SetupResources.dll2.0.dr Static PE information: real checksum: 0x1120b should be: 0x9889
Source: Setup.exe.0.dr Static PE information: real checksum: 0x241d1 should be: 0x2b297
Source: SetupResources.dll18.0.dr Static PE information: real checksum: 0x108c5 should be: 0x81a2
Source: SetupResources.dll0.0.dr Static PE information: real checksum: 0xc251 should be: 0x7278
Source: SetupResources.dll3.0.dr Static PE information: real checksum: 0x130f6 should be: 0xfb6f
Source: SetupEngine.dll.0.dr Static PE information: real checksum: 0xe3382 should be: 0xe90f6
Source: SetupResources.dll15.0.dr Static PE information: real checksum: 0xc4a3 should be: 0x13cd1
Source: SetupResources.dll6.0.dr Static PE information: real checksum: 0x53a2 should be: 0x586f
Source: SetupResources.dll12.0.dr Static PE information: real checksum: 0x106a2 should be: 0x12659
Source: SetupResources.dll20.0.dr Static PE information: real checksum: 0x14ea0 should be: 0xd534
Source: ndp48-web.exe Static PE information: section name: .boxld01
Source: SetupResources.dll.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll0.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll1.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll2.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll3.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll4.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll5.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll6.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll7.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll8.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll9.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll10.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll11.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll12.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll13.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll14.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll15.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll16.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll17.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll18.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll19.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll20.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll21.0.dr Static PE information: section name: .00cfg
Source: SetupResources.dll22.0.dr Static PE information: section name: .00cfg
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1041\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1042\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1040\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1038\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\3082\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\SetupUi.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\2070\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\2052\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1044\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1043\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1046\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1045\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1049\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\SetupUtility.exe Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1028\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1025\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1053\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\sqmapi.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1055\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\SetupEngine.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1029\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1035\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1037\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1036\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1030\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1033\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1032\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1031\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\Setup.exe Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1033\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1030\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1043\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1040\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1031\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1035\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1036\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1038\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1045\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1029\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1028\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1037\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1025\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1032\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1042\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1041\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1044\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1053\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\3082\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1046\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\2070\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1055\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\2052\eula.rtf Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe File created: C:\5478d9557b6298dc63ac5974e1\1049\eula.rtf Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Registry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\VSSetup Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Process information set: NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exe Process information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE Jump to behavior
Source: C:\Windows\splwow64.exe Window / User API: threadDelayed 9896
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1041\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1042\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1040\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1038\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\3082\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\2070\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\2052\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1044\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1043\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1046\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1045\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1049\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\SetupUtility.exe Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1028\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1053\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1025\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1055\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1029\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1035\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1037\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1036\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1030\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1033\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1032\SetupResources.dll Jump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exe Dropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1031\SetupResources.dll Jump to dropped file
Source: C:\Windows\splwow64.exe Last function: Thread delayed
Source: C:\Windows\splwow64.exe Last function: Thread delayed
Source: C:\Users\user\Desktop\ndp48-web.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe File Volume queried: C:\ FullSizeInformation Jump to behavior
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000 Jump to behavior
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000
Source: C:\Windows\splwow64.exe Thread delayed: delay time: 120000
Source: Setup.exe, 00000001.00000002.4096365834.0000000008480000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\y
Source: Setup.exe, 00000001.00000002.4096712651.0000000009DE0000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}}
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process information queried: ProcessInformation Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Memory allocated: page read and write | page guard Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf" Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exe Process created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf" Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid Jump to behavior
No contacted IP infos