Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
ndp48-web.exe

Overview

General Information

Sample name:ndp48-web.exe
Analysis ID:1431611
MD5:34a5c76979563918b953e66e0d39c7ef
SHA1:4181398aa1fd5190155ac3a388434e5f7ea0b667
SHA256:0bba3094588c4bfec301939985222a20b340bf03431563dec8b2b4478b06fffa
Infos:

Detection

Score:3
Range:0 - 100
Whitelisted:false
Confidence:20%

Compliance

Score:48
Range:0 - 100

Signatures

Creates a process in suspended mode (likely to inject code)
Creates or modifies windows services
Drops PE files
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found dropped PE file which has not been started or loaded
PE file contains an invalid checksum
PE file contains executable resources (Code or Archives)
PE file contains sections with non-standard names
PE file does not import any functions
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample has a GUI, but Joe Sandbox has not found any clickable buttons, likely more UI automation may extend behavior
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample monitors window changes (e.g. starting applications), analyze the sample with the 'Simulates keyboard and window changes' cookbook
  • System is w10x64
  • ndp48-web.exe (PID: 7492 cmdline: "C:\Users\user\Desktop\ndp48-web.exe" MD5: 34A5C76979563918B953E66E0D39C7EF)
    • Setup.exe (PID: 7548 cmdline: C:\5478d9557b6298dc63ac5974e1\\Setup.exe /x86 /x64 /web MD5: 057CE4FB9C8E829AF369AFBC5C4DFD41)
      • WINWORD.EXE (PID: 7652 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
        • splwow64.exe (PID: 7864 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
      • WINWORD.EXE (PID: 3484 cmdline: "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf" MD5: 1A0C2C2E7D9C4BC18E91604E9B0C7678)
        • splwow64.exe (PID: 7520 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
        • splwow64.exe (PID: 7936 cmdline: C:\Windows\splwow64.exe 12288 MD5: 77DE7761B037061C7C112FD3C5B91E73)
  • cleanup
No configs have been found
No yara matches
Source: File createdAuthor: Nasreddine Bencherchali (Nextron Systems): Data: EventID: 11, Image: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE, ProcessId: 7652, TargetFilename: C:\Users\user\AppData\Roaming\Microsoft\Templates\~$Normal.dotm
No Snort rule has matched

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Compliance

barindex
Source: ndp48-web.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1033\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1030\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1043\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1040\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1031\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1035\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1036\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1038\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1045\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1029\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1028\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1037\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1025\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1032\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1042\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1041\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1044\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1053\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\3082\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1046\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\2070\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1055\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\2052\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1049\eula.rtfJump to behavior
Source: ndp48-web.exeStatic PE information: certificate valid
Source: ndp48-web.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: sqmapi.pdb source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643088661.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1642873053.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643183335.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097119067.000000006CA81000.00000020.00000001.01000000.00000006.sdmp, sqmapi.dll.0.dr
Source: Binary string: SetupEngine.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097226411.000000006CAC1000.00000020.00000001.01000000.00000005.sdmp, SetupEngine.dll.0.dr
Source: Binary string: SetupUtility.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: SetupUtility.pdb5 source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: Setup.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4094321813.0000000000EE1000.00000020.00000001.01000000.00000004.sdmp, Setup.exe.0.dr
Source: Binary string: -C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: SetupResources.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097511959.000000006E321000.00000020.00000001.01000000.0000000C.sdmp, SetupResources.dll20.0.dr, SetupResources.dll10.0.dr, SetupResources.dll4.0.dr, SetupResources.dll11.0.dr, SetupResources.dll5.0.dr, SetupResources.dll2.0.dr, SetupResources.dll13.0.dr, SetupResources.dll7.0.dr, SetupResources.dll12.0.dr, SetupResources.dll16.0.dr, SetupResources.dll14.0.dr, SetupResources.dll18.0.dr, SetupResources.dll19.0.dr, SetupResources.dll3.0.dr, SetupResources.dll17.0.dr, SetupResources.dll1.0.dr, SetupResources.dll9.0.dr, SetupResources.dll22.0.dr, SetupResources.dll6.0.dr, SetupResources.dll0.0.dr, SetupResources.dll15.0.dr, SetupResources.dll21.0.dr, SetupResources.dll.0.dr, SetupResources.dll8.0.dr
Source: Binary string: SetupUi.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4096935660.000000006C631000.00000020.00000001.01000000.0000000B.sdmp, SetupUi.dll.0.dr
Source: winword.exeMemory has grown: Private usage: 1MB later: 42MB
Source: 57C8EDB95DF3F0AD4EE2DC2B8CFD4157.2.drString found in binary or memory: http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab
Source: Setup.exe, 00000001.00000003.1674388120.00000000005BF000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.1674301361.00000000005B7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://go.mic
Source: SetupResources.dll10.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: SetupResources.dll10.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: SetupResources.dll7.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll1.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll11.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll4.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll22.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll14.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll17.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll16.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll19.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll13.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll5.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll8.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll9.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll10.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll21.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll2.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll18.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll0.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll3.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll15.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll6.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll12.0.drStatic PE information: No import functions for PE file found
Source: SetupResources.dll20.0.drStatic PE information: No import functions for PE file found
Source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000D1F000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1623425541.0000000000C6D000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000C98000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000002.4086062566.00000000000FD000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1642980054.0000000000D20000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSetupUI.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSetupUtility.exe\ vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSetupEngine.dllT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSetupResources.dllT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSetupResources.dllX vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSetupResources.dll\ vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameSetup.dllT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000000.1622920091.00000000000FD000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exe, 00000000.00000003.1643183335.0000000000CFF000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamesqmapi.dllj% vs ndp48-web.exe
Source: ndp48-web.exeBinary or memory string: OriginalFilenameBoxStub.exeT vs ndp48-web.exe
Source: ndp48-web.exeStatic PE information: EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
Source: classification engineClassification label: clean3.winEXE@14/132@0/0
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile created: C:\Users\user\AppData\Roaming\Microsoft\OfficeJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeMutant created: \Sessions\1\BaseNamedObjects\Global\NetFxSetupMutex
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\Users\user\AppData\Local\Temp\dd_ndp48-web_decompression_log.txtJump to behavior
Source: ndp48-web.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeFile read: C:\Windows\win.iniJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile read: C:\Users\user\Desktop\ndp48-web.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\ndp48-web.exe "C:\Users\user\Desktop\ndp48-web.exe"
Source: C:\Users\user\Desktop\ndp48-web.exeProcess created: C:\5478d9557b6298dc63ac5974e1\Setup.exe C:\5478d9557b6298dc63ac5974e1\\Setup.exe /x86 /x64 /web
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf"
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Users\user\Desktop\ndp48-web.exeProcess created: C:\5478d9557b6298dc63ac5974e1\Setup.exe C:\5478d9557b6298dc63ac5974e1\\Setup.exe /x86 /x64 /webJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf"Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf"Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288Jump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: unknown unknownJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess created: C:\Windows\splwow64.exe C:\Windows\splwow64.exe 12288
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: cabinet.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: cryptdll.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: cryptsp.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: clusapi.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: rsaenh.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: cryptbase.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: feclient.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: iertutil.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeSection loaded: apphelp.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: apphelp.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: acgenral.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: winmm.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: samcli.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msacm32.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: version.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: userenv.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: urlmon.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: mpr.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: sspicli.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: winmmbase.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: iertutil.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: srvcli.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: netutils.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: setupengine.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msi.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: winhttp.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: secur32.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: sqmapi.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: netapi32.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: wkscli.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msasn1.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: windows.storage.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: wldp.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: profapi.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msxml3.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msxml3.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: wintypes.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: wintypes.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: wintypes.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: setupui.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msxml6.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: riched20.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: usp10.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msls31.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: atlthunk.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: dataexchange.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: d3d11.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: dcomp.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: dxgi.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: twinapi.appcore.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: textshaping.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: propsys.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: edputil.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: windows.staterepositoryps.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: policymanager.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: msvcp110_win.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: appresolver.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: bcp47langs.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: slc.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: sppc.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: onecorecommonproxystub.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{F5078F32-C551-11D3-89B9-0000F81FE221}\InProcServer32Jump to behavior
Source: Templates.LNK.2.drLNK file: ..\..\Templates
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEFile opened: C:\Windows\SysWOW64\MsftEdit.dllJump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEWindow detected: Number of UI elements: 15
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEKey opened: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\CommonJump to behavior
Source: ndp48-web.exeStatic PE information: certificate valid
Source: initial sampleStatic PE information: Valid certificate with Microsoft Issuer
Source: ndp48-web.exeStatic file information: File size 1439328 > 1048576
Source: ndp48-web.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: ndp48-web.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: ndp48-web.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: ndp48-web.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: ndp48-web.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: ndp48-web.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: ndp48-web.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: ndp48-web.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: sqmapi.pdb source: ndp48-web.exe, 00000000.00000003.1642873053.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643088661.0000000000D1F000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1642873053.0000000000C98000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, ndp48-web.exe, 00000000.00000003.1643183335.0000000000CFF000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097119067.000000006CA81000.00000020.00000001.01000000.00000006.sdmp, sqmapi.dll.0.dr
Source: Binary string: SetupEngine.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097226411.000000006CAC1000.00000020.00000001.01000000.00000005.sdmp, SetupEngine.dll.0.dr
Source: Binary string: SetupUtility.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: SetupUtility.pdb5 source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, SetupUtility.exe.0.dr
Source: Binary string: Setup.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4094321813.0000000000EE1000.00000020.00000001.01000000.00000004.sdmp, Setup.exe.0.dr
Source: Binary string: -C:\NetFXDev1\binaries\x86ret\bin\i386\VSSetup\Utils\boxstub.pdb source: ndp48-web.exe
Source: Binary string: SetupResources.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4097511959.000000006E321000.00000020.00000001.01000000.0000000C.sdmp, SetupResources.dll20.0.dr, SetupResources.dll10.0.dr, SetupResources.dll4.0.dr, SetupResources.dll11.0.dr, SetupResources.dll5.0.dr, SetupResources.dll2.0.dr, SetupResources.dll13.0.dr, SetupResources.dll7.0.dr, SetupResources.dll12.0.dr, SetupResources.dll16.0.dr, SetupResources.dll14.0.dr, SetupResources.dll18.0.dr, SetupResources.dll19.0.dr, SetupResources.dll3.0.dr, SetupResources.dll17.0.dr, SetupResources.dll1.0.dr, SetupResources.dll9.0.dr, SetupResources.dll22.0.dr, SetupResources.dll6.0.dr, SetupResources.dll0.0.dr, SetupResources.dll15.0.dr, SetupResources.dll21.0.dr, SetupResources.dll.0.dr, SetupResources.dll8.0.dr
Source: Binary string: SetupUi.pdb source: ndp48-web.exe, 00000000.00000003.1641788908.0000000006102000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000002.4096935660.000000006C631000.00000020.00000001.01000000.0000000B.sdmp, SetupUi.dll.0.dr
Source: SetupResources.dll7.0.drStatic PE information: real checksum: 0x85b6 should be: 0x11869
Source: SetupResources.dll.0.drStatic PE information: real checksum: 0x6ea5 should be: 0x14bba
Source: SetupResources.dll1.0.drStatic PE information: real checksum: 0xeaf1 should be: 0xf9e7
Source: SetupResources.dll11.0.drStatic PE information: real checksum: 0x152f3 should be: 0xfcfd
Source: SetupUi.dll.0.drStatic PE information: real checksum: 0x5bb56 should be: 0x580a0
Source: SetupResources.dll4.0.drStatic PE information: real checksum: 0x15ab2 should be: 0x11a19
Source: SetupResources.dll22.0.drStatic PE information: real checksum: 0x79e2 should be: 0x14200
Source: SetupResources.dll14.0.drStatic PE information: real checksum: 0xb54d should be: 0xe4b6
Source: SetupResources.dll17.0.drStatic PE information: real checksum: 0x74cf should be: 0xed2c
Source: SetupResources.dll16.0.drStatic PE information: real checksum: 0x133a7 should be: 0x11cfc
Source: SetupResources.dll19.0.drStatic PE information: real checksum: 0x664a should be: 0x6bd6
Source: SetupResources.dll13.0.drStatic PE information: real checksum: 0xe0f8 should be: 0x12f83
Source: SetupResources.dll5.0.drStatic PE information: real checksum: 0xff36 should be: 0x92e3
Source: SetupResources.dll8.0.drStatic PE information: real checksum: 0x8bd9 should be: 0x12d34
Source: SetupResources.dll9.0.drStatic PE information: real checksum: 0xda87 should be: 0x11fd2
Source: SetupResources.dll10.0.drStatic PE information: real checksum: 0xccb2 should be: 0x10498
Source: SetupResources.dll2.0.drStatic PE information: real checksum: 0x1120b should be: 0x9889
Source: Setup.exe.0.drStatic PE information: real checksum: 0x241d1 should be: 0x2b297
Source: SetupResources.dll18.0.drStatic PE information: real checksum: 0x108c5 should be: 0x81a2
Source: SetupResources.dll0.0.drStatic PE information: real checksum: 0xc251 should be: 0x7278
Source: SetupResources.dll3.0.drStatic PE information: real checksum: 0x130f6 should be: 0xfb6f
Source: SetupEngine.dll.0.drStatic PE information: real checksum: 0xe3382 should be: 0xe90f6
Source: SetupResources.dll15.0.drStatic PE information: real checksum: 0xc4a3 should be: 0x13cd1
Source: SetupResources.dll6.0.drStatic PE information: real checksum: 0x53a2 should be: 0x586f
Source: SetupResources.dll12.0.drStatic PE information: real checksum: 0x106a2 should be: 0x12659
Source: SetupResources.dll20.0.drStatic PE information: real checksum: 0x14ea0 should be: 0xd534
Source: ndp48-web.exeStatic PE information: section name: .boxld01
Source: SetupResources.dll.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll0.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll1.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll2.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll3.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll4.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll5.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll6.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll7.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll8.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll9.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll10.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll11.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll12.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll13.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll14.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll15.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll16.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll17.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll18.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll19.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll20.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll21.0.drStatic PE information: section name: .00cfg
Source: SetupResources.dll22.0.drStatic PE information: section name: .00cfg
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1041\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1042\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1040\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1038\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\3082\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\SetupUi.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\2070\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\2052\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1044\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1043\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1046\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1045\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1049\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\SetupUtility.exeJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1028\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1025\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1053\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\sqmapi.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1055\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\SetupEngine.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1029\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1035\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1037\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1036\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1030\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1033\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1032\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1031\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\Setup.exeJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1033\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1030\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1043\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1040\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1031\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1035\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1036\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1038\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1045\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1029\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1028\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1037\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1025\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1032\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1042\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1041\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1044\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1053\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\3082\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1046\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\2070\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1055\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\2052\eula.rtfJump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeFile created: C:\5478d9557b6298dc63ac5974e1\1049\eula.rtfJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeRegistry key created: HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EventLog\Application\VSSetupJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOXJump to behavior
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\Windows\splwow64.exeProcess information set: NOALIGNMENTFAULTEXCEPT | NOOPENFILEERRORBOX
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXEJump to behavior
Source: C:\Windows\splwow64.exeWindow / User API: threadDelayed 9896
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1041\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1042\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1040\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1038\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\3082\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\2070\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\2052\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1044\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1043\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1046\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1045\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1049\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\SetupUtility.exeJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1028\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1053\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1025\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1055\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1029\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1035\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1037\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1036\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1030\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1033\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1032\SetupResources.dllJump to dropped file
Source: C:\Users\user\Desktop\ndp48-web.exeDropped PE file which has not been started: C:\5478d9557b6298dc63ac5974e1\1031\SetupResources.dllJump to dropped file
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Windows\splwow64.exeLast function: Thread delayed
Source: C:\Users\user\Desktop\ndp48-web.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000Jump to behavior
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
Source: C:\Windows\splwow64.exeThread delayed: delay time: 120000
Source: Setup.exe, 00000001.00000002.4096365834.0000000008480000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\y
Source: Setup.exe, 00000001.00000002.4096712651.0000000009DE0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000C5E500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{a33c735c-61ca-11ee-8c18-806e6f6e6963}#0000000007500000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#4&224f42ef&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}}
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess information queried: ProcessInformationJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeMemory allocated: page read and write | page guardJump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf"Jump to behavior
Source: C:\5478d9557b6298dc63ac5974e1\Setup.exeProcess created: C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE "C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf"Jump to behavior
Source: C:\Users\user\Desktop\ndp48-web.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
Windows Service
1
Windows Service
1
Masquerading
OS Credential Dumping1
Security Software Discovery
Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault AccountsScheduled Task/Job1
DLL Side-Loading
11
Process Injection
1
Disable or Modify Tools
LSASS Memory1
Process Discovery
Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
DLL Side-Loading
1
Virtualization/Sandbox Evasion
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
Extra Window Memory Injection
11
Process Injection
NTDS1
Application Window Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
DLL Side-Loading
LSA Secrets1
File and Directory Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
Extra Window Memory Injection
Cached Domain Credentials4
System Information Discovery
VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 process2 2 Behavior Graph ID: 1431611 Sample: ndp48-web.exe Startdate: 25/04/2024 Architecture: WINDOWS Score: 3 7 ndp48-web.exe 131 2->7         started        file3 22 C:\5478d9557b6298dc63ac5974e1\sqmapi.dll, PE32 7->22 dropped 24 C:\...\SetupUtility.exe, PE32 7->24 dropped 26 C:\5478d9557b6298dc63ac5974e1\SetupUi.dll, PE32 7->26 dropped 28 26 other files (none is malicious) 7->28 dropped 10 Setup.exe 5 9 7->10         started        process4 process5 12 WINWORD.EXE 44 55 10->12         started        14 WINWORD.EXE 51 93 10->14         started        process6 16 splwow64.exe 12->16         started        18 splwow64.exe 12->18         started        20 splwow64.exe 14->20         started       

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
ndp48-web.exe0%ReversingLabs
ndp48-web.exe0%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\5478d9557b6298dc63ac5974e1\1025\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1025\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1028\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1028\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1029\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1029\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1030\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1030\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1031\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1031\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1032\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1032\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1033\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1033\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1035\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1035\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1036\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1036\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1037\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1037\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1038\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1038\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1040\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1040\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1041\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1041\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1042\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1042\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1043\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1043\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1044\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1044\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1045\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1045\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1046\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1046\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1049\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1049\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1053\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1053\SetupResources.dll0%VirustotalBrowse
C:\5478d9557b6298dc63ac5974e1\1055\SetupResources.dll0%ReversingLabs
C:\5478d9557b6298dc63ac5974e1\1055\SetupResources.dll0%VirustotalBrowse
No Antivirus matches
SourceDetectionScannerLabelLink
bg.microsoft.map.fastly.net0%VirustotalBrowse
SourceDetectionScannerLabelLink
http://go.mic0%URL Reputationsafe
http://go.mic0%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
bg.microsoft.map.fastly.net
199.232.210.172
truefalseunknown
NameSourceMaliciousAntivirus DetectionReputation
http://go.micSetup.exe, 00000001.00000003.1674388120.00000000005BF000.00000004.00000020.00020000.00000000.sdmp, Setup.exe, 00000001.00000003.1674301361.00000000005B7000.00000004.00000020.00020000.00000000.sdmpfalse
  • URL Reputation: safe
  • URL Reputation: safe
unknown
No contacted IP infos
Joe Sandbox version:40.0.0 Tourmaline
Analysis ID:1431611
Start date and time:2024-04-25 14:25:42 +02:00
Joe Sandbox product:CloudBasic
Overall analysis duration:0h 8m 42s
Hypervisor based Inspection enabled:false
Report type:full
Cookbook file name:default.jbs
Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
Number of analysed new started processes analysed:18
Number of new started drivers analysed:0
Number of existing processes analysed:0
Number of existing drivers analysed:0
Number of injected processes analysed:0
Technologies:
  • EGA enabled
  • AMSI enabled
Analysis Mode:default
Analysis stop reason:Timeout
Sample name:ndp48-web.exe
Detection:CLEAN
Classification:clean3.winEXE@14/132@0/0
Cookbook Comments:
  • Found application associated with file extension: .exe
  • Override analysis time to 240000 for current running targets taking high CPU consumption
  • Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe
  • Excluded IPs from analysis (whitelisted): 52.109.0.91, 52.109.8.36, 52.113.194.132, 23.54.200.130, 199.232.210.172, 23.201.212.130
  • Excluded domains from analysis (whitelisted): slscr.update.microsoft.com, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, ecs-office.s-0005.s-msedge.net, roaming.officeapps.live.com, osiprod-cus-buff-azsc-000.centralus.cloudapp.azure.com, ocsp.digicert.com, login.live.com, e16604.g.akamaiedge.net, wus-azsc-config.officeapps.live.com, officeclient.microsoft.com, prod.fs.microsoft.com.akadns.net, ecs.office.com, fs.microsoft.com, prod.configsvc1.live.com.akadns.net, ctldl.windowsupdate.com, prod.roaming1.live.com.akadns.net, s-0005-office.config.skype.com, wu-bg-shim.trafficmanager.net, cus-azsc-000.roaming.officeapps.live.com, fe3cr.delivery.mp.microsoft.com, us1.roaming1.live.com.akadns.net, s-0005.s-msedge.net, config.officeapps.live.com, us.configsvc1.live.com.akadns.net, ecs.office.trafficmanager.net
  • Not all processes where analyzed, report is missing behavior information
  • Report size exceeded maximum capacity and may have missing behavior information.
  • Report size getting too big, too many NtOpenKeyEx calls found.
  • Report size getting too big, too many NtProtectVirtualMemory calls found.
  • Report size getting too big, too many NtQueryAttributesFile calls found.
  • Report size getting too big, too many NtQueryValueKey calls found.
TimeTypeDescription
14:26:39API Interceptor12438022x Sleep call for process: splwow64.exe modified
No context
MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
bg.microsoft.map.fastly.nethttps://1drv.ms/o/s!AmFI0faGJpjZhESzK-ltQ-Z_UHmf?e=0OfhLSGet hashmaliciousUnknownBrowse
  • 199.232.214.172
http://ipscanadvsf.comGet hashmaliciousUnknownBrowse
  • 199.232.214.172
https://www.canva.com/design/DAGDNh45X_4/PPCLYIV4Y8uUaoEW7ZJrJQ/view?utm_content=DAGDNh45X_4&utm_campaign=designshare&utm_medium=link&utm_source=editorGet hashmaliciousUnknownBrowse
  • 199.232.214.172
R0hb7jyBcv.exeGet hashmaliciousMars Stealer, PureLog Stealer, RedLine, SectopRAT, Stealc, Vidar, zgRATBrowse
  • 199.232.210.172
https://bind.bestresulttostart.com/scripts/statistics.js?s=7.8.2Get hashmaliciousUnknownBrowse
  • 199.232.214.172
SaturdayNight.exeGet hashmaliciousUnknownBrowse
  • 199.232.210.172
FTG_PD_04024024001.vbsGet hashmaliciousFormBook, GuLoaderBrowse
  • 199.232.214.172
SWIFT.exeGet hashmaliciousAgentTesla, PureLog StealerBrowse
  • 199.232.210.172
https://docs.google.com/presentation/d/e/2PACX-1vRA7cYu2pjKyfaCRROgTu4J2OpPGWE_raEqtGhCVl21QDvJzZsVPQtIU_FG6khcCjqxbwzOTOoBBBx6/pub?start=false&loop=false&delayms=3000&slide=id.pGet hashmaliciousUnknownBrowse
  • 199.232.214.172
page97.exeGet hashmaliciousLonePageBrowse
  • 199.232.210.172
No context
No context
No context
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (433), with CRLF line terminators
Category:dropped
Size (bytes):82394
Entropy (8bit):4.113900576434787
Encrypted:false
SSDEEP:384:4YPMFNhaVwV/VLVWPD66KUtycONAkwtj7l/XeqyEnmM7cBp9stCctFnDRydTJleD:XlxcdGUTJleYi
MD5:D8165BEB3B8433921D0D5611B85BFA35
SHA1:BEF57E3511E18170EBBC9AE3AEFD73CE3F50F8F4
SHA-256:B092668E0825F7F498ACDC1BF10E1D2CB6CA99497389142CF9AF815F25A4B712
SHA-512:9FA221F549B4E660C4F40C7AB0E483E3D9A9204248DA51675058F32F4F56667C782667295DECBB441A581F582A099FE34C6CC569D0C4EC13E85C680ABF5870B0
Malicious:false
Reputation:moderate, very likely benign file
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24440
Entropy (8bit):5.567810124820384
Encrypted:false
SSDEEP:384:VOyQGB2GQlfJnpSwBWoeWJWNeW1D/HRN7WtImlGJS:VRbQHhc1Dv6
MD5:51AD58DF739F0C0D005FE36B1350A6A3
SHA1:25069B754778651E70E1FB1BCEBE04575361104F
SHA-256:E1CF3D22AA1DC94E58DD946D319D9D8AFC8B6BBA80EF3CA7575185B8F3CE435A
SHA-512:B6E314B1987D06ADA1402B7DF068F257FDDBB767E9D73CBAC8845E2B338FF7709C8C4F33E97E32609C93A8268DB071FDB2AF96E7B87E1708633B74DE4188D441
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Reputation:moderate, very likely benign file
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........6............... ............................................@E.........................................@.../...........<..x#...p..........T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc..../...@...0..................@..@.reloc.......p.......:..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):13401
Entropy (8bit):4.012930636368038
Encrypted:false
SSDEEP:384:U3dyzhC8tePMiBhBMU50ysaaLah+Ks+g2:2qCTBhS3ysaaVKs+n
MD5:13431FD86B4023B8E11695360B22169C
SHA1:AF4F361DE88D390B27E8B6169AEF2C05FD6C2E00
SHA-256:AABCCC5B9E9FB2A2759C634CD94B8B5808BF9D32A46014C2F01E245405B84FEA
SHA-512:D5551965C051A4BB7F9DEC66D77CB3BEC386A82F44E9DC5A8CCC197EE15193F646DD741DA6612157FE4AE523DDAE9505A2FBD551B7521217710E9DAF71627D58
Malicious:false
Reputation:moderate, very likely benign file
Preview:{\rtf1\fbidis\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset178 Tahoma;}{\f1\fnil\fcharset0 Tahoma;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\rtlpar\sb120\sa120\sl240\slmult1\qr\b\f0\rtlch\fs20\lang2052\'d4\'d1\'e6\'d8 \'ca\'d1\'ce\'ed\'d5 \'c8\'d1\'c7\'e3\'cc\f1\ltrch MICROSOFT \f0\rtlch\'c7\'e1\'c5\'d6\'c7\'dd\'ed\'c9\par...\f1\ltrch NET FRAMEWORK\f0\rtlch \'e6\'cd\'d2\'e3 \'c7\'e1\'e1\'db\'c9 \'c7\'e1\'e3\'de\'ca\'d1\'e4\'c9 \'e1\'e4\'d9\'c7\'e3 \'c7\'e1\'ca\'d4\'db\'ed\'e1 \f1\ltrch MICROSOFT WINDOWS\f0\rtlch\par..\b0 \'ca\'de\'e6\'e3 \'d4\'d1\'df\'c9 \f1\ltrch Microsoft Corporation\f0\rtlch (\'c3\'e6 \'c5\'cd\'cf\'ec \'c7\'e1\'d4\'d1\'df\'c7\'ca \'c7\'e1\'ca\'c7\'c8\'da\'c9 \'e1\'e5\'c7 \'e6\'c7\'e1\'ca\'ed \'ed\'ca\'e3 \'ca\'cd\'cf\'ed\'cf\'e5\'c7 \'c8\'e4\'c7\'c1\'f0 \'da\'e1\'ec \'e3\'cd\'e1 \'c5\'de\'c7\'e3\'ca\'df) \'c8\'ca\'d1\'ce\'ed\'d5 \'e5\'d0\'c7 \'c7\'e1\'c8\'
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):70962
Entropy (8bit):4.147064693337759
Encrypted:false
SSDEEP:384:4YggFNhaVwV/VLV33zqjKUtycONAkrNsc2XcbacaQJETJ9bCHwx+DR+USWV/K1ND:+X7UysBSWV/K1+gwJg5H
MD5:F3A4FD6968658A18882CF300553F2F89
SHA1:B75CCAEFF41BF9C8586BCA612550CB9DCA6B09EA
SHA-256:53742293B25149B19D8677B15F6424FC71E308014B1BCF883E6949D1DAB3961C
SHA-512:9692C8577034C0E628A42D581F634ED174B4AF684EE87C947556888027215BBF4C92286A3AD1CB1792FC6F7392190719EBEF85B60FCE48E20239ABCB58D04D97
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):21368
Entropy (8bit):5.857562629697412
Encrypted:false
SSDEEP:384:U+YQxeOUkzS6cDn+8sRzWMEWDWNEWAD/HRN7Mjhl2H:UkeaW6FH3c+DvR
MD5:751EFB8A557EC3DF620A1D3D91FC7E8E
SHA1:4A82263312FC2343A55DBDB9935798BA8E31562E
SHA-256:1CE28FD9898191BD6B0DABBA472FBEA5E679F588F4DEB9DDD1755198F2919666
SHA-512:11753011A5C3AAC0F55765B95C375459E9E4117098EF150D5DAB07F7BF1E85F41FE0D763423A4400FC3707084488C8ED611CD0361BA5F5DF417F11CD271947D1
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........*............... .......................................S....@E.........................................@..D"...........0..x#...p..........T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...D"...@...$..................@..@.reloc.......p......................@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):12092
Entropy (8bit):4.336066103277271
Encrypted:false
SSDEEP:192:gINwQt7s0nc3eUIE/xR8j3uUZzWhgqwNmPD84okslotkOo0olQcpPzcXokPw1sdu:YQt7vc1Xy2ZJsiEBs52
MD5:4FE2BD1C6AB9896DB6FEC42A00B6BB67
SHA1:7B3278A6B0BF6961230399EA94DDA7FB1CC3D596
SHA-256:4DB6D43C560CCC02D0ADB570D4675223286D7B1949FAC1C5A16FFD1C8835A814
SHA-512:D3DFA73B58A7FCCF2165D022008AF3E28CB6D6FF6068731F8BC40419EE4B5B96DA7C53E314B56B48231F7FEDB8D6090C0F0B417DC791B44CC409F0DB63D510FE
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Times New Roman;}{\f1\fnil\fcharset134 SimSun;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 MICROSOFT \f1\'dc\'9b\'f3\'77\'d4\'f6\'d1\'61\'ca\'da\'99\'e0\'97\'6c\'bf\'ee\f0\lang1033\par..\lang2052 MICROSOFT WINDOWS \f1\'d7\'f7\'98\'49\'cf\'b5\'bd\'79\'b5\'c4\f0\lang1033 .NET FRAMEWORK \f1\'bc\'b0\'cf\'e0\'ea\'50\'d5\'5a\'d1\'d4\'cc\'d7\'bc\'fe\cf1\f0 \cf0\par..\b0\lang2052 Microsoft Corporation (\f1\'bb\'f2\'c6\'e4\'ea\'50\'82\'53\'c6\'f3\'98\'49\'a3\'ac\'d2\'95\'d9\'46\'d3\'c3\'91\'f4\'cb\'f9\'be\'d3\'d7\'a1\'b5\'c4\'b5\'d8\'fc\'63\'b6\'f8\'b6\'a8\f0\lang1033 ) \f1\'ca\'da\'99\'e0\'d9\'46\'d3\'c3\'91\'f4\'ca\'b9\'d3\'c3\'b1\'be\'d4\'f6\'d1\'61\'b3\'cc\'ca\'bd\'a1\'a3\'c8\'e7\'b9\'fb\'d9\'46\'d3\'c3\'91\'f4\'c8\'a1\'b5\'c3\f0 Microsoft Windows \f1\'d7\'f7\'
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (447), with CRLF line terminators
Category:dropped
Size (bytes):88026
Entropy (8bit):3.694845204319811
Encrypted:false
SSDEEP:384:4YQWbTP0qTvLSGf6KUtycONAkkMo+snsMsBTKTuTyTfQjkj/svHov+yJKe3dJTZT:x2LTwiJUQ
MD5:D6801174849373CDE3F1D214D80FE834
SHA1:50CAF47AA60B999CA7B43D3CEB75D0DBFFD2278A
SHA-256:CBB0DA2D1EFA7DE6736E67C978848D53ACF8B502BF3DAF43CE40B05076145A7C
SHA-512:A4CF812DC4FAC888DAD4CA986FCB07B93F45633FE5931F24AFFF4558D9A29734A0AC5D647F3BC631C377FBA816C19BD44178398BB6166F6F84E5F05ACB8E0A18
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25992
Entropy (8bit):5.304057123496457
Encrypted:false
SSDEEP:384:RY/pQUP8UtF/eQHHsUpfhxPh1KurWpAeWtWpdeWFD/HRN7RsjlGshKH:RDUxRqFDvR9
MD5:0324FBF9214800146690EEEDDE905C30
SHA1:81D204D02DA04854884E47A99C8B8D468AFA154B
SHA-256:22629C2BC84EE599C827825F84E47819BED1157BCEDEA11DDE0A854A4DE68DD1
SHA-512:78227848D1B722F35A0ABB2E788FECBCC5E41DD0D1C43386A529B79639EE32D129750E983D55D316AD9BC2833D1B9C5EE791BB9C11913839C3EAB8F9234A216C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... ......................................Q.....@E.........................................@...4...........B...#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....4...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):7930
Entropy (8bit):5.089689973221789
Encrypted:false
SSDEEP:192:h4SuzEDL7OFCPmypzj2MujquNs6t2fdCq8fy97OspIRgCOGzlQlmaZwZ4hgtE2:Fuzs7PGRt1UNWlAlWHtE2
MD5:E0EEC490F52FE2AB10B75E354ABFFC87
SHA1:CDCEA1632D1B42A08CE15919F0492CB35BA749ED
SHA-256:03E8EDE8A900D1E25414A5767980F8C2715B53D29CBFC40CE1B42075B175B0E1
SHA-512:127DCE385F8351A17D94086432B20DD6B2137CA4E9B1524827AE396BA81A1781E972A1729E9689BA688A4D308F398776BEEEBF72C0C29EB659C09EC9AD23B4F0
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset238 Tahoma;}{\f2\fnil Tahoma;}{\f3\fnil\fcharset0 Calibri;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 DODATKOV\'c9 LICEN\f1\'c8\f0\lang1033 N\'cd PODM\'cdNKY PRO SOFTWARE SPOLE\f1\'c8\f0 NOSTI MICROSOFT\par..\lang2052 .NET FRAMEWORK A\~P\f1\'d8\f0\lang1033 IDRU\f1\'8eEN\f0\'c9 JAZYKOV\'c9 SADY PRO OPERA\f1\'c8N\f0\'cd SYST\'c9M WINDOWS SPOLE\f1\'c8NOSTI MICROSOFT\cf1 \cf0\par..\b0\f0\lang2052 Licenci na tento dodatek v\'e1m poskytuje spole\f1\'e8\f0\lang1033 nost Microsoft Corporation (nebo jedna z\~jej\'edch afilac\'ed v\~z\'e1vislosti na tom, kde bydl\'edte). M\'e1te-li licenci k\~u\f1\'9e\f0\'edv\'e1n\'ed softwaru opera\f1\'e8n\f0\'edho syst\'e9mu Microsoft Windows (d\'e1le jen \f2\'84\f0 software\ldblquote ), sm\'edte tento dop
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (418), with CRLF line terminators
Category:dropped
Size (bytes):85600
Entropy (8bit):3.5900825904686604
Encrypted:false
SSDEEP:384:4Y4UFNhaVwV/VLVWPD66KUtycONAk9iqz3b4VYgkZAEbZfURtzBSmRLAgRQJYR2X:fgkZptSvJcR
MD5:03B1E582EC5454B2FA3599E788569DFA
SHA1:75845ACDD04FB17011218B06FD7C28830641F021
SHA-256:59884541554376A26143B105FA924B9F9961254D22DB8DEDF7DE7F3495D7A1DD
SHA-512:23D1B1C2E2C78692A48B959BDB70C3C321A76792885B19805CAFD543C0EF25856F8F115AF766EA46F20EB2C440EAF31E656726710B12AE5F362779BEA28035BC
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25464
Entropy (8bit):5.219994928447778
Encrypted:false
SSDEEP:384:t+5QCj/McAp5IOOWpSfeWRWpFfeW9D/HRN7WVFImlGJH:tSj1Na9Dvt
MD5:69CE7A41E23625A55819AD9BBCD45336
SHA1:86E9766E606D8DFEDA61A4100517CDC16F1084F0
SHA-256:CFC1AC54D49CBCC43045484B6FC775E6FA3B063DA5D9B2A96606990309780384
SHA-512:F2632D1ED8A94E5A6DCE9EEACECE6AAF13F20B96298A3C8DD3707A780A50185CE41BAA562093668503C5AB21498195CFA96897B40EEE1F85450490FCF272D66B
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........:............... .......................................R....@E.........................................@...3...........@..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....3...@...4..................@..@.reloc...............>..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):5814
Entropy (8bit):5.141288601487191
Encrypted:false
SSDEEP:96:MFutTWDeTJBPLzWTcuC56hPt7ye6BY4fj80xYnNvbYv5YRcnFGmNWIOpxFEibrmi:GSFBPLzWTcuC56hV7ye6HjvxCu5dG4ar
MD5:DCD287A517A6DD7A011B584FD5660811
SHA1:249318666D6A3D0903F00C954DD1309AA6A59859
SHA-256:271152060662CCCEB3D2F6EDCAEAA9E003391975AADC6DD6B26648B8A084DBE1
SHA-512:0DBBBF53B3F440F5732B102F1108EACF8315C2BA128C54E39B2B4A251D5E01BE51CEC9CCCA0F0FF59EF3EEFF2B82C1DA395E3A6B4DF05AA4F6CF7B2486402AE5
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 LICENSVILK\'c5R FOR MICROSOFT-SOFTWARETILL\'c6G\par...NET FRAMEWORK OG TILKNYTTEDE SPROGPAKKER TIL MICROSOFT WINDOWS-OPERATIVSYSTEMET\cf1 \cf0\par..\b0 Microsoft Corporation (eller, afh\'e6ngigt af hvor De bor, et af dets associerede virksomheder) licenserer dette till\'e6g til Dem. Hvis De har licens til at bruge Microsoft Windows-operativsystemsoftware (\ldblquote softwaren\rdblquote ), m\'e5 De anvende dette till\'e6g. De m\'e5 ikke bruge dette till\'e6g, hvis De ikke har licens til softwaren. De m\'e5 bruge dette till\'e6g sammen med hver gyldigt licenseret kopi af softwaren.\par..De f\'f8lgende licensvilk\'e5r beskriver yderligere vilk\'e5r for dette till\'e6g. Disse vilk\'
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (509), with CRLF line terminators
Category:dropped
Size (bytes):90342
Entropy (8bit):3.5994311724016628
Encrypted:false
SSDEEP:384:4Yw+ld52odZWPD66KUtycONAkXWc16MsyBABwPlPHCUBjp4RbcNU8oO0GAJGntzI:ga6UBABwPlPxY6VC7u3pg010Jsz/ziX
MD5:AFB4B1D7103DDCA43EA723ACBCDD31FD
SHA1:C4D95DFD4869DF636091E979C8B3BD7684004A48
SHA-256:961EFE11E9E3E553269CB14DC1B942E9AC68B86740D59AA35E4FF6E5913532DD
SHA-512:BDE563D158E38F7A46ABE564E365BBC9CFA235F4735F668A532919F0575BEAD27BDD6FA11AC50802C989F2F69371C2E9179C9AFFBC85954A9B4050F9122E26A5
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):26488
Entropy (8bit):5.19144350597098
Encrypted:false
SSDEEP:384:JdqQkKrhmsfWrpdkKQNSlvYVAtWtieWZWCieWHD/HRN7WLImlGJilAi:JjhmEcdXlvYVAVUHDvAT
MD5:62431931C0E7AEF5A55F831FD897C193
SHA1:8E76BA228BB72DED1F6D04CE9BA7634A0567BD33
SHA-256:7ED80F565427EEB1A0DB93EE5D2691D4BC7EA6DAEAE881FCABA21423510866CA
SHA-512:778B38C48695614A8B23FF84684C5032A50FFB60E9D625179D6AEE6EA10FA2919A0A40B11F7AE516C070DCFC8751232C593FE8C8FB696B189A85DD48A25342EA
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........>............... ............................................@E.........................................@...6...........D..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....6...@...8..................@..@.reloc...............B..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):6346
Entropy (8bit):5.194395199629307
Encrypted:false
SSDEEP:96:MtAqBQTZDyiRcm6KFaZxb4QFUdXHDjAZmOr3IRjPQPtSzb+5XpXGEJs4LQ9my2WW:+AIWoKFaZFLFUFHDjwmRIQHm1ZWeWH2
MD5:940967914EA121AAF09B119E37206A38
SHA1:7AB2B55EBE42C242DBBE8F1821C138F52843793E
SHA-256:992280EEA0CB8CD63878356A350801632A63CA669C1720F361FF2922243E701A
SHA-512:FD5527672BC9ABDC222F0EA1C76B13DED3BFACF7B253554F8269BB793BFAEA83083EFE5FA693F369267E97E029BE98B78ED49F9D5178C0C496C2DAD3D7A04C09
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil Tahoma;}{\f2\fnil\fcharset0 Calibri;}{\f3\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 ERG\'c4NZENDE LIZENZBESTIMMUNGEN F\'dcR MICROSOFT-SOFTWARE\par...NET FRAMEWORK UND ZGEH\'d6RIGE SPRACHPAKETE F\'dcR MICROSOFT WINDOWS-BETRIEBSSYSTEM\cf1 \cf0\par..\b0 Microsoft Corporation (oder eine andere Microsoft-Konzerngesellschaft, wenn diese an dem Ort, an dem Sie leben, die Software lizenziert) lizenziert diese Softwareerg\'e4nzung an Sie. Falls Sie eine Lizenz f\'fcr die Microsoft Windows-Betriebssystemsoftware (\f1\'84\f0 Software\f1\ldblquote\f0 ) besitzen, sind Sie berechtigt, diese Erg\lang1033\'e4nzung zu nutzen. Sie sind nicht berechtigt, sie zu verwenden, wenn Sie keine Lizenz f\'fcr die Software haben. Sie sind berechtigt, diese Softwareerg\'e4
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (565), with CRLF line terminators
Category:dropped
Size (bytes):92532
Entropy (8bit):4.323396785012504
Encrypted:false
SSDEEP:384:4Y7yvnT86nzWPD66KUtycONAkY+LoYRONOVA8HTiVEsmXadUkec00CfMMHlRcyvN:MqPQyZ0J7
MD5:71BDB323A746A4ADAB9CE42498E937BC
SHA1:8E58D4BA5623A50610BD99E82DF135708A9F130E
SHA-256:6C5A6E11A85C9E172E7748A9A9F19F8598870A63A103A7AC18CBBD0CDF026475
SHA-512:B7D66FA4F1A1B7130CDD801447FE0C4965CBA1618C01D4FF64B9707E3E132FB13858AA498EA26FB1E54B56DAF83E5E7958C6A4FCC1A4AD6DD6C2FFA966E58B76
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):27000
Entropy (8bit):5.611940130845044
Encrypted:false
SSDEEP:384:8TnQJphGfM2piLLsFXrEqRr1t5UZ4/s3JRDW+BeWxWrBeW5D/HRN7WRImlGJid:8YXGk2pDZ64kL7A5Dv8
MD5:D30B31E0C9C97061A8E07DCB56B4C199
SHA1:B48B248757C869C1186F6BF4EA3470A1E06C2222
SHA-256:D3DBEA64652620E74B73A67A63BE36085BFCA863A991B3022E322B6AC4D2347C
SHA-512:DEBA7BC3E680B85D19C8C6EBAAACFA390780781A71B152A2BE8FD89F54EF3AE0B65C34EACD4954BF62923BF8A0A3CBF4073F6535C15D25AF2A86FEEB76C00D20
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........@............... .......................................n....@E.........................................@...9...........F..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....9...@...:..................@..@.reloc...............D..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):16781
Entropy (8bit):3.801896227892115
Encrypted:false
SSDEEP:192:b2VVYIKIE5CC2c6UKfKWcNrjXX+EUtrlAUD55C+DEE6Wvhubi5pY92:q6UE5CC2/VYhir6q8p92
MD5:E9A32E66AF5386F4EC50D6F822E57145
SHA1:1798F05F60D087CAE4871D3F0DF99B2F121014F7
SHA-256:83D0876B44402760C3D31E58022AC84376CB9364F7E73984C8CADC9F18BA725C
SHA-512:EDF5AC378E8293A5F0A2ABD02208EB5C094FA997F67C20D746329E971FCADCB8C863191C50C27C5641C22ED1A9CF21C744BD2B9121E1D568DE7013CFB752E0DE
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset161 Tahoma;}{\f1\fnil\fcharset0 Tahoma;}{\f2\fnil\fcharset0 Calibri;}{\f3\fnil\fcharset161 Calibri;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052\'d3\'d5\'cc\'d0\'cb\'c7\'d1\'d9\'cc\'c1\'d4\'c9\'ca\'cf\'c9\f1\lang1033 \f0\lang1032\'cf\'d1\'cf\'c9\f1\lang1033 \f0\lang1032\'c1\'c4\'c5\'c9\'c1\'d3\f1\lang1033 \f0\lang1032\'d7\'d1\'c7\'d3\'c7\'d3\f1\lang1033 \f0\lang1032\'cb\'cf\'c3\'c9\'d3\'cc\'c9\'ca\'cf\'d5\f1\lang1033 \f0\lang1032\'d4\'c7\'d3\f1\lang1033 MICROSOFT\par..\lang2052 .NET FRAMEWORK \f0\'ca\'c1\'c9 \'d3\'d5\'cd\'c1\'d6\'c7 \'d0\'c1\'ca\'c5\'d4\'c1 \'c3\'cb\'d9\'d3\'d3\'d9\'cd \'c3\'c9\'c1 \'d4\'cf \'cb\'c5\'c9\'d4\'cf\'d5\'d1\'c3\'c9\'ca\'cf \'d3\'d5\'d3\'d4\'c7\'cc\'c1 MICROSOFT WINDOWS\cf1 \cf0\par..\b0\'c7 Microsoft Corporation (\'de, \'e1\'e
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (412), with CRLF line terminators
Category:dropped
Size (bytes):85180
Entropy (8bit):3.574274968616744
Encrypted:false
SSDEEP:384:4gS89tJKVQVfVjV2vjaCS89aEetgcsFTeyfg8NqJpR+enRROu5aeJInO/yJakC62:YeyfJqyJiT
MD5:47703BED025228689A1032EDAE56B4C4
SHA1:A2ABA33C7E8915025251574C81FE2E5AC6BC0893
SHA-256:05FC9352B918A710D51F68873FC522528265455B77014E8B0CD66C5E7AA71DC3
SHA-512:9D6EDA9FC3BE6116371D1B86B54B8B65CCD58C182105E0954870F75E2A6F4D7E8FC84462BFD3584175C0F849066E47D82CD18AE3BF1671E60CC237347B7CC00D
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t.". ./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k.". ./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k.". ./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24440
Entropy (8bit):5.235826870516069
Encrypted:false
SSDEEP:384:zt+QGZnU+9E2/yV/k6WpBeW9WpceWSD/HRN7EJhl2Z:z0Znvl/GejSDv9
MD5:3F975E8BB4CD4ADB9B5D21B2DA436AB6
SHA1:E017DD66CBD964228B3B9B84B14C892709FE3915
SHA-256:AB1D462944FDCB4AD2E6A4D37257F2FE2063744BB4E3DE55B4126DFB65D383FC
SHA-512:F99359F9118409FE7CBDC4390A48F2F661D7E1622B08AF75080E036400E1A3DAE118D92848E54A24168EB8B27E69D51A920BB26511C466868AFB42257B3EA048
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........6............... .......................................Z....@E.........................................@.../...........<..x#...p..........T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc..../...@...0..................@..@.reloc.......p.......:..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):4965
Entropy (8bit):5.100217952286715
Encrypted:false
SSDEEP:96:MC7BLEcTk6NDZSftJpn0WfoW6USPRl0D6R2jdmNt1Oc/fTp3hk0ifCmIbOEQCcQr:F+j6ToLp0WfkUSPRl0D42jITTpxOIbOu
MD5:47C47A12E6830B793150494D35D51637
SHA1:87A11FECE572F2A57982270533D6906DAF7DA218
SHA-256:4399B24E28BECFB3BB2820DAA09965860001492145FD7E2466DA7B740C31855D
SHA-512:1B85FF8F11AFAFAA7368E744D281D964313EB342D294CBBE0E1C5FAB3C5E817CA2B58BBCD7FC87A556F7575FD8E9D7404EB0A4F8E045E4C446BA83398EAB3127
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033\deflangfe1033{\fonttbl{\f0\fswiss\fprq2\fcharset0 Tahoma;}{\f1\froman\fprq2\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}{\*\mmathPr\mdispDef1\mwrapIndent1440 }\viewkind4\uc1 ..\pard\nowidctlpar\sb120\sa120\b\f0\fs20 MICROSOFT SOFTWARE SUPPLEMENTAL LICENSE TERMS\par....\pard\brdrb\brdrs\brdrw10\brsp20 \nowidctlpar\sb120\sa120 .NET FRAMEWORK AND ASSOCIATED LANGUAGE PACKS FOR MICROSOFT WINDOWS OPERATING SYSTEM\cf1 \cf0\par....\pard\nowidctlpar\sb120\sa120\b0 Microsoft Corporation (or based on where you live, one of its affiliates) licenses this supplement to you. If you are licensed to use Microsoft Windows operating system software (the \ldblquote software\rdblquote ), you may use this supplement. You may not use it if you do not have a license for the software. You may use this supplement with each validly licensed copy of the software.\par..The following license
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (450), with CRLF line terminators
Category:dropped
Size (bytes):86088
Entropy (8bit):3.6015669315324033
Encrypted:false
SSDEEP:384:4Ys04sUwpVbVkV4VbiO/6KUtyc6BM47+QqOYeBzW/jzKdm4Ne4Bti4l59R8fOaJt:Fr/lOfOaJ+Q
MD5:AD67691B3B5474154F65400E53DDFEF2
SHA1:DC8DC683BF9FEE12A5AB7297789A5C087E98FACC
SHA-256:1E828840AE8728AC809624845597406D4025D6DA7797B38F02946A30A48BFE7C
SHA-512:64EE113F0C3E173FEE6047CC41FF3E84181ABA2EB2B02CA5CC717CAAF1392E5E2F0EED7E7C469D821D86878443BC8EC64C66E2AFB1D850FB4C7E9823C3A5EA73
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25976
Entropy (8bit):5.226400462305246
Encrypted:false
SSDEEP:384:gWTQf1iZlLX8TIgAWMxeW8WM8eW7D/HRN7W5lAtXY:gl1clb8cj37DvI
MD5:DAEC777035B964E1C36E5C54420E7153
SHA1:1D0AD100D2DAB9929251C3CDFCCFD822968259BB
SHA-256:5D0AEF595C1D4B3DC658C809F8F0540DC7F689CD03FCBFC566737EA2BF360E47
SHA-512:F44682E253AC804F2F4D7F93DE6011762E9B6A788796E75BC6AC5C63D19D184CD00CE446C0157E7692827B308E6B0179BD79FE5D953E373FC0C97F03381979A2
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... ............................................@E.........................................@..h4...........B..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...h4...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):6581
Entropy (8bit):5.102650854402578
Encrypted:false
SSDEEP:192:GhZAXGy57Uh3loxqOsUcCEQmuUGsZes3+Db2:b57pqxVefb2
MD5:42A6665773E6F9F5E9F6AE725C73565D
SHA1:CC9D27AEC7FF248AA470646F43CDA329A836D598
SHA-256:CE98922719450764D7B2D8778DB5A267BF244B39599BB9699E9C15742E15BAA2
SHA-512:50744591E5D2449B9C3101833E6809A9CC33FD3ECA97A94498B3B2F6ED10BBBD001D4EB375E98BC1ACBD9A9FC155A179F130CAEDE02D193D5CFBABE738944814
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 MICROSOFT-OHJELMISTON T\'c4YDENNYSOSAN K\'c4YTT\'d6OIKEUSSOPIMUKSEN EHDOT\par...NET FRAMEWORK JA SIIHEN LIITTYV\'c4T KIELIPAKETIT MICROSOFT-K\'c4YTT\'d6J\'c4RJESTELM\'c4LLE\cf1 \cf0\par..\b0 Microsoft Corporation (tai asiakkaan asuinpaikan mukaisesti m\'e4\'e4r\'e4ytyv\'e4 Microsoft Corporationin konserniyhti\'f6) my\'f6nt\'e4\'e4 asiakkaalle t\'e4m\'e4n t\'e4ydennysosan k\'e4ytt\'f6oikeudet. Jos asiakkaalla on Microsoft Windows -k\'e4ytt\'f6j\'e4rjestelm\'e4ohjelmiston (\rdblquote ohjelmisto\rdblquote ) k\'e4ytt\'f6oikeudet, asiakas saa k\'e4ytt\'e4\'e4 t\'e4t\'e4 t\'e4ydennysosaa. Asiakas ei saa k\'e4ytt\'e4\'e4 t\'e4ydennysosaa, jos asiakkaalla ei ole ohjelmiston k\'e4ytt\'f6
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (466), with CRLF line terminators
Category:dropped
Size (bytes):89940
Entropy (8bit):3.585212518252936
Encrypted:false
SSDEEP:384:4YgEF9xWQ9RWPD66KUtycsmIPKCoEVDpFqpRatkxOGv1Gj8VjfRiLYcRryQMuvtR:V+skau8tbxhJNP/J
MD5:2C77CBAAF9C3ED0C4410C4B8C3C29C30
SHA1:110775CA1C6E252B4E8C8BF39B593DFB4D66206C
SHA-256:AB3D5571B57B7BB705BFFE13F37BD73894B0D12D09CC1FB1B438493A863C324C
SHA-512:C1438B9B95BD16503F5A14D743E9C6C40CB46CD24A4BB48ADF6F9162C61E8979C370E7E1EFF8989DB05FF5A496415A68B58CC16912A7C8215FECB72D252C5285
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):26488
Entropy (8bit):5.161097398212539
Encrypted:false
SSDEEP:384:QgmUQFGlMcGyXyGidxkbVWp1eWOWpIeWkD/HRN7tHhl2r:QgKGlVXodiKCkDvE
MD5:EBF7672BFE808CA0602D25FB6A5FA115
SHA1:8A3F92679B87D919260C3B74C27E790A301BB25B
SHA-256:DA4151C2A7DA521F5CDBCE42F3C03A2DE90A49E0AEE82DF5F75211310C3743AE
SHA-512:8AD4B9C8BB3DF55DBA0728C0E29F5162B9C97C9727C0828C094500FD02749B0D5D0BA21C06244F6369290DE18347B4081B02DD25B184FF98B6591B16A36F3C68
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........>............... ...........................................@E.........................................@..<7...........D..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...<7...@...8..................@..@.reloc...............B..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):6871
Entropy (8bit):5.049438505532205
Encrypted:false
SSDEEP:192:GbPZMFJgktbR9fpILE2DFZjG9bGCwOE+f7JtZhR/hjlx22:6ufr9feE2Jc8OfJHhjlx22
MD5:291BC09E4E69CD56426B4E63848BD967
SHA1:5123736A141AE3DF1ACBA60A3F4C613DEBE7A3DB
SHA-256:93FEF896B04650014F4A869D853E030EE3B00CED642FED928141F29123AE8140
SHA-512:06C299098C9D09373776E699D9BE817B3F80A0BBED775CE32E80BCBDF11380EC86CBEE0C12FCFFA24539AED35C3010C094038195DEDAA2BD7A9937C48B4179B7
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 TERMES DE CONTRAT DE LICENCE D\rquote UN SUPPL\'c9MENT MICROSOFT\par...NET FRAMEWORK ET PACKS LINGUISTIQUES ASSOCI\'c9S POUR SYST\'c8ME D\rquote EXPLOITATION MICROSOFT WINDOWS\cf1 \cf0\par..\b0 Microsoft Corporation (ou, en fonction du lieu o\'f9 vous vivez, l\rquote un de ses affili\'e9s) vous accorde une licence pour ce suppl\'e9ment. Si vous \'eates titulaire d'une licence d\rquote utilisation du logiciel de syst\'e8me d\rquote exploitation Microsoft Windows (le \'ab\~logiciel\~\'bb), vous \'eates autoris\'e9 \'e0 utiliser ce suppl\'e9ment. Vous n\rquote\'eates pas autoris\'e9 \'e0 l\rquote utiliser si vous ne disposez pas d\rquote une licence sur le logiciel. Vous pouvez uti
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (368), with CRLF line terminators
Category:dropped
Size (bytes):80592
Entropy (8bit):4.150156255323879
Encrypted:false
SSDEEP:384:4YsEJquUMovngPMIzVK6ptI6AmtycsOlrAyA/AUkkzmhygwREQ0mFfGQdJjwvSJf:9V0tJjw5o
MD5:631011D665AD08220FE248D9F8A103BA
SHA1:652C56998D0E8BF0C43F136FD90C69728BB0E111
SHA-256:E9877973BEF23498B586A9CF03230FC45A9EA8A3F75DECFA062B03BD31974B06
SHA-512:CF479C0C5167E011721BD6B0F5829A62C0C269B1E1BE13E5BB750516B8441A1D8CA20FAFD0D539066F84D669F6F5E9401C223B82E200501716C719D268C3C1A0
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):23928
Entropy (8bit):5.675500986856461
Encrypted:false
SSDEEP:384:+9SQYURokAHfWueWkWneW+D/HRN7W5lAtXOCt:+OUYtZ+DvXt
MD5:B5DC9BDF9BC1EC4A3ECA070FAB6A3B68
SHA1:22DC867D4C6175B78A3F389EB0B16B57F13BF397
SHA-256:40A437A3B225EE79A82BC36304CFDAB4E7CD7455B3A15AEA6BAD1BD7E87AAE9B
SHA-512:0D38DD0E784031D9BFE6E4493D40853D37FE2DD40A7474EAF84887B4D1680A292AC324D5BE6800F79487C7191C61D6BE7EC45403BBCAA4ECF896EAE492ED89FB
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........4............... ......................................Jf....@E.........................................@...-...........:..x#...p..........T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....-...@......................@..@.reloc.......p.......8..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):12839
Entropy (8bit):4.3429046104268805
Encrypted:false
SSDEEP:192:S/vZcyZvTnDZV/4qqoIVleXyfK3V7RkZqV0vPVMVo+VfwWknBUR1VFdrVxV5VRV1:czVz4CNY+W2
MD5:1AA6E136CAEAE287EFF59D64281451FC
SHA1:57C5384003360E539CAD84F1B242A636CE399895
SHA-256:A90EB5E94F3A7CA6D30F849C47DD6C35B0599FE66AF50A29C029520B81B2B434
SHA-512:1A7B763A8FBDA2316F838F5E6034591E52ED0940676A57B562F698284EEF56E8A2AE54A2AEC70CDC28E20CF3C079F6AD3E2FFB7BAD27A38477DFB5E79003D8FA
Malicious:false
Preview:{\rtf1\fbidis\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset177 Tahoma;}{\f1\fnil\fcharset0 Tahoma;}{\f2\fnil Tahoma;}{\f3\fnil\fcharset2 Symbol;}}..{\colortbl ;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\rtlpar\sb120\sa120\sl240\slmult1\qr\b\f0\rtlch\fs20\lang2052\'fa\'f0\'e0\'e9 \'f8\'f9\'e9\'e5\'ef \'ee\'f9\'ec\'e9\'ee\'e9\'ed \'f2\'e1\'e5\'f8 \'fa\'e5\'eb\'f0\'fa\f1\ltrch MICROSOFT\f0\rtlch\par..\f2\ltrch\ltrmark\f1\lang1033 .NET FRAMEWORK\f0\rtlch\lang1037 \'e5\'f2\'f8\'eb\'e5\'fa \'f9\'f4\'e4 \'f7\'f9\'e5\'f8\'e5\'fa \'f2\'e1\'e5\'f8 \'ee\'f2\'f8\'eb\'fa \'e4\'e4\'f4\'f2\'ec\'e4 \f1\ltrch\lang1033 MICROSOFT WINDOWS\f0\rtlch\lang1037\par..\b0\lang2052 \f1\ltrch Microsoft\f0\rtlch \f1\ltrch Corporation\f0\rtlch (\'e0\'e5 \'e0\'e7\'fa \'ee\'e4\'e7\'e1\'f8\'e5\'fa \'e4\'ee\'f1\'e5\'f0\'f4\'e5\'fa \'e0\'ec\'e9\'e4, \'e1\'e4\'fa\'e0\'ed \'ec\'ee\'f7\'e5\'ed \'ee\'e2\'e5\'f8\'e9\'ea) \'ee\'f2\'f0\'e9\'f7\'e4 \'ec\'ea \'f
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (490), with CRLF line terminators
Category:dropped
Size (bytes):89028
Entropy (8bit):3.683231411966104
Encrypted:false
SSDEEP:1536:QZa/alahI0IwCIu4F70S9BIzEERIJH0rji3kC4ILiv:QZayIexCXF70S9BIzEERIJH0rji3kCle
MD5:28E8A2833F3D5302A1F5C2A84FA8990A
SHA1:08977251EB62C6DF447C6754B2EC27A73D9071F1
SHA-256:E4261C9B8C779D58883820A531A19594D238F0CA9ECAC399505C569B0CCCDBC7
SHA-512:4A62AFE84D4EB03BF2C65826B5765F270B3C9A3403B972BB00DB66CB40B70D1809334FC3A8EDF012C1EA31E4E3B8C6FED6423E9DA14DD62AD76A12D525E515B9
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T.-.k.e.r.e.t.r.e.n.d.s.z.e.r."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):26488
Entropy (8bit):5.235551204977301
Encrypted:false
SSDEEP:768:ZmC9zOH4wHCbfqkmV6EMCCJEVqZi0MC4lqsDv:R9vwHUfFmV6aCJEVn0MC4lqWv
MD5:150AD95506943E5720F82F21C332FA5C
SHA1:B02F177051570D3BFECC608317EFDD0ED6022E98
SHA-256:35AE5CC953DF1069BEAB0F0FD2A000C6F07F0361D9C7B7A20FD34C456D136B5E
SHA-512:95C2771D3A2A013DA1F1163A03442C0412E03C90F144A01792398760723AF559A6B09D3C55167771E2868F5A58C888F9C621F9EF3860575A84AF97E0AC987708
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........>............... ............................................@E.........................................@...6...........D..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....6...@...8..................@..@.reloc...............B..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):7518
Entropy (8bit):5.129711597079359
Encrypted:false
SSDEEP:192:h4gyZnFZRS9jLSyOxGmWmuzd0XHLvJMG7auy2:sZoh8WmuiSGOuy2
MD5:D1169D1DC40442766F68165855A3A1D2
SHA1:A1A817E8DDDAE958D944102A6076E07E3F326152
SHA-256:50A534D5B14C6BE2C9AB6D538C7BD201A82504D34FCA379D7C52C49CD127EFC6
SHA-512:9BD90DC015CF3C99DF5A570EB5959B701F9606A4966662BED5D9EA51D89C71B12031558CDD517944BE8052F69B769E1EAAC7CFEC6B77A2C2B350A38F08C87955
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset238 Tahoma;}{\f2\fnil Tahoma;}{\f3\fnil\fcharset0 Calibri;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 KIEG\'c9SZ\'cdT\f1\'d5\f0\lang1033 LICENCFELT\'c9TELEK MICROSOFT-SZOFTVERHEZ\par..\lang2052 .NET KERET \'c9S KAPCSOL\'d3D\'d3 NYELVCSOMAGOK A MICROSOFT WINDOWS OPER\'c1CI\'d3S RENDSZERHEZ\cf1 \cf0\par..\b0 E kieg\'e9sz\'edt\'e9s licenc\'e9t a Microsoft Corporation (vagy az \'d6n lakhelye alapj\'e1n annak egy t\'e1rsv\'e1llalata) ny\'fajtja \'d6nnek. Ha \'d6n rendelkezik licenccel a Microsoft Windows oper\'e1ci\'f3s rendszer (a tov\'e1bbiakban a \f2\'84\f0 szoftver\f2\rdblquote\f0 ) haszn\lang1033\'e1lat\'e1hoz, akkor \'d6n haszn\'e1lhatja ezt a kieg\'e9sz\'edt\'e9st. Ha nem rendelkezik licenccel a szoftverhez, akkor nem haszn\'e1l
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (465), with CRLF line terminators
Category:dropped
Size (bytes):87876
Entropy (8bit):3.5638877175430346
Encrypted:false
SSDEEP:384:4YmLGeyl/eSWPD66KUtycs9/wTBiG+Hg3XLCMa1eHzNZNs4fuD4RBJBo5U6sxuwv:C1aYtJGk
MD5:E74A35A00E0228DE37EE911F93411ED2
SHA1:C1C0901EB552C21CE2817B7EDB94AF611B571A49
SHA-256:2EC36FB871853F60085BC972E08156483384F8C1D6E000F5DB1CC8CCCAD05F8C
SHA-512:8876E39093448D1AE5A1F53499272323747789FBAEFDF9BD852FEE161FA9C18CE0721164473A5A2279643B34A2727D870E0B802635288F2E32B15C40660AD06F
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25976
Entropy (8bit):5.202817500822518
Encrypted:false
SSDEEP:384:SRiQ3gzAmbFxPcRJksWo5mWueW7WPeWvD/HRN7skOhl2:SHmbFx1SGYvDvs
MD5:002B3CDF42B65A6FC508FDA46C82502F
SHA1:A2858216EE2EAD168EF2A279E855ADE7787AB2BE
SHA-256:2F15225D2430C54788EA9A34DDC06AE609F25436B7BDB151C95316A09D3CE251
SHA-512:D97E720CA4D20A12EF6E3AB329D1B3C4EB2D049CCEAA127EE1016B4460B8F04595931EBBF712B23C1228C95A0935C7713F7B611CB65607C4751EB2A465A72C53
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... ............................................@E.........................................@...4...........B..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....4...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):6343
Entropy (8bit):5.053837504669121
Encrypted:false
SSDEEP:96:MF5XTpDwXwx3ZZhoBv489Y2HW3UvrYh32w9z0Jr7dQlQQciyY8mhKWEMHP7/Xj4K:G3ZDa94gBDcIRm7cpPkjjdBqmJk7jsk2
MD5:2FBA51E419F1A5272244DCA1BB6FA8D1
SHA1:A43ADED44A95078B8FFA74085D8424CAECC327CE
SHA-256:8374535E147AB71B9F149E74E77FCCF3282FFA9257565CD4AF6DB471C47E9231
SHA-512:6DF7CBA1AA1C34EF0A887F072A489EC5D535DAABDA96F85E055DE3EE75FFCED1FB470BAB5C86DAC8D68697F82884606398F21C02B55079AC6FBAF69FF3E847AE
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 CONDIZIONI DI LICENZA SUPPLEMENTARI PER IL SOFTWARE MICROSOFT\par...NET FRAMEWORK E LANGUAGE PACK ASSOCIATI PER IL SISTEMA OPERATIVO MICROSOFT WINDOWS\cf1 \cf0\par..\b0 Microsoft Corporation (o, in base al luogo di residenza del licenziatario, una delle sue consociate) concede in licenza al licenziatario il presente supplemento. Qualora il licenziatario sia autorizzato a utilizzare il software del sistema operativo Microsoft Windows (il \ldblquote software\rdblquote ), potr\'e0 usare il presente supplemento. Il licenziatario potr\'e0 utilizzarlo solo qualora disponga di una licenza per il software. Il licenziatario potr\'e0 utilizzare il presente supplemento con ciascuna copia v
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (323), with CRLF line terminators
Category:dropped
Size (bytes):76966
Entropy (8bit):4.300323274289338
Encrypted:false
SSDEEP:384:4YZUFNhaVwV/VLVWPD66KUtycONAk8mZX4++oMeRCcLsRDJDhFfv:edGJ/
MD5:32E4D6F895A69BB2C373FF4C688D6B27
SHA1:57738235363C5F1A1C5651C65832396E3AEF4414
SHA-256:AE28910C1EF16CE70A5E97C5D02390AD8D64F80966E2BE3C4A56DB0C4038442D
SHA-512:5052E8A218CF71B0E08DE33665A58F9219282E00F2E4F6C19897A07863556A2408DC273AD3CC9257D98D6A57765321E0F1B051BED051F188947DEDA9D32DBDBE
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):22392
Entropy (8bit):5.785099960362018
Encrypted:false
SSDEEP:384:RSoG4kGkjAQIid0W5REWiW5cEWRD/HRN7Wm6ImlGJz9:E4kGkjF3YXDvb
MD5:2191BD92ABAF3D2094AD58EA59793C56
SHA1:C55969BCD8309A9DC36650068F5652EFCF813DB0
SHA-256:AA885980EABCAE6A41849E4C6E670A482F2B58CA94586AEF1F7EDCD899E8EDB3
SHA-512:8B328A0DEE95656CAEA990A7788CA8DAE71B33DD7149F81E7F2F9F75ABDB80FA5A56BA8C2CC1E890D60CADF69DDD4C1B73F0E2F691011194F5A4C9710C80E542
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!......................... ............................................@E.........................................@...'...........4..x#...p..........T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....'...@...(..................@..@.reloc.......p.......2..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):17981
Entropy (8bit):4.094780609805748
Encrypted:false
SSDEEP:192:X6XxHC3q0InM4PsOQOSquHlEiKoXfZX4pvW6qgkLhcg976bmFK3ZcdwKGK3m0kso:0+aIXCv9TV4v2
MD5:878C601A8EE79D8BC27DADA595F406A5
SHA1:E9165C7745D9801D868B799B2D6212169A640573
SHA-256:3BE9621F436874877D799A19EA638955616EF2B5B20A121C3E2105A82569D83C
SHA-512:99A5B033B2093B31269EE25509845B799E94B939DEA3F627C0B3624D7D8DEF87A1F0E4BC69E19E9F6C6CA4CB415FA65F96DA036CD658585BC4208AF2CE2BE2EC
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset128 MS PGothic;}{\f1\fnil\fcharset0 MS PGothic;}{\f2\fnil\fcharset134 SimSun;}{\f3\fnil\fcharset134 MS PGothic;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052\'83\'7d\'83\'43\'83\'4e\'83\'8d\'83\'5c\'83\'74\'83\'67\f1\lang1033 \f0\'83\'5c\'83\'74\'83\'67\'83\'45\'83\'46\'83\'41\'92\'c7\'89\'c1\'83\'89\'83\'43\'83\'5a\'83\'93\'83\'58\'8f\'f0\'8d\'80\par..\f1\lang2052 MICROSOFT WINDOWS\f2\'a1\'a1\f0\'83\'49\'83\'79\'83\'8c\'81\'5b\'83\'65\'83\'42\'83\'93\'83\'4f\f2\'a1\'a1\f0\'83\'56\'83\'58\'83\'65\'83\'80\'97\'70\f2\'a1\'a1\f1\lang1033 .NET FRAMEWORK \f0\'82\'a8\'82\'e6\'82\'d1\'95\'74\'91\'ae\'8c\'be\'8c\'ea\'83\'70\'83\'62\'83\'50\'81\'5b\'83\'57\cf1 \cf0\par..\b0\f1\lang2052 Microsoft Corporation (\f0\'82\'dc\'82\'bd\'82\'cd\'82\'a8\'8b\'71\'97\'6c\'82\'cc\'8
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (336), with CRLF line terminators
Category:dropped
Size (bytes):75218
Entropy (8bit):4.2482376114682285
Encrypted:false
SSDEEP:384:4YFyFFhyV4VnVLV//rCjKUtycONAkbETFU9WiucznfYbzqRjXU2ggRZVDhYAS+KY:1biucUb+xJr
MD5:47F8082069C52D2F7DB1FC6AAC2886DF
SHA1:4B5C371E9006C10685F2C59CA9A7EBFB4A597A0A
SHA-256:E86656EF2092C0E6CAF5B8B0BCA2D6CE5DEF273609C22187AE91236605D2E273
SHA-512:7BDAF721E561C46609054F6786624149FD824ABB1E3126B2A6B6385B56C6FE11414AF216FCA3EE2B1FE6A4B42CA8A19F46186AB1D4E70FB81B6F9AF013C40018
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):22392
Entropy (8bit):5.8343089789525635
Encrypted:false
SSDEEP:384:5zDG2GRc9zWpBeWkWpceW8D/HRN7W+hdImlGJgID:tsg8DvF2D
MD5:62916FB4601EC606FAF0AF963E11B621
SHA1:5C711ED1EB16A8FA76EFDF5E7BEC2E1EE8AA9AA1
SHA-256:F24C7D743680A233C4A97578E08D2384CCAC16CB29AA550D3F33D6D80E9FADFC
SHA-512:BC767B3E08FEFC282B774514BA9EB744EC34BCD87503225DFF52EA5A694BB9E001035EE47F00B9A7A1C2B432D9FCEF676DD6E9D623436406C19911BA92EB0DF6
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!......................... .......................................N....@E.........................................@..X&...........4..x#...p..........T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...X&...@...(..................@..@.reloc.......p.......2..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):17193
Entropy (8bit):4.230250761387094
Encrypted:false
SSDEEP:384:Xmo3HPb4mMhFehM9JSbty8PNXg/h7Q6PXJxt2aEnCJ0gG+Sy4NjvJRExEA5oMFr2:gFeh6JSbty8VXQh7JPJxcaECJ0gDSFNR
MD5:A404BE4F47FA7DB29DF4023E2F75034E
SHA1:9141A326F0D421CDC913E2DD9839398FB8F8480B
SHA-256:824C88479FF2A887E23838A03BD41C5C6F5C20F9CD3031FF2B2897529A1F39F6
SHA-512:76C1AE746305DACEBC732C0D84B4D86178C669228A1E40F8E0FB85A29C9662A54E04BEE83569393F6953E9696CF048EB990034372BFA89AE3CC9CFFF400FF209
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset129 Malgun Gothic;}{\f2\fnil\fcharset0 Calibri;}{\f3\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 MICROSOFT \f1\'bc\'d2\'c7\'c1\'c6\'ae\'bf\'fe\'be\'ee\f0\lang1033 \f1\'c3\'df\'b0\'a1\f0 \f1\'b1\'b8\'bc\'ba\f0 \f1\'bf\'e4\'bc\'d2\f0 \f1\'bb\'e7\'bf\'eb\'b1\'c7\f0 \f1\'b0\'e8\'be\'e0\'bc\'ad\f0\par..\lang2052 MICROSOFT WINDOWS \f1\'bf\'ee\'bf\'b5\'c3\'bc\'c1\'a6\'bf\'eb\f0\lang1033 .NET \f1\'c7\'c1\'b7\'b9\'c0\'d3\'bf\'f6\'c5\'a9\f0 \f1\'b9\'d7\f0 \f1\'b0\'fc\'b7\'c3\f0 \f1\'be\'f0\'be\'ee\f0 \f1\'c6\'d1\cf1\f0 \cf0\par..\b0\lang2052 Microsoft Corporation(\f1\'b6\'c7\'b4\'c2\f0\lang1033 \f1\'b0\'c5\'c1\'d6\f0 \f1\'c1\'f6\'bf\'aa\'bf\'a1\f0 \f1\'b5\'fb\'b6\'f3\f0 \f1\'b0\'e8\'bf\'ad\'bb\'e7\f0 \f1\'c1\'df\f0 \f1\'c7\'cf\'b3\
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (465), with CRLF line terminators
Category:dropped
Size (bytes):87426
Entropy (8bit):3.5774747627046524
Encrypted:false
SSDEEP:384:4YroNVxJ4i/5Qbkkk5vWPD66KUtycsyUja9FQvFzyDZAZIudv7YGoDq1RYktgNVX:GvREQIudjuqGhHtP0tJJ8Z
MD5:E939717E7EAF1B7F53C4B752E62A22E7
SHA1:CA5A66C452EC6CA8BC04DE95EAC1616CF3980992
SHA-256:8AFDF3D2C0FD2370889E3FD96BC2742831CDC6041AF0A407123C27F8D76D68A6
SHA-512:EBFA725B8EFC4448D669BEEA6F56EAB9A317793FF1E21CBC51E015A1A31DFB8B1408E9DF15023B878ACA220465DBEDE09254F9A524EF7F6060877844994E17AA
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):27000
Entropy (8bit):5.168209025236721
Encrypted:false
SSDEEP:384:TP0c+uc0WYDxYv0hvOUjs1tWWiLeWUW9LeWMD/HRN7Psjhl2NM:R+ucq9rMDvPs7
MD5:6B5DA66D58CBB93AB58508E39762DACF
SHA1:01F052C63B33EB77C7CA6E3BB7F85D748E90C4B7
SHA-256:EF9D89D9FB91B28006D88A7314B25334EC9484B045C1EF1E360D190E57411271
SHA-512:F467670DA52B4DAB70A2520CBC46FDD135C667E7EF2F826443FAA7AD680ABAA6A0A74DA4EC568EE1237A4C3449D97510FA84A5912DF5E0A110EF496995B65BB4
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........@............... ............................................@E.........................................@..$8...........F..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...$8...@...:..................@..@.reloc...............D..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):5965
Entropy (8bit):5.137067604759464
Encrypted:false
SSDEEP:96:MFStTSD7RPxNNcHEywBHSX8LYiUEvaYaBcUMkVla15AM1YgnWnwKx0mfZCuP7MpY:GVPxuEywxg4EEyXNseGGZ34F/slW2
MD5:26B16F6395F6469DA2CCE621BA66C7F3
SHA1:E0A4A64B018A8A4FA07B92E6277534EFB7A6840E
SHA-256:D6547D3047F7B606CF84CCBED44C5047C0E3F6FEECFEB7F0A87EE451FC2FF7A7
SHA-512:F60B5CEEDC32BABC005C013C533239E80FE54A77AC8D246EB1B35895E416A89930FAE30B9DBF8DD77A164153849EECCB1008F49DE4DF22AF3EE5BF703A6F0901
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 AANVULLENDE LICENTIEVOORWAARDEN VOOR MICROSOFT-SOFTWARE\par...NET FRAMEWORK EN GEKOPPELDE TAALPAKKETTEN VOOR HET MICROSOFT WINDOWS-BESTURINGSSYSTEEM\cf1 \cf0\par..\b0 Microsoft Corporation (of, afhankelijk uw locatie, een van haar gelieerde ondernemingen) geeft dit supplement aan u in licentie. Als u bevoegd bent tot het gebruik van het Microsoft Windows-besturingssysteem (de \ldblquote software\rdblquote ), mag u dit supplement gebruiken. Als u geen licentie voor de software hebt, mag u de aanvulling niet gebruiken. U mag dit supplement gebruiken bij elk geldig in licentie gegeven exemplaar van de software.\par..De volgende licentievoorwaarden beschrijven aanvullende gebruiksvo
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (402), with CRLF line terminators
Category:dropped
Size (bytes):86910
Entropy (8bit):3.5923702375201585
Encrypted:false
SSDEEP:384:4YX7lskoDBkIWPD66KUtycONAkhdkmgJljMFwrbDbGBklKn9COrtQ2GCJYkTQQv:UkBU9Ct2GCJYu9
MD5:B0D9E4DAC3935BB596BB83B7D8474F8F
SHA1:29CE971B1A3CCF6F09ECED6BFF8E778DF13F3D35
SHA-256:3C309A5509D42E6485E9123BC6AF5EC43CF2FAA8AFEAD5062676E85AB7F96ADD
SHA-512:AF4E4032A3B4A1696A3F252C03C8F5364089320E4181EBCCD39D569D7577B11B70B4AE694D4A74E09BB61505664A01733DCCB2D80AED64CB7142225DDDD997E2
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):24968
Entropy (8bit):5.2188768786363955
Encrypted:false
SSDEEP:384:8GWm2GWm2GWm2Lpf3QkxtYkxIwcSMN5/sWIeWsWVeWbD/HRN7EnejlGshd:A/xtYkqBD5/uPbDvYbQ
MD5:D681E1D3708566488A2C68AF355C58AF
SHA1:4DCDC8730DF86829A066720EC49D7ABF54E90CBC
SHA-256:879337C0A6A94F8961064D5E286C140D9FF57382147A0E2CB622322261A9A123
SHA-512:D4941C007539D5C34AC68491CF84DFA7284C27AA51CB4CEE71D4399BDBA040CFBF23BF6BF57F90A9C229F9BB352B2BA9A6050A69AECC6312F01B84790C6BAFE6
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........8............... ............................................@E.........................................@...1...........>...#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....1...@...2..................@..@.reloc...............<..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):5649
Entropy (8bit):5.126111549309469
Encrypted:false
SSDEEP:96:MFxITVDRr7F4SCwVwTclq54aMeBESUw80kvYGfqBI5PvfYJD0ARldNrgxUeiWN7t:Gk/F4SCwVwclq54aMeqSUwvkvbCBWnao
MD5:3C9F4B239DDC64151765EDDF658E788F
SHA1:9BE17903A7B604CA4A91AB1417207CC73FF2EFFA
SHA-256:91D3D81F8E0663200D4A6FA6689CC6936C50DB001514FE803A638B861196997A
SHA-512:06D3CBA3B66C2CBA29FC89DAB17AEED99731CDAD8A42C553F60E3B127017BDE327E622C826E614C30CC1B8E4E3D2CDE4C453F47929A9D0EFCECB26030BF3167F
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 TILLEGGSLISENSVILK\'c5R FOR MICROSOFT-PROGRAMVARE\par...NET FRAMEWORK OG TILKNYTTEDE SPR\'c5KPAKKER FOR MICROSOFT WINDOWS-OPERATIVSYSTEM\cf1 \cf0\par..\b0 Microsoft Corporation (eller, avhengig av hvor du bor, et av dets tilknyttede selskaper) lisensierer dette tillegget til deg. Hvis du har lisens for bruk av Microsoft Windows-operativsystemprogramvare (\ldblquote programvare\rdblquote ), kan du bruke dette tillegget. Du har ikke tillatelse til \'e5 bruke det hvis du ikke har lisens for programvaren. Du kan bruke dette tillegget sammen med alle gyldig lisensierte kopier av programvaren.\par..F\'f8lgende lisensvilk\'e5r beskriver ekstra bruksvilk\'e5r for dette tillegget. Disse
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (469), with CRLF line terminators
Category:dropped
Size (bytes):89824
Entropy (8bit):3.6659525153012087
Encrypted:false
SSDEEP:768:9QUuGp9Vi0iG0XE2Uq4DplOe6lsQjPLJbOzdH:/CjJyZ
MD5:C3A238FFBF2DBB9F758E5C5B33948971
SHA1:56CEB241F3780DC4A9814332F44369188DED3E77
SHA-256:2F0BEBA8A56CCCADDFE6E0ECC3130D0EFAFB7F84CC0FA4E8DB9D85C840E24241
SHA-512:2DEF165951B958195A339F8B4A38ABA310C428FBF89F0D7E708D44255F3CF59953550F8E4772626AA125E4A2CB3328601B5CA097F5E355423F4D5094CB8155EA
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25976
Entropy (8bit):5.2431920900196305
Encrypted:false
SSDEEP:384:o+V05/Q+CNfvaRr2CWeeWcWveW7D/HRN7SFDhl2By:obqV6Z7DvSFx
MD5:59708860CD9FB256669A9D9E2E0D72CD
SHA1:7AD8568CCD88D311173EA4477876BE8581BB76AD
SHA-256:D86286C5FE73A46F1240A6177E7F9144757E0EA97060344F6C3609322C96B568
SHA-512:18BC8DB37D3E0F47F8C887792F11A88E26057F0D8B8B034A4423C5B7AB9E544D654E4902B339003BBA92CF78CE96C256FB3896879E8F218E434F1DF9A794BE5C
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... .......................................y....@E.........................................@..`5...........B..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...`5...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):7595
Entropy (8bit):5.290678933267692
Encrypted:false
SSDEEP:192:h4IX0BvJz1fsz7OCevVH58uNgwsX3uDNPDEPH0Yx9Fa2:4zum38u82sUya2
MD5:A5A99B184ADEA12986B1283D7E6B5365
SHA1:D477FFBA3C9199A0C74DC688AA41CC4D06530829
SHA-256:0E931904C4C9BEDE08BEE5985A5912351EFB927787941E33E174EC9373F81476
SHA-512:C3A23F9AF8B339669AB45A165F99990808D4D838B6664E444C8AEC2873CE26AFCC1EDC844EC68B5C0F7E10A37D911004D28C83B080A37EE7C322CF6E11F13F0A
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset238 Tahoma;}{\f2\fnil Tahoma;}{\f3\fnil\fcharset0 Calibri;}{\f4\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 UZUPE\f1\'a3\f0\lang1033 NIAJ\f1\'a5\f0 CE POSTANOWIENIA LICENCYJNE DOTYCZ\f1\'a5\f0 CE OPROGRAMOWANIA\par..\lang2052 .NET FRAMEWORK I POWI\f1\'a5\f0\lang1033 ZANYCH PAKIET\'d3W J\f1\'caZYKOWYCH SYSTEMU OPERACYJNEGO MICROSOFT WINDOWS\cf1 \cf0\par..\b0\f0\lang2052 Microsoft Corporation (albo, w\~zale\f1\'bf\f0\lang1033 no\f1\'9cci od miejsca zamieszkania Licencjobiorcy, jeden z\~podmiot\f0\'f3w stowarzyszonych Microsoft Corporation) udziela Licencjobiorcy licencji na niniejsze uzupe\f1\'b3nienie. Je\'9cli Licencjobiorca ma licencj\'ea na korzystanie z systemu operacyjnego Microsoft Windows (\f2\'84\f0 oprogramowanie\f2\rdblquote\f0
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (426), with CRLF line terminators
Category:dropped
Size (bytes):86684
Entropy (8bit):3.589843127864851
Encrypted:false
SSDEEP:384:4Yjbb8UAjJUgYN5s6KUtycONAkIuroXIGSPchHL4lzSv3kOY8vg2m/qKdxEcyJ2w:qUbcyJzyN7K
MD5:4A892AA3FEDBFE5991B6FF46C00AF55C
SHA1:421FE8F80432C56D022FF2911C4A5708093184C3
SHA-256:AADBD1DF74FC82A43F86F1F40D5065A802B2DB71652525A78D258FDA3197A743
SHA-512:9391096AD6C721B50A300F3C8285291086C0F302F77A7EDEE7283EC8EB7432171EDDE5998D5C76587C6431EB3C7E5CBA176D0C31F6963ACD8D954EA9C6A6E619
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25992
Entropy (8bit):5.227890225105695
Encrypted:false
SSDEEP:384:eFiQP70DnTB1Hcpm1WYeWfWVeWzWD/HRN7MjlGshe:exQ3B18saCDvd
MD5:157DA28C4DEC27279322A99D90A27DFA
SHA1:8E9928BAE175E16CA21A5F3D101DABE9C8BD7F32
SHA-256:B67BC7E8532AC429152877F368CAB07CE7D78BF49B144A2E188792C05D47AA38
SHA-512:E2FE019976FB33CF18F6870B5CC4C6EC34C609A5D2A0FBB4536C45EC0A95173AE023A817A1E2F1760F10BA0760F8B925DF00D96F54C643AC50EA901156A6C0B5
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... .......................................t....@E.........................................@...4...........B...#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....4...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):6166
Entropy (8bit):5.089363857063007
Encrypted:false
SSDEEP:96:MFklMuTyDyuCBhgerTSwp2BPVr84Y4nyoZveAY2vqpMETEGEZrHkB60037tY6Al5:GOzhge/lsZVr9TZt6qj5ZSRW+IcLW2
MD5:4F7E0CF0AB641752ACF8168B7AF115C2
SHA1:99AC6551112C1F308B4C939F75C73A098E2EC7C3
SHA-256:F714F0963E1CE7C6A73B27585EB6B197E29875E195B97885737817E51DED42AD
SHA-512:0B81A0AF33F7B1D76477656CEFD32744567A1F50C25405C2B0DAD1E7F31A08CA8C94A7C93A401F076D7D7B285BD407018A52BCF4DC905E9F5B9C378428EAE742
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 TERMOS DE LICEN\'c7A COMPLEMENTARES PARA SOFTWARE DA MICROSOFT\par...NET FRAMEWORK E PACOTES DE IDIOMAS ASSOCIADOS PARA O SISTEMA OPERACIONAL MICROSOFT WINDOWS\cf1 \cf0\par..\b0 a Microsoft Corporation (ou, dependendo do local em que voc\'ea esteja domiciliado, uma das afiliadas dela) fornece a voc\'ea a licen\'e7a deste suplemento. Se voc\'ea estiver licenciado para usar o software do sistema operacional Microsoft Windows (o \ldblquote software\rdblquote ), poder\'e1 usar o suplemento. Voc\'ea n\'e3o poder\'e1 us\'e1-lo se n\'e3o tiver a licen\'e7a para o software. Voc\'ea poder\'e1 usar este suplemento com cada c\'f3pia v\'e1lida licenciada do software.\par..Os termos de licen
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (463), with CRLF line terminators
Category:dropped
Size (bytes):88486
Entropy (8bit):4.201430078423779
Encrypted:false
SSDEEP:384:4kbCNVxJ4i/5Qbkkk5vWPD66KUtycONAkDS72HrkSVfGo/RGKVcng5/spnBthXlK:EfVUJi
MD5:D46F34E95E94FBFA4CB4A8DCC7BA3211
SHA1:3E2150C9DD44C4B3416051534CCF84968F2737CD
SHA-256:A787B2F493C3248991877F61E210BB0231D357D06AA2671917D2AD4E528C9F67
SHA-512:C740F7EBA5187699B39265BA2238121A20D935D1320C0E344B767D537618CC2954BB7A6BACAE12E7121CD1B4BCA1CEB84E11BB80A347E7C2C79E87EB899ADB7A
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...0.9.:.@.>.A.>.D.B."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25976
Entropy (8bit):5.567035650384759
Encrypted:false
SSDEEP:384:Rkt0p4rRVjRc9nko6eWeeW4D/HRN7W6L2slAtXK:8Je4Dv6I
MD5:4F22E1307E1EFC6AB3908F768BC6EC3A
SHA1:B440F5EBE429B3D3B872DFAE021C15675DD7D7B5
SHA-256:47D5FDFBD54DD07718DFE9A8C2EB25997D77E67697DB3938BC616C1B552F4D24
SHA-512:EC78D7DE6BF46361F0A6DBEA27EF3178ACA43A86E88A427CC3001FC98ADD81A577978C91D508A25B6421F9028C8F2C4FB5DDDC98DF8C326753C0912661CD7E5F
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... ......................................M.....@E.........................................@...5...........B..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....5...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):17877
Entropy (8bit):3.7007700023730234
Encrypted:false
SSDEEP:192:3sSfSUdEnAoagO35YaK8IaK2AXhvepPqh1Wh9+WOv35rBfCviD/bNizD0Z1yDJeZ:vCngnd40E35tO0MJUEh2F+7fDyrC+U2
MD5:C0A21ED9322DFA67AB5D71CC576982A0
SHA1:74896F49DCE77069854F5B320C0C8D412BE676D6
SHA-256:1EA50FA040F7FE2E420039646C1A3F6F99756D7B1159CE1002A148C639761650
SHA-512:AEEACFEFE2B791AB51504541C52F8C22C55EB6D148DF30274F5B8256C2DCAE2E3B9C6C3FA74667A5AD5C545DFAA40613F40987500D709C4BA38AD8FE674E4A26
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset204 Tahoma;}{\f1\fnil\fcharset0 Tahoma;}{\f2\fnil\fcharset0 Calibri;}{\f3\fnil Tahoma;}{\f4\fnil\fcharset2 Symbol;}{\f5\fnil\fcharset204 Calibri;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052\'c4\'ce\'cf\'ce\'cb\'cd\'c8\'d2\'c5\'cb\'dc\'cd\'db\'c5\f1\lang1033 \f0\lang1049\'d3\'d1\'cb\'ce\'c2\'c8\'df\f1\lang1033 \f0\lang1049\'cb\'c8\'d6\'c5\'cd\'c7\'c8\'c8\f1\lang1033 \f0\lang1049\'cd\'c0\f1\lang1033 \f0\lang1049\'c8\'d1\'cf\'ce\'cb\'dc\'c7\'ce\'c2\'c0\'cd\'c8\'c5\f1\lang1033 \f0\lang1049\'cf\'d0\'ce\'c3\'d0\'c0\'cc\'cc\'cd\'ce\'c3\'ce\f1\lang1033 \f0\lang1049\'ce\'c1\'c5\'d1\'cf\'c5\'d7\'c5\'cd\'c8\'df\f1\lang1033 MICROSOFT\par..\lang2052 .NET FRAMEWORK \f0\'c8 \'d1\'c2\'df\'c7\'c0\'cd\'cd\'db\'c5 \'df\'c7\'db\'ca\'ce\'c2\'db\'c5 \'cf\'c0\'ca\'c5\'d2\'db \'c4\'cb\'df \'ce\'cf\'c5\'d0
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (433), with CRLF line terminators
Category:dropped
Size (bytes):85610
Entropy (8bit):3.599243577088427
Encrypted:false
SSDEEP:384:4Y/w+WCXVVV6VOVWPD66KUtycONAkK2JuWf59pW7fx1uOuos98LSGcgqBV6kMQjc:yvV7fxAnIXrJJpoc
MD5:CB2E2EDF7D7FEFDE9B3894923407F8C0
SHA1:541EC570F26BB30F4BE35F1A87D4CCF6BC660F67
SHA-256:874E5D7E45603AD70CA353E8DC6BF42944594F911D17C79BE8966DC01D27EB73
SHA-512:045FADDA432280EC961DA53B914ADC9D9A31D02140282B3B37E89F01723D64B5659E3C1A61E9344F4440813EFB8B932CF45F859B97CFBDC158C0802D70C5ECDA
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25464
Entropy (8bit):5.263783899501219
Encrypted:false
SSDEEP:384:rWPdQMxbmoI8WE7M/oZVQZWpjeW+WpqeWzD/HRN75hl2q:rwxbm96xVTQzDvx
MD5:B776D2EB2E66BB1DE5FC737704173460
SHA1:5D66C04A49D4D3291DE33F7B945328025804E297
SHA-256:FCD13D65B8CFBE2035CC63D10BB5C7F2558967E61CE605FB88F413819303077B
SHA-512:B79F0A978F0355632515E9B2C8D472581246145CF54E3407633D1F57CDECDFA68E8E47CD43E121177D9CBCA052470D4526109F25D26F84BC733B50378E132A22
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........:............... ............................................@E.........................................@..\2...........@..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...\2...@...4..................@..@.reloc...............>..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):5745
Entropy (8bit):5.172187457525236
Encrypted:false
SSDEEP:96:MFPN/T0DK/t2JznY9CFKBUF985AYJ/vNXYGMvWSGZbYLnziYXi3YY7ZEpc2FnoP3:G10JznWCI+rlcFvSGxYLbXQpeop6X6HV
MD5:FF3F5628B4B3E988D1EE082CD4F514A7
SHA1:6C40FAE2124C630D05D0EB6F1B5A7F4901D05D0E
SHA-256:C920E7CD21DB8FF2822048023B6530815CA4537B5557B1482E8B8CA4A7798A70
SHA-512:EE3C2F74B715EC9724194E77C7C02F4CA60C083C248838FCCAFEF3FA1076282562C9AB603707BF710875BFD0349E817C9DC8AF13CD5C10D0D04B96293A744A6F
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 LICENSVILLKOR F\'d6R TILL\'c4GG TILL PROGRAMVARA FR\'c5N MICROSOFT\par...NET FRAMEWORK OCH TILLH\'d6RANDE SPR\'c5KPAKET F\'d6R MICROSOFT WINDOWS OPERATIVSYSTEM\cf1 \cf0\par..\b0 Microsoft Corporation (eller ett av dess koncernbolag, beroende p\'e5 var du bor) licensierar detta till\'e4gg till dig. Om du innehar licens f\'f6r Microsoft Windows-operativsystemprogramvara (\rdblquote programvaran\rdblquote ) f\'e5r du anv\'e4nda detta till\'e4gg. Du har inte r\'e4tt att anv\'e4nda det om du inte innehar licens f\'f6r programvaran. Du f\'e5r anv\'e4nda detta till\'e4gg med varje giltigt licensierat exemplar av programvaran.\par..F\'f6ljande licensvillkor beskriver ytterligare anv\'e4
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (452), with CRLF line terminators
Category:dropped
Size (bytes):85564
Entropy (8bit):3.6944587958679307
Encrypted:false
SSDEEP:1536:67gos8tlQm/wobG+PKarUdTvJ4rtRevbS6bh:67gos8tlQm/wobG+PKarUdTvJ4rtRezd
MD5:F020B0E38F1295924F1833E77859FC9A
SHA1:17467F2EBB8CBCA89119D30B3BA7AE30691921E1
SHA-256:8CE790ECA06BAE1B01F40F732580ADEA86D4C22B28D1E701E033C6C9983500C2
SHA-512:BF01AEA04827A46CB60CACF97993B319643E90ACA82E1ABC2C6750F01DE0D638FC1B73931FE80E5441128EBA70F364C1000B4CCD053B2E241C0A3916B75D670A
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25464
Entropy (8bit):5.294787660401921
Encrypted:false
SSDEEP:384:TMYQAynHUSBQJvIE97ZIMQMtXd2XbtRSwWxeWeWMeWfD/HRN7wyAhl2Yn:TDynHUSKJvI8I5MXd2XbtR8MfDvwyC
MD5:C9DFDA8948680ECC97A8BBE2F97114CB
SHA1:130B97562C2A45A3A87784E6B3A6818755A09C83
SHA-256:F008E0A673EBD471AF052C4F8259BFBFB9F028C203E96B18D53A179BF5017703
SHA-512:6B1C397884755CE6AAE4E63CD7B232BB24C1A9C5FBE51DF58B461751E6CD5ACA5611FF65D54F50A5CD7823FFB661B84174F07C654933B20D43A62DF13C2815F6
Malicious:false
Antivirus:
  • Antivirus: ReversingLabs, Detection: 0%
  • Antivirus: Virustotal, Detection: 0%, Browse
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........:............... .......................................0....@E.........................................@...2...........@..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....2...@...4..................@..@.reloc...............>..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):8089
Entropy (8bit):5.10960269961769
Encrypted:false
SSDEEP:192:93kB8xWbjs++3y+irO1a3Aq+zT8/fdBziV+XPXZpP37h2:Gq++8waekfD2V+XbN2
MD5:1604BE6036737CE1701330A4F54917EC
SHA1:02E9ED8FFCD35B22DB9ADA931FFAFEBEF9B967E6
SHA-256:50C95114D6340431FAC2F752844B9E5C08024A88E464B1D4AFDE460545A3A3CF
SHA-512:B8BC20395CF84AFB43820B9E61DC7E1EE201A453AE354A6E91B45D7AB35F9E8B391829DAADC06D342DCE355151ECD801EBBDC67123B46B75C6832296E6DFE8FC
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset238 Tahoma;}{\f2\fnil\fcharset0 Calibri;}{\f3\fnil\fcharset2 Symbol;}{\f4\fnil\fcharset238 Calibri;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 MICROSOFT YAZILIM EK\f1\u304?\f0\lang1033 L\f1\u304?\f0 SANS KO\f1\'aa\f0 ULLARI\par..\lang2052 MICROSOFT WINDOWS \f1\u304?\'aa\f0\lang1033 LET\f1\u304?M S\u304?STEM\u304? \u304?\f0\'c7\f1\u304?N .NET FRAMEWORK VE \u304?L\u304?\'aaK\u304?L\u304? D\u304?L PAKETLER\u304?\cf1 \cf0\par..\b0\f0\lang2052 Microsoft Corporation (veya ya\f1\'ba\f0\lang1033 ad\f1\u305?\u287?\u305?n\u305?z yere ba\u287?l\u305? olarak Microsoft Corporation'\u305?n ba\u287?l\u305? kurulu\'balar\u305?ndan biri) bu ekin lisans\u305?n\u305? size vermektedir. Microsoft Windows i\'baletim sistemi yaz\u305?l\u305?m\u305?n\u305? (\ldblquote yaz\u305?l\u3
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):70900
Entropy (8bit):4.164978668180238
Encrypted:false
SSDEEP:384:4YqL8FNhaVwV/VLVWPD66KUtycONAk9xkZtmqaDCWehZtTfVxzR/8XMHRd4LOPcW:tkZtmqaCpmXw4LOPjAJN6
MD5:6CC370B95C9F3E3D28315759B496E977
SHA1:09E4AAD0A389F0F876D21E132123DBBD83DC1314
SHA-256:93E519E8CC173A3F1AA8DD8113AD4A1BE0B5B8D40E1D0A1563DBA2054B50433A
SHA-512:3B2F19F97CB07F5C845D85CEE1A0932C19DDD0EFC0433E4B6F092E0E7782E9454C6FF43EB54A943E1E85764CA2CE8FF36A239AC319B09FD8042669D24AF27F91
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):20856
Entropy (8bit):5.833525007549292
Encrypted:false
SSDEEP:384:gkSEQw+3xH4G0XVW1eWuW8eWBD/HRN7Wa7lAtXKqt:gkRuZsBDvyt
MD5:F67D13820BE86A0BDF9D6DDE2FA400A1
SHA1:F9B2FFA3F1EE870E49B494A585C49B212CE907CC
SHA-256:E9733A3FE748058D474923B9DE7FE1A6F4BAAFD0B592D72D05D0A6A69B3CA574
SHA-512:5803DDAC3FFA423EF9EA47AE05AD8B821E58A86F3BC372638F939FA99E0757A17C54FCCA5C4000CD0155623514401ACAF4F2F4C28039FA1563CC103CBE41BBE6
Malicious:false
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........(............... .......................................3....@E.........................................@...!..............x#...p..........T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....!...@..."..................@..@.reloc.......p.......,..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):9626
Entropy (8bit):4.087933797548139
Encrypted:false
SSDEEP:192:dXpyqkFt7t2fPreF/XAaz+t1ei+tomLAio7WyfoBkfynOgLo5hbBiYH1TuY7GCfA:FpfnlNMFhI2
MD5:F05B0D04CD20864FFCFECDEE13949D58
SHA1:B65A5CCBF46A9E078B175EF82BD978DEFCE8DEE3
SHA-256:F2508D347BBC11784AD33C9FAE913C243198F9517CC9743BE56C74F28587B9A9
SHA-512:FED09DE434AF31D239F71660E5BBCC5EDC8D310C5EF5031EDC66FA911BAD3107B97DA2462AD12EB439D71A3B391FEB7E2E475E54B58CC324240D16E8118124D6
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset134 SimSun;}{\f1\fnil\fcharset0 SimSun;}{\f2\fnil\fcharset0 Tahoma;}{\f3\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl230\slmult0\b\f0\fs20\lang2052\'ce\'a2\'c8\'ed\'c8\'ed\'bc\'fe\'b2\'b9\'b3\'e4\'b3\'cc\'d0\'f2\'d0\'ed\'bf\'c9\'cc\'f5\'bf\'ee\par..\'d3\'c3\'d3\'da MICROSOFT WINDOWS \'b2\'d9\'d7\'f7\'cf\'b5\'cd\'b3\'b5\'c4.NET FRAMEWORK \'d3\'eb\'cf\'e0\'b9\'d8\'d3\'ef\'d1\'d4\'b0\'fc\cf1 \cf0\par..\b0\'ce\'a2\'c8\'ed\'b9\'ab\'cb\'be\'a3\'a8\'bb\'f2\'c4\'fa\'cb\'f9\'d4\'da\'b5\'d8\'b5\'c4\'ce\'a2\'c8\'ed\'b9\'ab\'cb\'be\'b5\'c4\'b9\'d8\'c1\'aa\'b9\'ab\'cb\'be\'a3\'a9\'cf\'d6\'ca\'da\'d3\'e8\'c4\'fa\'b1\'be\'b2\'b9\'b3\'e4\'c8\'ed\'bc\'fe\'b5\'c4\'d0\'ed\'bf\'c9\'a1\'a3\'c8\'e7\'b9\'fb\'c4\'fa\'bb\'f1\'b5\'c3\'c1\'cb Microsoft Windows \'b2\'d9\'d7\'f7\'cf\'b5\'cd\'b3\'c8\'ed\'bc\'fe\'a3\'a8\'d2\'
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (445), with CRLF line terminators
Category:dropped
Size (bytes):88388
Entropy (8bit):3.5912866156337344
Encrypted:false
SSDEEP:384:4Y+lFNhaVwV/VLVWPD66KUtycONAkkIxHIbcwl8TQYOdxIL1FskOYNigvR/nikku:45u6kzX0JZ5OW
MD5:5B73409A0F1CBB707CD62A7956BC2F92
SHA1:1CE52FD3746C5BEE7A3C3EF5AA8958E44B8761E3
SHA-256:193090F4472F1A1C5ED10AB97FA4BF77BD4FF3F172F380EF4A53FEF39989159A
SHA-512:ECC775F665B7F0A192D04BD372542E3FADF89B47E4CC5373D2597B9DF321B386E89F6FA695C0871FD56691BE126E16443AF91A7DA34DE018CEB47F90AA30E3F7
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25976
Entropy (8bit):5.173033117483033
Encrypted:false
SSDEEP:384:ez0W2Z7TShQkObTqUvWpKeWQWpDeWeD/HRN7Mqhl2h:PBShQVb5DeDvMP
MD5:CD5ADC3856F5E244983F884ADD4B0974
SHA1:38ACFFA5637059EA03BC66B210E75DD349E03589
SHA-256:6E8B50BB4F2DF7FB6C104FDE197253250BEF65459C897224A2284DAD223313E4
SHA-512:5102B87D3F67AA2FF7CD67C1122EE4C1733B4C646AC26B073E91209338E70C277147C694809D4D5AA086A0F528262C0702A026EBDA21DF766DC8E263A1FE026F
Malicious:false
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... ......................................6.....@E.........................................@..`5...........B..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc...`5...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):6284
Entropy (8bit):5.084888320970751
Encrypted:false
SSDEEP:192:GnIKgPqA2ezJpbFODr5dDXuTEGMXv3BosgW2:fCA2el/iyTkXuW2
MD5:D611F7F4978F3960627E889316C4ADDF
SHA1:A4FB1EA1FB64BFDF2B850947F4B7254BE2E01D31
SHA-256:803C4739D74B27A72754607AD69C41A4C311CFDBADA1A6BFE8FA47B31A9E74C6
SHA-512:EADC6D4EC6EE1ADF76EBBAFAD45C2A78744931857FC555733558B125E0F77AD1200E3B1D4D9FEED60F2B37B220A6CB29A060A81FB8062B528489A098E7BFDAD3
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 TERMOS DE LICEN\'c7A SUPLEMENTAR DE SOFTWARE DA MICROSOFT\par...NET FRAMEWORK E PACOTES DE IDIOMAS ASSOCIADOS PARA SISTEMA OPERATIVO MICROSOFT WINDOWS\cf1 \cf0\par..\b0 A Microsoft Corporation (ou, dependendo do pa\'eds ou regi\'e3o em que reside, uma das respetivas empresas afiliadas) licencia este suplemento para o Adquirente. Se o Adquirente estiver licenciado para utilizar software do sistema operativo Microsoft Windows (o \ldblquote software\rdblquote ), poder\'e1 utilizar este suplemento. O Cliente n\'e3o poder\'e1 utiliz\'e1-lo se n\'e3o tiver uma licen\'e7a para o software. Poder\'e1 utilizar este suplemento com cada c\'f3pia do software licenciada de modo v\'e1lido.\par
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (436), with CRLF line terminators
Category:dropped
Size (bytes):87662
Entropy (8bit):3.565842667501489
Encrypted:false
SSDEEP:384:4YI0PfH7g2HbWPD66KUtycsJ7ULMYIex7UM/I9aXdoBchU7aF/6JD1NDoAjJuL4y:IAMVgZN08Jtikin
MD5:E2FC9D2A4FC56B64E3981DD7E0B076D5
SHA1:1660468AC360A0A52F1A84887A9BB9C6CA3C9D8D
SHA-256:9E224A5F7A5C83DF1AB31743520A05252C3CDCC9E97526264DA716166D2B29F9
SHA-512:CA9098A09A7450D02BDA76F1D64480F27679610441E3DF0858B231DE4599F53DDF245B69D181D3FDD37EE846EB085DDA0EC85CF1825EC2C7F0EAEEA8423FEFD3
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.".>..... . .<.L.o.c.a.l.i.z.e.d.D.a.t.a.>..... . . . .<.L.a.n.g.u.a.g.e.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.i.c.r.o.s.o.f.t.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.F.x.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=."...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.D.o.t.N.e.t.U.m.b.r.e.l.l.a.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k."./.>..... . . . . . .<.T.e.x.t. .I.D.=.".#.(.l.o.c...B.r.a.n.d.i.n.g._.M.a.j.o.r.M.i.n.o.r.).". .L.o.c.a.l.i.z.e.d.T.e.x.t.=.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):25976
Entropy (8bit):5.133854006275226
Encrypted:false
SSDEEP:384:NJSQSmzBbYOqMpje8mWHeWI8mW2eWTD/HRN7WRImlGJC:N0mJHFyCI7TDvS
MD5:328EBD40C9DABF91A88D883E3A38186B
SHA1:E5A1BA4F20DB499FFBB192BBCCF41331DBB13BAF
SHA-256:65EBEBE480072ACBE8B9D5E9D129472301638244C96793B2C815A12F5B9333AE
SHA-512:BA6DB56A28C5F060CFA01D43AB2466A73625AA0680A6D8475BA19AA6F43D9FCEA1CC635D2ADCB24DC47DA2658157D41F6EC0E5AB908F625D9C57568A6BC1C3F1
Malicious:false
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............u..u..u.Z.q..u.....u...w..u.Rich.u.........PE..L....`.`.........."!.........<............... ...........................................@E.........................................@...5...........B..x#..............T...........................h...@............................................text............................... ..`.data........ ......................@....00cfg.......0......................@..@.rsrc....5...@...6..................@..@.reloc...............@..............@..B................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
Category:dropped
Size (bytes):6114
Entropy (8bit):5.055174898107239
Encrypted:false
SSDEEP:96:MMGaZ0pDeXex2HBHUB78dnY+cIvmwYvfmzPUJI+OXlH/iE0AsYyBOGqUCS9i1VTw:NGfcU1EWI1tw9JfTXK2CUjDW2
MD5:078313B7397CA95EF02B96A79EE53FA5
SHA1:DD52C2B72569CDE270A2153C616F90E45E290BB6
SHA-256:5ED152A56E2E0FEF7827864D5B7998CF95CCC5492250E419B0D29027B8AF512C
SHA-512:BF42ED20834FD872B15A6D99D0E7ABFC8C3067E3AFE972206107D9132373B8589DDEFEE0EBB9315FB92FDB6F71B7D57B6984AA24E7D44933C047F8AAD75A5224
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\nouicompat\deflang1033{\fonttbl{\f0\fnil\fcharset0 Tahoma;}{\f1\fnil\fcharset0 Calibri;}{\f2\fnil\fcharset2 Symbol;}}..{\colortbl ;\red255\green255\blue255;\red0\green0\blue0;\red0\green0\blue255;}..{\*\generator Riched20 10.0.16299}\viewkind4\uc1 ..\pard\sb120\sa120\sl240\slmult1\b\f0\fs20\lang2052 T\'c9RMINOS SUPLEMENTARIOS DE LA LICENCIA DE SOFTWARE DE MICROSOFT\par...NET FRAMEWORK Y PAQUETES DE IDIOMAS ASOCIADOS PARA EL SISTEMA OPERATIVO WINDOWS\cf1 \cf0\par..\b0 Microsoft Corporation (o, en funci\'f3n del lugar en el que usted resida, una de las sociedades de su grupo) le concede a Usted la licencia de este complemento. Si dispone de licencia de uso para el software del sistema operativo Microsoft Windows (el \ldblquote software\rdblquote ), puede utilizar este suplemento. No puede utilizarlo si no dispone de una licencia del software. Podr\'e1 utilizar este suplemento con cada copia con licencia v\'e1lida del software.\par..Los siguientes t\'e9rmino
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:HTML document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):16118
Entropy (8bit):3.6434775915277604
Encrypted:false
SSDEEP:192:7Ddx3KOTczFQ21Kp4n5DTx1iDecPeLHLHQFJFjZWblWUxFzJzcKHjT:fdsOT01KcBUFJFEWUxFzvHH
MD5:CD131D41791A543CC6F6ED1EA5BD257C
SHA1:F42A2708A0B42A13530D26515274D1FCDBFE8490
SHA-256:E139AF8858FE90127095AC1C4685BCD849437EF0DF7C416033554703F5D864BB
SHA-512:A6EE9AF8F8C2C7ACD58DD3C42B8D70C55202B382FFC5A93772AF7BF7D7740C1162BB6D38A4307B1802294A18EB52032D410E128072AF7D4F9D54F415BE020C9A
Malicious:false
Preview:..<.!.D.O.C.T.Y.P.E. .h.t.m.l. .P.U.B.L.I.C. .".-././.W.3.C././.D.T.D. .X.H.T.M.L. .1...1././.E.N.". .".h.t.t.p.:././.w.w.w...w.3...o.r.g./.T.R./.x.h.t.m.l.1.1./.D.T.D./.x.h.t.m.l.1.1...d.t.d.".>.....<.!.-.-. .T.h.e. .E.x.t.e.n.d.e.d. .C.o.p.y.r.i.g.h.t./.T.r.a.d.e.m.a.r.k. .L.a.n.g.u.a.g.e. .R.e.s.i.d.e.s. .A.t.:. .h.t.t.p.:././.w.w.w...m.i.c.r.o.s.o.f.t...c.o.m./.i.n.f.o./.c.p.y.r.t.I.n.f.r.g...h.t.m. .-.-.>.....<.h.t.m.l. .x.m.l.n.s.=.".h.t.t.p.:././.w.w.w...w.3...o.r.g./.1.9.9.9./.x.h.t.m.l.".>.....<.h.e.a.d.>.......<.m.e.t.a. .h.t.t.p.-.e.q.u.i.v.=.".C.o.n.t.e.n.t.-.T.y.p.e.". .c.o.n.t.e.n.t.=.".t.e.x.t./.h.t.m.l.;. .c.h.a.r.s.e.t.=.u.t.f.-.1.6."./.>.<.b.a.s.e. .t.a.r.g.e.t.=."._.b.l.a.n.k."./.>.......<.s.t.y.l.e. .t.y.p.e.=.".t.e.x.t./.c.s.s.".>.........h.t.m.l.{.o.v.e.r.f.l.o.w.:.s.c.r.o.l.l.}.........b.o.d.y.{.f.o.n.t.-.s.i.z.e.:.1.0.p.t.;.f.o.n.t.-.f.a.m.i.l.y.:.V.e.r.d.a.n.a.;.c.o.l.o.r.:.#.0.0.0.0.0.0.;.b.a.c.k.g.r.o.u.n.d.-.c.o.l.o.r.:.#.F.0.F.0.F.0.}...........h.e.a.d.e.r.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 13 icons, 16x16, 16 colors, 4 bits/pixel, 16x16, 8 bits/pixel
Category:dropped
Size (bytes):88533
Entropy (8bit):7.210526848639953
Encrypted:false
SSDEEP:1536:xWayqxMQP8ZOs0JOG58d8vo2zYOvvHAj/4/aXj/Nhhg73BVp5vEdb:e/gB4H8vo2no0/aX7C7Dct
MD5:F9657D290048E169FFABBBB9C7412BE0
SHA1:E45531D559C38825FBDE6F25A82A638184130754
SHA-256:B74AD253B9B8F9FCADE725336509143828EE739CC2B24782BE3ECFF26F229160
SHA-512:8B93E898148EB8A751BC5E4135EFB36E3AC65AF34EAAC4EA401F1236A2973F003F84B5CFD1BBEE5E43208491AA1B63C428B64E52F7591D79329B474361547268
Malicious:false
Preview:..............(...............h...............h...f... .............. .............. ..........^...00......h....#..00..........n)..00...........8........ .h....T.. .... .....&Y..00.... ..%...i........ ._...v...(....... ....................................................................................................w......x......................x..ww...........h...............................w.....w.x..........x................xwvwg.................................................................(....... ...................................jO:.mS?.qWD.v\I.|cP..kX..q_..sa..yg..{j...p..nh..pj..uo..|u..xq..|r..|u..rx..zy..|w.}.y...q...d...y...{......S...]..d..i..r..|...j..j...y...e...k...l..q...y...~...v...y..s..s..m...m...l...n...k...t...l.............................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):126132
Entropy (8bit):2.8078116281505556
Encrypted:false
SSDEEP:192:ly3ul6MeeS80xxb11yXXVzzzzzlzTTTbt/Pu:lj6MeeSXxxb11yXXVzzzzzlzTTTbt/Pu
MD5:D39BAD9DDA7B91613CB29B6BD55F0901
SHA1:6D079DF41E31FBC836922C19C5BE1A7FC38AC54E
SHA-256:D80FFEB020927F047C11FC4D9F34F985E0C7E5DFEA9FB23F2BC134874070E4E6
SHA-512:FAD8CB2B9007A7240421FBC5D621C3092D742417C60E8BB248E2BAA698DCADE7CA54B24452936C99232436D92876E9184EAF79D748C96AA1FE8B29B0E384EB82
Malicious:false
Preview:..................6...00......h...5... ......................................(...m...................00.............. ..........Z$...............-..........h....3........ .....29........ .(....=..@@.... .(B..,E..00.... ..%..T...((.... .h....... .... .....d......... ............... ............... .h...L....PNG........IHDR.............\r.f....pHYs..........o.d....IDATx......@....C~.iB..,...B!2.?....>..|...@.....9..a..a..a..a..a..a..a..a..a..a..a..a..a..a...k.gz..r..g..6...............................................`.u].#.v....[l..&..&..&..&..&..&..&..&..&..&..&..&..&..&......v..<7{..I.. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. L. .Xk=.C@...g..0..0..0..0..0..0..0..0..0..0..0..0..0..0.....<[....Y._:.s..6............................................;...=.{....a..................................................>O?.|.d..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):143901
Entropy (8bit):4.318601286795364
Encrypted:false
SSDEEP:1536:NR6EoU1Gq8cXWK8Q3aTQgAFPNG6D4ZH7iEfPF1Ir:NR6dcXWs3a0JPNG6D0H7iEfPF0
MD5:9B70C7FA81DCA6D3B992037D0C251D92
SHA1:83A11F4B7A5020616257FEF143A7C32164D3927C
SHA-256:18226B9D56D2B1C070A2C606428892773CB00B5B4B95397E79D01DE26685CCD4
SHA-512:A771725B16E23086B1EE37336F904A047445E8C6A6CA505B9AFF5A20948F8DFA53FE07CB07A13CB9CB7A5BBC7484009A40A91ED9EB8B7F5726307EFC6A991A17
Malicious:false
Preview:..............M...6...00......h....... ......................................(...............x ......00..........[>.. ...........M...............U..........h...s\........ .. ...a........ .(...m...@@.... .(B......00.... ..%......((.... .h...e... .... ............... .....u......... ......&........ .h....-...PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[....E.|g^xf.g.#.....q.\u..zM....U.....(...0|Y}.4M7..&1./z..:.I..{(..P...J....rC.$$2._..r.+z...H..u\d.V.I.`..... ....I..v...'k2e.w7(.`.'Q..w....J.T9..P..TK.j.S......R...C..Q=I.._F(.B.C...ew.r.Y....x$.4M""2..<>..x...1..0._.[....8.4.}g...n..d..'.R8.!._...Z.e...I.-...D.W.Pk...m.p5.^.?J i&..}.e..j.B........@..$..X$.+_...~..\E]4.".......H...H..M.|..._......P.H.g eM..+. ..."(y..0._h...b.....m. .......P.b.J~......@^....*eN..-..n.g.../.f..)A...c.[..g@..7Ub....,.Q.J.WP..A..K-...p..].m<.d.....>.r..,.c1..2O..he.#z..d..t..:...|.0.16...;L4.I*.d4,.E..M.8.......|2u<J#.K..uq.OK..Q..B<I!...i."".u..%K..B..L......
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):143932
Entropy (8bit):4.322992398695786
Encrypted:false
SSDEEP:768:qZvaGyae28qOtnAjW6HvC2TpjTUmhIKosFE607deph1z:SyaeNqOtnYxpjTUmhSf607MpD
MD5:0CCA04A3468575FDCEFEE9957E32F904
SHA1:AE5A03B47DF97F5F1B14DCA3539A1C4B0F407F15
SHA-256:B94E68C711B3B06D9A63C80AD013C7C7BBDB5F8E82CBC866B246FF22D99B03FE
SHA-512:A59D832EE7D956CE348E0A73893E44683DB148BC2FC54765B69921D710FEFFA2C1F652FAFC7B8961CCB1D4A12D1DEA701D7BB62956D4904A52CF1BE6EB022FEF
Malicious:false
Preview:..............l...6...00......h....... ......................................(...............^ ......00..........`>.. ...........M...............U..........h...x\........ .. ...a........ .(.......@@.... .(B......00.... ..%......((.... .h....... .... ............... ............... ......'........ .h....-...PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[r.8.ES../hg.wF....A..I...".J.... E..i......Y....g...k....g..}..... 8R...>. ..@P......Al .`X...D........-.s<..l..@......x`...(....U....9H..^...)........8$Sp2.KF .gd.L.c......A.|l........ ...$.......Q.X#.;..A xy..C./....!..<.....ve...O..{T..Hr.=SP.g.....jB(...( <...6<.%...f.....S......."...X...K;.../../O..=....A..&ox...m.C...Y.);..G...tZ.f.....o..]...#..2...A.../.,....B. ....D....... ..k1.."w8.I..'.......6.....G(.D4,.E....0.......r...|..#..p.....5f...h.F....W.....&..O......... ..H..G...D....!5v.V.%W.\..<..+.%8.?....." .....9.i.)P..d.J|v.........X......}.{/7v...i..;..>l.H............H...>d....4 ..,
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):144110
Entropy (8bit):4.328841453415788
Encrypted:false
SSDEEP:768:OhncLqco0HEHkK69kCer0lDFLaFbLNrc9V9WvALsFobzqFeeFYwfot082:2nVSHEEll+0aF3Nrc9V0vQjbuFnFYwfj
MD5:F824905E5501603E6720B784ADD71BDD
SHA1:D71B15E1168306C1E698250EDC5F99F624C73E6F
SHA-256:D15A6F1EEFEFE4F9CD51B7B22E9C7B07C7ACAD72FD53E5F277E6D4E0976036C3
SHA-512:3914B1FADCF6B90D106AB536687E5BADB1B09B60450E0B75F403F7DCA32C2DC63D68C0918D10359DA4F4113406DCC4E02FA0C02941D8B1BADBA021C60AFACE9A
Malicious:false
Preview:..............O...6...00......h....... ......................................(................ ......00...........>.. ..........UM...............U..........h....\........ ..!..-b........ .(...>...@@.... .(B..f...00.... ..%......((.... .h...6... .... ............... .....F......... ......'........ .h........PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[v.H.E.^=/<..........%.yH.#....s.zH.T...4MBr1.........\..{7..`..[.A.....G..}/E... (....E...z7..c../.....M.=.@ ..UNd.. ...+R[.C...5.......0.(z.+@...%y..#+.. .&[.2A...5Y..+:....${."B..R....*.c.~F....`...<...4M2n..("...92........H.<..<x..("....(....48+P.......W.Y..g........j.Ye!.......G......2.....4.$.[.=,.I..:)U.x].:.D...\...E...C.3.....*"(!..@.j.G.7F.... .R.].....H...1......"Hy.....V..!.Q~~Z..q.^An...U..&j..F;{...LA~&.&S5.F..._.....R.(..,.H....."}J.5...Q..s...e".2.n.....^d.....0.W@[u...I...+.......".c1..".xFP.G.$jL..@......{7.....J.....d.>.Ht...MA.#..E;.$.....{...f....!*.A'.....Y...A...;!G..
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):144151
Entropy (8bit):4.330072191797617
Encrypted:false
SSDEEP:1536:A6lW3a5tctzX68cuJJx41on58wGWJNHw01Rh5acFS:bVs+j6Jx41on58SJNHhR3acFS
MD5:0ADE6BE0DF29400E5534AA71ABFA03F6
SHA1:6DDE6E571B2FA45AB2CACF565E488ECACE01DB56
SHA-256:C2F6FAA18B16F728AE5536D5992CC76A4B83530A1EA74B9D11BEBDF871CF3B4E
SHA-512:57CE956375097B8AEED4605B7816E8EEBA139A4151D2516B46E7F0E2E917276264040039319CC9012796EED5405E005AC4DE20CAFFDB99EE59DB06C868901A83
Malicious:false
Preview:..................6...00......h....... ..........=...............%...........(................ ..5...00...........>.. ...........M..............@V..........h....]........ .. ..pb........ .(...g...@@.... .(B......00.... ..%......((.... .h..._... .... ............... .....o......... ......'........ .h........PNG........IHDR.............\r.f....pHYs..........o.d...QIDATx..Yv.H.FC}z_.....V.~..m..1...}..S.r...@.z..H ......M....<...Z7.....[........d...>. >.@P......A\.c..p....C.....p.T.A.d..b.. ...N.....=..*b....8&r"En{% ..dH..}.....L.../.....1a2.)...#2'J.E..pB.....h@.@.H.............?.....-.M..x.<.[$..'.....D.|>Ee..e...b..;...k.%.8......q...F!...O.x.Gi.p.....J..+.'."...b.L.s.u....@:.,......q...>.....*"(!..@...h.....'..E..).u i.#...D.n(.$...z.d?. ..*..f.w..H/f.x..%..WF......H.4=.o>...;.@27.#.I.i..=.L...#..d.@..........dI.../.,.q.i.X6.p..b\....Z..& :.*.K..`X.D..;x*....8 r,..@......c........u...H8...T....8....q.+0...-A{."Z......#.....Uu.K...}.8..s..0...'.Z9...sv|....;!...
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):144033
Entropy (8bit):4.33440096558093
Encrypted:false
SSDEEP:3072:WaSx7OtXuTIEDZy6aeDxyDQkVXJspRlWaqVzic:GtN6JspRlW7V9
MD5:267B198FEF022D3B1D44CCA7FE589373
SHA1:F48215DF0F855328509A47C441A14E3578A20195
SHA-256:303989B692A57FE34B47BB2F926B91AC605F288AE6C9479B33EAF15A14EB33AC
SHA-512:A492BCAB782AE385FBCA6E0081926E41578778A7F196405372BB0F177AE0E47322859314068FB16167310AC50183F9DD507832B187382E494C3889CD6C64C129
Malicious:false
Preview:..................6...00......h....... ......................................(................ ......00...........>.. ...........M..............-V..........h....\........ .. ..]b........ .(......@@.... .(B......00.... ..%..A...((.... .h....... .... .....Q......... ............... ......'........ .h...9....PNG........IHDR.............\r.f....pHYs..........o.d...3IDATx..[..8.D.9./yg.w&...G.Z-.z.Q...$2H.. %Q.q...c.....h..4b!......CC.[.!....m...-.A.h.I..........H./.......~..?g../...64..d.X...Oh..d.U.x{...LV1e..Gh..d.Q.eK.....$.Jm.......xB.........4.....z..B. n......x......G........Z.......~..[C.xw.S?.}.uX.....[.s......a..".3.....n.4.9.P..c1......5...V....=.A.K.#..N..8^....~p....S.Em..d..T...tt&.Gk..b..G5.}...s..W....@Zqy...v%0.h..........L.....[U.......A.....B..i.%..6^.....J....e[...}...lI.x?Q...g.wh...w3.cX..M.\.Cz..4.{.UxHT...Pe...=.O.\......P........). {.W....$s>.3......I.Le.Y;.:\.|.1?.>.H.d...fD%..dtWb.$....h..)>..\=......pd..g.xv.~.SD.....G..3...,9.~..{&
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):143871
Entropy (8bit):4.3211025564539325
Encrypted:false
SSDEEP:1536:d8eXVC4CJa6lUvS/gzDJeI6jvquEGEhoyGce:d8ErzFeI6jAhoyO
MD5:25F0D572761CB610BDAD6DD980C46CC7
SHA1:6270EE0684700C5A4D01CD964DC05B82719B0370
SHA-256:CE2AFC0AA52B3D459D6D8D7C551F7B8FBF323E2260326908C37A13F21FEE423E
SHA-512:DB061086D1DB6379593CC066860C31667DC20FE4CD60D73E2E16FE1DCA9990060ECE5396FAFC5C023A9BED19DD251BDA7537A6018B58420CE838276F7430F79D
Malicious:false
Preview:..............]...6...00......h....... ......................................(...............n ......00..........a>.. ...........M...............U..........h...y\........ .n ...a........ .(...O...@@.... .(B..w...00.... ..%......((.... .h...G... .... ............... .....W......... ......&........ .h....-...PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[v..E.^=/zfqff.,.#.[.J.^.....V.U.H.MJ.....%.........C.-$...n..A#..>.2...H.E....2...H.W..}7E... .#..."..?..@..Z....9Q.E.....!`..E.....-T..[.. (.g........!.C.(.` ...XP...).@l(.@..........................b....k....k........r....wX.@[.G.......d...V.....{...r.......J.......E;.........5..2(%.....J.-....-.#a.uq...J. .U.eQi..:.s4E.%.T.......i.>....%.K)j.,.H.D-$mF._D...a.P%.w#P.b..x..W....%....b.....G.Vc..@...U....ZK/....Fe...]j.....*......Z.d<..].i.......k1..2w8.$kM..@...r......[..z.9.'...1...e#>+_.>V{.....<."b;v.$.F..v...e..4M.._.........q.D..@.:..:H\........L.....s.E`.f.;...B._.4......X.....R..,.V.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):143881
Entropy (8bit):4.322458101334011
Encrypted:false
SSDEEP:1536:t7JrB+BXJwqLQRLcYah14KPsrFK3QrPa8KGL73:t7wgAYs2KC5rPa8fL73
MD5:5AC2B8E1A766C204F996D9CE33FB3DB4
SHA1:09CBABDD17A5A0215AD5D5AF509EA9EC315373B6
SHA-256:EE387D9642DF93E4240361077AF6051C1B7E643C3CF110F43DA42E0EFE29A375
SHA-512:802B84DEDC195C21DE32E3ABBED02B8646AFFDFA75525E8B1984869B207A7FA02EE91938C0D2CB511D7911FC00EF612D03B6F2EA3615B01548BD408302B08F44
Malicious:false
Preview:..............O...6...00......h....... ......................................(...............M ......00..........2>.. ...........L...............U..........h...J\........ .. ...a........ .(...Y...@@.... .(B......00.... ..%......((.... .h...Q... .... ............... .....a......... ......&........ .h....-...PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[....F.Yg^..l..F..?4.....V.[H.m...1.......~.8..............}&.... ....... >.@p4.....A\ ..X...D..?....h.}y.......@....0.......-T..[.. .Q........=D.....1Y..82..8%[h..O. ..d.K.......!.~|...Q%.U.3.... .8..]kM.%..........-.ep..+}...~......E!..j......G?ao...\.H...-*..........+....ePJ.......w.$.?.S.k}dy....J.....VAq.M#..).X..."H}..K1il.....}...2VS*lt.r.....j.v.;...j.U..n...~..m<..x,..I*.D......&R..!....y.j..B.Z./.L....".Rw...e.@L2._X.d..;x.u..G..u.V..x!..B. r....p.@..G..e.[..v27U....Ik.+........pU...+G.j..0v..#.o;....b.k........#..8...v......$.."`..s...+..d.r.v.kU!..M.b..8.*}Zu... .YU....MN....p/.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):144084
Entropy (8bit):4.326089154684614
Encrypted:false
SSDEEP:1536:H36R8gfxxj979YnfXEtJ3mo4X78E+FhqYLGgWjj:H4VYEXmPXgE+FhqYLGgWv
MD5:B4947D242AB4A902031FCD1FFD3A56CD
SHA1:4014A05642118A306C742F56878DB1EA61E78B6B
SHA-256:995C9F4EA0D98C0C4E5037EDE43FC44A680D85CB1E37C782ADAB775915E975B8
SHA-512:A9C468B6C444B528898FE6FA26F42B57E7890C1992BA03E670CA849E9BADBBAD74C2D923EABEF5AB88631AE7ABDE4477286C43D755AB566D1A70EC8E84A4FF93
Malicious:false
Preview:..............i...6...00......h....... ......................................(................ ......00...........>.. ...........M..............,V..........h....\........ .. ..\b........ .(...$...@@.... .(B..L...00.... ..%..t...((.... .h....... .... ............... .....,......... ......'........ .h...l....PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[....D..g^......c7......+.|..FURf.Wq...@>Zko.......{...Y.......o.....H.....f...Y....Z{k..-...k....7.M....:.`x...........H..'... ..".\...s".)r.U..8&..2.!30..d.N..d.......8......Y(......P.&....#....8#.G...!.q...]kM8......KQF}......^..Zk.........b.Z.{.......3.....VqG .v....v.....H...!J.!.1...O..+...p..Q.i...7./W....3>..Oh..e.*.AZ..".9..*....X....e6....x*.9R..[.....x...cL\.2.(....K..{..w.4....s.....[.Rd9-H..@.@.,5....$"2U.(C.6...8KU.y#z..5........C.@...J..$jM.3....Iu.y%bm.3...... ..ZD..0..hM,v..^..r.i..0. .sj.]s.wzr..[.-.)..9....=8r..5....0..../YL....U...@.w...c.J.;b._.(..h..8....P....[..$W...~
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):143835
Entropy (8bit):4.318333743951936
Encrypted:false
SSDEEP:768:1Va5Ab1+DYEeloJH1iE6DtzC1QY0kaazdkgEZmape4XQ2EZjK9DNn:na5A4YnoJH0jmuY0kaMdkgEVzQ3j8
MD5:E7A252C763CE259F800183FD9DD1F512
SHA1:4601C87F90E1C0061A7137370358AE11A4D83A23
SHA-256:FDE052EFE70C27D8023065F0859627FC88BF86E166016E9CB00185C21DE52742
SHA-512:B140883EB89872306C7DBC4DFE75B204D927295649D3DE9230748465628BDDA4D2E6C8806FF2E5DA9647EE45838200A1CBA44CB7222F9173202F369465C4DA05
Malicious:false
Preview:..............i...6...00......h....... ......................................(...............^ ......00..........]>.. ...........M...............U..........h...u\........ .N ...a........ .(...+...@@.... .(B..S...00.... ..%..{...((.... .h...#... .... ............... .....3......... ......&........ .h...s-...PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..]........\;Krg......h..G.CR|.3.`[.......QH>Zk....y=.....@.....i.y..$.R...G#... 0...?. .4.......A\.....h._..6..+. D....X...@../.......,..m............@.$.L}..............,..}..........H...).....kf...S;...Z..B.<x.@....I.{X..M.?.+...&.U...GUp.;.C..'%+....lRY.....0...........O...|...w.*.A....g...28.O.r.h....\!.......g.cf...|/.J.-v.M .s.H......i...........Y...._.......4.@E....U.). S@..{.GiC...\x...........2..*H3/R[....a. ...<D....y.IN..d8..:. ..m.&bn.3.B.... ..ZD..0..x..VI[.h.Y....1.k.$..oh..9....{./.......o.L.hl:Z.x........4M.;....A;n.5..o..^..HN..iG...!.o..x..........M..}.... ...Q-.,...
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):144064
Entropy (8bit):4.335692332950691
Encrypted:false
SSDEEP:1536:nbtXI1SFXgmf17HEUoatyEqmTfHsNG3jiXZdK4A:btiMp7k56RTHs03jiXZdK4A
MD5:8853DA1F831CAE28E59D45F5E51885AC
SHA1:496EEFCFA68DE25ABB899ADDF39498D8420BFA3D
SHA-256:0203C7D678464641C016DC3D658ABA0A68F20B9A141D6E3EE1820C5B8B6401DB
SHA-512:1A48F52C305713F08059A83C9EC1B03CE310A068E3ABBC546CB458C6B56934852637EF9DA8BEEACADD91DC06F338ADB7FD7D709F906D2A5F533132283EF05197
Malicious:false
Preview:..................6...00......h....... ..........+...........................(................ ..#...00...........>.. ...........M..............<V..........h....]........ .. ..lb........ .(.......@@.... .(B..8...00.... ..%..`...((.... .h....... .... .....p......... ............... ......'........ .h...X....PNG........IHDR.............\r.f....pHYs..........o.d...?IDATx..mr.:.E.W./zgqv&....nE.l}...pO...xi."q.)Y.>.i.......g.........F7....w.I!..H.E..}.E... 8....n. ..@PF...E... .H._C..... .A...(.$.@...*Z{.B.. j.......8.C.........,.....l..v<Y..............!.~|......*........V`..g.y...}k.%.?..[..C.|s&...|4......4$pE.....G...,f..e.......>.Z)U.A).x^|:RP..........+..dPB.#.:{..u.;......T.A.k...h...b......k.f.~.....\....3...N../.@.(c..t.. ...~.F.Z{...z..f..qp.0j..X./.J..@...._..#.Rs...e H<2.^h.d...T.y.^.a....3Q]F.k1.."w8.I..).B......$?.k3.."v......V.a....d.[r..a).f'a.@.3.....W...5!N.8..5.<_....T*J...!K4.k-.t.....T].Z...s#..........J.. .x.vT.h.DXB.[F.R.;.k.Z.d....Hm..
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):126548
Entropy (8bit):2.9017236155530575
Encrypted:false
SSDEEP:192:cICfR9iBLLLLLLiii1dkx2Xwi+XI7b6ZZZZZZZZZZGGGGys7v5Z7vvvvvvvvvvwF:H2R9iJJi56ZZZZZZZZZZGGGGyHIIIhh0
MD5:C66BBE8F84496EF85F7AF6BED5212CEC
SHA1:1E4EAB9CC728916A8B1C508F5AC8AE38BB4E7BF1
SHA-256:1372C7F132595DDAD210C617E44FEDFF7A990A9E8974CC534CA80D897DD15ABD
SHA-512:5DABF65EC026D8884E1D80DCDACB848C1043EF62C9EBD919136794B23BE0DEB3F7F1ACDFF5A4B25A53424772B32BD6F91BA1BD8C5CF686C41477DD65CB478187
Malicious:false
Preview:..................6...00......h....... ..........4...........................(...................,...00.............. ..........w%..........................h....4........ .U...O:........ .(....>..@@.... .(B...F..00.... ..%.....((.... .h....... .... ............... ............... .....4......... .h........PNG........IHDR.............\r.f....pHYs..........o.d...HIDATx......F.E..y)4.2kE...0..&."u..@x .......s.M.....#..&..&..&..&..&..&..&..&..&..&..&..&..&...........C....e...r..Fg......Y# ...3F@.`Gg..........'8K.........x..G@........8j...^....x..E@.............E........r.......z.&.....u..c.........{.......8.+/.. o.n...F7................................0..G@...........9.7....a......o..." ....x......9.'....0.{D@....X.....6.......h..F@.`.s.3...;..|...........8O....`.sD@..I.8~....h.cG@....8n...^`.cF@..E.8^...^h.cE@....8N..........Xd..0.............................................>V.`...m...r.@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):126246
Entropy (8bit):2.8519432791654697
Encrypted:false
SSDEEP:192:+7yhu1uz//TAAA555AAAAAr99899AubBqj:oX1uz//TAAA555AAAAAr998991bBy
MD5:6125F32AA97772AFDFF2649BD403419B
SHA1:D84DA82373B599AED496E0D18901E3AFFB6CFACA
SHA-256:A0C7B4B17A69775E1D94123DFCEEC824744901D55B463BA9DCA9301088F12EA5
SHA-512:C4BDCD72FA4F2571C505FDB0ADC69F7911012B6BDEB422DCA64F79F7CC1286142E51B8D03B410735CD2BD7BC7C044C231A3A31775C8E971270BEB4763247850F
Malicious:false
Preview:..................6...00......h...I... ......................................(...............-.......00.............. ..........~$..............&-..........h....3........ . ...V9........ .(...v=..@@.... .(B...E..00.... ..%.....((.... .h...n... .... ............... .....~......... ............... .h........PNG........IHDR.............\r.f....pHYs..........o.d....IDATx......@..A..y)..2.E&.pc..t._.......<...u].;=...;=.0G. L. L. L. L. L. L. L. L. L. L. L. L. L. .;=........k...m..&..&..&..&..&..&..&..&..&..&..&..&..&..&.....[v..M.c..@..@..@..@..@..@..@..@..@..@..@..@..@..@..@.{.l.~........................................................G...`..0..0..0..0..0..0..0..0..0..0..0..0..0..0..0...2...=6................................................N...U.G.......a..a..a..a..a..a..a..a..a..a..a..a..a..a..a......f..{v... L. L. L. L. L. L. L. L. L. L. L. L. L. L. l...........l..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&..&......N........4.... L. L. L. L.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):136313
Entropy (8bit):3.597503085869211
Encrypted:false
SSDEEP:768:ZVbWxNMz9t/g2FQyvy90J0FUvvCI1873m8WjLvGMB2vrcpWSrem1b06EXsnS5O+I:rb3z9tY2uwSuvWSma
MD5:889472312E724195D7B946EECAEA20C1
SHA1:D099C44B794F7D0414CDA5BA9A6DF432347FF513
SHA-256:C9CA53F83A5CC10F726248D47FF82981B584B3FF62EE591229A8237C11340991
SHA-512:511B4BAE756FD61AB4E7F8F7173A6B0BDA6AB2AEFB7C4C77E78ECAE3B7DE080CEC575DB6AF110C195F58BC7B2ABCAB0F1477271A31CE6D2AF10634B632E0BF39
Malicious:false
Preview:..............B...6...00......h...x... ......................................(.......................00...........,.. ..........~;..............&D..........h....J........ .s...VP........ .(....d..@@.... .(B...l..00.... ..%......((.... .h....... .... .....)......... ............... .....Y......... .h........PNG........IHDR.............\r.f....pHYs..........o.d....IDATx...]v*....#.;/....`d.L.n.$."3...f/...yN..B...E..p8|~.......Z..x8|~P..l..E........o....(..(.......EP..P......j.........EP..P..?..P.5P....../E.....W.(..(.d...."..H"j.(.\(....."...*k.(..(.`....".....j.(.X(.g]..E..@.8....z..W.......uP...>....h......".........-....`.,...z..&...-..6..X..oQ.5Q.F...."....K.(..(.7u...E...."...E....$.... ......=.A.......E....A...b.....A........ ...@.c..|.+....E.M....(......."X.l....(........"..L....(.[.....D..H[....E.W.. ..."xO.. .x.E...@.....9a.....E.p.@.1.Ep_.....$..g._....t.0E.^....(./n.@..A."X^....u-.e.@.A.".^....u).i.@.QA."0/.......Y..|tP..L..;....E(......x9...8
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 19 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, 48x48, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):143990
Entropy (8bit):4.123683788676836
Encrypted:false
SSDEEP:768:RB/Nn07yYIG+Tl6iaYO+xQNM11AdKgw3w:Rh+7+Tl6iawyEAdKgw3w
MD5:ECA24331CE0850D188BD2EB5C22DE684
SHA1:53E910C03AA6BC423717C5B175670517F26F00A4
SHA-256:DEBA0A7A6E2CA99D3380D35AE33F8D266806FDBCBF75FB06B5718BE5873258F6
SHA-512:A3DE7DEB9A0EB2F40B56F1DC435A01578D6F0EE299F7159560029E965E7785F0197F3E98FF2EC9C2C39C8078C125454C19E81D5F6291A90010D7704F57312DB9
Malicious:false
Preview:..............=...6...00......h...s... ......................................(...............o.......00..........B=.. ...........K...............T..........h...Z[........ .."...`........ .(......@@.... .(B.....00.... ..%......((.... .h....... .... .....&......... ............... .....V'........ .h........PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[r.8.D.Sw_..,..Z..#aJqlY..l.}~.j.#..A......"..0<...y./.....:........?........xM.....o..8..H...-H..H.....-<_...>.@E..u..G2.....B.........-.......}.$.[$..(..(.^"8..p......8....|n.<.....?....!.....G"XG.x......5...^.?....6.C._R...7z.......z.....KdaH..@....w...y.4..~.'..z.A..`.>{..I.=..;.0...g...~..Ao..J.l..9....R!.....t!...+..a.A..H/...+..a.Af....K.{X.{..3.*..Z...Z...gL..\.......\...i....o....bM....M.l_..UA.j ....>i%.,.H!...W......P;..<k}OH.....D....@......"K ...v.....\.D\....j...&.?8....-[...X....j]`..9Q5.0..f.K..&..3."H ...F.K.Ot@.&a.%.}.P."*..R..`...+...k..5...J.V...M{...;........./^q.G.j.Q.t....f}
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 36 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, -128x-128, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):190199
Entropy (8bit):3.926410784165316
Encrypted:false
SSDEEP:768:G6mPq2pmss03yYI8yghoENpqcVnPnn3zcrFTZqV:G6mPDalENpLFn3zcrtZqV
MD5:7D1BCCCE4F2EE7C824C6304C4A2F9736
SHA1:2C21BF8281AC211759B1D48C6B1217DD6DDFB870
SHA-256:BFB0332DF9FA20DEA30F0DB53CEAA389DF2722FD1ACF37F40AF954237717532D
SHA-512:16F9BF72B2DDC2178A6F1B439DEDABE36A82C9293E0E64CFACCBF5297786D33025A5E15AA3C4DC00B878B53FE032F0B7ED3DEE476D288195FB3F929037BDCDBE
Malicious:false
Preview:....$.............F...........h(..9...@@......h....;..00......h....F..((..........qL.. ..........9Q..............!T...............V..........(....W...............X...............Y...............Z...............[..........(L..`r..@@......(.......00..............((..........X... ..........................................p...........h...x...........@................... ......................... ............... .(..../..@@.... .(B...7..00.... ..%...y..((.... .h....... .... ............... ............... .....?......... .h............. .p..._......... ............... .....g....PNG........IHDR.............\r.f....pHYs..........o.d....IDATx..[......}9;..3{e9.3.q.s.#R.)|U|..O...H_.k]W..L.t....`...A..2M./..?,B?.....z...b..."S.B..L.?....!.E.......B_d...._+..?2.'$.zd........... ..D.o.......H....AF..2..H....>C.p..>.j..!.x.......... ..BF......?72.... ......@..o..........=:>M....i.n.......(.".u]q....e.q.k<..aT#........k7oEI.QLa4#.....E..`.#.....*.m.........F.....6.o..|}.__.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:MS Windows icon resource - 36 icons, 256x256, 16 colors with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 4 bits/pixel, -128x-128, 16 colors, 4 bits/pixel
Category:dropped
Size (bytes):199341
Entropy (8bit):3.2001483853537294
Encrypted:false
SSDEEP:1536:cpUNHIL4Oj0qwL2IupGF8yJtJFFhxGgX/3/HRVq:8mHILxnDIiGFxG4s
MD5:C8824EA3CE0A54FF1E89F8A296B4E64B
SHA1:333FEB78E9BB088650CE90DEA0F0CCC57D54A803
SHA-256:4BB9EA033F4E93DBF42FC74E6FAF94FE8B777A34836F7D537436CBE409FD743F
SHA-512:C40E40E0CB2AAA7CF7CCCBE29CA4530FF0E0A4DE9A7328996305DB6DFD6994CBE085FAB7B8F666BBD3D1EFD95406EA26B1376AA81908ACE60DC131A4E9C32D40
Malicious:false
Preview:....$.............F...........h(......@@......h...Y4..00......h....>..((..........)E..$$......X....I.. ..........IN..............1Q...............S...............U..........(....W...............X..........(L...k..@@......(.......00..............((..............$$......X...3... ......................`...3...............................[...........h...c......... ............... .(....,..@@.... .(B...4..00.... ..%...v..((.... .h...}...$$.... ........ .... .....m......... ............... ............... .....M......... ............... .h............. ............... ..........PNG........IHDR.............\r.f....pHYs..........o.d...]IDATx...[r#...PP.}.;.zg...6mY..J...9.....n.*...U....5jz~~~...Zk.z.^f?.........O.c.l~.z.^/...Q].. ..(...B.&.P..F$.@..T..(..#.. ...E..ac.. ...C..`C.....U..H.F.'.@7.+?....Do.`i...qB,7.......`Y.7...V%...a.E.0.P.I.$..Qz..}?W$..F..G.$.w.....A.0.....H"....5.E.0.....H......I.0...........5.&..F..O.LTw.g..D..L...%.&.?.o2<....L...#.&Xg..dz.<B....0...l.....9...@
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (614), with CRLF line terminators
Category:dropped
Size (bytes):2792198
Entropy (8bit):3.7092092700097195
Encrypted:false
SSDEEP:3072:4cveZOvedveoOveMve8OveeveHOvecygL+MscIl:mygL+MsJ
MD5:8E8C25B11FFE1D7BC70E2A31600EDA7A
SHA1:1452B55EF634E4E5B002CE302702D0C50487FF6C
SHA-256:A2BEC4E2AFD573422045C8C2F461166508535E67ABD32942D4D6FBED77B9FAF8
SHA-512:4A622A5D3748CE412BF529B11D305A5A06DD381A9B972FA08D0528DC738D50A979307CE6DFB14C9B481952672CA9C3A1BE43669796E5E178B23436B84BD0542A
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .x.m.l.n.s.:.i.r.o.n.m.a.n.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p./.2.0.0.8./.0.1./.i.m.". .S.e.t.u.p.V.e.r.s.i.o.n.=.".1...0.".>..... . .<.U.I. .D.l.l.=.".S.e.t.u.p.U.i...d.l.l.". .N.a.m.e.=.".M.i.c.r.o.s.o.f.t. ...N.E.T. .F.r.a.m.e.w.o.r.k. .4...8. .S.e.t.u.p.". .V.e.r.s.i.o.n.=.".4...8...0.4.1.1.5.". ./.>..... . .<.C.o.n.f.i.g.u.r.a.t.i.o.n.>..... . . . .<.D.i.s.a.b.l.e.d.C.o.m.m.a.n.d.L.i.n.e.S.w.i.t.c.h.e.s.>..... . . . . . .<.C.o.m.m.a.n.d.L.i.n.e.S.w.i.t.c.h. .N.a.m.e.=.".c.r.e.a.t.e.l.a.y.o.u.t.". ./.>..... . . . .<./.D.i.s.a.b.l.e.d.C.o.m.m.a.n.d.L.i.n.e.S.w.i.t.c.h.e.s.>..... . . . .<.U.s.e.r.E.x.p.e.r.i.e.n.c.e.D.a.t.a.C.o.l.l.e.c.t.i.o.n. .P.o.l.i.c.y.=.".O.S.C.o.n.t.r.o.l.l.e.d.". ./.>..... . . . .<.B.l.o.c.k.i.n.g.M.u.t.e.x. .N.a.m.e.=.".
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):122760
Entropy (8bit):6.319021816050886
Encrypted:false
SSDEEP:1536:jC5s1sWfcdmUtZ4e8ZXUSbeQCtyXWPQqOkAzoIt01WZnqxMQP8ZOs0JzoK9CeAUY:jKLmAgUSSQC4XeDOkeoNQ/gBFoWCnU
MD5:057CE4FB9C8E829AF369AFBC5C4DFD41
SHA1:094F9D5F107939250F03253CF6BB3A93AE5B2A10
SHA-256:60DD7D10B3F88F1B17E39464BB2D7CA77C9267B846D90CF5728A518A117BD21B
SHA-512:CAE4DF73A5B28863C14A5207FBBE4E0630E71215AA1271FE61117523CC32B8B82CD1BA63F698907FBFEB36D4007BB0F463828025957505CFCBB200F4ED5D3A52
Malicious:false
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........c..0..0..0 ..1..0P."0..0P. 0...0P.!0...0w..1...0w..1...0w..1...09..0..0..0...0 ..1..0 ..1..0 ..1..0 .,0..0 ..1..0Rich..0................PE..L....`.`.........."..................`............@..................................A....@...... ......................x....1..<....@...................#...........Y..T...........................HZ..@............0...............................text............................... ..`.data...............................@....idata.......0......................@..@.rsrc........@......................@..@.reloc..............................@..B................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):914824
Entropy (8bit):6.463140726430683
Encrypted:false
SSDEEP:24576:ZG2ynlYANtzSXWnTNPO5I4IHm7ONx3ZFaJ/KGvUnh:ZG2ynlYADzc3I4IHm7OjyJ/nvUnh
MD5:F9618535477DDFEF9FE8B531A44BE1A3
SHA1:C137A4C7994032A6410EF0A7E6F0F3C5ACB68E03
SHA-256:236BF2B5CF6014B8EE22484AFE172ACE512CC99DBA85080B082D47E9E189EA5C
SHA-512:B85AE1A9CC334E9352C51AA94B2C74C6C067957E0E6021F7309A1C194FC64C0C50BB5EFEAEF7030E8689D75A22798F74CF719366A2FDCCE26E23692510BFE064
Malicious:false
Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.............,..,..,.+.,..,.+.,..,<.B,..,Uq},..,Uq.,g.,Uq~,..,r..-..,r..-..,r..-..,<.G,..,..,..,%..-..,%..-..,%..-..,%.s,..,%..-..,Rich..,........PE..L....`.`.........."!.....@...................P.......................................3....@A........................pN..........|....0..(................#...@.......1..T...................@2.......1..@............................................text....?.......@.................. ..`.data...(....P.......D..............@....idata...'.......(..................@..@.tls......... ......................@....rsrc...(....0......................@..@.reloc.......@......................@..B................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):344440
Entropy (8bit):6.469225671212221
Encrypted:false
SSDEEP:6144:VTjfyZYXoH/6pPjW8CXunm+BgS1m/0yB8L:VuYLPK8m+BN1UPB8L
MD5:6F51E9B469F95EDB9156C74B4B0F4E1B
SHA1:5224C3DE0FA4895297898F76ED5647EF40D924F8
SHA-256:9FD4639955338928731A8AB6E131175949A179931B8C9D4FCADD2367D749B826
SHA-512:920F6525852A3A3636722FA8A36112D5402B22B7D93469443EBA2B782EF27D25532A8B6A922DAD2A60709C24E74527F639E2744BFD30635DDA80AB364376A32E
Malicious:false
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........K..f...f...f.3.....f.3.....f.3.....f...e...f...c...f...b...f.Zt....f...g.u.f.C.e...f.C.o...f.C.f...f.C....f.C.d...f.Rich..f.........PE..L....`.`.........."!.....|..........0........................................`......V.....@A........................ ...................................x#.......J.....T...........................8...@............................................text....{.......|.................. ..`.data...D9..........................@....idata..............................@..@.tls................................@....rsrc...............................@..@.reloc...J.......L..................@..B........................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, ASCII text, with very long lines (335), with CRLF line terminators
Category:dropped
Size (bytes):32572
Entropy (8bit):4.979287100529779
Encrypted:false
SSDEEP:768:hlzLm8eYhsLP8s05GFaAMET/chT+cxcW8G2P4oeTMC:lwchT+cxcDm
MD5:A9F6A028E93F3F6822EB900EC3FDA7AD
SHA1:8FF2E8F36D690A687233DBD2E72D98E16E7EF249
SHA-256:AAF8CB1A9AF89D250CBC0893A172E2C406043B1F81A211CB93604F165B051848
SHA-512:1C51392C334AEA17A25B20390CD4E7E99AA6373E2C2B97E7304CF7EC1A16679051A41E124C7BC890B02B890D4044B576B666EF50D06671F7636E4701970E8DDC
Malicious:false
Preview:<?xml version="1.0" encoding="utf-8"?>..<xs:schema xmlns:xs="http://www.w3.org/2001/XMLSchema".. xmlns="http://schemas.microsoft.com/SetupUI/2008/01/imui".. xmlns:imui="http://schemas.microsoft.com/SetupUI/2008/01/imui".. targetNamespace="http://schemas.microsoft.com/SetupUI/2008/01/imui".. elementFormDefault="qualified"..attributeFormDefault="unqualified"..>.... <xs:annotation>.. <xs:documentation>.. Copyright (c) Microsoft Corporation. All rights reserved... Schema for describing DevDiv "Setup UI Info".. </xs:documentation>.. </xs:annotation>.... <xs:element name="SetupUI">.. <xs:annotation>.. <xs:documentation>specifies UI dll, and lists of MSIs MSPs and EXEs</xs:documentation>.. </xs:annotation>.. <xs:complexType>.. <xs:sequence>.. <xs:choice>.. <xs:element ref="UI" minOccurs="1" maxOccurs="1"></xs:element>.. <xs:element ref="Strings" minOccurs="1" maxOccurs="1"></xs:element>..
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):311368
Entropy (8bit):6.648834384332185
Encrypted:false
SSDEEP:3072:xX7UkkkAg0FuAxZIrnnFujuw54qAYghp05vxMnW6FlZz3LUlimXBzmQHkyQUNKm/:1AORnnFujhGp05g9z3uioNPHioqkpf
MD5:2A20FF4988DB90AE0632D898916950CA
SHA1:F822B12F4EFB31A99EC4DF9A4D9C9806C55648FA
SHA-256:289E23983692BDBD58AB0CB3B1668B5158D90A9937721185A75247A44D0C3243
SHA-512:02003B403EC2375B9EE004978D522C91666F4AA642288EAD9963FF0E5701D2AB8EFA9B3854F13DCA8D85CF7B6B2890B000148A24D3565C9E4399B27936B691B0
Malicious:false
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$............t.Q.t.Q.t.Qb..Q.t.Q../Q.t.Q..-Q#t.Q..,Q.t.Q,..P.t.Q,..P.t.Q,..P.t.Qb..Q.t.Q.t.Q.t.Q{..P.t.Q{..P.t.Q{..P.t.Q{.!Q.t.Q.tIQ.t.Q{..P.t.QRich.t.Q........PE..L......].........."...............................@.......................................@...... ..................P.......,........ ...t...........~..HB.......+......T...................P...........@...............(............................text.............................. ..`.data....!..........................@....idata..............................@..@.tls................................@....rsrc....t... ...v..................@..@.reloc...+.......,...R..............@..B........................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PC bitmap, Windows 3.x format, 200 x 200 x 24, image size 120002, resolution 11808 x 11808 px/m, cbSize 120056, bits offset 54
Category:dropped
Size (bytes):120056
Entropy (8bit):2.0719076875994795
Encrypted:false
SSDEEP:384:pu66qlxe0UqtcSiS2gLsd5xfAg+zqFv4t:LP
MD5:BC32088BFAA1C76BA4B56639A2DEC592
SHA1:84B47AA37BDA0F4CD196BD5F4BD6926A594C5F82
SHA-256:B05141DBC71669A7872A8E735E5E43A7F9713D4363B7A97543E1E05DCD7470A7
SHA-512:4708015AA57F1225D928BFAC08ED835D31FD7BDF2C0420979FD7D0311779D78C392412E8353A401C1AA1885568174F6B9A1E02B863095FA491B81780D99D0830
Malicious:false
Preview:BM........6...(....................... ... ............-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.-\.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):14084
Entropy (8bit):3.701412990655975
Encrypted:false
SSDEEP:384:VqZo71GHY3vqaqMnYfHHVXIHjfBHwnwXCa+F:VqB
MD5:8A28B474F4849BEE7354BA4C74087CEA
SHA1:C17514DFC33DD14F57FF8660EB7B75AF9B2B37B0
SHA-256:2A7A44FB25476886617A1EC294A20A37552FD0824907F5284FADE3E496ED609B
SHA-512:A7927700D8050623BC5C761B215A97534C2C260FCAB68469B7A61C85E2DFF22ED9CF57E7CB5A6C8886422ABE7AC89B5C71E569741DB74DAA2DCB4152F14C2369
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p.U.I. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p.U.I./.2.0.0.8./.0.1./.i.m.u.i.". ..... . . . . . . . . .x.m.l.n.s.:.i.m.u.i.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p.U.I./.2.0.0.8./.0.1./.i.m.u.i.". .>..... . .<.S.t.r.i.n.g.s.>..... . . . .<.!.-.-. .R.e.f.l.e.c.t.i.v.e. .p.r.o.p.e.r.t.y. .p.a.g.e. .-.-.>..... . . . .<.I.D.S._.I.S._.R.E.A.L.L.Y._.C.A.N.C.E.L.>.#.(.l.o.c...i.d.s._.i.s._.r.e.a.l.l.y._.c.a.n.c.e.l.).<./.I.D.S._.I.S._.R.E.A.L.L.Y._.C.A.N.C.E.L.>......... . . . .<.!.-.-. .S.y.s.t.e.m. .R.e.q.u.i.r.e.m.e.n.t.s. .p.a.g.e. .-.-.>..... . . . .<.S.Y.S.R.E.Q.P.A.G.E._.R.E.Q.U.I.R.E.D._.A.N.D._.A.V.A.I.L.A.B.L.E._.D.I.S.K._.S.P.A.C.E.>.#.(.l.o.c...s.y.s.r.e.q.p.a.g.e._.r.e.q.u.i.r.e.d._.a.n.d._.a.v.a.i.l.a.b.l.e._.d.i.s.k._.s.p.a.c.e.).<./.S.Y.S.R.E.Q.P.A.G.E._.R.E.Q.U.I.R.E.D._.A.N.D._.A.V.A.I.L.A.B.L.E._.D.I.S.K._.S.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:XML 1.0 document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):65404
Entropy (8bit):3.049184035496474
Encrypted:false
SSDEEP:1536:24UR0d5vud5vcZ2QYQLIN/N7pfMGgrX8FPirziPfwws36z7y/HoQilwJwowJwXZR:24UR0d5vud5vcZ2QYQLIN/N7pfMGgrX5
MD5:C99059ACB88A8B651D7AB25E4047A52D
SHA1:45114125699FA472D54BC4C45C881667C117E5D4
SHA-256:B879F9BC5B79349FA7B0BDBE63167BE399C5278454C96773885BD70FBFE7C81D
SHA-512:B23A7051F94D72D5A1A0914107E5C2BE46C0DDEE7CA510167065B55E2D1CB25F81927467370700B1CC7449348D152E9562566DE501F3EA5673A2072248572E3B
Malicious:false
Preview:..<.?.x.m.l. .v.e.r.s.i.o.n.=.".1...0.". .e.n.c.o.d.i.n.g.=.".u.t.f.-.1.6.".?.>.....<.S.e.t.u.p.U.I. .x.m.l.n.s.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p.U.I./.2.0.0.8./.0.1./.i.m.u.i.". .x.m.l.n.s.:.i.m.u.i.=.".h.t.t.p.:././.s.c.h.e.m.a.s...m.i.c.r.o.s.o.f.t...c.o.m./.S.e.t.u.p.U.I./.2.0.0.8./.0.1./.i.m.u.i.". .>..... . .<.U.I.>......... . . . .<.R.e.s.o.u.r.c.e.D.l.l.>.S.e.t.u.p.R.e.s.o.u.r.c.e.s...d.l.l.<./.R.e.s.o.u.r.c.e.D.l.l.>..... . . . .<.!.-.-..... . . . .<.S.p.l.a.s.h.S.c.r.e.e.n.>..... . . . . . .<.H.i.d.e./.>..... . . . .<./.S.p.l.a.s.h.S.c.r.e.e.n.>..... . . . .-.-.>..... . . . .<.S.p.l.a.s.h.S.c.r.e.e.n.>..... . . . . . .<.F.i.l.e.N.a.m.e.>.S.p.l.a.s.h.S.c.r.e.e.n...b.m.p.<./.F.i.l.e.N.a.m.e.>..... . . . .<./.S.p.l.a.s.h.S.c.r.e.e.n.>......... . . . .<.L.C.I.D.H.i.n.t.s.>..... . . . . . .<.L.C.I.D.H.i.n.t.>..... . . . . . . . .<.R.e.g.K.e.y.>.H.K.C.U.\.S.o.f.t.w.a.r.e.\.M.i.c.r.o.s.o.f.t.\.V.i.s.u.a.l.S.t.u.d.i.o.\.9...0.\.G.e.n.e.r.a.l.<./.
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PC bitmap, Windows 3.x format, 49 x 49 x 32, image size 9606, resolution 11808 x 11808 px/m, cbSize 9660, bits offset 54
Category:dropped
Size (bytes):9660
Entropy (8bit):2.468970576931721
Encrypted:false
SSDEEP:12:0sUJX6qqfq+fk2CbCbCbB18e31331/V/SJ31jqAJ31DxJp1hQPJVsPP91bDUmJ35:0sUPHn2MMMQkEHDUx9Hk
MD5:41C22EFA84CA74F0CE7076EB9A482E38
SHA1:8E4A371FD51A61244D11C4FC97D738905CE00FBB
SHA-256:255025A0D79EF2DAC04BD610363F966EF58328400BF31E1F8915E676478CD750
SHA-512:8C83EDEECBD7D5FB64AA7F841BE3992BA8303B158A5360D9C7EAFB085CBC9B7258AF40F50570E0CA051CB6D235EA7E3EACF5CB8C7E39750601061F0B57338395
Malicious:false
Preview:BM.%......6...(...1...1..... ......%.. ... ............-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-\..-
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
Category:dropped
Size (bytes):228752
Entropy (8bit):6.648657735644274
Encrypted:false
SSDEEP:3072:dl5e8m9Z5G6ZUMIiaQVedGGEc6SYm8X/UvHFupHIjNNlMi/fbtcICcu0b9+x0o/N:WG6ZUon6GVSYmnGHEvlMMac59+xfbZ
MD5:0C0E41EFEEC8E4E78B43D7812857269A
SHA1:846033946013F959E29CD27FF3F0EAA17CB9E33F
SHA-256:048D51885874D62952E150D69489BCFB643A5131CE8B70A49F10DFB34832702C
SHA-512:E11DA01852A92833C1632E121A2F2B6588B58F4F2166339A28DD02DAD6AF231A2260A7E5FC92E415D05AA65B71E8BBDA065E82A2DB49BB94B6CF2FE82B646C28
Malicious:false
Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........_+..>EV.>EV.>EVWI.V.>EV.>DV.?EVWI.V.>EVWI.V.>EVWI.V.>EVWI.V.>EV..;V.>EVWI.V.>EVWI.V.>EVWI.V.>EVRich.>EV................PE..L......P...........!.........P......)........ .......................................8....@.............................P...,3.......P...............Z...#...`..@*......8...........................x...@............0..,............................text............................... ..`.data...H.... ......................@....idata.......0......................@..@.rsrc........P.......*..............@..@.reloc..@*...`...,..................@..B................................................................................................................................................................................................................................................................................................................
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:PC bitmap, Windows 3.x format, 164 x 628 x 8, image size 102994, resolution 3779 x 3779 px/m, cbSize 104072, bits offset 1078
Category:dropped
Size (bytes):104072
Entropy (8bit):7.2628723112196
Encrypted:false
SSDEEP:768:QKUpOeBmAj72KbvEvffvCv7cTIMUHuRzHA8X9H51T9ho4xw7CgB1:QKULmAfbvEv47cIHzE9vo4SuU1
MD5:B0075CEE80173D764C0237E840BA5879
SHA1:B4CF45CD5BB036F4F210DFCBA6AC16665A7C56A8
SHA-256:AB18374B3AAB10E5979E080D0410579F9771DB888BA1B80A5D81BA8896E2D33A
SHA-512:71A748C82CC8B0B42EF5A823BAC4819D290DA2EDDBB042646682BCCC7EB7AB320AFDCFDFE08B1D9EEBE149792B1259982E619F8E33845E33EEC808C546E5C829
Malicious:false
Preview:BM........6...(.......t...........R...................};.......F.......T...c....H..b...t...m...z...d...a..._...f...f....&..x...j...w...o...k...r....+..........|...u...|...q...v...w...|...2..~...z.......x...........{.................................................................... ...#..:..P..e................................#..#..&..(..+..+..-........EDA................$..,../..4..2..6..;...........................$..'..,..0..:..?..E......................6..5..>...D...I...K...Q...j...................=...D...L...P...U...V...\...r.....................Y...\...`...d...b...f...j...l...{..................................`...g...o...u...|....................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):338
Entropy (8bit):3.4620383296566426
Encrypted:false
SSDEEP:6:kKbey8QMiJFN+SkQlPlEGYRMY9z+s3Ql2DUevat:TeyVckPlE99SCQl2DUevat
MD5:0D6149F295BC82FBBBFFF19AD17A70FE
SHA1:C7BEBBEBCBAF7DADE8724EF23EF68FA8ABDC3C14
SHA-256:199914F559E86057F580CB661EE694B6D9BAA7BA027BAF6C14332FF5D132D748
SHA-512:FC6AD90E6D4D474907A64C1D777B570C00B2E8BEC0444CB0672CE78368621F0129851F39CE4315A79D8CFEA4489C4FFF47A510499A88122F38DAC3D2886A0987
Malicious:false
Preview:p...... ..........A.....(...................................................@... .........p.........$...............h.t.t.p.:././.c.t.l.d.l...w.i.n.d.o.w.s.u.p.d.a.t.e...c.o.m./.m.s.d.o.w.n.l.o.a.d./.u.p.d.a.t.e./.v.3./.s.t.a.t.i.c./.t.r.u.s.t.e.d.r./.e.n./.d.i.s.a.l.l.o.w.e.d.c.e.r.t.s.t.l...c.a.b...".7.4.6.7.8.7.a.3.f.0.d.9.1.:.0."...
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:JSON data
Category:dropped
Size (bytes):520156
Entropy (8bit):4.907666742859367
Encrypted:false
SSDEEP:3072:9omubOSb3F2Fq9VMjNYof+pmpnGDubTxZO7aYb6f5780K2:+bOq3OjNymtGyT
MD5:036628E3E3F0728DAA7D53AC1B3EF8CC
SHA1:65327D9039335E1BAF9E14639AE355195766C9EC
SHA-256:2CAEC4D00BD356241B8B405B1B74386C677D501A7A23CE6EF916EAF912541544
SHA-512:C6524E4C732E1827B4FA8DA07DFF92F3024E15822578C6945B8A076498A85FF0D0C933E01F2AF98BA90A3E6A24DAB1601C07BE9D8D7193F4FB48A8E63FA75821
Malicious:false
Preview:{"MajorVersion":4,"MinorVersion":39,"Expiration":14,"Fonts":[{"a":[4294966911],"f":"Abadi","fam":[],"sf":[{"c":[1,0],"dn":"Abadi","fs":32696,"ful":[{"lcp":983041,"lsc":"Latn","ltx":"Abadi"}],"gn":"Abadi","id":"23643452060","p":[2,11,6,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":26215680},{"c":[1,0],"dn":"Abadi Extra Light","fs":22180,"ful":[{"lcp":983042,"lsc":"Latn","ltx":"Abadi Extra Light"}],"gn":"Abadi Extra Light","id":"17656736728","p":[2,11,2,4,2,1,4,2,2,4],"sub":[],"t":"ttf","u":[2147483651,0,0,0],"v":197263,"w":13108480}]},{"a":[4294966911],"f":"ADLaM Display","fam":[],"sf":[{"c":[536870913,0],"dn":"ADLaM Display Regular","fs":140072,"ful":[{"lcp":983040,"lsc":"Latn","ltx":"ADLaM Display"}],"gn":"ADLaM Display","id":"31965479471","p":[2,1,0,0,0,0,0,0,0,0],"sub":[],"t":"ttf","u":[2147491951,1107296330,0,0],"v":131072,"w":26215680}]},{"a":[4294966911],"f":"Agency FB","fam":[],"sf":[{"c":[536870913,0],"dn":"Agency FB Bold","fs":54372,"ful":[{"lcp":9830
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:TrueType Font data, 10 tables, 1st "OS/2", 7 names, Microsoft, language 0x409, \251 2018 Microsoft Corporation. All Rights Reserved.msofp_4_39RegularVersion 4.39;O365
Category:dropped
Size (bytes):767532
Entropy (8bit):6.559103097590493
Encrypted:false
SSDEEP:12288:zn84XUdLDs51UJQSOf9VvLXHyheIQ47gEFGHtAgk3+/yLQ/zlm1kjFKy6Nyjbqq+:j8XNDs5+ivOXgm1kYvyz2
MD5:1BE236301B686323302632C0EACCFD6F
SHA1:7EF18B642DBFA9FB6E8AFABACB50F6CA6BD73BB4
SHA-256:90200D640623BFB0518B18D72C3F9828BC6EDA63EAB2DA90FBC27A08AAD165D7
SHA-512:BA6763BDB0C19103E417D808939739EF61FC15C7C4E7A8D10BB0120DC461D028054FF20A54BCB9A98FA9702B412D14CDC0270F2147F6C3FF5CB22A711934F276
Malicious:false
Preview:........... OS/29....(...`cmap.s.(.......pglyf..&?...\....head2'.........6hheaE.@r.......$hmtxr..........0loca.+.....(...4maxp........... name.X+.........post...<....... .........Z.9_.<...........<........$....Aa...................Q....Aa....Aa.........................~...................................................3..............................MS .@.......(...Q................. ...........d...........0...J.......8.......>..........+a..#...,................................................/...K.......z...............N......*...!...-...+........z.......h..%^..3...&j..+...+%..'R..+..."....................l......$A...,.......g...&...=.......X..&........*......&....B..(B...............#.......j...............+...P...5...@...)..........#...)Q...............*...{.. ....?..'...#....N...7......<...;>.............. ]...........5......#....s.......$.......$.......^..................+...>....H.......%...7.......6.......O...V...........K......"........c...N......!...............$...&...*p..
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):2278
Entropy (8bit):3.848314940012102
Encrypted:false
SSDEEP:48:uiTrlKxsxxuixl9Il8u8okMHzL0dobYtkSJG/s6d1rc:vPYcMTgdHUm
MD5:EC3C5A0432D63824E959B316E782187F
SHA1:11BDCBBE3FC704ACA83585F56CC8F809410BB16B
SHA-256:0476A7D6D8E169D190E1E5792AB1217B9B4ED79EECEA0A5BCB916C984C1E0CAD
SHA-512:A4C98E2A6A9545717020BDE5FD371A35BA57A7BF26D4413D2AF30DF3A3A24BAE9CC4FE168D6A97AE93AE4B7C6C1827C8807341A2C468B8B97447AD8E721A0E59
Malicious:false
Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".C.J.1.m.u.g.S.o.z.s.S.9.x.S.Z./.Q.v.O.c.+.E.J.4.u.2.c.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.O.i.w.N.B.S.X.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.A.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.z.e.M.G.p.B.
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):4542
Entropy (8bit):4.0037241446782
Encrypted:false
SSDEEP:96:YYcOEuvBnXvpxdB7gkmMYFeW6K12kOZdzj7nkLQKjItvwoHD:YSEupX9B7gKYEWFkxPnm7KwoHD
MD5:65A143DF329CFA66B47A91C06A7EA2F0
SHA1:08F201E9CAED250178EDB0C1040FAE72C614C3EB
SHA-256:1631CC82CDD92C112CB39F8A4F9B4C205C5CCA596D06185E02ABD6F0987C8E40
SHA-512:D56D3DF752609BD0CF02C1635470683AB900D6C4E61E0EDE529CABF29EB19BE746F497C023636A1FE631C5969BE2003BE8C7DED9D3120B2D46DE6D2BDC0E12C5
Malicious:false
Preview:{.".T.B.D.a.t.a.S.t.o.r.e.O.b.j.e.c.t.".:.{.".H.e.a.d.e.r.".:.{.".O.b.j.e.c.t.T.y.p.e.".:.".T.o.k.e.n.R.e.s.p.o.n.s.e.".,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.a.j.o.r.".:.2.,.".S.c.h.e.m.a.V.e.r.s.i.o.n.M.i.n.o.r.".:.1.}.,.".O.b.j.e.c.t.D.a.t.a.".:.{.".S.y.s.t.e.m.D.e.f.i.n.e.d.P.r.o.p.e.r.t.i.e.s.".:.{.".R.e.q.u.e.s.t.I.n.d.e.x.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".V.q.Y.a.6.3.X.Y.9.b.4.Y.b.C.Z.g.f.0.u.y.E.6.v.n.x.e.w.=.".}.,.".E.x.p.i.r.a.t.i.o.n.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".j.n.p.2.G.g.y.X.2.g.E.=.".}.,.".S.t.a.t.u.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.f.a.l.s.e.,.".V.a.l.u.e.".:.".A.w.A.A.A.A.=.=.".}.,.".R.e.s.p.o.n.s.e.B.y.t.e.s.".:.{.".T.y.p.e.".:.".I.n.l.i.n.e.B.y.t.e.s.".,.".I.s.P.r.o.t.e.c.t.e.d.".:.t.r.u.e.,.".V.a.l.u.e.".:.".A.Q.A.A.A.N.C.M.n.d.8.B.F.d.E.R.j.H.o.A.w.E./.C.l.+.s.B.A.A.A.A.z.e.M.G.p.B.
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):1536
Entropy (8bit):1.1061695326289382
Encrypted:false
SSDEEP:6:slzXlcIaKblfaqp1hqtYrsfcjU0ktJ6gm+lllvET4ZJdZb:EjlcIa4LFqCscKtw+lllvE0dl
MD5:8B897AFACDF983781325C1A5E15E3C39
SHA1:F210C3EAC93F139FB13FC0D4B5B3E5B7E261B005
SHA-256:FD355AA377417480C68BB11F0664397F2D12AD2AF428B11BDBB4C562C8763ABB
SHA-512:BFE53270FE2169096131BAB28CFF1E3D3077EE9A2A0B0C853437A6203EF3B0103FA524496E166035F27DD9A6E9393857B228ACB849F2277EB1FDFEF49059B7A2
Malicious:false
Preview:D.e.t.a.i.l.s.......N.E.T. .F.r.a.m.e.w.o.r.k. .4...8. .o.r. .a. .l.a.t.e.r. .u.p.d.a.t.e. .i.s. .a.l.r.e.a.d.y. .i.n.s.t.a.l.l.e.d. .o.n. .t.h.i.s. .c.o.m.p.u.t.e.r.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!5..>*.CJ..K
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):1024
Entropy (8bit):0.03351732319703582
Encrypted:false
SSDEEP:3:ol3lG:40
MD5:830FBF83999E052538EAF156AB6ECB17
SHA1:9F6C69FA4232801D3A4857C630BA7A719662135A
SHA-256:D5098A2CEAE815DB29CD53C76F85240C95DC4D2E3FEDDD71D628617064C29869
SHA-512:A83E2E9D5274F0065A26C306F355E9590D6126297EAD87AF053CC78FB64CB31694C533139F72686C77FC772148181D8AAE973E65978D04E5F20F6F6C6BA0A013
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):1536
Entropy (8bit):1.1061695326289382
Encrypted:false
SSDEEP:6:slzXlcIaKblfaqp1hqtYrsfcjU0ktJ6gm+lllvET4ZJdZb:EjlcIa4LFqCscKtw+lllvE0dl
MD5:8B897AFACDF983781325C1A5E15E3C39
SHA1:F210C3EAC93F139FB13FC0D4B5B3E5B7E261B005
SHA-256:FD355AA377417480C68BB11F0664397F2D12AD2AF428B11BDBB4C562C8763ABB
SHA-512:BFE53270FE2169096131BAB28CFF1E3D3077EE9A2A0B0C853437A6203EF3B0103FA524496E166035F27DD9A6E9393857B228ACB849F2277EB1FDFEF49059B7A2
Malicious:false
Preview:D.e.t.a.i.l.s.......N.E.T. .F.r.a.m.e.w.o.r.k. .4...8. .o.r. .a. .l.a.t.e.r. .u.p.d.a.t.e. .i.s. .a.l.r.e.a.d.y. .i.n.s.t.a.l.l.e.d. .o.n. .t.h.i.s. .c.o.m.p.u.t.e.r.......................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................!5..>*.CJ..K
Process:C:\5478d9557b6298dc63ac5974e1\Setup.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 2057
Category:dropped
Size (bytes):276
Entropy (8bit):4.911147031403735
Encrypted:false
SSDEEP:6:L4VXdLz6DyoVR5QalKefqeS4CAYOBFQrZIG62:MXdLOffQalqeS4CAJ8lIz2
MD5:3E6FC45076A192B91BE2451C152593E0
SHA1:CE9F2D509148EC7CCF7E571C0DD0D9E416136736
SHA-256:5785F21E3A0AA016D125747F8EFD038EAC8D65F379C398B4F557CAC992DF3D33
SHA-512:DA8CB0D5628406279A4D09F06386917E972CE68918720A090F6C0E9D1161AB3371AFFED2D39A44ED2F365A272C1D9B8E777A41EE82576951C0007DE8DBE98353
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\deflang2057{\fonttbl{\f0\fnil\fcharset0 MS Shell Dlg 2;}}..\viewkind4\uc1\pard\ul\b\f0\fs23 Details\ulnone\b0\fs17\par..\par..\pard\li175 .NET Framework 4.8 or a later update is already installed on this computer.\par..\pard\par..\par..\par..}...
Process:C:\5478d9557b6298dc63ac5974e1\Setup.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 2057
Category:dropped
Size (bytes):276
Entropy (8bit):4.911147031403735
Encrypted:false
SSDEEP:6:L4VXdLz6DyoVR5QalKefqeS4CAYOBFQrZIG62:MXdLOffQalqeS4CAJ8lIz2
MD5:3E6FC45076A192B91BE2451C152593E0
SHA1:CE9F2D509148EC7CCF7E571C0DD0D9E416136736
SHA-256:5785F21E3A0AA016D125747F8EFD038EAC8D65F379C398B4F557CAC992DF3D33
SHA-512:DA8CB0D5628406279A4D09F06386917E972CE68918720A090F6C0E9D1161AB3371AFFED2D39A44ED2F365A272C1D9B8E777A41EE82576951C0007DE8DBE98353
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\deflang2057{\fonttbl{\f0\fnil\fcharset0 MS Shell Dlg 2;}}..\viewkind4\uc1\pard\ul\b\f0\fs23 Details\ulnone\b0\fs17\par..\par..\pard\li175 .NET Framework 4.8 or a later update is already installed on this computer.\par..\pard\par..\par..\par..}...
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:ASCII text, with very long lines (1338), with CRLF line terminators
Category:dropped
Size (bytes):11331
Entropy (8bit):5.5027161736649095
Encrypted:false
SSDEEP:192:MTKKTXh/hzal/ke6Cs06LKv9xwVMW6dITLJtL+4zf4HnV+:MVTR5zal/ke6Cs0L1xwV76dIv7L+4zfD
MD5:E72D363B76572E75993530BD9B453919
SHA1:5E1E0826273A3304061A888A236E7B421B171FEC
SHA-256:E25A34E35FA85C18B78D3303D7446A39B439CBED8F0EF326E4E40470A1BE4A0E
SHA-512:D86043CBDF4FDC86431360E0B89E02734C12FAEAD6F712ACE6F4F875B9B48C6A7CF67AE483EE1F9B3B97CB29C37B3D388BF387B2525C1F02D278D9B200A58C35
Malicious:false
Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..04/25/2024 12:26:38.167.WINWORD (0x1DE4).0x1E38.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":23,"Time":"2024-04-25T12:26:38.167Z","Contract":"Office.System.Activity","Activity.CV":"lif83mkZgk2abr3xcW6LBQ.7.1","Activity.Duration":220,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Activity.Result.Code":-2147024890,"Activity.Result.Type":"HRESULT","Activity.Result.Tag":528307459}...04/25/2024 12:26:38.167.WINWORD (0x1DE4).0x1E38.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.ProcessIdleQueueJob","Flags":33777014401990913,"InternalSequenceNumber":24,"Time":"2024-04-25T12:26:38.167Z","Contract":"Office.System.Activity","Activity.CV":"lif83mkZgk2abr3xcW6LBQ.7","Activity.Duration":2004,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Data.FailureD
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):20971520
Entropy (8bit):0.009696641803978336
Encrypted:false
SSDEEP:384:CJTx9ifvKvapo6peJqu2GdIhm6tlCRRcBZ:CJTx9ifvKvapvpeJqu2lm6tlCRRcBZ
MD5:D8105A47EE583CF68E3A965A30863E36
SHA1:A390EF24D3B3B1D3BF40BA498F74366DFB6B195B
SHA-256:7CD80F676208CAA192B63F07F158047DB8EA7A364D765B094BC8EFEC3A3515B1
SHA-512:68A0B72325DCC8BA6F92D64588BA19AACF6C4B376C1B05DAD91F5954AE3B1E4088A0234087CE53469F94627684D07C18B3B79A5467E35261E80C0C83D9FB22E9
Malicious:false
Preview:Timestamp.Process.TID.Area.Category.EventID.Level.Message.Correlation..04/25/2024 12:26:42.305.WINWORD (0xD9C).0x1890.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.LoadXmlRules","Flags":33777014401990913,"InternalSequenceNumber":24,"Time":"2024-04-25T12:26:42.305Z","Contract":"Office.System.Activity","Activity.CV":"HhdWJCze+k+f4aCKzWq9JA.7.1","Activity.Duration":242,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Activity.Result.Code":-2147024890,"Activity.Result.Type":"HRESULT","Activity.Result.Tag":528307459}...04/25/2024 12:26:42.305.WINWORD (0xD9C).0x1890.Microsoft Word.Telemetry Event.b7vzq.Medium.SendEvent {"EventName":"Office.Telemetry.ProcessIdleQueueJob","Flags":33777014401990913,"InternalSequenceNumber":25,"Time":"2024-04-25T12:26:42.305Z","Contract":"Office.System.Activity","Activity.CV":"HhdWJCze+k+f4aCKzWq9JA.7","Activity.Duration":565,"Activity.Count":1,"Activity.AggMode":0,"Activity.Success":false,"Data.FailureDiag
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):20971520
Entropy (8bit):0.0
Encrypted:false
SSDEEP:3::
MD5:8F4E33F3DC3E414FF94E5FB6905CBA8C
SHA1:9674344C90C2F0646F0B78026E127C9B86E3AD77
SHA-256:CD52D81E25F372E6FA4DB2C0DFCEB59862C1969CAB17096DA352B34950C973CC
SHA-512:7FB91E868F3923BBD043725818EF3A5D8D08EBF1059A18AC0FE07040D32EEBA517DA11515E6A4AFAEB29BCC5E0F1543BA2C595B0FE8E6167DDC5E6793EDEF5BB
Malicious:false
Preview:........................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
Process:C:\5478d9557b6298dc63ac5974e1\Setup.exe
File Type:HTML document, Unicode text, UTF-16, little-endian text, with CRLF line terminators
Category:dropped
Size (bytes):16118
Entropy (8bit):3.6434775915277604
Encrypted:false
SSDEEP:192:7Ddx3KOTczFQ21Kp4n5DTx1iDecPeLHLHQFJFjZWblWUxFzJzcKHjT:fdsOT01KcBUFJFEWUxFzvHH
MD5:CD131D41791A543CC6F6ED1EA5BD257C
SHA1:F42A2708A0B42A13530D26515274D1FCDBFE8490
SHA-256:E139AF8858FE90127095AC1C4685BCD849437EF0DF7C416033554703F5D864BB
SHA-512:A6EE9AF8F8C2C7ACD58DD3C42B8D70C55202B382FFC5A93772AF7BF7D7740C1162BB6D38A4307B1802294A18EB52032D410E128072AF7D4F9D54F415BE020C9A
Malicious:false
Preview:..<.!.D.O.C.T.Y.P.E. .h.t.m.l. .P.U.B.L.I.C. .".-././.W.3.C././.D.T.D. .X.H.T.M.L. .1...1././.E.N.". .".h.t.t.p.:././.w.w.w...w.3...o.r.g./.T.R./.x.h.t.m.l.1.1./.D.T.D./.x.h.t.m.l.1.1...d.t.d.".>.....<.!.-.-. .T.h.e. .E.x.t.e.n.d.e.d. .C.o.p.y.r.i.g.h.t./.T.r.a.d.e.m.a.r.k. .L.a.n.g.u.a.g.e. .R.e.s.i.d.e.s. .A.t.:. .h.t.t.p.:././.w.w.w...m.i.c.r.o.s.o.f.t...c.o.m./.i.n.f.o./.c.p.y.r.t.I.n.f.r.g...h.t.m. .-.-.>.....<.h.t.m.l. .x.m.l.n.s.=.".h.t.t.p.:././.w.w.w...w.3...o.r.g./.1.9.9.9./.x.h.t.m.l.".>.....<.h.e.a.d.>.......<.m.e.t.a. .h.t.t.p.-.e.q.u.i.v.=.".C.o.n.t.e.n.t.-.T.y.p.e.". .c.o.n.t.e.n.t.=.".t.e.x.t./.h.t.m.l.;. .c.h.a.r.s.e.t.=.u.t.f.-.1.6."./.>.<.b.a.s.e. .t.a.r.g.e.t.=."._.b.l.a.n.k."./.>.......<.s.t.y.l.e. .t.y.p.e.=.".t.e.x.t./.c.s.s.".>.........h.t.m.l.{.o.v.e.r.f.l.o.w.:.s.c.r.o.l.l.}.........b.o.d.y.{.f.o.n.t.-.s.i.z.e.:.1.0.p.t.;.f.o.n.t.-.f.a.m.i.l.y.:.V.e.r.d.a.n.a.;.c.o.l.o.r.:.#.0.0.0.0.0.0.;.b.a.c.k.g.r.o.u.n.d.-.c.o.l.o.r.:.#.F.0.F.0.F.0.}...........h.e.a.d.e.r.
Process:C:\5478d9557b6298dc63ac5974e1\Setup.exe
File Type:HTML document, Unicode text, UTF-16, little-endian text, with very long lines (389), with CRLF line terminators
Category:dropped
Size (bytes):109380
Entropy (8bit):3.681954226234908
Encrypted:false
SSDEEP:768:fdsOTLyUFJFEWUxFzvzvRMGp9f4BPQJkqtBnKoX:fdsWyUr+WUxpvzJpWQZ
MD5:DE5934E7B046748AA4752253FF0D6035
SHA1:3D67638B81B9624BD413664958A0404029F40BFD
SHA-256:6711B98F24251EDD76ED536458E97A4396D93D60BE4075C96CA01C2691D607C5
SHA-512:DC2D5BFFDB9D980849E6E66AEC5D70DE5C196F635A2BC98CC1405B56C2CD1506C1AC6549B68CA46511F490FCB9DA0F41799C4DB4178D6D269EBCD1A92E8CEE4C
Malicious:false
Preview:..<.!.D.O.C.T.Y.P.E. .h.t.m.l. .P.U.B.L.I.C. .".-././.W.3.C././.D.T.D. .X.H.T.M.L. .1...1././.E.N.". .".h.t.t.p.:././.w.w.w...w.3...o.r.g./.T.R./.x.h.t.m.l.1.1./.D.T.D./.x.h.t.m.l.1.1...d.t.d.".>.....<.!.-.-. .T.h.e. .E.x.t.e.n.d.e.d. .C.o.p.y.r.i.g.h.t./.T.r.a.d.e.m.a.r.k. .L.a.n.g.u.a.g.e. .R.e.s.i.d.e.s. .A.t.:. .h.t.t.p.:././.w.w.w...m.i.c.r.o.s.o.f.t...c.o.m./.i.n.f.o./.c.p.y.r.t.I.n.f.r.g...h.t.m. .-.-.>.....<.h.t.m.l. .x.m.l.n.s.=.".h.t.t.p.:././.w.w.w...w.3...o.r.g./.1.9.9.9./.x.h.t.m.l.".>.....<.h.e.a.d.>.......<.m.e.t.a. .h.t.t.p.-.e.q.u.i.v.=.".C.o.n.t.e.n.t.-.T.y.p.e.". .c.o.n.t.e.n.t.=.".t.e.x.t./.h.t.m.l.;. .c.h.a.r.s.e.t.=.u.t.f.-.1.6."./.>.<.b.a.s.e. .t.a.r.g.e.t.=."._.b.l.a.n.k."./.>.......<.s.t.y.l.e. .t.y.p.e.=.".t.e.x.t./.c.s.s.".>.........h.t.m.l.{.o.v.e.r.f.l.o.w.:.s.c.r.o.l.l.}.........b.o.d.y.{.f.o.n.t.-.s.i.z.e.:.1.0.p.t.;.f.o.n.t.-.f.a.m.i.l.y.:.V.e.r.d.a.n.a.;.c.o.l.o.r.:.#.0.0.0.0.0.0.;.b.a.c.k.g.r.o.u.n.d.-.c.o.l.o.r.:.#.F.0.F.0.F.0.}...........h.e.a.d.e.r.
Process:C:\5478d9557b6298dc63ac5974e1\Setup.exe
File Type:HTML document, Unicode text, UTF-16, little-endian text, with very long lines (389), with CRLF line terminators
Category:dropped
Size (bytes):54172
Entropy (8bit):3.7212020758378865
Encrypted:false
SSDEEP:384:fdsOT01KcBUFJFEWUxFzvHTvRM3g8ChpwoZ:fdsOTLyUFJFEWUxFzvzvRMGpT
MD5:C9CCF1ECDA7DC84C08E30D5E2AC1C5FB
SHA1:946C119163358F77CDE168E08F3073DC87D07F4A
SHA-256:70C9B6DC0990BA118FB943D92B3D5F1B3FA22B0F66A5C847948E68D73A262DAD
SHA-512:0C750696B19A19499BF62D782CC2B45CAACE496E217415CABC60BC5F78D4DED4DF8490F4C885FBF4ECC31D8A8F6C055A03CE4D7965118386086D9FF71FE24004
Malicious:false
Preview:..<.!.D.O.C.T.Y.P.E. .h.t.m.l. .P.U.B.L.I.C. .".-././.W.3.C././.D.T.D. .X.H.T.M.L. .1...1././.E.N.". .".h.t.t.p.:././.w.w.w...w.3...o.r.g./.T.R./.x.h.t.m.l.1.1./.D.T.D./.x.h.t.m.l.1.1...d.t.d.".>.....<.!.-.-. .T.h.e. .E.x.t.e.n.d.e.d. .C.o.p.y.r.i.g.h.t./.T.r.a.d.e.m.a.r.k. .L.a.n.g.u.a.g.e. .R.e.s.i.d.e.s. .A.t.:. .h.t.t.p.:././.w.w.w...m.i.c.r.o.s.o.f.t...c.o.m./.i.n.f.o./.c.p.y.r.t.I.n.f.r.g...h.t.m. .-.-.>.....<.h.t.m.l. .x.m.l.n.s.=.".h.t.t.p.:././.w.w.w...w.3...o.r.g./.1.9.9.9./.x.h.t.m.l.".>.....<.h.e.a.d.>.......<.m.e.t.a. .h.t.t.p.-.e.q.u.i.v.=.".C.o.n.t.e.n.t.-.T.y.p.e.". .c.o.n.t.e.n.t.=.".t.e.x.t./.h.t.m.l.;. .c.h.a.r.s.e.t.=.u.t.f.-.1.6."./.>.<.b.a.s.e. .t.a.r.g.e.t.=."._.b.l.a.n.k."./.>.......<.s.t.y.l.e. .t.y.p.e.=.".t.e.x.t./.c.s.s.".>.........h.t.m.l.{.o.v.e.r.f.l.o.w.:.s.c.r.o.l.l.}.........b.o.d.y.{.f.o.n.t.-.s.i.z.e.:.1.0.p.t.;.f.o.n.t.-.f.a.m.i.l.y.:.V.e.r.d.a.n.a.;.c.o.l.o.r.:.#.0.0.0.0.0.0.;.b.a.c.k.g.r.o.u.n.d.-.c.o.l.o.r.:.#.F.0.F.0.F.0.}...........h.e.a.d.e.r.
Process:C:\5478d9557b6298dc63ac5974e1\Setup.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 2057
Category:dropped
Size (bytes):276
Entropy (8bit):4.911147031403735
Encrypted:false
SSDEEP:6:L4VXdLz6DyoVR5QalKefqeS4CAYOBFQrZIG62:MXdLOffQalqeS4CAJ8lIz2
MD5:3E6FC45076A192B91BE2451C152593E0
SHA1:CE9F2D509148EC7CCF7E571C0DD0D9E416136736
SHA-256:5785F21E3A0AA016D125747F8EFD038EAC8D65F379C398B4F557CAC992DF3D33
SHA-512:DA8CB0D5628406279A4D09F06386917E972CE68918720A090F6C0E9D1161AB3371AFFED2D39A44ED2F365A272C1D9B8E777A41EE82576951C0007DE8DBE98353
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\deflang2057{\fonttbl{\f0\fnil\fcharset0 MS Shell Dlg 2;}}..\viewkind4\uc1\pard\ul\b\f0\fs23 Details\ulnone\b0\fs17\par..\par..\pard\li175 .NET Framework 4.8 or a later update is already installed on this computer.\par..\pard\par..\par..\par..}...
Process:C:\5478d9557b6298dc63ac5974e1\Setup.exe
File Type:Rich Text Format data, version 1, ANSI, code page 1252, default language ID 2057
Category:modified
Size (bytes):276
Entropy (8bit):4.911147031403735
Encrypted:false
SSDEEP:6:L4VXdLz6DyoVR5QalKefqeS4CAYOBFQrZIG62:MXdLOffQalqeS4CAJ8lIz2
MD5:3E6FC45076A192B91BE2451C152593E0
SHA1:CE9F2D509148EC7CCF7E571C0DD0D9E416136736
SHA-256:5785F21E3A0AA016D125747F8EFD038EAC8D65F379C398B4F557CAC992DF3D33
SHA-512:DA8CB0D5628406279A4D09F06386917E972CE68918720A090F6C0E9D1161AB3371AFFED2D39A44ED2F365A272C1D9B8E777A41EE82576951C0007DE8DBE98353
Malicious:false
Preview:{\rtf1\ansi\ansicpg1252\deff0\deflang2057{\fonttbl{\f0\fnil\fcharset0 MS Shell Dlg 2;}}..\viewkind4\uc1\pard\ul\b\f0\fs23 Details\ulnone\b0\fs17\par..\par..\pard\li175 .NET Framework 4.8 or a later update is already installed on this computer.\par..\pard\par..\par..\par..}...
Process:C:\Users\user\Desktop\ndp48-web.exe
File Type:CSV text
Category:dropped
Size (bytes):1005
Entropy (8bit):5.187469451424963
Encrypted:false
SSDEEP:24:mtrRuB0ekjmztj10v9LK4Fq3jHIWtkFxjHKbFIKIoF0:mtSSmzt50vk4WIWShD
MD5:DCB212ECAFCA6B81B21F176FFDB85B6E
SHA1:563272BAA39F6F25CC9497837E13E8BDC641356F
SHA-256:02615184AA4B7A4580CE1BA7A072C92F815CE1174A31AE2D3458789DED7301DC
SHA-512:083143CA428EDA11FF4206BC0FC35A71A251F4420691DC65D839634ED6150FD805F1F9C3A4936A9C9B95F6290DBA2E3CB612C033C0641EB9E6056430374EB39C
Malicious:false
Preview:[4/25/2024, 14:26:28] === Logging started: 2024/04/25 14:26:28 ===..[4/25/2024, 14:26:28] Executable: C:\Users\user\Desktop\ndp48-web.exe v4.8.4115.0..[4/25/2024, 14:26:28] --- logging level: standard ---..[4/25/2024, 14:26:28] Successfully bound to the ClusApi.dll..[4/25/2024, 14:26:28] Error 0x800706d9: Failed to open the current cluster..[4/25/2024, 14:26:28] Cluster drive map: ''..[4/25/2024, 14:26:28] Considering drive: 'C:\'.....[4/25/2024, 14:26:28] Considering drive: 'D:\'.....[4/25/2024, 14:26:28] Drive 'D:\' is rejected because of the unknown or unsuitable drive type..[4/25/2024, 14:26:28] Drive 'C:\' has been selected as the largest fixed drive..[4/25/2024, 14:26:28] Directory 'C:\5478d9557b6298dc63ac5974e1\' has been selected for file extraction..[4/25/2024, 14:26:28] Extracting files to: C:\5478d9557b6298dc63ac5974e1\..[4/25/2024, 14:26:30] Extraction took 1.953 seconds..[4/25/2024, 14:26:30] Executing command line: 'C:\5478d9557b6298dc63ac5974e1\\Setup.exe /x86 /x64 /w
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):162
Entropy (8bit):4.053723428955606
Encrypted:false
SSDEEP:3:goN+CAfEBLOBFQrJbIrXEas5VuFl/DeRKsjsY2N:l4CAYOBFQrZIGmL7sj5q
MD5:667E2C1CCDF2F9C4DC30A961E4362AB4
SHA1:D096A1D787161948934C99364004D8C6EA7FD199
SHA-256:4EE0085BD621FA5E9592ECDA5FFF6467785BB28975018F95592A4CC102380DB7
SHA-512:FD715116C58457F2920A6CEA19CFDB8B0C5969FB9CDFE0AAC1A56A592535C628A6EDC142B4A3B4D0453D271C05CEACA1820D5689E31D1E715FDA7367ACF07F47
Malicious:false
Preview:...........................................................8 or a later update is already installed on this computer.\par..\pard\p..........yD.3.}..i....PY3..=.h
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):162
Entropy (8bit):4.089627420128181
Encrypted:false
SSDEEP:3:KVGl/lilKlRAGlmVQEAfEBLOBFQrJbIrXEas5VuFl/02a3lspn:KVy/4KDkAYOBFQrZIGms2xpn
MD5:6CE48C0D8E9102F74AD235DDC72792C2
SHA1:10C821BC2CA584DDE1808270F5AB7CD4EEBDA477
SHA-256:AFE1822DA215B874CEA471BA18C5305EFF44A215E3C46F057E7936F7B2B91358
SHA-512:F434B52393BEB3B03F903EB0A5C70858D07948B9A2CDD6A0FEF511666AEE5A164C27543D1BA50E247C8C89388989B0A977D5B0D5A052C27CA6BEB316F98A7CB1
Malicious:false
Preview:.user..................................................j.o.n.e.s...ter update is already installed on this computer.\par..\pard\p.........J._....}..i....(Y...=.h
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):30
Entropy (8bit):1.2389205950315936
Encrypted:false
SSDEEP:3:AOZ:AO
MD5:BB60905373DD750F890489DBFFBACF2F
SHA1:A323605502252AC49BCA09D3D6A8E97ADF4CDAAA
SHA-256:B2082B1C0B4CE7F9FC8DA4666C0A146ACEC50ABE2B98206888454583DE668643
SHA-512:F5118C6A6150E7F432AA072013F9A97B2C45A4949A15AD442A4544061E5685B253783BEC356153208CBF1E3D250FE5F549072E801CEDFC96A14A18B1DC42702A
Malicious:false
Preview:....7.........................
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Directory, ctime=Thu Apr 25 11:26:37 2024, mtime=Thu Apr 25 11:26:40 2024, atime=Thu Apr 25 11:26:40 2024, length=0, window=hide
Category:dropped
Size (bytes):1164
Entropy (8bit):4.669997983749347
Encrypted:false
SSDEEP:12:8XJMtC4UlGI4CICH25+MQ/+Id0/AFF7SLwjTWzXoVjV4Vl+EjAArHSuT1lilG3m1:8ZEaGl+zR6YFF4NyQAAmuTqT4XqyFm
MD5:835FF1CDEF5E4942E6BAB0C3D67EED54
SHA1:08BFB125C0FA2D2D9A3CC832C996C1B09CBF101E
SHA-256:7D9AF1E3B71C1CE1FBAA457EAE623D9DFFEFA1C1F030B2B1AB57B00ADB12B084
SHA-512:E99CC9C17177048D324A9225C376BD4631C85D3F9F2972C5B4147FF951FB6887C9D6852E31B793521E5B5A7D07E3321C02C66F882132FF9001E32961C219CF94
Malicious:false
Preview:L..................F.................5.......-.............................[....P.O. .:i.....+00.../C:\...................x.1.....CW;^..Users.d......OwH.XMc....................:.....K...U.s.e.r.s...@.s.h.e.l.l.3.2...d.l.l.,.-.2.1.8.1.3.....P.1......XKc..user.<......CW.^.XMc.............................j.o.n.e.s.....V.1.....CW.^..AppData.@......CW.^.XMc...........................%..A.p.p.D.a.t.a.....V.1......XKc..Roaming.@......CW.^.XKc...........................:..R.o.a.m.i.n.g.....\.1......XTc..MICROS~1..D......CW.^.XTc..........................j`..M.i.c.r.o.s.o.f.t.....\.1......XSc..TEMPLA~1..D......XSc.XSc.....C.....................h..T.e.m.p.l.a.t.e.s.......a...............-.......`............F.......C:\Users\user\AppData\Roaming\Microsoft\Templates........\.....\.T.e.m.p.l.a.t.e.s...........................>.e.L.:..er.=....`.......X.......960781...........hT..CrF.f4... ..T..b...,.......hT..CrF.f4... ..T..b...,..................1SPS.XF.L8C....&.m.q............/...S
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:ASCII text, with CRLF line terminators
Category:dropped
Size (bytes):28
Entropy (8bit):4.351823225551765
Encrypted:false
SSDEEP:3:bDuMJlv:bCy
MD5:4E30A3397E81DD38A188E78FC94E5A77
SHA1:95E2EFA493065E02C7370BEFBE5A4BC1340CF5EF
SHA-256:DDD0B5A9B8BD9275DDD6BD1D9D033C56734A5BB184B4371E50C2200B903397CB
SHA-512:6D9BA51003C7C056E2628F8C435029C8A62E4A7E9A40B59C952AF160B91449AA4B9E5E4084A275E1825C6BE0CD1C8EE22709BEB1C13839BE8B29C63B2509DF53
Malicious:false
Preview:[folders]..Templates.LNK=0..
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:Microsoft Word 2007+
Category:dropped
Size (bytes):19351
Entropy (8bit):7.470339352923866
Encrypted:false
SSDEEP:384:Jrt+BNxt/ZtNNU/xY8VKcBEyBFagQ8VdM6ri24fPW+92Art:VAxllNMxY8kcmGaKc+et
MD5:E20C79F97B24C273AB7715C9ACD88E8E
SHA1:BC2D66C6FBF10B1AD391D54B5D3A4B2275EF764B
SHA-256:7CE0303CA5FC3ABE5971F6C16C9DB3AA7C5F81AB67712DA812792A086955F24F
SHA-512:2A0112ED42795D2A3FFB2D461E9E59C8997177C6A1EF118B1B73DF350A2CDBED02D4659872EBEBFF1738631512C6D1E3B710017591E494D603A27BC39AA33489
Malicious:false
Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):162
Entropy (8bit):4.761768024043488
Encrypted:false
SSDEEP:3:KVGl/lilKlRAGlZvAq8EmDmJryQjevRfYDEZUM9Cea4aa72Nn:KVy/4KDDvAq8Em65YoMRaXM2Nn
MD5:5E3B8FF4B35B75CDBA7CE7E2317C71B9
SHA1:720E1BA558DACAF08FD02F831F90DAFFC356AACD
SHA-256:50DF2A78AFAD42AE16899047FA1CACC92FB659D8BCCDBE408D41C41ABF0546F6
SHA-512:4FC1CE0F8364AFB871EB9F4A19A35CE7594C3EC6EA505F30BCEE4FCC4263141F04E0858CA62615970EF33E56CB411C9717D1F2DC8C7DFDA5C2D8C926A27F2920
Malicious:false
Preview:.user..................................................j.o.n.e.s.....qR.k....$.,.%].X!l....~._....e....Ld4.}y.2!#.......^-M.i..........._....}..i....x....=.h
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:Microsoft Word 2007+
Category:dropped
Size (bytes):19351
Entropy (8bit):7.470339352923866
Encrypted:false
SSDEEP:384:Jrt+BNxt/ZtNNU/xY8VKcBEyBFagQ8VdM6ri24fPW+92Art:VAxllNMxY8kcmGaKc+et
MD5:E20C79F97B24C273AB7715C9ACD88E8E
SHA1:BC2D66C6FBF10B1AD391D54B5D3A4B2275EF764B
SHA-256:7CE0303CA5FC3ABE5971F6C16C9DB3AA7C5F81AB67712DA812792A086955F24F
SHA-512:2A0112ED42795D2A3FFB2D461E9E59C8997177C6A1EF118B1B73DF350A2CDBED02D4659872EBEBFF1738631512C6D1E3B710017591E494D603A27BC39AA33489
Malicious:false
Preview:PK..........!.Q3.p............[Content_Types].xml ...(.....................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................N.0.E.H.C.-J\X ......J..0....K......H...R*.D.g..3.H....M!`.l.....J.j;*...>.b.Fa...B....wz...<`F..K6.._s.r.F`.<X.T....7....U.._t:.\:...<&....A%&:f.9..H.hd..*1y.Lx.k)".........e..k.g.....)....&......A...3..WNN.U..e...<....'4(.....x.....nh.t.....p7..j..s...I@.w6.X..C.Tp...r+..^..F.N...".az...h.[!F.!...g...i"...C..n9.~l...3.....H..V..9.2.,)s..GZD..mo6M..a.!...q$.......O..r-.........PK..........!.........N......
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:modified
Size (bytes):12
Entropy (8bit):0.41381685030363374
Encrypted:false
SSDEEP:3:/l:
MD5:E4A1661C2C886EBB688DEC494532431C
SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
Malicious:false
Preview:............
Process:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
File Type:data
Category:dropped
Size (bytes):12
Entropy (8bit):0.41381685030363374
Encrypted:false
SSDEEP:3:/l:
MD5:E4A1661C2C886EBB688DEC494532431C
SHA1:A2AE2A7DB83B33DC95396607258F553114C9183C
SHA-256:B76875C50EF704DBBF7F02C982445971D1BBD61AEBE2E4B28DDC58A1D66317D5
SHA-512:EFDCB76FB40482BC94E37EAE3701E844BF22C7D74D53AEF93AC7B6AE1C1094BA2F853875D2C66A49A7075EA8C69F5A348B786D6EE0FA711669279D04ADAAC22C
Malicious:false
Preview:............
File type:PE32 executable (GUI) Intel 80386, for MS Windows
Entropy (8bit):7.933576390037491
TrID:
  • Win32 Executable (generic) a (10002005/4) 99.96%
  • Generic Win/DOS Executable (2004/3) 0.02%
  • DOS Executable Generic (2002/1) 0.02%
  • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
File name:ndp48-web.exe
File size:1'439'328 bytes
MD5:34a5c76979563918b953e66e0d39c7ef
SHA1:4181398aa1fd5190155ac3a388434e5f7ea0b667
SHA256:0bba3094588c4bfec301939985222a20b340bf03431563dec8b2b4478b06fffa
SHA512:642721c60d52051c7f3434d8710fe3406a7cfe10b2b39e90ea847719ed1697d7c614f2df44ad50412b1df8c98dd78fdc57ca1d047d28c81ac158092e5fb18040
SSDEEP:24576:xGHL3siy910NSmtLvUDSRbm4Jah1rVx8MjoGO8W6cbZtgd6AmpITsz0+lLF7cy:mL3s7K8eTUDBzrVx8MjoGO8W6cbs8NpT
TLSH:2165222333B0C473D0A3163097A1A3B62D79B2BB4370854BBFA4572D1F667D066B9B16
File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........_..T>.WT>.WT>.WO.DWU>.Ws..WW>.W...WU>.W;HqWz>.W;HDW@>.W;HpW=>.W...WE>.WT>.W.>.WO.uW.>.WO.AWU>.WO.@WU>.WO.GWU>.WRichT>.W.......
Icon Hash:46165f4553a1f271
Entrypoint:0x418ee7
Entrypoint Section:.text
Digitally signed:true
Imagebase:0x400000
Subsystem:windows gui
Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE, 32BIT_MACHINE
DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Time Stamp:0x596BD5FC [Sun Jul 16 21:09:16 2017 UTC]
TLS Callbacks:
CLR (.Net) Version:
OS Version Major:5
OS Version Minor:1
File Version Major:5
File Version Minor:1
Subsystem Version Major:5
Subsystem Version Minor:1
Import Hash:9b2f6a441f9ff8df98ae6e9e6b5d4271
Signature Valid:true
Signature Issuer:CN=Microsoft Code Signing PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Signature Validation Error:The operation completed successfully
Error Number:0
Not Before, Not After
  • 15/12/2020 21:31:45 02/12/2021 21:31:45
Subject Chain
  • CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
Version:3
Thumbprint MD5:658DCC2A890351DF97DC9F05146283C0
Thumbprint SHA-1:ABDCA79AF9DD48A0EA702AD45260B3C03093FB4B
Thumbprint SHA-256:E39CC80A0DF6F2BED821D11B49717306138C1D19FD20190336BF1C4297638A79
Serial:33000001DF6BF02E92A74AB4D00000000001DF
Instruction
call 00007F2B9502ACD8h
jmp 00007F2B9502918Eh
cmp ecx, dword ptr [00429050h]
jne 00007F2B95029304h
rep ret
jmp 00007F2B9502AD5Fh
mov edi, edi
push ebp
mov ebp, esp
mov eax, dword ptr [ebp+08h]
mov edx, eax
mov cx, word ptr [eax]
add eax, 02h
test cx, cx
jne 00007F2B950292F7h
mov cx, word ptr [ebp+0Ch]
sub eax, 02h
cmp eax, edx
je 00007F2B95029307h
cmp word ptr [eax], cx
jne 00007F2B950292F6h
cmp word ptr [eax], cx
je 00007F2B95029304h
xor eax, eax
pop ebp
ret
mov edi, edi
push ebp
mov ebp, esp
push esi
mov esi, dword ptr [ebp+08h]
push edi
test esi, esi
je 00007F2B95029309h
mov edi, dword ptr [ebp+0Ch]
test edi, edi
jne 00007F2B95029317h
call 00007F2B9502AFF9h
push 00000016h
pop esi
mov dword ptr [eax], esi
call 00007F2B9502AF9Dh
mov eax, esi
pop edi
pop esi
pop ebp
ret
mov eax, dword ptr [ebp+10h]
test eax, eax
jne 00007F2B95029307h
mov word ptr [esi], ax
jmp 00007F2B950292E1h
mov edx, esi
sub edx, eax
movzx ecx, word ptr [eax]
mov word ptr [edx+eax], cx
add eax, 02h
test cx, cx
je 00007F2B95029305h
dec edi
jne 00007F2B950292F0h
xor eax, eax
test edi, edi
jne 00007F2B950292D6h
mov word ptr [esi], ax
call 00007F2B9502AFB9h
push 00000022h
pop ecx
mov dword ptr [eax], ecx
mov esi, ecx
jmp 00007F2B950292BEh
mov edi, edi
push ebp
mov ebp, esp
lea eax, dword ptr [ebp+14h]
push eax
push 00000000h
push dword ptr [ebp+10h]
push dword ptr [ebp+0Ch]
push dword ptr [ebp+08h]
call 00007F2B9502BE52h
add esp, 14h
pop ebp
Programming Language:
  • [ASM] VS2010 SP1 build 40219
  • [ C ] VS2005 build 50727
  • [C++] VS2010 build 30319
  • [ASM] VS2010 build 30319
  • [ C ] VS2010 build 30319
  • [EXP] VS2010 SP1 build 40219
  • [RES] VS2010 SP1 build 40219
  • [LNK] VS2010 SP1 build 40219
NameVirtual AddressVirtual Size Is in Section
IMAGE_DIRECTORY_ENTRY_EXPORT0x280e00x9a.text
IMAGE_DIRECTORY_ENTRY_IMPORT0x2d0000xb4.idata
IMAGE_DIRECTORY_ENTRY_RESOURCE0x300000x1ee4.rsrc
IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
IMAGE_DIRECTORY_ENTRY_SECURITY0x15d2a00x23c0
IMAGE_DIRECTORY_ENTRY_BASERELOC0x320000x1a38.reloc
IMAGE_DIRECTORY_ENTRY_DEBUG0x10400x1c.text
IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
IMAGE_DIRECTORY_ENTRY_TLS0x00x0
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x58000x40.text
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
IMAGE_DIRECTORY_ENTRY_IAT0x2d3540x2a0.idata
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x27ff40x60.text
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
.text0x10000x2717a0x272007b3b1ee9ae8ad7764ec9d706f5340480False0.5425132288338658Matlab v4 mat-file (little endian) \227\305A, numeric, rows 4352195, columns 06.57385410268325IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
.data0x290000x37600x1400a149d291b9bcd11002c627167764f938False0.2154296875data2.4578047267305063IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
.idata0x2d0000x11e80x120021f29dcea9763e518871fb03f70a5066False0.4370659722222222data5.496931567610224IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.boxld010x2f0000xb60x200118f53165c330598d57a34ca3d476f86False0.248046875data1.655867030025736IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.rsrc0x300000x1ee40x20000fd002798f59e06d78e2d5855cb4e247False0.3275146484375data4.292525485894544IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
.reloc0x320000x29440x2a000e90504f35d64a06ae725d5c4572a9e4False0.5183221726190477data4.988671510567249IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
NameRVASizeTypeLanguageCountryZLIB Complexity
RT_ICON0x302980x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512EnglishUnited States0.46639784946236557
RT_ICON0x305800x128Device independent bitmap graphic, 16 x 32 x 4, image size 128EnglishUnited States0.6216216216216216
RT_DIALOG0x306a80x10cdataEnglishUnited States0.6492537313432836
RT_DIALOG0x307b40x170dataEnglishUnited States0.5135869565217391
RT_STRING0x309240x582dataEnglishUnited States0.33687943262411346
RT_STRING0x30ea80xb4dataEnglishUnited States0.55
RT_STRING0x30f5c0x40dataEnglishUnited States0.6875
RT_GROUP_ICON0x30f9c0x22dataEnglishUnited States1.0
RT_VERSION0x30fc00x60cdata0.2532299741602067
RT_VERSION0x315cc0x380dataEnglishUnited States0.46763392857142855
RT_MANIFEST0x3194c0x598XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States0.4490223463687151
DLLImport
ADVAPI32.dllCreateWellKnownSid, InitializeSecurityDescriptor, SetEntriesInAclW, SetSecurityDescriptorDacl, SetSecurityDescriptorOwner, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, DecryptFileW
KERNEL32.dllGetTickCount, SetEnvironmentVariableW, GetLastError, ExpandEnvironmentStringsW, CreateProcessW, Sleep, WaitForSingleObject, GetExitCodeProcess, CloseHandle, SetFileAttributesW, InitializeCriticalSection, CreateEventW, GetEnvironmentVariableW, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, SetEvent, GetCommandLineW, lstrlenW, CompareStringW, LocalFree, CreateDirectoryW, QueryDosDeviceW, GetLogicalDriveStringsW, GetDiskFreeSpaceExW, GetDriveTypeW, CreateFileW, DeviceIoControl, SetErrorMode, RemoveDirectoryW, MoveFileExW, GetProcAddress, GetSystemDirectoryW, LoadLibraryW, GetModuleHandleW, CreateThread, LocalAlloc, RaiseException, ExitThread, WaitForMultipleObjects, ResetEvent, CreateEventA, GetSystemInfo, FileTimeToSystemTime, FileTimeToLocalFileTime, FileTimeToDosDateTime, GetModuleHandleA, GetVersionExA, SetFileTime, LocalFileTimeToFileTime, DosDateTimeToFileTime, SetEndOfFile, DuplicateHandle, ReadFile, SetFilePointerEx, GlobalFree, GetCommandLineA, HeapSetInformation, GetStartupInfoW, SetUnhandledExceptionFilter, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameW, GetModuleFileNameA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, InterlockedDecrement, HeapCreate, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, IsDebuggerPresent, HeapFree, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, HeapAlloc, LCMapStringW, FreeLibrary, InterlockedExchange, RtlUnwind, SetFilePointer, GetConsoleCP, GetConsoleMode, MultiByteToWideChar, GetStringTypeW, HeapSize, HeapReAlloc, IsProcessorFeaturePresent, SetStdHandle, WriteConsoleW, FlushFileBuffers, CreateFileA, GetLocalTime, GetComputerNameW, lstrlenA, FormatMessageW, GetSystemTime, GetTimeZoneInformation, SystemTimeToTzSpecificLocalTime, DeleteFileW, GetFileAttributesW, FindFirstFileW, FindNextFileW, FindClose, GetCurrentDirectoryW, SetCurrentDirectoryW, GetProcessHeap, GlobalAlloc, LoadLibraryA
COMCTL32.dll
RPCRT4.dllUuidToStringW, UuidCreate, RpcStringFreeW
SHELL32.dllCommandLineToArgvW, SHBrowseForFolderW, SHGetPathFromIDListW
SHLWAPI.dllPathRemoveExtensionW
USER32.dllMessageBoxW, GetTopWindow, GetWindowThreadProcessId, GetWindow, SendMessageW, PostMessageW, DialogBoxParamW, GetDlgItem, SetWindowTextW, EndDialog, PostQuitMessage, LoadStringW, SetWindowLongW, GetWindowLongW, CharUpperW
OLEAUT32.dllSysAllocString, VariantClear
NameOrdinalAddress
?dwPlaceholder@@3PAEA10x42f000
_DecodePointerInternal@420x40b99c
_EncodePointerInternal@430x40b981
Language of compilation systemCountry where language is spokenMap
EnglishUnited States
TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
Apr 25, 2024 14:26:41.002829075 CEST1.1.1.1192.168.2.40xb096No error (0)bg.microsoft.map.fastly.net199.232.210.172A (IP address)IN (0x0001)false
Apr 25, 2024 14:26:41.002829075 CEST1.1.1.1192.168.2.40xb096No error (0)bg.microsoft.map.fastly.net199.232.214.172A (IP address)IN (0x0001)false

Click to jump to process

Click to jump to process

Click to dive into process behavior distribution

Click to jump to process

Target ID:0
Start time:14:26:28
Start date:25/04/2024
Path:C:\Users\user\Desktop\ndp48-web.exe
Wow64 process (32bit):true
Commandline:"C:\Users\user\Desktop\ndp48-web.exe"
Imagebase:0xd0000
File size:1'439'328 bytes
MD5 hash:34A5C76979563918B953E66E0D39C7EF
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:false

Target ID:1
Start time:14:26:30
Start date:25/04/2024
Path:C:\5478d9557b6298dc63ac5974e1\Setup.exe
Wow64 process (32bit):true
Commandline:C:\5478d9557b6298dc63ac5974e1\\Setup.exe /x86 /x64 /web
Imagebase:0xee0000
File size:122'760 bytes
MD5 hash:057CE4FB9C8E829AF369AFBC5C4DFD41
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:false

Target ID:2
Start time:14:26:36
Start date:25/04/2024
Path:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Wow64 process (32bit):true
Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo1.rtf"
Imagebase:0x6e0000
File size:1'620'872 bytes
MD5 hash:1A0C2C2E7D9C4BC18E91604E9B0C7678
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:true

Target ID:4
Start time:14:26:39
Start date:25/04/2024
Path:C:\Windows\splwow64.exe
Wow64 process (32bit):false
Commandline:C:\Windows\splwow64.exe 12288
Imagebase:0x7ff770df0000
File size:163'840 bytes
MD5 hash:77DE7761B037061C7C112FD3C5B91E73
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:true

Target ID:8
Start time:14:26:41
Start date:25/04/2024
Path:C:\Program Files (x86)\Microsoft Office\root\Office16\WINWORD.EXE
Wow64 process (32bit):true
Commandline:"C:\Program Files (x86)\Microsoft Office\Root\Office16\WINWORD.EXE" /i "C:\Users\user\AppData\Local\Temp\BlockersInfo2.rtf"
Imagebase:0x6e0000
File size:1'620'872 bytes
MD5 hash:1A0C2C2E7D9C4BC18E91604E9B0C7678
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:false

Target ID:9
Start time:14:26:44
Start date:25/04/2024
Path:C:\Windows\splwow64.exe
Wow64 process (32bit):false
Commandline:C:\Windows\splwow64.exe 12288
Imagebase:0x7ff770df0000
File size:163'840 bytes
MD5 hash:77DE7761B037061C7C112FD3C5B91E73
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:true

Target ID:11
Start time:14:26:45
Start date:25/04/2024
Path:C:\Windows\splwow64.exe
Wow64 process (32bit):false
Commandline:C:\Windows\splwow64.exe 12288
Imagebase:0x7ff770df0000
File size:163'840 bytes
MD5 hash:77DE7761B037061C7C112FD3C5B91E73
Has elevated privileges:true
Has administrator privileges:true
Programmed in:C, C++ or other language
Reputation:moderate
Has exited:false

No disassembly