Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
2Stejb80vJ.exe

Overview

General Information

Sample name:2Stejb80vJ.exe
renamed because original name is a hash value
Original sample name:d29ed04c296d7d0415de3da4229fcabb9f47cf6ba5800dfb11d57c35061d4d9b.exe
Analysis ID:1631760
MD5:b95ef20686db0da52f6796fa134f76a7
SHA1:ac96b10b8bee3607d0cdf3ee153927ad74152bbf
SHA256:d29ed04c296d7d0415de3da4229fcabb9f47cf6ba5800dfb11d57c35061d4d9b
Tags:exeuser-adrian__luca
Infos:

Detection

FormBook
Score:100
Range:0 - 100
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for URL or domain
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected AntiVM3
Yara detected FormBook
.NET source code contains potential unpacker
Found direct / indirect Syscall (likely to bypass EDR)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Maps a DLL or memory area into another process
Modifies the context of a thread in another process (thread injection)
Performs DNS queries to domains with low reputation
Queues an APC in another process (thread injection)
Switches to a custom stack to bypass stack traces
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Tries to harvest and steal browser information (history, passwords, etc)
Tries to steal Mail credentials (via file / registry access)
Writes to foreign memory regions
Yara detected Costura Assembly Loader
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if the current process is being debugged
Contains functionality for execution timing, often used to detect debuggers
Contains functionality to access loader functionality (e.g. LdrGetProcedureAddress)
Contains functionality to call native functions
Contains functionality to read the PEB
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Enables debug privileges
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
Queries the volume information (name, serial number etc) of a device
Sample execution stops while process was sleeping (likely an evasion)
Sample file is different than original file name gathered from version info
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)

Classification

  • System is w10x64
  • 2Stejb80vJ.exe (PID: 6872 cmdline: "C:\Users\user\Desktop\2Stejb80vJ.exe" MD5: B95EF20686DB0DA52F6796FA134F76A7)
    • InstallUtil.exe (PID: 7128 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe" MD5: 5D4073B2EB6D217C19F2B22F21BF8D57)
      • UPM8KZRaz30lCAjNcEm6.exe (PID: 4224 cmdline: "C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\oH7OzLtBL61l.exe" MD5: 9C98D1A23EFAF1B156A130CEA7D2EE3A)
        • msfeedssync.exe (PID: 6892 cmdline: "C:\Windows\SysWOW64\msfeedssync.exe" MD5: E1C1AB8118F67D856FD140FB7175BF13)
          • UPM8KZRaz30lCAjNcEm6.exe (PID: 5556 cmdline: "C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\M7Wk0TA6V.exe" MD5: 9C98D1A23EFAF1B156A130CEA7D2EE3A)
          • firefox.exe (PID: 7164 cmdline: "C:\Program Files\Mozilla Firefox\Firefox.exe" MD5: C86B1BE9ED6496FE0E0CBE73F81D8045)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
00000002.00000002.1511972245.0000000000FC0000.00000040.10000000.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
    0000000A.00000002.3727661903.0000000005840000.00000040.80000000.00040000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
      00000000.00000002.1267757306.00000000030B6000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
        00000009.00000002.3725575572.0000000002860000.00000004.00000800.00020000.00000000.sdmpJoeSecurity_FormBook_1Yara detected FormBookJoe Security
          00000000.00000002.1288833714.0000000005D10000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
            Click to see the 9 entries
            SourceRuleDescriptionAuthorStrings
            2.2.InstallUtil.exe.400000.0.unpackJoeSecurity_FormBook_1Yara detected FormBookJoe Security
              2.2.InstallUtil.exe.400000.0.raw.unpackJoeSecurity_FormBook_1Yara detected FormBookJoe Security
                0.2.2Stejb80vJ.exe.46c16ce.2.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                  0.2.2Stejb80vJ.exe.5d10000.12.raw.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                    0.2.2Stejb80vJ.exe.47c0ec0.4.unpackJoeSecurity_CosturaAssemblyLoaderYara detected Costura Assembly LoaderJoe Security
                      Click to see the 5 entries
                      No Sigma rule has matched
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-03-07T15:12:31.326599+010020507451Malware Command and Control Activity Detected192.168.2.649687148.72.247.7080TCP
                      2025-03-07T15:12:54.685396+010020507451Malware Command and Control Activity Detected192.168.2.64969246.30.211.3880TCP
                      2025-03-07T15:13:08.835529+010020507451Malware Command and Control Activity Detected192.168.2.64969647.83.1.9080TCP
                      2025-03-07T15:13:45.332674+010020507451Malware Command and Control Activity Detected192.168.2.649700149.104.184.8980TCP
                      2025-03-07T15:13:58.653417+010020507451Malware Command and Control Activity Detected192.168.2.649704209.74.64.5880TCP
                      2025-03-07T15:14:15.972251+010020507451Malware Command and Control Activity Detected192.168.2.649708199.59.243.22880TCP
                      2025-03-07T15:14:29.276813+010020507451Malware Command and Control Activity Detected192.168.2.64971213.248.169.4880TCP
                      2025-03-07T15:14:43.737178+010020507451Malware Command and Control Activity Detected192.168.2.64971647.83.1.9080TCP
                      2025-03-07T15:14:57.052520+010020507451Malware Command and Control Activity Detected192.168.2.649720104.21.112.180TCP
                      2025-03-07T15:15:10.236719+010020507451Malware Command and Control Activity Detected192.168.2.64972413.248.169.4880TCP
                      2025-03-07T15:15:26.184320+010020507451Malware Command and Control Activity Detected192.168.2.649728103.106.67.11280TCP
                      2025-03-07T15:15:39.548031+010020507451Malware Command and Control Activity Detected192.168.2.64973213.248.169.4880TCP
                      2025-03-07T15:15:52.968511+010020507451Malware Command and Control Activity Detected192.168.2.649736144.76.229.20380TCP
                      2025-03-07T15:16:06.600943+010020507451Malware Command and Control Activity Detected192.168.2.64974013.248.169.4880TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-03-07T15:12:31.326599+010028554651A Network Trojan was detected192.168.2.649687148.72.247.7080TCP
                      2025-03-07T15:12:54.685396+010028554651A Network Trojan was detected192.168.2.64969246.30.211.3880TCP
                      2025-03-07T15:13:08.835529+010028554651A Network Trojan was detected192.168.2.64969647.83.1.9080TCP
                      2025-03-07T15:13:45.332674+010028554651A Network Trojan was detected192.168.2.649700149.104.184.8980TCP
                      2025-03-07T15:13:58.653417+010028554651A Network Trojan was detected192.168.2.649704209.74.64.5880TCP
                      2025-03-07T15:14:15.972251+010028554651A Network Trojan was detected192.168.2.649708199.59.243.22880TCP
                      2025-03-07T15:14:29.276813+010028554651A Network Trojan was detected192.168.2.64971213.248.169.4880TCP
                      2025-03-07T15:14:43.737178+010028554651A Network Trojan was detected192.168.2.64971647.83.1.9080TCP
                      2025-03-07T15:14:57.052520+010028554651A Network Trojan was detected192.168.2.649720104.21.112.180TCP
                      2025-03-07T15:15:10.236719+010028554651A Network Trojan was detected192.168.2.64972413.248.169.4880TCP
                      2025-03-07T15:15:26.184320+010028554651A Network Trojan was detected192.168.2.649728103.106.67.11280TCP
                      2025-03-07T15:15:39.548031+010028554651A Network Trojan was detected192.168.2.64973213.248.169.4880TCP
                      2025-03-07T15:15:52.968511+010028554651A Network Trojan was detected192.168.2.649736144.76.229.20380TCP
                      2025-03-07T15:16:06.600943+010028554651A Network Trojan was detected192.168.2.64974013.248.169.4880TCP
                      TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                      2025-03-07T15:12:47.059093+010028554641A Network Trojan was detected192.168.2.64968946.30.211.3880TCP
                      2025-03-07T15:12:49.619920+010028554641A Network Trojan was detected192.168.2.64969046.30.211.3880TCP
                      2025-03-07T15:12:52.166486+010028554641A Network Trojan was detected192.168.2.64969146.30.211.3880TCP
                      2025-03-07T15:13:01.241814+010028554641A Network Trojan was detected192.168.2.64969347.83.1.9080TCP
                      2025-03-07T15:13:03.736032+010028554641A Network Trojan was detected192.168.2.64969447.83.1.9080TCP
                      2025-03-07T15:13:06.335638+010028554641A Network Trojan was detected192.168.2.64969547.83.1.9080TCP
                      2025-03-07T15:13:17.851562+010028554641A Network Trojan was detected192.168.2.649697149.104.184.8980TCP
                      2025-03-07T15:13:20.397938+010028554641A Network Trojan was detected192.168.2.649698149.104.184.8980TCP
                      2025-03-07T15:13:22.944712+010028554641A Network Trojan was detected192.168.2.649699149.104.184.8980TCP
                      2025-03-07T15:13:50.971414+010028554641A Network Trojan was detected192.168.2.649701209.74.64.5880TCP
                      2025-03-07T15:13:53.535104+010028554641A Network Trojan was detected192.168.2.649702209.74.64.5880TCP
                      2025-03-07T15:13:56.058603+010028554641A Network Trojan was detected192.168.2.649703209.74.64.5880TCP
                      2025-03-07T15:14:08.320125+010028554641A Network Trojan was detected192.168.2.649705199.59.243.22880TCP
                      2025-03-07T15:14:10.948267+010028554641A Network Trojan was detected192.168.2.649706199.59.243.22880TCP
                      2025-03-07T15:14:13.413482+010028554641A Network Trojan was detected192.168.2.649707199.59.243.22880TCP
                      2025-03-07T15:14:21.520466+010028554641A Network Trojan was detected192.168.2.64970913.248.169.4880TCP
                      2025-03-07T15:14:24.025765+010028554641A Network Trojan was detected192.168.2.64971013.248.169.4880TCP
                      2025-03-07T15:14:26.712497+010028554641A Network Trojan was detected192.168.2.64971113.248.169.4880TCP
                      2025-03-07T15:14:35.851143+010028554641A Network Trojan was detected192.168.2.64971347.83.1.9080TCP
                      2025-03-07T15:14:38.397742+010028554641A Network Trojan was detected192.168.2.64971447.83.1.9080TCP
                      2025-03-07T15:14:40.946016+010028554641A Network Trojan was detected192.168.2.64971547.83.1.9080TCP
                      2025-03-07T15:14:49.428774+010028554641A Network Trojan was detected192.168.2.649717104.21.112.180TCP
                      2025-03-07T15:14:51.960642+010028554641A Network Trojan was detected192.168.2.649718104.21.112.180TCP
                      2025-03-07T15:14:54.532997+010028554641A Network Trojan was detected192.168.2.649719104.21.112.180TCP
                      2025-03-07T15:15:02.633798+010028554641A Network Trojan was detected192.168.2.64972113.248.169.4880TCP
                      2025-03-07T15:15:05.227262+010028554641A Network Trojan was detected192.168.2.64972213.248.169.4880TCP
                      2025-03-07T15:15:07.686722+010028554641A Network Trojan was detected192.168.2.64972313.248.169.4880TCP
                      2025-03-07T15:15:18.539634+010028554641A Network Trojan was detected192.168.2.649725103.106.67.11280TCP
                      2025-03-07T15:15:21.066237+010028554641A Network Trojan was detected192.168.2.649726103.106.67.11280TCP
                      2025-03-07T15:15:23.639867+010028554641A Network Trojan was detected192.168.2.649727103.106.67.11280TCP
                      2025-03-07T15:15:31.701583+010028554641A Network Trojan was detected192.168.2.64972913.248.169.4880TCP
                      2025-03-07T15:15:34.338197+010028554641A Network Trojan was detected192.168.2.64973013.248.169.4880TCP
                      2025-03-07T15:15:36.972394+010028554641A Network Trojan was detected192.168.2.64973113.248.169.4880TCP
                      2025-03-07T15:15:45.324867+010028554641A Network Trojan was detected192.168.2.649733144.76.229.20380TCP
                      2025-03-07T15:15:47.921367+010028554641A Network Trojan was detected192.168.2.649734144.76.229.20380TCP
                      2025-03-07T15:15:50.422758+010028554641A Network Trojan was detected192.168.2.649735144.76.229.20380TCP
                      2025-03-07T15:15:58.968441+010028554641A Network Trojan was detected192.168.2.64973713.248.169.4880TCP
                      2025-03-07T15:16:01.517408+010028554641A Network Trojan was detected192.168.2.64973813.248.169.4880TCP
                      2025-03-07T15:16:04.080981+010028554641A Network Trojan was detected192.168.2.64973913.248.169.4880TCP
                      2025-03-07T15:16:12.130704+010028554641A Network Trojan was detected192.168.2.64974113.248.169.4880TCP
                      2025-03-07T15:16:14.678749+010028554641A Network Trojan was detected192.168.2.64974213.248.169.4880TCP
                      2025-03-07T15:16:17.255249+010028554641A Network Trojan was detected192.168.2.64974313.248.169.4880TCP

                      Click to jump to signature section

                      Show All Signature Results

                      AV Detection

                      barindex
                      Source: 2Stejb80vJ.exeAvira: detected
                      Source: http://www.askvtwv8.top/uztg/Avira URL Cloud: Label: malware
                      Source: http://www.askvtwv8.top/uztg/?G0L=GB6XqptpYp&ut1tI=+nnD4c3c3KEL/rpdey5PpuGEtusQHjNHKRoYtOqDasD0Qg1/WG/4NRhjA5miSBE9J8NC1pB0d1xeGfzelhsR1S3jYJp+47fQ47PDO4Kd95McmCWmHYCq+jA9bpNCOZRxRWyQ4ww=Avira URL Cloud: Label: malware
                      Source: 2Stejb80vJ.exeVirustotal: Detection: 48%Perma Link
                      Source: 2Stejb80vJ.exeReversingLabs: Detection: 68%
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000002.00000002.1511972245.0000000000FC0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000002.3727661903.0000000005840000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3725575572.0000000002860000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000008.00000002.3725515204.00000000041B0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1511179304.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3723672280.0000000002470000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3724115187.0000000002710000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1513679898.0000000003420000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                      Source: 2Stejb80vJ.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                      Source: 2Stejb80vJ.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Source: Binary string: msfeedssync.pdbUGP source: InstallUtil.exe, 00000002.00000002.1511482654.0000000000B18000.00000004.00000020.00020000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3724366403.000000000076E000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: 2Stejb80vJ.exe, 00000000.00000002.1290052858.0000000006480000.00000004.08000000.00040000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004563000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: InstallUtil.exe, 00000002.00000002.1512128441.0000000001060000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3725902542.0000000002E0E000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3725902542.0000000002C70000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1511427615.000000000291B000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1513328412.0000000002AC0000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: 2Stejb80vJ.exe, 00000000.00000002.1290052858.0000000006480000.00000004.08000000.00040000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004563000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: InstallUtil.exe, InstallUtil.exe, 00000002.00000002.1512128441.0000000001060000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, msfeedssync.exe, 00000009.00000002.3725902542.0000000002E0E000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3725902542.0000000002C70000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1511427615.000000000291B000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1513328412.0000000002AC0000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: InstallUtil.pdb\rvr hr_CorExeMainmscoree.dll source: msfeedssync.exe, 00000009.00000002.3724212347.0000000002772000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3726343665.000000000329C000.00000004.10000000.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580741225.000000000340C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 0000000B.00000002.1804393597.000000003187C000.00000004.80000000.00040000.00000000.sdmp
                      Source: Binary string: msfeedssync.pdb source: InstallUtil.exe, 00000002.00000002.1511482654.0000000000B18000.00000004.00000020.00020000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3724366403.000000000076E000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdbSHA256}Lq source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdb source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: InstallUtil.pdb source: msfeedssync.exe, 00000009.00000002.3724212347.0000000002772000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3726343665.000000000329C000.00000004.10000000.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580741225.000000000340C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 0000000B.00000002.1804393597.000000003187C000.00000004.80000000.00040000.00000000.sdmp
                      Source: Binary string: C:\Work\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3725289857.0000000000F7F000.00000002.00000001.01000000.00000007.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1579858391.0000000000F7F000.00000002.00000001.01000000.00000007.sdmp
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0248C680 FindFirstFileW,FindNextFileW,FindClose,9_2_0248C680
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 4x nop then jmp 06465590h0_2_064654D0
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 4x nop then jmp 06465590h0_2_064654D8
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 4x nop then xor eax, eax9_2_02479EC0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 4x nop then mov ebx, 00000004h9_2_02AB04E8

                      Networking

                      barindex
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49695 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49693 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49694 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49696 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49696 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49690 -> 46.30.211.38:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49691 -> 46.30.211.38:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49701 -> 209.74.64.58:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49687 -> 148.72.247.70:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49687 -> 148.72.247.70:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49706 -> 199.59.243.228:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49714 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49703 -> 209.74.64.58:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49708 -> 199.59.243.228:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49708 -> 199.59.243.228:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49699 -> 149.104.184.89:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49710 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49718 -> 104.21.112.1:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49711 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49712 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49712 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49697 -> 149.104.184.89:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49692 -> 46.30.211.38:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49692 -> 46.30.211.38:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49716 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49716 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49689 -> 46.30.211.38:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49733 -> 144.76.229.203:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49720 -> 104.21.112.1:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49730 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49720 -> 104.21.112.1:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49734 -> 144.76.229.203:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49700 -> 149.104.184.89:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49700 -> 149.104.184.89:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49722 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49742 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49726 -> 103.106.67.112:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49731 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49740 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49740 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49732 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49705 -> 199.59.243.228:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49732 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49728 -> 103.106.67.112:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49728 -> 103.106.67.112:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49738 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49698 -> 149.104.184.89:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49743 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49713 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49741 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49729 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49717 -> 104.21.112.1:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49721 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49707 -> 199.59.243.228:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49702 -> 209.74.64.58:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49709 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49704 -> 209.74.64.58:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49704 -> 209.74.64.58:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49723 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49719 -> 104.21.112.1:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49736 -> 144.76.229.203:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49736 -> 144.76.229.203:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49737 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49715 -> 47.83.1.90:80
                      Source: Network trafficSuricata IDS: 2050745 - Severity 1 - ET MALWARE FormBook CnC Checkin (GET) M5 : 192.168.2.6:49724 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855465 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (GET) M2 : 192.168.2.6:49724 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49739 -> 13.248.169.48:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49727 -> 103.106.67.112:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49725 -> 103.106.67.112:80
                      Source: Network trafficSuricata IDS: 2855464 - Severity 1 - ETPRO MALWARE FormBook CnC Checkin (POST) M3 : 192.168.2.6:49735 -> 144.76.229.203:80
                      Source: DNS query: www.melengkung.xyz
                      Source: DNS query: www.berkilau.xyz
                      Source: DNS query: www.seasay.xyz
                      Source: DNS query: www.seasay.xyz
                      Source: DNS query: www.seasay.xyz
                      Source: DNS query: www.shibfestival.xyz
                      Source: DNS query: www.031234103.xyz
                      Source: DNS query: www.corsix.xyz
                      Source: DNS query: www.dogebonus.xyz
                      Source: Joe Sandbox ViewIP Address: 144.76.229.203 144.76.229.203
                      Source: Joe Sandbox ViewIP Address: 13.248.169.48 13.248.169.48
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
                      Source: global trafficHTTP traffic detected: GET /2i0k/?G0L=GB6XqptpYp&ut1tI=WeJYadYniKRZByzzvxCLkkT/xti9VVMxwhfBQxnm132QdHMxzjTmB7Uw1lV55of2Ql4+U0VOq1+fhb57LzOydbzqbp/IZSD6gq9oPJFLXUDkZYj1AmTpf49c+0TtcAhO79gfZn4= HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.rds845.shopConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /wydt/?ut1tI=5VV5zaVyioKvui6f8qyG3IDGVPdlSdk2dL73T3ZYMn8k+e/vfjfehV3uAXE74CW6mr84kubQb7PqfuL3sByk4zAHSCf3WxUfTguS+kvnS9xqBSPOxgzlOh0MefbSUW4+G6if384=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.schoeler.proConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /uzd2/?ut1tI=fT9N3FsFDTNmTIZF4xptKfralz4kO9B+ENo/4lsaoo6HwYKpm4Najr2/W9Iv2vCiqIxfJAhVyMrxfUWcGsu8s4NcSddAFPEATdGR+1Krlc4bMxgLXUkZ9+4qwx2v0B27l+HM6E0=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.kpilal.infoConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /bl60/?ut1tI=7KqBeI51pekf0AVUSicAI1mJWWXcRARBaI0jAhY/A6pzh5mI8UIGMoQN96TYM7FYKU4GVIyckkKWvlHhgwmaAPr5PDKlfB0Nypg1LMgEB4DjXvFpXBtAkVFg1XxlfnTdf41yxLk=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.zkkv3oae.vipConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /m9bw/?G0L=GB6XqptpYp&ut1tI=c65Z66AH1nUgI224hybr4IHRoXEWVrV7RgpnxZMoMLGYnYeAoGqkN18+TNo8D4wVxrXfp68kmIM9xs3h0cs0qBmzaG/IJhDBE6KkOXv1fGCXK96Lmu+F1mhSNooUcKLPluRUpxM= HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.thrivell.lifeConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /cpbw/?ut1tI=j9x9kJU7UcAYEWEUt+89zuhJLorgOhrRwP39zrhC/EoZ+NnF04QyCgHeuwZnNkDy+Eh6VfeEAKF098oSI0wQVyoKCk+kNqeZ5J32c0Yn0TaV9onAGPkZAad5NAUzp9eQRGuVGi8=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.sscexampyq.watchesConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /0y3r/?G0L=GB6XqptpYp&ut1tI=NNsUrfDYogd5KgEmfHOhLiCUpL/ycyxUxiUVjETpADofQQCG23LbddXApMRWYwqNAPEF3q7toS5EuqqD+puOFUcCoZs2SjXBx6OKWylLgLNsG7+G8BBWhyCM6ST7exjkwRtD7v8= HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.melengkung.xyzConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /wbzo/?ut1tI=q3KlCKDmK4ELQKWWUcg/FlbQjxqr8Ug1u9jBPrpibm9/r1bZuSVNTJsKRKTfBrL1Q74mhVPLBmu2gNX7pDwWH1ZFwu0RuU1OqXQ55frXrQuy4zOufCIf2xZSmE4mBVnP4X7L4o8=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.vvxcss.infoConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /uztg/?G0L=GB6XqptpYp&ut1tI=+nnD4c3c3KEL/rpdey5PpuGEtusQHjNHKRoYtOqDasD0Qg1/WG/4NRhjA5miSBE9J8NC1pB0d1xeGfzelhsR1S3jYJp+47fQ47PDO4Kd95McmCWmHYCq+jA9bpNCOZRxRWyQ4ww= HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.askvtwv8.topConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /0a6h/?ut1tI=4iO46mqIBVv4+k9W6LsUvCVaOUZDGEFnn7WAcz/P0eLSsJADjC1P1ze0v25FROBtMqAu0yYT6nFt/u3VwLGumvmxY2ZCttU2tqN3zj8iga/CXHm+gHUKrZMhfx8ALGtb6zfPvbA=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.berkilau.xyzConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /36xs/?G0L=GB6XqptpYp&ut1tI=RgfpXspOgsNiHmosVF1KbpPv72dzNmiTBjL/Nd6qGeZ/g3rBomzgIOO7wigAI/htEgjf23cNUotiJq7H3GsdxzDVPbajzumommKHi90NSuQU+p/ERxGsu2ZmMOqrV9flKg0CCRQ= HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.seasay.xyzConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /gy4u/?ut1tI=LcvWm9PoXmh0ed+OrIDToYlIrZw2q35DEYIU6sknWZxapDsLCzJUOh5d+BBm/MfusN5GInj1wF1Jz1YJRWWIBTh6UJL8j/qwdkhQ8cf9NXR7wD6CkVng0KVakLL3T+jqTA6cIG0=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.shibfestival.xyzConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /z0it/?G0L=GB6XqptpYp&ut1tI=DaqYyDhfRyWIR4xS4E63/qTRIQgqoWSI9b+QdYveO98qQ64GTsQjKE9BhC2RGwgAmUZQI386DZwQTzGkc+2gVo8kGrmTzk6IQynrcBxHw5zDhLwaeX/sIAA/FuuaSbwjCsR/ynE= HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.031234103.xyzConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficHTTP traffic detected: GET /vfs3/?ut1tI=KGtC6huJ4au9g2crOn4yKOveJg5tp2yoY9H48UkY9VT0CpunUoTAthUg4dvK3NVgO3OSivHm6ijFKYAZ8peYOGRBruj7bSpN0ILzuWa3aDCwm2BYeKRUnvFyJDHwcZleLFCIw3c=&G0L=GB6XqptpYp HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USHost: www.corsix.xyzConnection: closeUser-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16
                      Source: global trafficDNS traffic detected: DNS query: www.rds845.shop
                      Source: global trafficDNS traffic detected: DNS query: www.schoeler.pro
                      Source: global trafficDNS traffic detected: DNS query: www.kpilal.info
                      Source: global trafficDNS traffic detected: DNS query: www.zkkv3oae.vip
                      Source: global trafficDNS traffic detected: DNS query: www.thrivell.life
                      Source: global trafficDNS traffic detected: DNS query: www.sscexampyq.watches
                      Source: global trafficDNS traffic detected: DNS query: www.melengkung.xyz
                      Source: global trafficDNS traffic detected: DNS query: www.vvxcss.info
                      Source: global trafficDNS traffic detected: DNS query: www.askvtwv8.top
                      Source: global trafficDNS traffic detected: DNS query: www.berkilau.xyz
                      Source: global trafficDNS traffic detected: DNS query: www.seasay.xyz
                      Source: global trafficDNS traffic detected: DNS query: www.shibfestival.xyz
                      Source: global trafficDNS traffic detected: DNS query: www.031234103.xyz
                      Source: global trafficDNS traffic detected: DNS query: www.corsix.xyz
                      Source: global trafficDNS traffic detected: DNS query: www.dogebonus.xyz
                      Source: unknownHTTP traffic detected: POST /wydt/ HTTP/1.1Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7Accept-Language: en-USAccept-Encoding: gzip, deflateHost: www.schoeler.proOrigin: http://www.schoeler.proCache-Control: max-age=0Connection: closeContent-Length: 210Content-Type: application/x-www-form-urlencodedReferer: http://www.schoeler.pro/wydt/User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:2.0) Gecko/20100101 Firefox/4.0 Opera 12.16Data Raw: 75 74 31 74 49 3d 30 58 39 5a 77 75 6f 46 32 72 2f 43 7a 68 32 34 34 35 43 58 6b 34 7a 6d 51 63 6f 5a 58 64 70 6d 44 5a 76 74 4d 68 6c 59 5a 6b 4d 43 33 4b 76 50 61 51 54 73 6f 54 62 41 58 7a 5a 4b 6b 48 32 6e 76 34 56 4c 77 2b 4c 69 64 6f 71 53 65 4e 43 43 67 6b 65 78 32 46 70 39 62 68 6a 56 50 41 55 68 55 79 69 52 33 6a 57 59 61 50 74 49 4a 42 66 59 34 67 79 73 45 51 4d 6a 58 4f 66 64 4e 7a 59 5a 4c 6f 53 54 2b 71 43 43 5a 36 71 33 4b 37 62 7a 42 78 78 53 67 31 57 64 49 45 41 76 4b 67 57 32 50 4c 4b 36 41 69 51 38 48 59 6c 56 32 4a 30 6b 6c 7a 51 49 47 79 47 2b 67 67 5a 39 57 58 49 77 6e 55 68 75 30 45 52 6d 6c 39 52 33 Data Ascii: ut1tI=0X9ZwuoF2r/Czh2445CXk4zmQcoZXdpmDZvtMhlYZkMC3KvPaQTsoTbAXzZKkH2nv4VLw+LidoqSeNCCgkex2Fp9bhjVPAUhUyiR3jWYaPtIJBfY4gysEQMjXOfdNzYZLoST+qCCZ6q3K7bzBxxSg1WdIEAvKgW2PLK6AiQ8HYlV2J0klzQIGyG+ggZ9WXIwnUhu0ERml9R3
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0 (Ubuntu)Date: Fri, 07 Mar 2025 14:12:46 GMTContent-Type: text/html; charset=UTF-8Content-Length: 162Connection: closeData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0 (Ubuntu)Date: Fri, 07 Mar 2025 14:12:49 GMTContent-Type: text/html; charset=UTF-8Content-Length: 162Connection: closeData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0 (Ubuntu)Date: Fri, 07 Mar 2025 14:12:52 GMTContent-Type: text/html; charset=UTF-8Content-Length: 162Connection: closeData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0 (Ubuntu)Date: Fri, 07 Mar 2025 14:12:54 GMTContent-Type: text/html; charset=UTF-8Content-Length: 162Connection: closeData Raw: 3c 68 74 6d 6c 3e 0d 0a 3c 68 65 61 64 3e 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 3c 2f 68 65 61 64 3e 0d 0a 3c 62 6f 64 79 3e 0d 0a 3c 63 65 6e 74 65 72 3e 3c 68 31 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 68 72 3e 3c 63 65 6e 74 65 72 3e 6e 67 69 6e 78 2f 31 2e 31 38 2e 30 20 28 55 62 75 6e 74 75 29 3c 2f 63 65 6e 74 65 72 3e 0d 0a 3c 2f 62 6f 64 79 3e 0d 0a 3c 2f 68 74 6d 6c 3e 0d 0a Data Ascii: <html><head><title>404 Not Found</title></head><body><center><h1>404 Not Found</h1></center><hr><center>nginx/1.18.0 (Ubuntu)</center></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundServer: nginx/1.18.0Date: Fri, 07 Mar 2025 14:13:03 GMTTransfer-Encoding: chunkedConnection: closeData Raw: 30 0d 0a 0d 0a Data Ascii: 0
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:13:50 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:13:53 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:13:55 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/htmlData Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:13:58 GMTServer: ApacheContent-Length: 389Connection: closeContent-Type: text/html; charset=utf-8Data Raw: 3c 21 44 4f 43 54 59 50 45 20 68 74 6d 6c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 3c 6d 65 74 61 20 68 74 74 70 2d 65 71 75 69 76 3d 22 43 6f 6e 74 65 6e 74 2d 54 79 70 65 22 20 63 6f 6e 74 65 6e 74 3d 22 74 65 78 74 2f 68 74 6d 6c 3b 20 63 68 61 72 73 65 74 3d 77 69 6e 64 6f 77 73 2d 31 32 35 32 22 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e Data Ascii: <!DOCTYPE html PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1252"><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:15:45 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:15:47 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:15:50 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: global trafficHTTP traffic detected: HTTP/1.1 404 Not FoundDate: Fri, 07 Mar 2025 14:15:52 GMTServer: ApacheContent-Length: 315Connection: closeContent-Type: text/html; charset=iso-8859-1Data Raw: 3c 21 44 4f 43 54 59 50 45 20 48 54 4d 4c 20 50 55 42 4c 49 43 20 22 2d 2f 2f 49 45 54 46 2f 2f 44 54 44 20 48 54 4d 4c 20 32 2e 30 2f 2f 45 4e 22 3e 0a 3c 68 74 6d 6c 3e 3c 68 65 61 64 3e 0a 3c 74 69 74 6c 65 3e 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 3c 2f 74 69 74 6c 65 3e 0a 3c 2f 68 65 61 64 3e 3c 62 6f 64 79 3e 0a 3c 68 31 3e 4e 6f 74 20 46 6f 75 6e 64 3c 2f 68 31 3e 0a 3c 70 3e 54 68 65 20 72 65 71 75 65 73 74 65 64 20 55 52 4c 20 77 61 73 20 6e 6f 74 20 66 6f 75 6e 64 20 6f 6e 20 74 68 69 73 20 73 65 72 76 65 72 2e 3c 2f 70 3e 0a 3c 70 3e 41 64 64 69 74 69 6f 6e 61 6c 6c 79 2c 20 61 20 34 30 34 20 4e 6f 74 20 46 6f 75 6e 64 0a 65 72 72 6f 72 20 77 61 73 20 65 6e 63 6f 75 6e 74 65 72 65 64 20 77 68 69 6c 65 20 74 72 79 69 6e 67 20 74 6f 20 75 73 65 20 61 6e 20 45 72 72 6f 72 44 6f 63 75 6d 65 6e 74 20 74 6f 20 68 61 6e 64 6c 65 20 74 68 65 20 72 65 71 75 65 73 74 2e 3c 2f 70 3e 0a 3c 2f 62 6f 64 79 3e 3c 2f 68 74 6d 6c 3e 0a Data Ascii: <!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>404 Not Found</title></head><body><h1>Not Found</h1><p>The requested URL was not found on this server.</p><p>Additionally, a 404 Not Founderror was encountered while trying to use an ErrorDocument to handle the request.</p></body></html>
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1267757306.00000000030B6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                      Source: UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000002.3727661903.000000000589B000.00000040.80000000.00040000.00000000.sdmpString found in binary or memory: http://www.031234103.xyz
                      Source: UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000002.3727661903.000000000589B000.00000040.80000000.00040000.00000000.sdmpString found in binary or memory: http://www.031234103.xyz/z0it/
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ac.ecosia.org?q=
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.ecosia.org/assets/images/ico/favicon.icohttps://www.ecosia.org/search?q=
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/favicon.icohttps://ch.search.yahoo.com/search
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://ch.search.yahoo.com/sugg/chrome?output=fxjson&appid=crmas&command=
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/ac/?q=
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/chrome_newtabv20-
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://duckduckgo.com/favicon.icohttps://duckduckgo.com/?q=
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://gemini.google.com/app?q=
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-net
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-netJ
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://github.com/mgravell/protobuf-neti
                      Source: msfeedssync.exe, 00000009.00000002.3724212347.000000000278E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_authorize.srfclient_id=00000000480728C5&scope=service::ssl.live.com::
                      Source: msfeedssync.exe, 00000009.00000003.1694442203.0000000007423000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_authorize.srfhttps://login.live.com/oauth20_desktop.srfhttps://login.
                      Source: msfeedssync.exe, 00000009.00000002.3724212347.000000000278E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_desktop.srf&lw=1&fl=wld2)
                      Source: msfeedssync.exe, 00000009.00000002.3724212347.000000000278E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_desktop.srf?lc=1033
                      Source: msfeedssync.exe, 00000009.00000002.3724212347.000000000278E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_desktop.srflc=1033
                      Source: msfeedssync.exe, 00000009.00000002.3724212347.000000000278E000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_logout.srf?client_id=00000000480728C5&redirect_uri=https://login.live
                      Source: msfeedssync.exe, 00000009.00000002.3724212347.00000000027B4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://login.live.com/oauth20_logout.srfclient_id=00000000480728C5&redirect_uri=https://login.live.
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/11564914/23354;
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1267757306.00000000030B6000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/14436606/23354
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/q/2152978/23354
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.ecosia.org/newtab/v20
                      Source: msfeedssync.exe, 00000009.00000002.3726343665.0000000003E5E000.00000004.10000000.00040000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3728048573.0000000005A00000.00000004.00000800.00020000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000002.3725944309.0000000003FCE000.00000004.00000001.00040000.00000000.sdmpString found in binary or memory: https://www.google.com
                      Source: msfeedssync.exe, 00000009.00000003.1698444106.0000000007448000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.google.com/images/branding/product/ico/googleg_alldp.ico
                      Source: msfeedssync.exe, 00000009.00000002.3726343665.0000000004638000.00000004.10000000.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000002.3725944309.00000000047A8000.00000004.00000001.00040000.00000000.sdmpString found in binary or memory: https://www.seasay.xyz/36xs/?G0L=GB6XqptpYp&amp;ut1tI=RgfpXspOgsNiHmosVF1KbpPv72dzNmiTBjL/Nd6qGeZ/g3
                      Source: msfeedssync.exe, 00000009.00000002.3726343665.0000000004638000.00000004.10000000.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000002.3725944309.00000000047A8000.00000004.00000001.00040000.00000000.sdmpString found in binary or memory: https://www.seasay.xyz/36xs/?G0L=GB6XqptpYp&ut1tI=RgfpXspOgsNiHmosVF1KbpPv72dzNmiTBjL/Nd6qGeZ/g3rBom

                      E-Banking Fraud

                      barindex
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000002.00000002.1511972245.0000000000FC0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000002.3727661903.0000000005840000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3725575572.0000000002860000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000008.00000002.3725515204.00000000041B0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1511179304.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3723672280.0000000002470000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3724115187.0000000002710000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1513679898.0000000003420000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_0646A7A0 NtResumeThread,0_2_0646A7A0
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_06466D90 NtProtectVirtualMemory,0_2_06466D90
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_0646A799 NtResumeThread,0_2_0646A799
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_06466D89 NtProtectVirtualMemory,0_2_06466D89
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0042C763 NtClose,2_2_0042C763
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2B60 NtClose,LdrInitializeThunk,2_2_010D2B60
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2DF0 NtQuerySystemInformation,LdrInitializeThunk,2_2_010D2DF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2C70 NtFreeVirtualMemory,LdrInitializeThunk,2_2_010D2C70
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D35C0 NtCreateMutant,LdrInitializeThunk,2_2_010D35C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D4340 NtSetContextThread,2_2_010D4340
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D4650 NtSuspendThread,2_2_010D4650
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2B80 NtQueryInformationFile,2_2_010D2B80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2BA0 NtEnumerateValueKey,2_2_010D2BA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2BE0 NtQueryValueKey,2_2_010D2BE0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2BF0 NtAllocateVirtualMemory,2_2_010D2BF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2AB0 NtWaitForSingleObject,2_2_010D2AB0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2AD0 NtReadFile,2_2_010D2AD0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2AF0 NtWriteFile,2_2_010D2AF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2D00 NtSetInformationFile,2_2_010D2D00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2D10 NtMapViewOfSection,2_2_010D2D10
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2D30 NtUnmapViewOfSection,2_2_010D2D30
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2DB0 NtEnumerateKey,2_2_010D2DB0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2DD0 NtDelayExecution,2_2_010D2DD0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2C00 NtQueryInformationProcess,2_2_010D2C00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2C60 NtCreateKey,2_2_010D2C60
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2CA0 NtQueryInformationToken,2_2_010D2CA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2CC0 NtQueryVirtualMemory,2_2_010D2CC0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2CF0 NtOpenProcess,2_2_010D2CF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2F30 NtCreateSection,2_2_010D2F30
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2F60 NtCreateProcessEx,2_2_010D2F60
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2F90 NtProtectVirtualMemory,2_2_010D2F90
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2FA0 NtQuerySection,2_2_010D2FA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2FB0 NtResumeThread,2_2_010D2FB0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2FE0 NtCreateFile,2_2_010D2FE0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2E30 NtWriteVirtualMemory,2_2_010D2E30
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2E80 NtReadVirtualMemory,2_2_010D2E80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2EA0 NtAdjustPrivilegesToken,2_2_010D2EA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2EE0 NtQueueApcThread,2_2_010D2EE0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D3010 NtOpenDirectoryObject,2_2_010D3010
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D3090 NtSetValueKey,2_2_010D3090
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D39B0 NtGetContextThread,2_2_010D39B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D3D10 NtOpenProcessToken,2_2_010D3D10
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D3D70 NtOpenThread,2_2_010D3D70
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE4340 NtSetContextThread,LdrInitializeThunk,9_2_02CE4340
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE4650 NtSuspendThread,LdrInitializeThunk,9_2_02CE4650
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2AD0 NtReadFile,LdrInitializeThunk,9_2_02CE2AD0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2AF0 NtWriteFile,LdrInitializeThunk,9_2_02CE2AF0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2BE0 NtQueryValueKey,LdrInitializeThunk,9_2_02CE2BE0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2BF0 NtAllocateVirtualMemory,LdrInitializeThunk,9_2_02CE2BF0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2BA0 NtEnumerateValueKey,LdrInitializeThunk,9_2_02CE2BA0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2B60 NtClose,LdrInitializeThunk,9_2_02CE2B60
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2EE0 NtQueueApcThread,LdrInitializeThunk,9_2_02CE2EE0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2E80 NtReadVirtualMemory,LdrInitializeThunk,9_2_02CE2E80
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2FE0 NtCreateFile,LdrInitializeThunk,9_2_02CE2FE0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2FB0 NtResumeThread,LdrInitializeThunk,9_2_02CE2FB0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2F30 NtCreateSection,LdrInitializeThunk,9_2_02CE2F30
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2CA0 NtQueryInformationToken,LdrInitializeThunk,9_2_02CE2CA0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2C60 NtCreateKey,LdrInitializeThunk,9_2_02CE2C60
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2C70 NtFreeVirtualMemory,LdrInitializeThunk,9_2_02CE2C70
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2DD0 NtDelayExecution,LdrInitializeThunk,9_2_02CE2DD0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2DF0 NtQuerySystemInformation,LdrInitializeThunk,9_2_02CE2DF0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2D10 NtMapViewOfSection,LdrInitializeThunk,9_2_02CE2D10
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2D30 NtUnmapViewOfSection,LdrInitializeThunk,9_2_02CE2D30
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE35C0 NtCreateMutant,LdrInitializeThunk,9_2_02CE35C0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE39B0 NtGetContextThread,LdrInitializeThunk,9_2_02CE39B0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2AB0 NtWaitForSingleObject,9_2_02CE2AB0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2B80 NtQueryInformationFile,9_2_02CE2B80
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2EA0 NtAdjustPrivilegesToken,9_2_02CE2EA0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2E30 NtWriteVirtualMemory,9_2_02CE2E30
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2F90 NtProtectVirtualMemory,9_2_02CE2F90
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2FA0 NtQuerySection,9_2_02CE2FA0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2F60 NtCreateProcessEx,9_2_02CE2F60
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2CC0 NtQueryVirtualMemory,9_2_02CE2CC0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2CF0 NtOpenProcess,9_2_02CE2CF0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2C00 NtQueryInformationProcess,9_2_02CE2C00
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2DB0 NtEnumerateKey,9_2_02CE2DB0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE2D00 NtSetInformationFile,9_2_02CE2D00
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE3090 NtSetValueKey,9_2_02CE3090
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE3010 NtOpenDirectoryObject,9_2_02CE3010
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE3D70 NtOpenThread,9_2_02CE3D70
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE3D10 NtOpenProcessToken,9_2_02CE3D10
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02499330 NtReadFile,9_2_02499330
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_024991D0 NtCreateFile,9_2_024991D0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02499610 NtAllocateVirtualMemory,9_2_02499610
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02499420 NtDeleteFile,9_2_02499420
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_024994C0 NtClose,9_2_024994C0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02ABF884 NtUnmapViewOfSection,9_2_02ABF884
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_0149ABC00_2_0149ABC0
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_0149EE880_2_0149EE88
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_014919B80_2_014919B8
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_0149ABB10_2_0149ABB1
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_014919B80_2_014919B8
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_064635C00_2_064635C0
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_064635B00_2_064635B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004186C32_2_004186C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004030002_2_00403000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004168C32_2_004168C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040E0C32_2_0040E0C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004100D32_2_004100D3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004168BE2_2_004168BE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004021DA2_2_004021DA
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004021E02_2_004021E0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004011A02_2_004011A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040E25C2_2_0040E25C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040E2072_2_0040E207
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040E2132_2_0040E213
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040239D2_2_0040239D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004023A02_2_004023A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0042ED532_2_0042ED53
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004026902_2_00402690
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040FEAD2_2_0040FEAD
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040FEB32_2_0040FEB3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010901002_2_01090100
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113A1182_2_0113A118
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011281582_2_01128158
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011541A22_2_011541A2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011601AA2_2_011601AA
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011581CC2_2_011581CC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011320002_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115A3522_2_0115A352
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011603E62_2_011603E6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE3F02_2_010AE3F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011402742_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011202C02_2_011202C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A05352_2_010A0535
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011605912_2_01160591
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011444202_2_01144420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011524462_2_01152446
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114E4F62_2_0114E4F6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C47502_2_010C4750
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A07702_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109C7C02_2_0109C7C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BC6E02_2_010BC6E0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B69622_2_010B6962
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0116A9A62_2_0116A9A6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AA8402_2_010AA840
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010868B82_2_010868B8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE8F02_2_010CE8F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115AB402_2_0115AB40
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01156BD72_2_01156BD7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA802_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AAD002_2_010AAD00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113CD1F2_2_0113CD1F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B8DBF2_2_010B8DBF
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109ADE02_2_0109ADE0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0C002_2_010A0C00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140CB52_2_01140CB5
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090CF22_2_01090CF2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01142F302_2_01142F30
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E2F282_2_010E2F28
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C0F302_2_010C0F30
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01114F402_2_01114F40
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111EFA02_2_0111EFA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01092FC82_2_01092FC8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010ACFE02_2_010ACFE0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115EE262_2_0115EE26
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0E592_2_010A0E59
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115CE932_2_0115CE93
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B2E902_2_010B2E90
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115EEDB2_2_0115EEDB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D516C2_2_010D516C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108F1722_2_0108F172
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0116B16B2_2_0116B16B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AB1B02_2_010AB1B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114F0CC2_2_0114F0CC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115F0E02_2_0115F0E0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011570E92_2_011570E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115132D2_2_0115132D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108D34C2_2_0108D34C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E739A2_2_010E739A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A52A02_2_010A52A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BB2C02_2_010BB2C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011412ED2_2_011412ED
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011575712_2_01157571
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113D5B02_2_0113D5B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011695C32_2_011695C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115F43F2_2_0115F43F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010914602_2_01091460
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115F7B02_2_0115F7B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E56302_2_010E5630
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011516CC2_2_011516CC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011359102_2_01135910
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A99502_2_010A9950
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BB9502_2_010BB950
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110D8002_2_0110D800
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A38E02_2_010A38E0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115FB762_2_0115FB76
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BFB802_2_010BFB80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01115BF02_2_01115BF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010DDBF92_2_010DDBF9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01157A462_2_01157A46
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115FA492_2_0115FA49
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01113A6C2_2_01113A6C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E5AA02_2_010E5AA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01141AA32_2_01141AA3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114DAC62_2_0114DAC6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A3D402_2_010A3D40
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01151D5A2_2_01151D5A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01157D732_2_01157D73
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BFDC02_2_010BFDC0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01119C322_2_01119C32
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115FCF22_2_0115FCF2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115FF092_2_0115FF09
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A1F922_2_010A1F92
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115FFB12_2_0115FFB1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01063FD52_2_01063FD5
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01063FD22_2_01063FD2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A9EB02_2_010A9EB0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D302C09_2_02D302C0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D502749_2_02D50274
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D703E69_2_02D703E6
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CBE3F09_2_02CBE3F0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6A3529_2_02D6A352
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D420009_2_02D42000
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D681CC9_2_02D681CC
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D641A29_2_02D641A2
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D701AA9_2_02D701AA
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D381589_2_02D38158
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CA01009_2_02CA0100
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D4A1189_2_02D4A118
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CCC6E09_2_02CCC6E0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CAC7C09_2_02CAC7C0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CD47509_2_02CD4750
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB07709_2_02CB0770
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D5E4F69_2_02D5E4F6
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D624469_2_02D62446
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D544209_2_02D54420
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D705919_2_02D70591
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB05359_2_02CB0535
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CAEA809_2_02CAEA80
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D66BD79_2_02D66BD7
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6AB409_2_02D6AB40
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CDE8F09_2_02CDE8F0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02C968B89_2_02C968B8
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CBA8409_2_02CBA840
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D7A9A69_2_02D7A9A6
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CC69629_2_02CC6962
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6EEDB9_2_02D6EEDB
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6CE939_2_02D6CE93
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CC2E909_2_02CC2E90
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB0E599_2_02CB0E59
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6EE269_2_02D6EE26
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CA2FC89_2_02CA2FC8
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CBCFE09_2_02CBCFE0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D2EFA09_2_02D2EFA0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D24F409_2_02D24F40
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D52F309_2_02D52F30
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CF2F289_2_02CF2F28
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CD0F309_2_02CD0F30
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CA0CF29_2_02CA0CF2
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D50CB59_2_02D50CB5
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB0C009_2_02CB0C00
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CAADE09_2_02CAADE0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CC8DBF9_2_02CC8DBF
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CBAD009_2_02CBAD00
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D4CD1F9_2_02D4CD1F
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CCB2C09_2_02CCB2C0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D512ED9_2_02D512ED
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB52A09_2_02CB52A0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CF739A9_2_02CF739A
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02C9D34C9_2_02C9D34C
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6132D9_2_02D6132D
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D5F0CC9_2_02D5F0CC
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6F0E09_2_02D6F0E0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D670E99_2_02D670E9
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CBB1B09_2_02CBB1B0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CE516C9_2_02CE516C
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02C9F1729_2_02C9F172
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D7B16B9_2_02D7B16B
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D616CC9_2_02D616CC
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CF56309_2_02CF5630
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6F7B09_2_02D6F7B0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CA14609_2_02CA1460
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6F43F9_2_02D6F43F
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D4D5B09_2_02D4D5B0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D675719_2_02D67571
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D5DAC69_2_02D5DAC6
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CF5AA09_2_02CF5AA0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D51AA39_2_02D51AA3
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D67A469_2_02D67A46
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6FA499_2_02D6FA49
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D23A6C9_2_02D23A6C
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D25BF09_2_02D25BF0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CEDBF99_2_02CEDBF9
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CCFB809_2_02CCFB80
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6FB769_2_02D6FB76
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB38E09_2_02CB38E0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D1D8009_2_02D1D800
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB99509_2_02CB9950
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CCB9509_2_02CCB950
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D459109_2_02D45910
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB9EB09_2_02CB9EB0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB1F929_2_02CB1F92
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6FFB19_2_02D6FFB1
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6FF099_2_02D6FF09
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D6FCF29_2_02D6FCF2
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D29C329_2_02D29C32
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CCFDC09_2_02CCFDC0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CB3D409_2_02CB3D40
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D61D5A9_2_02D61D5A
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02D67D739_2_02D67D73
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02481D909_2_02481D90
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0247AE209_2_0247AE20
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0247CE309_2_0247CE30
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0247AF649_2_0247AF64
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0247AF709_2_0247AF70
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0247AFB99_2_0247AFB9
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0247CC0A9_2_0247CC0A
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0247CC109_2_0247CC10
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0248361B9_2_0248361B
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_024836209_2_02483620
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_024854209_2_02485420
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0249BAB09_2_0249BAB0
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02ABE3139_2_02ABE313
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02ABE1F59_2_02ABE1F5
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02ABE6AC9_2_02ABE6AC
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02ABD7789_2_02ABD778
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02ABCA189_2_02ABCA18
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02ABC9EE9_2_02ABC9EE
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: String function: 02CF7E54 appears 101 times
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: String function: 02D1EA12 appears 86 times
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: String function: 02D2F290 appears 105 times
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: String function: 02CE5130 appears 58 times
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: String function: 02C9B970 appears 250 times
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: String function: 0110EA12 appears 86 times
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: String function: 010D5130 appears 58 times
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: String function: 0111F290 appears 105 times
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: String function: 010E7E54 appears 110 times
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: String function: 0108B970 appears 250 times
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1266356154.00000000012FE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameclr.dllT vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000000.1256043614.0000000000D2F000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenameCvoxsgsfodj.exe8 vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1290052858.0000000006480000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004563000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameMicrosoft.Win32.TaskScheduler.dll\ vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1285928493.00000000057C0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameZnozcpry.dll" vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1267757306.0000000003041000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilename vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmpBinary or memory string: OriginalFilenameprotobuf-net.dllJ vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exeBinary or memory string: OriginalFilenameCvoxsgsfodj.exe8 vs 2Stejb80vJ.exe
                      Source: 2Stejb80vJ.exeStatic PE information: EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, ITaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask'
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, TaskFolder.csTask registration methods: 'RegisterTaskDefinition', 'RegisterTask', 'CreateFolder'
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, Task.csTask registration methods: 'RegisterChanges', 'CreateTask'
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, TaskService.csTask registration methods: 'CreateFromToken'
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, TaskPrincipal.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, User.csSecurity API names: System.Security.Principal.SecurityIdentifier.Translate(System.Type)
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, TaskSecurity.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskSecurity.GetAccessControlSectionsFromChanges()
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, TaskSecurity.csSecurity API names: System.Security.AccessControl.CommonObjectSecurity.AddAccessRule(System.Security.AccessControl.AccessRule)
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, TaskFolder.csSecurity API names: Microsoft.Win32.TaskScheduler.TaskFolder.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, Task.csSecurity API names: Microsoft.Win32.TaskScheduler.Task.GetAccessControl(System.Security.AccessControl.AccessControlSections)
                      Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@7/1@22/10
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMutant created: NULL
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile created: C:\Users\user\AppData\Local\Temp\1euF2H00KJump to behavior
                      Source: 2Stejb80vJ.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                      Source: 2Stejb80vJ.exeStatic file information: TRID: Win32 Executable (generic) Net Framework (10011505/4) 49.83%
                      Source: C:\Program Files\Mozilla Firefox\firefox.exeFile read: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.iniJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                      Source: msfeedssync.exe, 00000009.00000003.1698926092.0000000002824000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1698926092.00000000027F1000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3724212347.00000000027F1000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3724212347.0000000002824000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: CREATE TABLE password_notes (id INTEGER PRIMARY KEY AUTOINCREMENT, parent_id INTEGER NOT NULL REFERENCES logins ON UPDATE CASCADE ON DELETE CASCADE DEFERRABLE INITIALLY DEFERRED, key VARCHAR NOT NULL, value BLOB, date_created INTEGER NOT NULL, confidential INTEGER, UNIQUE (parent_id, key));
                      Source: 2Stejb80vJ.exeVirustotal: Detection: 48%
                      Source: 2Stejb80vJ.exeReversingLabs: Detection: 68%
                      Source: unknownProcess created: C:\Users\user\Desktop\2Stejb80vJ.exe "C:\Users\user\Desktop\2Stejb80vJ.exe"
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeProcess created: C:\Windows\SysWOW64\msfeedssync.exe "C:\Windows\SysWOW64\msfeedssync.exe"
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"Jump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeProcess created: C:\Windows\SysWOW64\msfeedssync.exe "C:\Windows\SysWOW64\msfeedssync.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"Jump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: mscoree.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: apphelp.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: version.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: cryptsp.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: rsaenh.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: amsi.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: msasn1.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeSection loaded: gpapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: wininet.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: kernel.appcore.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: uxtheme.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: ieframe.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: iertutil.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: netapi32.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: version.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: userenv.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: winhttp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: wkscli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: netutils.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: sspicli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: windows.storage.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: wldp.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: profapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: secur32.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: mlang.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: propsys.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: winsqlite3.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: vaultcli.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: wintypes.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: dpapi.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: cryptbase.dllJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeSection loaded: wininet.dllJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeSection loaded: mswsock.dllJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeSection loaded: dnsapi.dllJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeSection loaded: iphlpapi.dllJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeSection loaded: fwpuclnt.dllJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeSection loaded: rasadhlp.dllJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{0EE7644B-1BAD-48B1-9889-0281C206EB85}\InprocServer32Jump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\15.0\Outlook\Profiles\Outlook\Jump to behavior
                      Source: 2Stejb80vJ.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR
                      Source: 2Stejb80vJ.exeStatic PE information: Virtual size of .text is bigger than: 0x100000
                      Source: 2Stejb80vJ.exeStatic file information: File size 2779136 > 1048576
                      Source: 2Stejb80vJ.exeStatic PE information: Raw size of .text is bigger than: 0x100000 < 0x2a5e00
                      Source: 2Stejb80vJ.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE
                      Source: Binary string: msfeedssync.pdbUGP source: InstallUtil.exe, 00000002.00000002.1511482654.0000000000B18000.00000004.00000020.00020000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3724366403.000000000076E000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdbSHA256e source: 2Stejb80vJ.exe, 00000000.00000002.1290052858.0000000006480000.00000004.08000000.00040000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004563000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdbUGP source: InstallUtil.exe, 00000002.00000002.1512128441.0000000001060000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3725902542.0000000002E0E000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3725902542.0000000002C70000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1511427615.000000000291B000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1513328412.0000000002AC0000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: C:\Users\dahall\Documents\GitHubRepos\TaskScheduler\TaskService\obj\Release\net40\Microsoft.Win32.TaskScheduler.pdb source: 2Stejb80vJ.exe, 00000000.00000002.1290052858.0000000006480000.00000004.08000000.00040000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004563000.00000004.00000800.00020000.00000000.sdmp
                      Source: Binary string: wntdll.pdb source: InstallUtil.exe, InstallUtil.exe, 00000002.00000002.1512128441.0000000001060000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, msfeedssync.exe, 00000009.00000002.3725902542.0000000002E0E000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3725902542.0000000002C70000.00000040.00001000.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1511427615.000000000291B000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000003.1513328412.0000000002AC0000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: InstallUtil.pdb\rvr hr_CorExeMainmscoree.dll source: msfeedssync.exe, 00000009.00000002.3724212347.0000000002772000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3726343665.000000000329C000.00000004.10000000.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580741225.000000000340C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 0000000B.00000002.1804393597.000000003187C000.00000004.80000000.00040000.00000000.sdmp
                      Source: Binary string: msfeedssync.pdb source: InstallUtil.exe, 00000002.00000002.1511482654.0000000000B18000.00000004.00000020.00020000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3724366403.000000000076E000.00000004.00000020.00020000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdbSHA256}Lq source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: protobuf-net.pdb source: 2Stejb80vJ.exe, 00000000.00000002.1280336868.00000000040BD000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1280336868.0000000004041000.00000004.00000800.00020000.00000000.sdmp, 2Stejb80vJ.exe, 00000000.00000002.1289228726.0000000005DC0000.00000004.08000000.00040000.00000000.sdmp
                      Source: Binary string: InstallUtil.pdb source: msfeedssync.exe, 00000009.00000002.3724212347.0000000002772000.00000004.00000020.00020000.00000000.sdmp, msfeedssync.exe, 00000009.00000002.3726343665.000000000329C000.00000004.10000000.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580741225.000000000340C000.00000004.00000001.00040000.00000000.sdmp, firefox.exe, 0000000B.00000002.1804393597.000000003187C000.00000004.80000000.00040000.00000000.sdmp
                      Source: Binary string: C:\Work\JoeSecurity\trunk\src\windows\usermode\tools\FakeChrome\Release\Chrome.pdb source: UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3725289857.0000000000F7F000.00000002.00000001.01000000.00000007.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1579858391.0000000000F7F000.00000002.00000001.01000000.00000007.sdmp

                      Data Obfuscation

                      barindex
                      Source: 2Stejb80vJ.exe, ElementProgram.cs.Net Code: ModifyAutomatableElement System.AppDomain.Load(byte[])
                      Source: 0.2.2Stejb80vJ.exe.40bd5b0.6.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
                      Source: 0.2.2Stejb80vJ.exe.40bd5b0.6.raw.unpack, ListDecorator.cs.Net Code: Read
                      Source: 0.2.2Stejb80vJ.exe.40bd5b0.6.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
                      Source: 0.2.2Stejb80vJ.exe.40bd5b0.6.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
                      Source: 0.2.2Stejb80vJ.exe.40bd5b0.6.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
                      Source: 0.2.2Stejb80vJ.exe.406d590.3.raw.unpack, TypeModel.cs.Net Code: TryDeserializeList
                      Source: 0.2.2Stejb80vJ.exe.406d590.3.raw.unpack, ListDecorator.cs.Net Code: Read
                      Source: 0.2.2Stejb80vJ.exe.406d590.3.raw.unpack, TypeSerializer.cs.Net Code: CreateInstance
                      Source: 0.2.2Stejb80vJ.exe.406d590.3.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateInstance
                      Source: 0.2.2Stejb80vJ.exe.406d590.3.raw.unpack, TypeSerializer.cs.Net Code: EmitCreateIfNull
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, ReflectionHelper.cs.Net Code: InvokeMethod
                      Source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, XmlSerializationHelper.cs.Net Code: ReadObjectProperties
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.46c16ce.2.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.5d10000.12.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.47c0ec0.4.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.5d10000.12.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.46c16ce.2.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.4658df0.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.4630dd0.9.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 0.2.2Stejb80vJ.exe.47c0ec0.4.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000000.00000002.1267757306.00000000030B6000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1288833714.0000000005D10000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1280336868.00000000047C0000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000000.00000002.1280336868.0000000004563000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: Process Memory Space: 2Stejb80vJ.exe PID: 6872, type: MEMORYSTR
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_06464C69 push es; iretd 0_2_06464C70
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_06464C15 push es; ret 0_2_06464C68
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeCode function: 0_2_06461889 push es; ret 0_2_064618A8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004170F5 push ebp; ret 2_2_004171B1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004170B6 push ecx; iretd 2_2_004170B7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00417152 push ebp; ret 2_2_004171B1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_004032A0 push eax; ret 2_2_004032A2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00414B89 push ebx; iretd 2_2_00414B8A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00401450 push esi; retf 89E0h2_2_00401545
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00418C2D push ss; retf 2_2_00418CBA
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0040BD8D push eax; retf 2_2_0040BD8E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00417E53 push es; ret 2_2_00417E82
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00417ED2 push esi; iretd 2_2_00417EDA
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00415FE3 push esi; retf 2_2_00415FEE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0106225F pushad ; ret 2_2_010627F9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010627FA pushad ; ret 2_2_010627F9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010909AD push ecx; mov dword ptr [esp], ecx2_2_010909B6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0106283D push eax; iretd 2_2_01062858
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01061368 push eax; iretd 2_2_01061369
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02CA09AD push ecx; mov dword ptr [esp], ecx9_2_02CA09B6
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02478AEA push eax; retf 9_2_02478AEB
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02484BB0 push es; ret 9_2_02484BDF
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0249080D push edi; ret 9_2_0249080E
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02484C2F push esi; iretd 9_2_02484C37
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02482D40 push esi; retf 9_2_02482D4B
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0248DADD push ecx; retf 9_2_0248DADE
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_024818E6 push ebx; iretd 9_2_024818E7
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02483E52 push ebp; ret 9_2_02483F0E
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02483E13 push ecx; iretd 9_2_02483E14
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02483EAF push ebp; ret 9_2_02483F0E
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_02AB4669 push ebx; retf 9_2_02AB466A
                      Source: 0.2.2Stejb80vJ.exe.57c0000.10.raw.unpack, oy1EET92y3t9NHaTcFf.csHigh entropy of concatenated method names: 'jMn9UASrIW', 'keT98Q8phc', 'LC09gmLcAD', 'r9U9XgwePS', 'ckO9SoBZJY', 'mNp9GymHkU', 't1l93BGBkQ', 'Xn49Q81fhT', 'axj9e3hDX9', 'C3K9Fw3ZxG'
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess information set: NOGPFAULTERRORBOX | NOOPENFILEERRORBOXJump to behavior

                      Malware Analysis System Evasion

                      barindex
                      Source: Yara matchFile source: Process Memory Space: 2Stejb80vJ.exe PID: 6872, type: MEMORYSTR
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105CD324
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105CD7E4
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105CD944
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105CD504
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105CD544
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105CD1E4
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105D0154
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI/Special instruction interceptor: Address: 7FF9105CDA44
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1267757306.00000000030B6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: SBIEDLL.DLL
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory allocated: 1490000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory allocated: 3040000 memory reserve | memory write watchJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory allocated: 5040000 memory reserve | memory write watchJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D096E rdtsc 2_2_010D096E
                      Source: C:\Windows\SysWOW64\msfeedssync.exeWindow / User API: threadDelayed 1075Jump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeWindow / User API: threadDelayed 8897Jump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeAPI coverage: 0.7 %
                      Source: C:\Windows\SysWOW64\msfeedssync.exeAPI coverage: 2.8 %
                      Source: C:\Windows\SysWOW64\msfeedssync.exe TID: 7040Thread sleep count: 1075 > 30Jump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exe TID: 7040Thread sleep time: -2150000s >= -30000sJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exe TID: 7040Thread sleep count: 8897 > 30Jump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exe TID: 7040Thread sleep time: -17794000s >= -30000sJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe TID: 1368Thread sleep time: -65000s >= -30000sJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe TID: 1368Thread sleep count: 36 > 30Jump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe TID: 1368Thread sleep time: -54000s >= -30000sJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe TID: 1368Thread sleep count: 36 > 30Jump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe TID: 1368Thread sleep time: -36000s >= -30000sJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeLast function: Thread delayed
                      Source: C:\Windows\SysWOW64\msfeedssync.exeLast function: Thread delayed
                      Source: C:\Windows\SysWOW64\msfeedssync.exeCode function: 9_2_0248C680 FindFirstFileW,FindNextFileW,FindClose,9_2_0248C680
                      Source: 1euF2H00K.9.drBinary or memory string: Interactive Brokers - EU East & CentralVMware20,11696487552
                      Source: firefox.exe, 0000000B.00000002.1805656747.00000215317CC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dllDD=
                      Source: 1euF2H00K.9.drBinary or memory string: account.microsoft.com/profileVMware20,11696487552u
                      Source: 1euF2H00K.9.drBinary or memory string: secure.bankofamerica.comVMware20,11696487552|UE
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: PasswordVMware20,11696487552^
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: interactivebrokers.co.inVMware20,1)Yr
                      Source: 1euF2H00K.9.drBinary or memory string: discord.comVMware20,11696487552f
                      Source: 1euF2H00K.9.drBinary or memory string: bankofamerica.comVMware20,11696487552x
                      Source: 1euF2H00K.9.drBinary or memory string: www.interactivebrokers.comVMware20,11696487552}
                      Source: 1euF2H00K.9.drBinary or memory string: ms.portal.azure.comVMware20,11696487552
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1267757306.00000000030B6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: Microsoft|VMWare|Virtual
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: rd.comVMware20,11696487552f
                      Source: 1euF2H00K.9.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696487552
                      Source: 1euF2H00K.9.drBinary or memory string: global block list test formVMware20,11696487552
                      Source: 1euF2H00K.9.drBinary or memory string: Interactive Brokers - COM.HKVMware20,11696487552
                      Source: 1euF2H00K.9.drBinary or memory string: tasks.office.comVMware20,11696487552o
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Interactive Brokers - NDCDYNVMware20,116
                      Source: 1euF2H00K.9.drBinary or memory string: AMC password management pageVMware20,11696487552
                      Source: msfeedssync.exe, 00000009.00000002.3724212347.0000000002772000.00000004.00000020.00020000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000002.3725362894.00000000015EA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: COM.HKVMware20,11696487552
                      Source: 1euF2H00K.9.drBinary or memory string: interactivebrokers.co.inVMware20,11696487552d
                      Source: 1euF2H00K.9.drBinary or memory string: dev.azure.comVMware20,11696487552j
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: rokers - EU WestVMware20,11696487552n
                      Source: 1euF2H00K.9.drBinary or memory string: interactivebrokers.comVMware20,11696487552
                      Source: 1euF2H00K.9.drBinary or memory string: Interactive Brokers - HKVMware20,11696487552]
                      Source: 1euF2H00K.9.drBinary or memory string: microsoft.visualstudio.comVMware20,11696487552x
                      Source: 1euF2H00K.9.drBinary or memory string: netportal.hdfcbank.comVMware20,11696487552
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: ms.portal.azure.comVMware20,1
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: tion PasswordVMware20,11696487552}
                      Source: 1euF2H00K.9.drBinary or memory string: trackpan.utiitsl.comVMware20,11696487552h
                      Source: 1euF2H00K.9.drBinary or memory string: Interactive Brokers - NDCDYNVMware20,11696487552z
                      Source: 2Stejb80vJ.exe, 00000000.00000002.1267757306.00000000030B6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: VMware|VIRTUAL|A M I|Xen
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: x.intuit.comVMware20,11696487552t
                      Source: 1euF2H00K.9.drBinary or memory string: outlook.office365.comVMware20,11696487552t
                      Source: 1euF2H00K.9.drBinary or memory string: www.interactivebrokers.co.inVMware20,11696487552~
                      Source: 1euF2H00K.9.drBinary or memory string: Canara Change Transaction PasswordVMware20,11696487552^
                      Source: 1euF2H00K.9.drBinary or memory string: Interactive Brokers - GDCDYNVMware20,11696487552p
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: microsoft.visualstudio.comVMware20,11696487552
                      Source: 1euF2H00K.9.drBinary or memory string: Interactive Brokers - EU WestVMware20,11696487552n
                      Source: 1euF2H00K.9.drBinary or memory string: outlook.office.comVMware20,11696487552s
                      Source: 1euF2H00K.9.drBinary or memory string: Test URL for global passwords blocklistVMware20,11696487552
                      Source: msfeedssync.exe, 00000009.00000002.3728191152.00000000074B5000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: .bankofamerica.comVMware20,11696
                      Source: 1euF2H00K.9.drBinary or memory string: turbotax.intuit.comVMware20,11696487552t
                      Source: 1euF2H00K.9.drBinary or memory string: Canara Transaction PasswordVMware20,11696487552x
                      Source: 1euF2H00K.9.drBinary or memory string: Canara Transaction PasswordVMware20,11696487552}
                      Source: 1euF2H00K.9.drBinary or memory string: Interactive Brokers - non-EU EuropeVMware20,11696487552
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess information queried: ProcessInformationJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess queried: DebugPortJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D096E rdtsc 2_2_010D096E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_00417853 LdrLoadDll,2_2_00417853
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01150115 mov eax, dword ptr fs:[00000030h]2_2_01150115
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113A118 mov ecx, dword ptr fs:[00000030h]2_2_0113A118
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113A118 mov eax, dword ptr fs:[00000030h]2_2_0113A118
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113A118 mov eax, dword ptr fs:[00000030h]2_2_0113A118
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113A118 mov eax, dword ptr fs:[00000030h]2_2_0113A118
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov eax, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov ecx, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov eax, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov eax, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov ecx, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov eax, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov eax, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov ecx, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov eax, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E10E mov ecx, dword ptr fs:[00000030h]2_2_0113E10E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C0124 mov eax, dword ptr fs:[00000030h]2_2_010C0124
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01128158 mov eax, dword ptr fs:[00000030h]2_2_01128158
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01124144 mov eax, dword ptr fs:[00000030h]2_2_01124144
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01124144 mov eax, dword ptr fs:[00000030h]2_2_01124144
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01124144 mov ecx, dword ptr fs:[00000030h]2_2_01124144
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01124144 mov eax, dword ptr fs:[00000030h]2_2_01124144
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01124144 mov eax, dword ptr fs:[00000030h]2_2_01124144
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096154 mov eax, dword ptr fs:[00000030h]2_2_01096154
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096154 mov eax, dword ptr fs:[00000030h]2_2_01096154
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108C156 mov eax, dword ptr fs:[00000030h]2_2_0108C156
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164164 mov eax, dword ptr fs:[00000030h]2_2_01164164
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164164 mov eax, dword ptr fs:[00000030h]2_2_01164164
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D0185 mov eax, dword ptr fs:[00000030h]2_2_010D0185
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111019F mov eax, dword ptr fs:[00000030h]2_2_0111019F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111019F mov eax, dword ptr fs:[00000030h]2_2_0111019F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111019F mov eax, dword ptr fs:[00000030h]2_2_0111019F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111019F mov eax, dword ptr fs:[00000030h]2_2_0111019F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01134180 mov eax, dword ptr fs:[00000030h]2_2_01134180
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01134180 mov eax, dword ptr fs:[00000030h]2_2_01134180
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114C188 mov eax, dword ptr fs:[00000030h]2_2_0114C188
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114C188 mov eax, dword ptr fs:[00000030h]2_2_0114C188
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108A197 mov eax, dword ptr fs:[00000030h]2_2_0108A197
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108A197 mov eax, dword ptr fs:[00000030h]2_2_0108A197
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108A197 mov eax, dword ptr fs:[00000030h]2_2_0108A197
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E1D0 mov eax, dword ptr fs:[00000030h]2_2_0110E1D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E1D0 mov eax, dword ptr fs:[00000030h]2_2_0110E1D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E1D0 mov ecx, dword ptr fs:[00000030h]2_2_0110E1D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E1D0 mov eax, dword ptr fs:[00000030h]2_2_0110E1D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E1D0 mov eax, dword ptr fs:[00000030h]2_2_0110E1D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011561C3 mov eax, dword ptr fs:[00000030h]2_2_011561C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011561C3 mov eax, dword ptr fs:[00000030h]2_2_011561C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011661E5 mov eax, dword ptr fs:[00000030h]2_2_011661E5
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C01F8 mov eax, dword ptr fs:[00000030h]2_2_010C01F8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01114000 mov ecx, dword ptr fs:[00000030h]2_2_01114000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01132000 mov eax, dword ptr fs:[00000030h]2_2_01132000
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE016 mov eax, dword ptr fs:[00000030h]2_2_010AE016
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE016 mov eax, dword ptr fs:[00000030h]2_2_010AE016
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE016 mov eax, dword ptr fs:[00000030h]2_2_010AE016
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE016 mov eax, dword ptr fs:[00000030h]2_2_010AE016
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01126030 mov eax, dword ptr fs:[00000030h]2_2_01126030
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108A020 mov eax, dword ptr fs:[00000030h]2_2_0108A020
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108C020 mov eax, dword ptr fs:[00000030h]2_2_0108C020
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116050 mov eax, dword ptr fs:[00000030h]2_2_01116050
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01092050 mov eax, dword ptr fs:[00000030h]2_2_01092050
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BC073 mov eax, dword ptr fs:[00000030h]2_2_010BC073
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109208A mov eax, dword ptr fs:[00000030h]2_2_0109208A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010880A0 mov eax, dword ptr fs:[00000030h]2_2_010880A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011560B8 mov eax, dword ptr fs:[00000030h]2_2_011560B8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011560B8 mov ecx, dword ptr fs:[00000030h]2_2_011560B8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011280A8 mov eax, dword ptr fs:[00000030h]2_2_011280A8
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011120DE mov eax, dword ptr fs:[00000030h]2_2_011120DE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010980E9 mov eax, dword ptr fs:[00000030h]2_2_010980E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108A0E3 mov ecx, dword ptr fs:[00000030h]2_2_0108A0E3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011160E0 mov eax, dword ptr fs:[00000030h]2_2_011160E0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108C0F0 mov eax, dword ptr fs:[00000030h]2_2_0108C0F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D20F0 mov ecx, dword ptr fs:[00000030h]2_2_010D20F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA30B mov eax, dword ptr fs:[00000030h]2_2_010CA30B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA30B mov eax, dword ptr fs:[00000030h]2_2_010CA30B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA30B mov eax, dword ptr fs:[00000030h]2_2_010CA30B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108C310 mov ecx, dword ptr fs:[00000030h]2_2_0108C310
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B0310 mov ecx, dword ptr fs:[00000030h]2_2_010B0310
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115A352 mov eax, dword ptr fs:[00000030h]2_2_0115A352
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111035C mov eax, dword ptr fs:[00000030h]2_2_0111035C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111035C mov eax, dword ptr fs:[00000030h]2_2_0111035C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111035C mov eax, dword ptr fs:[00000030h]2_2_0111035C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111035C mov ecx, dword ptr fs:[00000030h]2_2_0111035C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111035C mov eax, dword ptr fs:[00000030h]2_2_0111035C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111035C mov eax, dword ptr fs:[00000030h]2_2_0111035C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01112349 mov eax, dword ptr fs:[00000030h]2_2_01112349
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0116634F mov eax, dword ptr fs:[00000030h]2_2_0116634F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113437C mov eax, dword ptr fs:[00000030h]2_2_0113437C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108E388 mov eax, dword ptr fs:[00000030h]2_2_0108E388
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108E388 mov eax, dword ptr fs:[00000030h]2_2_0108E388
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108E388 mov eax, dword ptr fs:[00000030h]2_2_0108E388
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B438F mov eax, dword ptr fs:[00000030h]2_2_010B438F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B438F mov eax, dword ptr fs:[00000030h]2_2_010B438F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01088397 mov eax, dword ptr fs:[00000030h]2_2_01088397
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01088397 mov eax, dword ptr fs:[00000030h]2_2_01088397
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01088397 mov eax, dword ptr fs:[00000030h]2_2_01088397
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011343D4 mov eax, dword ptr fs:[00000030h]2_2_011343D4
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011343D4 mov eax, dword ptr fs:[00000030h]2_2_011343D4
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E3DB mov eax, dword ptr fs:[00000030h]2_2_0113E3DB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E3DB mov eax, dword ptr fs:[00000030h]2_2_0113E3DB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E3DB mov ecx, dword ptr fs:[00000030h]2_2_0113E3DB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113E3DB mov eax, dword ptr fs:[00000030h]2_2_0113E3DB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A3C0 mov eax, dword ptr fs:[00000030h]2_2_0109A3C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A3C0 mov eax, dword ptr fs:[00000030h]2_2_0109A3C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A3C0 mov eax, dword ptr fs:[00000030h]2_2_0109A3C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A3C0 mov eax, dword ptr fs:[00000030h]2_2_0109A3C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A3C0 mov eax, dword ptr fs:[00000030h]2_2_0109A3C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A3C0 mov eax, dword ptr fs:[00000030h]2_2_0109A3C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010983C0 mov eax, dword ptr fs:[00000030h]2_2_010983C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010983C0 mov eax, dword ptr fs:[00000030h]2_2_010983C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010983C0 mov eax, dword ptr fs:[00000030h]2_2_010983C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010983C0 mov eax, dword ptr fs:[00000030h]2_2_010983C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011163C0 mov eax, dword ptr fs:[00000030h]2_2_011163C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114C3CD mov eax, dword ptr fs:[00000030h]2_2_0114C3CD
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A03E9 mov eax, dword ptr fs:[00000030h]2_2_010A03E9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C63FF mov eax, dword ptr fs:[00000030h]2_2_010C63FF
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE3F0 mov eax, dword ptr fs:[00000030h]2_2_010AE3F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE3F0 mov eax, dword ptr fs:[00000030h]2_2_010AE3F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE3F0 mov eax, dword ptr fs:[00000030h]2_2_010AE3F0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108823B mov eax, dword ptr fs:[00000030h]2_2_0108823B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114A250 mov eax, dword ptr fs:[00000030h]2_2_0114A250
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114A250 mov eax, dword ptr fs:[00000030h]2_2_0114A250
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0116625D mov eax, dword ptr fs:[00000030h]2_2_0116625D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096259 mov eax, dword ptr fs:[00000030h]2_2_01096259
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01118243 mov eax, dword ptr fs:[00000030h]2_2_01118243
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01118243 mov ecx, dword ptr fs:[00000030h]2_2_01118243
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108A250 mov eax, dword ptr fs:[00000030h]2_2_0108A250
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01140274 mov eax, dword ptr fs:[00000030h]2_2_01140274
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108826B mov eax, dword ptr fs:[00000030h]2_2_0108826B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01094260 mov eax, dword ptr fs:[00000030h]2_2_01094260
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01094260 mov eax, dword ptr fs:[00000030h]2_2_01094260
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01094260 mov eax, dword ptr fs:[00000030h]2_2_01094260
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE284 mov eax, dword ptr fs:[00000030h]2_2_010CE284
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE284 mov eax, dword ptr fs:[00000030h]2_2_010CE284
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01110283 mov eax, dword ptr fs:[00000030h]2_2_01110283
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01110283 mov eax, dword ptr fs:[00000030h]2_2_01110283
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01110283 mov eax, dword ptr fs:[00000030h]2_2_01110283
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A02A0 mov eax, dword ptr fs:[00000030h]2_2_010A02A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A02A0 mov eax, dword ptr fs:[00000030h]2_2_010A02A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011262A0 mov eax, dword ptr fs:[00000030h]2_2_011262A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011262A0 mov ecx, dword ptr fs:[00000030h]2_2_011262A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011262A0 mov eax, dword ptr fs:[00000030h]2_2_011262A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011262A0 mov eax, dword ptr fs:[00000030h]2_2_011262A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011262A0 mov eax, dword ptr fs:[00000030h]2_2_011262A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011262A0 mov eax, dword ptr fs:[00000030h]2_2_011262A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011662D6 mov eax, dword ptr fs:[00000030h]2_2_011662D6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A2C3 mov eax, dword ptr fs:[00000030h]2_2_0109A2C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A2C3 mov eax, dword ptr fs:[00000030h]2_2_0109A2C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A2C3 mov eax, dword ptr fs:[00000030h]2_2_0109A2C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A2C3 mov eax, dword ptr fs:[00000030h]2_2_0109A2C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A2C3 mov eax, dword ptr fs:[00000030h]2_2_0109A2C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A02E1 mov eax, dword ptr fs:[00000030h]2_2_010A02E1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A02E1 mov eax, dword ptr fs:[00000030h]2_2_010A02E1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A02E1 mov eax, dword ptr fs:[00000030h]2_2_010A02E1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01126500 mov eax, dword ptr fs:[00000030h]2_2_01126500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164500 mov eax, dword ptr fs:[00000030h]2_2_01164500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164500 mov eax, dword ptr fs:[00000030h]2_2_01164500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164500 mov eax, dword ptr fs:[00000030h]2_2_01164500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164500 mov eax, dword ptr fs:[00000030h]2_2_01164500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164500 mov eax, dword ptr fs:[00000030h]2_2_01164500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164500 mov eax, dword ptr fs:[00000030h]2_2_01164500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164500 mov eax, dword ptr fs:[00000030h]2_2_01164500
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE53E mov eax, dword ptr fs:[00000030h]2_2_010BE53E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE53E mov eax, dword ptr fs:[00000030h]2_2_010BE53E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE53E mov eax, dword ptr fs:[00000030h]2_2_010BE53E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE53E mov eax, dword ptr fs:[00000030h]2_2_010BE53E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE53E mov eax, dword ptr fs:[00000030h]2_2_010BE53E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0535 mov eax, dword ptr fs:[00000030h]2_2_010A0535
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0535 mov eax, dword ptr fs:[00000030h]2_2_010A0535
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0535 mov eax, dword ptr fs:[00000030h]2_2_010A0535
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0535 mov eax, dword ptr fs:[00000030h]2_2_010A0535
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0535 mov eax, dword ptr fs:[00000030h]2_2_010A0535
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0535 mov eax, dword ptr fs:[00000030h]2_2_010A0535
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098550 mov eax, dword ptr fs:[00000030h]2_2_01098550
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098550 mov eax, dword ptr fs:[00000030h]2_2_01098550
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C656A mov eax, dword ptr fs:[00000030h]2_2_010C656A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C656A mov eax, dword ptr fs:[00000030h]2_2_010C656A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C656A mov eax, dword ptr fs:[00000030h]2_2_010C656A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C4588 mov eax, dword ptr fs:[00000030h]2_2_010C4588
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01092582 mov eax, dword ptr fs:[00000030h]2_2_01092582
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01092582 mov ecx, dword ptr fs:[00000030h]2_2_01092582
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE59C mov eax, dword ptr fs:[00000030h]2_2_010CE59C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011105A7 mov eax, dword ptr fs:[00000030h]2_2_011105A7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011105A7 mov eax, dword ptr fs:[00000030h]2_2_011105A7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011105A7 mov eax, dword ptr fs:[00000030h]2_2_011105A7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B45B1 mov eax, dword ptr fs:[00000030h]2_2_010B45B1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B45B1 mov eax, dword ptr fs:[00000030h]2_2_010B45B1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE5CF mov eax, dword ptr fs:[00000030h]2_2_010CE5CF
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE5CF mov eax, dword ptr fs:[00000030h]2_2_010CE5CF
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010965D0 mov eax, dword ptr fs:[00000030h]2_2_010965D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA5D0 mov eax, dword ptr fs:[00000030h]2_2_010CA5D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA5D0 mov eax, dword ptr fs:[00000030h]2_2_010CA5D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC5ED mov eax, dword ptr fs:[00000030h]2_2_010CC5ED
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC5ED mov eax, dword ptr fs:[00000030h]2_2_010CC5ED
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010925E0 mov eax, dword ptr fs:[00000030h]2_2_010925E0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE5E7 mov eax, dword ptr fs:[00000030h]2_2_010BE5E7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C8402 mov eax, dword ptr fs:[00000030h]2_2_010C8402
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C8402 mov eax, dword ptr fs:[00000030h]2_2_010C8402
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C8402 mov eax, dword ptr fs:[00000030h]2_2_010C8402
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108E420 mov eax, dword ptr fs:[00000030h]2_2_0108E420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108E420 mov eax, dword ptr fs:[00000030h]2_2_0108E420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108E420 mov eax, dword ptr fs:[00000030h]2_2_0108E420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108C427 mov eax, dword ptr fs:[00000030h]2_2_0108C427
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116420 mov eax, dword ptr fs:[00000030h]2_2_01116420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116420 mov eax, dword ptr fs:[00000030h]2_2_01116420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116420 mov eax, dword ptr fs:[00000030h]2_2_01116420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116420 mov eax, dword ptr fs:[00000030h]2_2_01116420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116420 mov eax, dword ptr fs:[00000030h]2_2_01116420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116420 mov eax, dword ptr fs:[00000030h]2_2_01116420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01116420 mov eax, dword ptr fs:[00000030h]2_2_01116420
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA430 mov eax, dword ptr fs:[00000030h]2_2_010CA430
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114A456 mov eax, dword ptr fs:[00000030h]2_2_0114A456
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CE443 mov eax, dword ptr fs:[00000030h]2_2_010CE443
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B245A mov eax, dword ptr fs:[00000030h]2_2_010B245A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108645D mov eax, dword ptr fs:[00000030h]2_2_0108645D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111C460 mov ecx, dword ptr fs:[00000030h]2_2_0111C460
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BA470 mov eax, dword ptr fs:[00000030h]2_2_010BA470
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BA470 mov eax, dword ptr fs:[00000030h]2_2_010BA470
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BA470 mov eax, dword ptr fs:[00000030h]2_2_010BA470
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0114A49A mov eax, dword ptr fs:[00000030h]2_2_0114A49A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111A4B0 mov eax, dword ptr fs:[00000030h]2_2_0111A4B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010964AB mov eax, dword ptr fs:[00000030h]2_2_010964AB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C44B0 mov ecx, dword ptr fs:[00000030h]2_2_010C44B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010904E5 mov ecx, dword ptr fs:[00000030h]2_2_010904E5
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC700 mov eax, dword ptr fs:[00000030h]2_2_010CC700
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090710 mov eax, dword ptr fs:[00000030h]2_2_01090710
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C0710 mov eax, dword ptr fs:[00000030h]2_2_010C0710
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110C730 mov eax, dword ptr fs:[00000030h]2_2_0110C730
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC720 mov eax, dword ptr fs:[00000030h]2_2_010CC720
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC720 mov eax, dword ptr fs:[00000030h]2_2_010CC720
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C273C mov eax, dword ptr fs:[00000030h]2_2_010C273C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C273C mov ecx, dword ptr fs:[00000030h]2_2_010C273C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C273C mov eax, dword ptr fs:[00000030h]2_2_010C273C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C674D mov esi, dword ptr fs:[00000030h]2_2_010C674D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C674D mov eax, dword ptr fs:[00000030h]2_2_010C674D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C674D mov eax, dword ptr fs:[00000030h]2_2_010C674D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01114755 mov eax, dword ptr fs:[00000030h]2_2_01114755
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111E75D mov eax, dword ptr fs:[00000030h]2_2_0111E75D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090750 mov eax, dword ptr fs:[00000030h]2_2_01090750
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2750 mov eax, dword ptr fs:[00000030h]2_2_010D2750
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2750 mov eax, dword ptr fs:[00000030h]2_2_010D2750
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098770 mov eax, dword ptr fs:[00000030h]2_2_01098770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0770 mov eax, dword ptr fs:[00000030h]2_2_010A0770
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113678E mov eax, dword ptr fs:[00000030h]2_2_0113678E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010907AF mov eax, dword ptr fs:[00000030h]2_2_010907AF
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011447A0 mov eax, dword ptr fs:[00000030h]2_2_011447A0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109C7C0 mov eax, dword ptr fs:[00000030h]2_2_0109C7C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011107C3 mov eax, dword ptr fs:[00000030h]2_2_011107C3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B27ED mov eax, dword ptr fs:[00000030h]2_2_010B27ED
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B27ED mov eax, dword ptr fs:[00000030h]2_2_010B27ED
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B27ED mov eax, dword ptr fs:[00000030h]2_2_010B27ED
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111E7E1 mov eax, dword ptr fs:[00000030h]2_2_0111E7E1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010947FB mov eax, dword ptr fs:[00000030h]2_2_010947FB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010947FB mov eax, dword ptr fs:[00000030h]2_2_010947FB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A260B mov eax, dword ptr fs:[00000030h]2_2_010A260B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A260B mov eax, dword ptr fs:[00000030h]2_2_010A260B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A260B mov eax, dword ptr fs:[00000030h]2_2_010A260B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A260B mov eax, dword ptr fs:[00000030h]2_2_010A260B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A260B mov eax, dword ptr fs:[00000030h]2_2_010A260B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A260B mov eax, dword ptr fs:[00000030h]2_2_010A260B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A260B mov eax, dword ptr fs:[00000030h]2_2_010A260B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D2619 mov eax, dword ptr fs:[00000030h]2_2_010D2619
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E609 mov eax, dword ptr fs:[00000030h]2_2_0110E609
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109262C mov eax, dword ptr fs:[00000030h]2_2_0109262C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C6620 mov eax, dword ptr fs:[00000030h]2_2_010C6620
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C8620 mov eax, dword ptr fs:[00000030h]2_2_010C8620
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AE627 mov eax, dword ptr fs:[00000030h]2_2_010AE627
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AC640 mov eax, dword ptr fs:[00000030h]2_2_010AC640
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA660 mov eax, dword ptr fs:[00000030h]2_2_010CA660
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA660 mov eax, dword ptr fs:[00000030h]2_2_010CA660
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C2674 mov eax, dword ptr fs:[00000030h]2_2_010C2674
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115866E mov eax, dword ptr fs:[00000030h]2_2_0115866E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115866E mov eax, dword ptr fs:[00000030h]2_2_0115866E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01094690 mov eax, dword ptr fs:[00000030h]2_2_01094690
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01094690 mov eax, dword ptr fs:[00000030h]2_2_01094690
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC6A6 mov eax, dword ptr fs:[00000030h]2_2_010CC6A6
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C66B0 mov eax, dword ptr fs:[00000030h]2_2_010C66B0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA6C7 mov ebx, dword ptr fs:[00000030h]2_2_010CA6C7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA6C7 mov eax, dword ptr fs:[00000030h]2_2_010CA6C7
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011106F1 mov eax, dword ptr fs:[00000030h]2_2_011106F1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011106F1 mov eax, dword ptr fs:[00000030h]2_2_011106F1
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E6F2 mov eax, dword ptr fs:[00000030h]2_2_0110E6F2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E6F2 mov eax, dword ptr fs:[00000030h]2_2_0110E6F2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E6F2 mov eax, dword ptr fs:[00000030h]2_2_0110E6F2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E6F2 mov eax, dword ptr fs:[00000030h]2_2_0110E6F2
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111C912 mov eax, dword ptr fs:[00000030h]2_2_0111C912
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01088918 mov eax, dword ptr fs:[00000030h]2_2_01088918
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01088918 mov eax, dword ptr fs:[00000030h]2_2_01088918
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E908 mov eax, dword ptr fs:[00000030h]2_2_0110E908
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110E908 mov eax, dword ptr fs:[00000030h]2_2_0110E908
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0112892B mov eax, dword ptr fs:[00000030h]2_2_0112892B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111892A mov eax, dword ptr fs:[00000030h]2_2_0111892A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164940 mov eax, dword ptr fs:[00000030h]2_2_01164940
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01110946 mov eax, dword ptr fs:[00000030h]2_2_01110946
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D096E mov eax, dword ptr fs:[00000030h]2_2_010D096E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D096E mov edx, dword ptr fs:[00000030h]2_2_010D096E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010D096E mov eax, dword ptr fs:[00000030h]2_2_010D096E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B6962 mov eax, dword ptr fs:[00000030h]2_2_010B6962
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B6962 mov eax, dword ptr fs:[00000030h]2_2_010B6962
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B6962 mov eax, dword ptr fs:[00000030h]2_2_010B6962
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01134978 mov eax, dword ptr fs:[00000030h]2_2_01134978
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01134978 mov eax, dword ptr fs:[00000030h]2_2_01134978
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111C97C mov eax, dword ptr fs:[00000030h]2_2_0111C97C
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011189B3 mov esi, dword ptr fs:[00000030h]2_2_011189B3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011189B3 mov eax, dword ptr fs:[00000030h]2_2_011189B3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011189B3 mov eax, dword ptr fs:[00000030h]2_2_011189B3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010909AD mov eax, dword ptr fs:[00000030h]2_2_010909AD
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010909AD mov eax, dword ptr fs:[00000030h]2_2_010909AD
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115A9D3 mov eax, dword ptr fs:[00000030h]2_2_0115A9D3
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011269C0 mov eax, dword ptr fs:[00000030h]2_2_011269C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A9D0 mov eax, dword ptr fs:[00000030h]2_2_0109A9D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A9D0 mov eax, dword ptr fs:[00000030h]2_2_0109A9D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A9D0 mov eax, dword ptr fs:[00000030h]2_2_0109A9D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A9D0 mov eax, dword ptr fs:[00000030h]2_2_0109A9D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A9D0 mov eax, dword ptr fs:[00000030h]2_2_0109A9D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109A9D0 mov eax, dword ptr fs:[00000030h]2_2_0109A9D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C49D0 mov eax, dword ptr fs:[00000030h]2_2_010C49D0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111E9E0 mov eax, dword ptr fs:[00000030h]2_2_0111E9E0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C29F9 mov eax, dword ptr fs:[00000030h]2_2_010C29F9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C29F9 mov eax, dword ptr fs:[00000030h]2_2_010C29F9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111C810 mov eax, dword ptr fs:[00000030h]2_2_0111C810
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113483A mov eax, dword ptr fs:[00000030h]2_2_0113483A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113483A mov eax, dword ptr fs:[00000030h]2_2_0113483A
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CA830 mov eax, dword ptr fs:[00000030h]2_2_010CA830
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B2835 mov eax, dword ptr fs:[00000030h]2_2_010B2835
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B2835 mov eax, dword ptr fs:[00000030h]2_2_010B2835
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B2835 mov eax, dword ptr fs:[00000030h]2_2_010B2835
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B2835 mov ecx, dword ptr fs:[00000030h]2_2_010B2835
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B2835 mov eax, dword ptr fs:[00000030h]2_2_010B2835
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B2835 mov eax, dword ptr fs:[00000030h]2_2_010B2835
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01094859 mov eax, dword ptr fs:[00000030h]2_2_01094859
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01094859 mov eax, dword ptr fs:[00000030h]2_2_01094859
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C0854 mov eax, dword ptr fs:[00000030h]2_2_010C0854
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01126870 mov eax, dword ptr fs:[00000030h]2_2_01126870
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01126870 mov eax, dword ptr fs:[00000030h]2_2_01126870
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111E872 mov eax, dword ptr fs:[00000030h]2_2_0111E872
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111E872 mov eax, dword ptr fs:[00000030h]2_2_0111E872
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111C89D mov eax, dword ptr fs:[00000030h]2_2_0111C89D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090887 mov eax, dword ptr fs:[00000030h]2_2_01090887
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BE8C0 mov eax, dword ptr fs:[00000030h]2_2_010BE8C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_011608C0 mov eax, dword ptr fs:[00000030h]2_2_011608C0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115A8E4 mov eax, dword ptr fs:[00000030h]2_2_0115A8E4
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC8F9 mov eax, dword ptr fs:[00000030h]2_2_010CC8F9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CC8F9 mov eax, dword ptr fs:[00000030h]2_2_010CC8F9
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110EB1D mov eax, dword ptr fs:[00000030h]2_2_0110EB1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164B00 mov eax, dword ptr fs:[00000030h]2_2_01164B00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BEB20 mov eax, dword ptr fs:[00000030h]2_2_010BEB20
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BEB20 mov eax, dword ptr fs:[00000030h]2_2_010BEB20
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01158B28 mov eax, dword ptr fs:[00000030h]2_2_01158B28
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01158B28 mov eax, dword ptr fs:[00000030h]2_2_01158B28
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01162B57 mov eax, dword ptr fs:[00000030h]2_2_01162B57
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01162B57 mov eax, dword ptr fs:[00000030h]2_2_01162B57
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01162B57 mov eax, dword ptr fs:[00000030h]2_2_01162B57
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01162B57 mov eax, dword ptr fs:[00000030h]2_2_01162B57
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113EB50 mov eax, dword ptr fs:[00000030h]2_2_0113EB50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01138B42 mov eax, dword ptr fs:[00000030h]2_2_01138B42
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01126B40 mov eax, dword ptr fs:[00000030h]2_2_01126B40
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01126B40 mov eax, dword ptr fs:[00000030h]2_2_01126B40
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0115AB40 mov eax, dword ptr fs:[00000030h]2_2_0115AB40
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01088B50 mov eax, dword ptr fs:[00000030h]2_2_01088B50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01144B4B mov eax, dword ptr fs:[00000030h]2_2_01144B4B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01144B4B mov eax, dword ptr fs:[00000030h]2_2_01144B4B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0108CB7E mov eax, dword ptr fs:[00000030h]2_2_0108CB7E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01144BB0 mov eax, dword ptr fs:[00000030h]2_2_01144BB0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01144BB0 mov eax, dword ptr fs:[00000030h]2_2_01144BB0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0BBE mov eax, dword ptr fs:[00000030h]2_2_010A0BBE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0BBE mov eax, dword ptr fs:[00000030h]2_2_010A0BBE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B0BCB mov eax, dword ptr fs:[00000030h]2_2_010B0BCB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B0BCB mov eax, dword ptr fs:[00000030h]2_2_010B0BCB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B0BCB mov eax, dword ptr fs:[00000030h]2_2_010B0BCB
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113EBD0 mov eax, dword ptr fs:[00000030h]2_2_0113EBD0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090BCD mov eax, dword ptr fs:[00000030h]2_2_01090BCD
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090BCD mov eax, dword ptr fs:[00000030h]2_2_01090BCD
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090BCD mov eax, dword ptr fs:[00000030h]2_2_01090BCD
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111CBF0 mov eax, dword ptr fs:[00000030h]2_2_0111CBF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BEBFC mov eax, dword ptr fs:[00000030h]2_2_010BEBFC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098BF0 mov eax, dword ptr fs:[00000030h]2_2_01098BF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098BF0 mov eax, dword ptr fs:[00000030h]2_2_01098BF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098BF0 mov eax, dword ptr fs:[00000030h]2_2_01098BF0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0111CA11 mov eax, dword ptr fs:[00000030h]2_2_0111CA11
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010BEA2E mov eax, dword ptr fs:[00000030h]2_2_010BEA2E
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CCA24 mov eax, dword ptr fs:[00000030h]2_2_010CCA24
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CCA38 mov eax, dword ptr fs:[00000030h]2_2_010CCA38
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B4A35 mov eax, dword ptr fs:[00000030h]2_2_010B4A35
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010B4A35 mov eax, dword ptr fs:[00000030h]2_2_010B4A35
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0A5B mov eax, dword ptr fs:[00000030h]2_2_010A0A5B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010A0A5B mov eax, dword ptr fs:[00000030h]2_2_010A0A5B
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096A50 mov eax, dword ptr fs:[00000030h]2_2_01096A50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096A50 mov eax, dword ptr fs:[00000030h]2_2_01096A50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096A50 mov eax, dword ptr fs:[00000030h]2_2_01096A50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096A50 mov eax, dword ptr fs:[00000030h]2_2_01096A50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096A50 mov eax, dword ptr fs:[00000030h]2_2_01096A50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096A50 mov eax, dword ptr fs:[00000030h]2_2_01096A50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01096A50 mov eax, dword ptr fs:[00000030h]2_2_01096A50
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110CA72 mov eax, dword ptr fs:[00000030h]2_2_0110CA72
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0110CA72 mov eax, dword ptr fs:[00000030h]2_2_0110CA72
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CCA6F mov eax, dword ptr fs:[00000030h]2_2_010CCA6F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CCA6F mov eax, dword ptr fs:[00000030h]2_2_010CCA6F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CCA6F mov eax, dword ptr fs:[00000030h]2_2_010CCA6F
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0113EA60 mov eax, dword ptr fs:[00000030h]2_2_0113EA60
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_0109EA80 mov eax, dword ptr fs:[00000030h]2_2_0109EA80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01164A80 mov eax, dword ptr fs:[00000030h]2_2_01164A80
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C8A90 mov edx, dword ptr fs:[00000030h]2_2_010C8A90
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098AA0 mov eax, dword ptr fs:[00000030h]2_2_01098AA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01098AA0 mov eax, dword ptr fs:[00000030h]2_2_01098AA0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E6AA4 mov eax, dword ptr fs:[00000030h]2_2_010E6AA4
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E6ACC mov eax, dword ptr fs:[00000030h]2_2_010E6ACC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E6ACC mov eax, dword ptr fs:[00000030h]2_2_010E6ACC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010E6ACC mov eax, dword ptr fs:[00000030h]2_2_010E6ACC
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01090AD0 mov eax, dword ptr fs:[00000030h]2_2_01090AD0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C4AD0 mov eax, dword ptr fs:[00000030h]2_2_010C4AD0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C4AD0 mov eax, dword ptr fs:[00000030h]2_2_010C4AD0
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CAAEE mov eax, dword ptr fs:[00000030h]2_2_010CAAEE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010CAAEE mov eax, dword ptr fs:[00000030h]2_2_010CAAEE
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01148D10 mov eax, dword ptr fs:[00000030h]2_2_01148D10
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01148D10 mov eax, dword ptr fs:[00000030h]2_2_01148D10
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AAD00 mov eax, dword ptr fs:[00000030h]2_2_010AAD00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AAD00 mov eax, dword ptr fs:[00000030h]2_2_010AAD00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010AAD00 mov eax, dword ptr fs:[00000030h]2_2_010AAD00
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_010C4D1D mov eax, dword ptr fs:[00000030h]2_2_010C4D1D
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01086D10 mov eax, dword ptr fs:[00000030h]2_2_01086D10
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeCode function: 2_2_01086D10 mov eax, dword ptr fs:[00000030h]2_2_01086D10
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess token adjusted: DebugJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory allocated: page read and write | page guardJump to behavior

                      HIPS / PFW / Operating System Protection Evasion

                      barindex
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtAllocateVirtualMemory: Direct from: 0x77172BFCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtDelayExecution: Direct from: 0x77172DDCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtProtectVirtualMemory: Direct from: 0x77167B2EJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtQuerySystemInformation: Direct from: 0x77172DFCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtReadFile: Direct from: 0x77172ADCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtQueryInformationProcess: Direct from: 0x77172C26Jump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtResumeThread: Direct from: 0x77172FBCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtWriteVirtualMemory: Direct from: 0x7717490CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtCreateUserProcess: Direct from: 0x7717371CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtOpenKeyEx: Direct from: 0x77172B9CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtNotifyChangeKey: Direct from: 0x77173C2CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtSetInformationProcess: Direct from: 0x77172C5CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtProtectVirtualMemory: Direct from: 0x77172F9CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtResumeThread: Direct from: 0x771736ACJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtMapViewOfSection: Direct from: 0x77172D1CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtWriteVirtualMemory: Direct from: 0x77172E3CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtCreateMutant: Direct from: 0x771735CCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtDeviceIoControlFile: Direct from: 0x77172AECJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtAllocateVirtualMemory: Direct from: 0x77172BECJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtTerminateThread: Direct from: 0x77172FCCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtQueryInformationToken: Direct from: 0x77172CACJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtCreateFile: Direct from: 0x77172FECJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtOpenFile: Direct from: 0x77172DCCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtClose: Direct from: 0x77172B6C
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtSetInformationThread: Direct from: 0x771663F9Jump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtAllocateVirtualMemory: Direct from: 0x77173C9CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtQueryAttributesFile: Direct from: 0x77172E6CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtSetInformationThread: Direct from: 0x77172B4CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtReadVirtualMemory: Direct from: 0x77172E8CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtCreateKey: Direct from: 0x77172C6CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtQueryVolumeInformationFile: Direct from: 0x77172F2CJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtAllocateVirtualMemory: Direct from: 0x771748ECJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtQuerySystemInformation: Direct from: 0x771748CCJump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeNtOpenSection: Direct from: 0x77172E0CJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe base: 400000 value starts with: 4D5AJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeSection loaded: NULL target: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe protection: execute and read and writeJump to behavior
                      Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeSection loaded: NULL target: C:\Windows\SysWOW64\msfeedssync.exe protection: execute and read and writeJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: NULL target: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe protection: read writeJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: NULL target: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exe protection: execute and read and writeJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: read writeJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeSection loaded: NULL target: C:\Program Files\Mozilla Firefox\firefox.exe protection: execute and read and writeJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeThread register set: target process: 7164Jump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeThread APC queued: target process: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe base: 400000Jump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe base: 401000Jump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe base: 977008Jump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"Jump to behavior
                      Source: C:\Program Files (x86)\fxrjKwUKrvQridGVYEaSFvBVHCNqlIcCsabusilbsfxzKtipCMOGFeQZroOuArTlbnbzVaQKI\UPM8KZRaz30lCAjNcEm6.exeProcess created: C:\Windows\SysWOW64\msfeedssync.exe "C:\Windows\SysWOW64\msfeedssync.exe"Jump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeProcess created: C:\Program Files\Mozilla Firefox\firefox.exe "C:\Program Files\Mozilla Firefox\Firefox.exe"Jump to behavior
                      Source: UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3725415583.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000000.1432934936.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580394013.0000000001A51000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Shell_TrayWnd
                      Source: UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3725415583.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000000.1432934936.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580394013.0000000001A51000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progman
                      Source: UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3725415583.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000000.1432934936.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580394013.0000000001A51000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Program ManagerW
                      Source: UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000002.3725415583.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 00000008.00000000.1432934936.0000000000FA1000.00000002.00000001.00040000.00000000.sdmp, UPM8KZRaz30lCAjNcEm6.exe, 0000000A.00000000.1580394013.0000000001A51000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progmanlock
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeQueries volume information: C:\Users\user\Desktop\2Stejb80vJ.exe VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                      Source: C:\Users\user\Desktop\2Stejb80vJ.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior

                      Stealing of Sensitive Information

                      barindex
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000002.00000002.1511972245.0000000000FC0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000002.3727661903.0000000005840000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3725575572.0000000002860000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000008.00000002.3725515204.00000000041B0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1511179304.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3723672280.0000000002470000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3724115187.0000000002710000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1513679898.0000000003420000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\CookiesJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Network\Local StateJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Web DataJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\CookiesJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Local StateJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Network\CookiesJump to behavior
                      Source: C:\Windows\SysWOW64\msfeedssync.exeKey opened: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows Messaging Subsystem\Profiles\Outlook\Jump to behavior

                      Remote Access Functionality

                      barindex
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 2.2.InstallUtil.exe.400000.0.raw.unpack, type: UNPACKEDPE
                      Source: Yara matchFile source: 00000002.00000002.1511972245.0000000000FC0000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 0000000A.00000002.3727661903.0000000005840000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3725575572.0000000002860000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000008.00000002.3725515204.00000000041B0000.00000040.00000001.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1511179304.0000000000400000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3723672280.0000000002470000.00000040.80000000.00040000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000009.00000002.3724115187.0000000002710000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                      Source: Yara matchFile source: 00000002.00000002.1513679898.0000000003420000.00000040.10000000.00040000.00000000.sdmp, type: MEMORY
                      ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                      Gather Victim Identity InformationAcquire InfrastructureValid Accounts1
                      Scheduled Task/Job
                      1
                      Scheduled Task/Job
                      512
                      Process Injection
                      3
                      Virtualization/Sandbox Evasion
                      1
                      OS Credential Dumping
                      221
                      Security Software Discovery
                      Remote Services1
                      Email Collection
                      1
                      Encrypted Channel
                      Exfiltration Over Other Network MediumAbuse Accessibility Features
                      CredentialsDomainsDefault AccountsScheduled Task/Job1
                      DLL Side-Loading
                      1
                      Scheduled Task/Job
                      1
                      Disable or Modify Tools
                      LSASS Memory3
                      Virtualization/Sandbox Evasion
                      Remote Desktop Protocol1
                      Archive Collected Data
                      3
                      Ingress Tool Transfer
                      Exfiltration Over BluetoothNetwork Denial of Service
                      Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)1
                      Abuse Elevation Control Mechanism
                      512
                      Process Injection
                      Security Account Manager2
                      Process Discovery
                      SMB/Windows Admin Shares1
                      Data from Local System
                      4
                      Non-Application Layer Protocol
                      Automated ExfiltrationData Encrypted for Impact
                      Employee NamesVirtual Private ServerLocal AccountsCronLogin Hook1
                      DLL Side-Loading
                      1
                      Deobfuscate/Decode Files or Information
                      NTDS1
                      Application Window Discovery
                      Distributed Component Object ModelInput Capture4
                      Application Layer Protocol
                      Traffic DuplicationData Destruction
                      Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                      Abuse Elevation Control Mechanism
                      LSA Secrets2
                      File and Directory Discovery
                      SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
                      Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts3
                      Obfuscated Files or Information
                      Cached Domain Credentials113
                      System Information Discovery
                      VNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
                      DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                      Software Packing
                      DCSyncRemote System DiscoveryWindows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                      Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job1
                      DLL Side-Loading
                      Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                      Hide Legend

                      Legend:

                      • Process
                      • Signature
                      • Created File
                      • DNS/IP Info
                      • Is Dropped
                      • Is Windows Process
                      • Number of created Registry Values
                      • Number of created Files
                      • Visual Basic
                      • Delphi
                      • Java
                      • .Net C# or VB.NET
                      • C, C++ or other language
                      • Is malicious
                      • Internet
                      behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1631760 Sample: 2Stejb80vJ.exe Startdate: 07/03/2025 Architecture: WINDOWS Score: 100 28 www.shibfestival.xyz 2->28 30 www.seasay.xyz 2->30 32 16 other IPs or domains 2->32 42 Suricata IDS alerts for network traffic 2->42 44 Antivirus detection for URL or domain 2->44 46 Antivirus / Scanner detection for submitted sample 2->46 50 6 other signatures 2->50 10 2Stejb80vJ.exe 2 2->10         started        signatures3 48 Performs DNS queries to domains with low reputation 30->48 process4 signatures5 62 Tries to detect sandboxes and other dynamic analysis tools (process name or module or function) 10->62 64 Writes to foreign memory regions 10->64 66 Injects a PE file into a foreign processes 10->66 13 InstallUtil.exe 10->13         started        process6 signatures7 68 Maps a DLL or memory area into another process 13->68 16 UPM8KZRaz30lCAjNcEm6.exe 13->16 injected process8 signatures9 40 Found direct / indirect Syscall (likely to bypass EDR) 16->40 19 msfeedssync.exe 13 16->19         started        process10 signatures11 52 Tries to steal Mail credentials (via file / registry access) 19->52 54 Tries to harvest and steal browser information (history, passwords, etc) 19->54 56 Modifies the context of a thread in another process (thread injection) 19->56 58 3 other signatures 19->58 22 UPM8KZRaz30lCAjNcEm6.exe 19->22 injected 26 firefox.exe 19->26         started        process12 dnsIp13 34 www.thrivell.life 209.74.64.58, 49701, 49702, 49703 MULTIBAND-NEWHOPEUS United States 22->34 36 www.seasay.xyz 103.106.67.112, 49725, 49726, 49727 VOYAGERNET-AS-APVoyagerInternetLtdNZ New Zealand 22->36 38 8 other IPs or domains 22->38 60 Found direct / indirect Syscall (likely to bypass EDR) 22->60 signatures14

                      This section contains all screenshots as thumbnails, including those not shown in the slideshow.