Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
|
initial sample
|
||
C:\Users\user\AppData\Local\Temp\MSI9A55.tmp
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\RarSFX0\0x0409.ini
|
Unicode text, UTF-16, little-endian text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\RarSFX0\Data1.cab
|
Microsoft Cabinet archive data, many, 14538947 bytes, 19 files, at 0x5c +A "_05552B74CCDE077E19276A4B56E61CF6", iFolder 0x1
+A "_B05A2AB076DDA62641C63DBF405CBA38", 7 cffolders, ID 1111, number 1, 105 datablocks, 0x1 compression
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\RarSFX0\Lakes Environmental WRPLOT View - Freeware V.8.0.2.MSI
|
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Code page: 1252, Title: Installation
Database, Author: InstallShield Software Corporation, Keywords: Installer,MSI,Database, Comments: Contact: Your local administrator,
Template: Intel;1033, Last Saved By: InstallShield, Revision Number: {79A894FC-A5C1-4F47-BD8C-296A0B8F9A34}, Last Printed:
Wed Mar 21 11:30:00 2018, Create Time/Date: Wed Mar 21 11:30:00 2018, Last Saved Time/Date: Wed Mar 21 11:30:00 2018, Number
of Pages: 200, Number of Words: 0, Number of Characters: 0, Name of Creating Application: InstallShield 2009 - Express Edition
15, Security: 1
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\RarSFX0\Setup.ini
|
Generic INItialization configuration [Startup]
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\RarSFX0\instmsia.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\RarSFX0\instmsiw.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|