Loading ...

Play interactive tourEdit tour

Windows Analysis Report setup.exe

Overview

General Information

Sample Name:setup.exe
Analysis ID:502663
MD5:fe5c2e1333b4477d029dedc9c1b5dd4d
SHA1:ce7e5a597b98eb1ec36a48e4368997b787228544
SHA256:fc91558efb40b16dd9f6b0e93c972a0f1ff85cad3ddefdd7028c2628d75a9ab9
Infos:

Most interesting Screenshot:

Detection

Score:5
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Uses 32bit PE files
PE file contains strange resources
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Uses code obfuscation techniques (call, push, ret)
Detected potential crypto function
Found evasive API chain (may stop execution after checking a module file name)
Contains functionality to check if a window is minimized (may be used to check if an application is visible)
Contains functionality to dynamically determine API calls
PE file contains executable resources (Code or Archives)

Classification

Process Tree

  • System is w10x64
  • setup.exe (PID: 7152 cmdline: 'C:\Users\user\Desktop\setup.exe' MD5: FE5C2E1333B4477D029DEDC9C1B5DD4D)
  • cleanup

Malware Configuration

No configs have been found

Yara Overview

No yara matches

Sigma Overview

No Sigma rule has matched

Jbx Signature Overview

Click to jump to signature section

Show All Signature Results

There are no malicious signatures, click here to show all signatures.

Source: setup.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP, RELOCS_STRIPPED
Source: Binary string: c:\P4\NIInstallers\trunk\17.5\src\MetaInstaller\Unicode_Release\setup.pdb source: setup.exe, 00000000.00000002.306404235.00000000007E7000.00000040.00020000.sdmp
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00531CB0 FindFirstFileW,FindClose,
Source: setup.exeString found in binary or memory: http://apache.org/xml/UknownNS
Source: setup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpString found in binary or memory: http://apache.org/xml/UknownNSUCS4UCS-4UCS_4UCS-4
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/calculate-src-ofs
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/continue-after-fatal-error
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/disable-default-entity-resolution
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/dom-has-psvi-info
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/dom/byte-order-mark
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/dom/user-adopts-DOMDocument
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/generate-synthetic-annotations
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/nonvalidating/load-external-dtd
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/schema/ignore-annotations
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/standard-uri-conformant
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validate-annotations
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation-error-as-fatal
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/cache-grammarFromParse
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/dynamic
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/identity-constraint-checking
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/ignoreCachedDTD
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/schema
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/schema-full-checking
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/schema/skip-dtd-validation
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/validation/use-cachedGrammarInParse
Source: setup.exeString found in binary or memory: http://apache.org/xml/messages/XML4CErrors
Source: setup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpString found in binary or memory: http://apache.org/xml/messages/XML4CErrors#FIXEDEBCDIC-CP-USIBM037IBM1047IBM-1047IBM1140IBM01140CCSI
Source: setup.exeString found in binary or memory: http://apache.org/xml/messages/XMLDOMMsg
Source: setup.exeString found in binary or memory: http://apache.org/xml/messages/XMLErrors
Source: setup.exeString found in binary or memory: http://apache.org/xml/messages/XMLValidity
Source: setup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpString found in binary or memory: http://apache.org/xml/messages/XMLValidityWINDOWS-1252XERCES-XMLCHxmlxml
Source: setup.exeString found in binary or memory: http://apache.org/xml/parser-use-DOMDocument-from-Implementation
Source: setup.exeString found in binary or memory: http://apache.org/xml/properties/scannerName
Source: setup.exeString found in binary or memory: http://apache.org/xml/properties/schema/external-noNamespaceSchemaLocation
Source: setup.exeString found in binary or memory: http://apache.org/xml/properties/schema/external-schemaLocation
Source: setup.exeString found in binary or memory: http://apache.org/xml/properties/security-manager
Source: setup.exe, setup.exe, 00000000.00000002.306500404.00000000008EB000.00000040.00020000.sdmpString found in binary or memory: http://digital.ni.com/express.nsf/bycode/WinFastStartup
Source: setup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpString found in binary or memory: http://digital.ni.com/express.nsf/bycode/WinFastStartupSOFTWARE
Source: setup.exe, setup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpString found in binary or memory: http://digital.ni.com/express.nsf/bycode/exke86
Source: setup.exeString found in binary or memory: http://xml.org/sax/features/namespace-prefixes
Source: setup.exeString found in binary or memory: http://xml.org/sax/features/namespaces
Source: setup.exeString found in binary or memory: http://xml.org/sax/features/validation
Source: setup.exeStatic PE information: 32BIT_MACHINE, EXECUTABLE_IMAGE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP, RELOCS_STRIPPED
Source: setup.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: setup.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: setup.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_005780FA
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_005713F0
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00587710
Source: setup.exeStatic PE information: Resource name: RT_ICON type: COM executable for DOS
Source: setup.exeStatic PE information: Resource name: RT_GROUP_CURSOR type: unicos (cray) executable
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_005F67C0 FormatMessageW,GetLastError,
Source: C:\Users\user\Desktop\setup.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0053F498 FindResourceW,LoadResource,LockResource,FreeResource,
Source: setup.exeString found in binary or memory: JIS_C6229-1984-b-add
Source: setup.exeString found in binary or memory: jp-ocr-b-add
Source: setup.exeString found in binary or memory: JIS_C6229-1984-hand-add
Source: setup.exeString found in binary or memory: jp-ocr-hand-add
Source: setup.exeString found in binary or memory: http://apache.org/xml/features/nonvalidating/load-external-dtd
Source: setup.exeString found in binary or memory: pre-install
Source: setup.exeString found in binary or memory: ISO_6937-2-add
Source: setup.exeString found in binary or memory: The host/address '{0}' could not be resolved
Source: setup.exeString found in binary or memory: "%s" -startDir "%s" -xmlPath "%s"
Source: setup.exeString found in binary or memory: NATS-SEFI-ADD
Source: setup.exeString found in binary or memory: NATS-DANO-ADD
Source: setup.exeString found in binary or memory: "%s" -v -startDir "%s" -xmlPath "%s"
Source: setup.exeString found in binary or memory: "%s" -filePath "%s" -startDir "%s" -xmlPath "%s"
Source: setup.exeString found in binary or memory: User agreed to pre-install.
Source: setup.exeString found in binary or memory: .NET 3.5 pre-install is needed, but user denied the prompt to install. Cannot continue - exiting.
Source: setup.exeString found in binary or memory: .NET 3.5 pre-install is disabled via command-line or setup.ini flag -- nothing to do.
Source: setup.exeString found in binary or memory: .NET 3.5 pre-install is not required on this OS -- nothing to do.
Source: setup.exeString found in binary or memory: .NET 3.5 not in distribution or pre-install disabled -- nothing to do.
Source: setup.exeString found in binary or memory: .NET 4.0 pre-install is needed, but user denied the prompt to install. Cannot continue - exiting.
Source: setup.exeString found in binary or memory: .NET 4.x pre-install is disabled via command-line or setup.ini flag -- nothing to do.
Source: setup.exeString found in binary or memory: .NET 4.5.x or 4.6.x install requested, but we are on Server 2003 or XP. Skipping pre-install so that the distribution launch (or m
Source: setup.exeString found in binary or memory: .NET 4.x not in distribution or pre-install disabled -- nothing to do.
Source: classification engineClassification label: clean5.winEXE@1/0@0/0
Source: C:\Users\user\Desktop\setup.exeFile opened: C:\Windows\SysWOW64\RICHED32.DLL
Source: setup.exeStatic file information: File size 1466368 > 1048576
Source: setup.exeStatic PE information: Raw size of UPX1 is bigger than: 0x100000 < 0x144200
Source: Binary string: c:\P4\NIInstallers\trunk\17.5\src\MetaInstaller\Unicode_Release\setup.pdb source: setup.exe, 00000000.00000002.306404235.00000000007E7000.00000040.00020000.sdmp
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0057683A push ecx; ret
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00576B39 push ecx; ret
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0058D233 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,
Source: initial sampleStatic PE information: section name: UPX0
Source: initial sampleStatic PE information: section name: UPX1
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00538C8C MonitorFromWindow,IsIconic,GetWindowPlacement,GetWindowRect,
Source: C:\Users\user\Desktop\setup.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\Desktop\setup.exeEvasive API call chain: GetModuleFileName,DecisionNodes,Sleep
Source: C:\Users\user\Desktop\setup.exeEvasive API call chain: GetModuleFileName,DecisionNodes,ExitProcess
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00531CB0 FindFirstFileW,FindClose,
Source: setup.exeBinary or memory string: hGfsu
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00570867 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0058D233 LoadLibraryA,GetProcAddress,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,GetProcAddress,__encode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,__decode_pointer,
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_00570867 _memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_0056F98F IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoA,
Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoW,
Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoA,
Source: C:\Users\user\Desktop\setup.exeCode function: _strlen,_strlen,_GetPrimaryLen,EnumSystemLocalesA,
Source: C:\Users\user\Desktop\setup.exeCode function: __getptd,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_TranslateName,_GetLcidFromLangCountry,_GetLcidFromLanguage,_strlen,EnumSystemLocalesA,GetUserDefaultLCID,_ProcessCodePage,IsValidCodePage,IsValidLocale,GetLocaleInfoA,_strcpy_s,__invoke_watson,GetLocaleInfoA,GetLocaleInfoA,__itoa_s,
Source: C:\Users\user\Desktop\setup.exeCode function: _strlen,_GetPrimaryLen,EnumSystemLocalesA,
Source: C:\Users\user\Desktop\setup.exeCode function: GetLocaleInfoA,GetLocaleInfoA,GetACP,
Source: C:\Users\user\Desktop\setup.exeCode function: 0_2_005319A0 GetVersionExW,

Mitre Att&ck Matrix

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
Valid AccountsCommand and Scripting Interpreter2Path InterceptionPath InterceptionSoftware Packing1OS Credential DumpingSecurity Software Discovery11Remote ServicesArchive Collected Data1Exfiltration Over Other Network MediumEncrypted Channel1Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default AccountsNative API2Boot or Logon Initialization ScriptsBoot or Logon Initialization ScriptsObfuscated Files or Information11LSASS MemoryApplication Window Discovery1Remote Desktop ProtocolData from Removable MediaExfiltration Over BluetoothJunk DataExploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain AccountsAt (Linux)Logon Script (Windows)Logon Script (Windows)Obfuscated Files or InformationSecurity Account ManagerFile and Directory Discovery1SMB/Windows Admin SharesData from Network Shared DriveAutomated ExfiltrationSteganographyExploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local AccountsAt (Windows)Logon Script (Mac)Logon Script (Mac)Binary PaddingNTDSSystem Information Discovery12Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud

Behavior Graph

Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

Screenshots

Thumbnails

This section contains all screenshots as thumbnails, including those not shown in the slideshow.

windows-stand

Antivirus, Machine Learning and Genetic Malware Detection

Initial Sample

SourceDetectionScannerLabelLink
setup.exe1%VirustotalBrowse
setup.exe5%MetadefenderBrowse
setup.exe7%ReversingLabs

Dropped Files

No Antivirus matches

Unpacked PE Files

No Antivirus matches

Domains

No Antivirus matches

URLs

No Antivirus matches

Domains and IPs

Contacted Domains

No contacted domains info

URLs from Memory and Binaries

NameSourceMaliciousAntivirus DetectionReputation
http://apache.org/xml/parser-use-DOMDocument-from-Implementationsetup.exefalse
    high
    http://apache.org/xml/messages/XMLValiditysetup.exefalse
      high
      http://apache.org/xml/features/validation/dynamicsetup.exefalse
        high
        http://apache.org/xml/features/continue-after-fatal-errorsetup.exefalse
          high
          http://apache.org/xml/features/standard-uri-conformantsetup.exefalse
            high
            http://apache.org/xml/properties/schema/external-schemaLocationsetup.exefalse
              high
              http://apache.org/xml/features/dom-has-psvi-infosetup.exefalse
                high
                http://apache.org/xml/features/validation/identity-constraint-checkingsetup.exefalse
                  high
                  http://apache.org/xml/UknownNSUCS4UCS-4UCS_4UCS-4setup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpfalse
                    high
                    http://apache.org/xml/features/validate-annotationssetup.exefalse
                      high
                      http://apache.org/xml/features/dom/byte-order-marksetup.exefalse
                        high
                        http://xml.org/sax/features/namespacessetup.exefalse
                          high
                          http://apache.org/xml/features/dom/user-adopts-DOMDocumentsetup.exefalse
                            high
                            http://apache.org/xml/features/nonvalidating/load-external-dtdsetup.exefalse
                              high
                              http://apache.org/xml/features/validation/schema-full-checkingsetup.exefalse
                                high
                                http://apache.org/xml/features/schema/ignore-annotationssetup.exefalse
                                  high
                                  http://xml.org/sax/features/namespace-prefixessetup.exefalse
                                    high
                                    http://apache.org/xml/features/generate-synthetic-annotationssetup.exefalse
                                      high
                                      http://apache.org/xml/UknownNSsetup.exefalse
                                        high
                                        http://apache.org/xml/features/validation-error-as-fatalsetup.exefalse
                                          high
                                          http://apache.org/xml/features/calculate-src-ofssetup.exefalse
                                            high
                                            http://apache.org/xml/features/validation/cache-grammarFromParsesetup.exefalse
                                              high
                                              http://apache.org/xml/properties/schema/external-noNamespaceSchemaLocationsetup.exefalse
                                                high
                                                http://apache.org/xml/messages/XMLValidityWINDOWS-1252XERCES-XMLCHxmlxmlsetup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpfalse
                                                  high
                                                  http://xml.org/sax/features/validationsetup.exefalse
                                                    high
                                                    http://apache.org/xml/messages/XML4CErrors#FIXEDEBCDIC-CP-USIBM037IBM1047IBM-1047IBM1140IBM01140CCSIsetup.exe, 00000000.00000002.306026068.0000000000401000.00000040.00020000.sdmpfalse
                                                      high
                                                      http://apache.org/xml/features/validation/use-cachedGrammarInParsesetup.exefalse
                                                        high
                                                        http://apache.org/xml/messages/XML4CErrorssetup.exefalse
                                                          high
                                                          http://apache.org/xml/properties/security-managersetup.exefalse
                                                            high
                                                            http://apache.org/xml/features/validation/schema/skip-dtd-validationsetup.exefalse
                                                              high
                                                              http://apache.org/xml/properties/scannerNamesetup.exefalse
                                                                high
                                                                http://apache.org/xml/features/disable-default-entity-resolutionsetup.exefalse
                                                                  high
                                                                  http://apache.org/xml/features/validation/schemasetup.exefalse
                                                                    high
                                                                    http://apache.org/xml/features/validation/ignoreCachedDTDsetup.exefalse
                                                                      high
                                                                      http://apache.org/xml/messages/XMLDOMMsgsetup.exefalse
                                                                        high
                                                                        http://apache.org/xml/messages/XMLErrorssetup.exefalse
                                                                          high

                                                                          Contacted IPs

                                                                          No contacted IP infos

                                                                          General Information

                                                                          Joe Sandbox Version:33.0.0 White Diamond
                                                                          Analysis ID:502663
                                                                          Start date:14.10.2021
                                                                          Start time:08:36:46
                                                                          Joe Sandbox Product:CloudBasic
                                                                          Overall analysis duration:0h 6m 4s
                                                                          Hypervisor based Inspection enabled:false
                                                                          Report type:light
                                                                          Sample file name:setup.exe
                                                                          Cookbook file name:default.jbs
                                                                          Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 85, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                                          Number of analysed new started processes analysed:20
                                                                          Number of new started drivers analysed:0
                                                                          Number of existing processes analysed:0
                                                                          Number of existing drivers analysed:0
                                                                          Number of injected processes analysed:0
                                                                          Technologies:
                                                                          • HCA enabled
                                                                          • EGA enabled
                                                                          • HDC enabled
                                                                          • AMSI enabled
                                                                          Analysis Mode:default
                                                                          Analysis stop reason:Timeout
                                                                          Detection:CLEAN
                                                                          Classification:clean5.winEXE@1/0@0/0
                                                                          EGA Information:
                                                                          • Successful, ratio: 100%
                                                                          HDC Information:
                                                                          • Successful, ratio: 26.7% (good quality ratio 25%)
                                                                          • Quality average: 73.1%
                                                                          • Quality standard deviation: 28.8%
                                                                          HCA Information:Failed
                                                                          Cookbook Comments:
                                                                          • Adjust boot time
                                                                          • Enable AMSI
                                                                          • Found application associated with file extension: .exe
                                                                          Warnings:
                                                                          Show All
                                                                          • Exclude process from analysis (whitelisted): MpCmdRun.exe, audiodg.exe, BackgroundTransferHost.exe, WMIADAP.exe, backgroundTaskHost.exe, conhost.exe, svchost.exe, wuapihost.exe
                                                                          • Excluded IPs from analysis (whitelisted): 20.50.102.62, 20.54.110.249, 40.112.88.60, 2.20.178.56, 2.20.178.10, 8.247.248.249, 8.247.248.223, 8.247.244.249, 20.199.120.182, 2.20.178.24, 2.20.178.33, 95.100.216.89
                                                                          • Excluded domains from analysis (whitelisted): fg.download.windowsupdate.com.c.footprint.net, a767.dspw65.akamai.net, a1449.dscg2.akamai.net, fs-wildcard.microsoft.com.edgekey.net, fs-wildcard.microsoft.com.edgekey.net.globalredir.akadns.net, arc.msn.com, wns.notify.trafficmanager.net, consumer-displaycatalogrp-aks2aks-europe.md.mp.microsoft.com.akadns.net, arc.trafficmanager.net, displaycatalog.mp.microsoft.com, img-prod-cms-rt-microsoft-com.akamaized.net, prod.fs.microsoft.com.akadns.net, client.wns.windows.com, fs.microsoft.com, displaycatalog-rp-europe.md.mp.microsoft.com.akadns.net, neu-displaycatalogrp.frontdoor.bigcatalog.commerce.microsoft.com, ris-prod.trafficmanager.net, wu-shim.trafficmanager.net, asf-ris-prod-neu.northeurope.cloudapp.azure.com, ctldl.windowsupdate.com, e1723.g.akamaiedge.net, iris-de-prod-azsc-uks.uksouth.cloudapp.azure.com, download.windowsupdate.com.edgesuite.net, ris.api.iris.microsoft.com, displaycatalog-rp.md.mp.microsoft.com.akadns.net
                                                                          • Not all processes where analyzed, report is missing behavior information

                                                                          Simulations

                                                                          Behavior and APIs

                                                                          No simulations

                                                                          Joe Sandbox View / Context

                                                                          IPs

                                                                          No context

                                                                          Domains

                                                                          No context

                                                                          ASN

                                                                          No context

                                                                          JA3 Fingerprints

                                                                          No context

                                                                          Dropped Files

                                                                          No context

                                                                          Created / dropped Files

                                                                          No created / dropped files found

                                                                          Static File Info

                                                                          General

                                                                          File type:PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
                                                                          Entropy (8bit):7.907283747504906
                                                                          TrID:
                                                                          • Win32 Executable (generic) a (10002005/4) 99.39%
                                                                          • UPX compressed Win32 Executable (30571/9) 0.30%
                                                                          • Win32 EXE Yoda's Crypter (26571/9) 0.26%
                                                                          • Generic Win/DOS Executable (2004/3) 0.02%
                                                                          • DOS Executable Generic (2002/1) 0.02%
                                                                          File name:setup.exe
                                                                          File size:1466368
                                                                          MD5:fe5c2e1333b4477d029dedc9c1b5dd4d
                                                                          SHA1:ce7e5a597b98eb1ec36a48e4368997b787228544
                                                                          SHA256:fc91558efb40b16dd9f6b0e93c972a0f1ff85cad3ddefdd7028c2628d75a9ab9
                                                                          SHA512:04892dfb3d356952a3bd4cac9026a3fac52b220af6b8a6371e81293483dbdeb76f08e8182ae0301dedef4d2904a6c113d02d8d48307fe498a428b595b0ec03b4
                                                                          SSDEEP:24576:wJx22KNk+2ygEZZU6xUohcGGopn9iWsq/A9fzIDODmJfbtvyYtQEnRA2S/Y:w+29+2yn5+ohcGHpn97s7JzIa6dY4/RC
                                                                          File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......l...(.pA(.pA(.pA-./A,.pA...A+.pA!..A..pA!..A..pA6..A+.pA.K.A..pA.K.A7.pA(.qA..pA!..A..pA!..A).pA6..A).pA!..A).pARich(.pA.......

                                                                          File Icon

                                                                          Icon Hash:80b0a4b4a4e4e4e4

                                                                          Static PE Info

                                                                          General

                                                                          Entrypoint:0x90cf20
                                                                          Entrypoint Section:UPX1
                                                                          Digitally signed:false
                                                                          Imagebase:0x400000
                                                                          Subsystem:windows gui
                                                                          Image File Characteristics:32BIT_MACHINE, EXECUTABLE_IMAGE, REMOVABLE_RUN_FROM_SWAP, NET_RUN_FROM_SWAP, RELOCS_STRIPPED
                                                                          DLL Characteristics:TERMINAL_SERVER_AWARE
                                                                          Time Stamp:0x59E4BE15 [Mon Oct 16 14:11:33 2017 UTC]
                                                                          TLS Callbacks:
                                                                          CLR (.Net) Version:
                                                                          OS Version Major:5
                                                                          OS Version Minor:0
                                                                          File Version Major:5
                                                                          File Version Minor:0
                                                                          Subsystem Version Major:5
                                                                          Subsystem Version Minor:0
                                                                          Import Hash:ab8c7e344596e3e6d6c6a5375f98bde9

                                                                          Entrypoint Preview

                                                                          Instruction
                                                                          pushad
                                                                          mov esi, 007C9000h
                                                                          lea edi, dword ptr [esi-003C8000h]
                                                                          push edi
                                                                          or ebp, FFFFFFFFh
                                                                          jmp 00007FA984BCF942h
                                                                          nop
                                                                          nop
                                                                          nop
                                                                          nop
                                                                          nop
                                                                          nop
                                                                          mov al, byte ptr [esi]
                                                                          inc esi
                                                                          mov byte ptr [edi], al
                                                                          inc edi
                                                                          add ebx, ebx
                                                                          jne 00007FA984BCF939h
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          jc 00007FA984BCF91Fh
                                                                          mov eax, 00000001h
                                                                          add ebx, ebx
                                                                          jne 00007FA984BCF939h
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          adc eax, eax
                                                                          add ebx, ebx
                                                                          jnc 00007FA984BCF93Dh
                                                                          jne 00007FA984BCF95Ah
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          jc 00007FA984BCF951h
                                                                          dec eax
                                                                          add ebx, ebx
                                                                          jne 00007FA984BCF939h
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          adc eax, eax
                                                                          jmp 00007FA984BCF906h
                                                                          add ebx, ebx
                                                                          jne 00007FA984BCF939h
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          adc ecx, ecx
                                                                          jmp 00007FA984BCF984h
                                                                          xor ecx, ecx
                                                                          sub eax, 03h
                                                                          jc 00007FA984BCF943h
                                                                          shl eax, 08h
                                                                          mov al, byte ptr [esi]
                                                                          inc esi
                                                                          xor eax, FFFFFFFFh
                                                                          je 00007FA984BCF9A7h
                                                                          sar eax, 1
                                                                          mov ebp, eax
                                                                          jmp 00007FA984BCF93Dh
                                                                          add ebx, ebx
                                                                          jne 00007FA984BCF939h
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          jc 00007FA984BCF8FEh
                                                                          inc ecx
                                                                          add ebx, ebx
                                                                          jne 00007FA984BCF939h
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          jc 00007FA984BCF8F0h
                                                                          add ebx, ebx
                                                                          jne 00007FA984BCF939h
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          adc ecx, ecx
                                                                          add ebx, ebx
                                                                          jnc 00007FA984BCF921h
                                                                          jne 00007FA984BCF93Bh
                                                                          mov ebx, dword ptr [esi]
                                                                          sub esi, FFFFFFFCh
                                                                          adc ebx, ebx
                                                                          jnc 00007FA984BCF916h
                                                                          add ecx, 02h
                                                                          cmp ebp, FFFFFB00h
                                                                          adc ecx, 02h
                                                                          lea edx, dword ptr [eax+eax]

                                                                          Rich Headers

                                                                          Programming Language:
                                                                          • [ASM] VS2008 SP1 build 30729
                                                                          • [ C ] VS2008 SP1 build 30729
                                                                          • [ C ] VS2005 build 50727
                                                                          • [IMP] VS2005 build 50727
                                                                          • [RES] VS2008 build 21022
                                                                          • [C++] VS2008 build 21022
                                                                          • [EXP] VS2008 SP1 build 30729
                                                                          • [C++] VS2008 SP1 build 30729
                                                                          • [ C ] VS2003 (.NET) build 3077
                                                                          • [LNK] VS2008 SP1 build 30729

                                                                          Data Directories

                                                                          NameVirtual AddressVirtual Size Is in Section
                                                                          IMAGE_DIRECTORY_ENTRY_EXPORT0x52f79c0x6c.rsrc
                                                                          IMAGE_DIRECTORY_ENTRY_IMPORT0x52f41c0x380.rsrc
                                                                          IMAGE_DIRECTORY_ENTRY_RESOURCE0x50e0000x2141c.rsrc
                                                                          IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x50d0cc0x48UPX1
                                                                          IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x46e4ec0xc0UPX1
                                                                          IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                          IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0

                                                                          Sections

                                                                          NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                          UPX00x10000x3c80000x0unknownunknownunknownunknownIMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                          UPX10x3c90000x1450000x144200False0.985229162649data7.92638129371IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ
                                                                          .rsrc0x50e0000x220000x21a00False0.829874825743data7.3682539138IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_WRITE, IMAGE_SCN_MEM_READ

                                                                          Resources

                                                                          NameRVASizeTypeLanguageCountry
                                                                          RT_CURSOR0x4b27000x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b28340xb4dataEnglishUnited States
                                                                          RT_CURSOR0x4b28e80x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b2a1c0x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b2b500x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b2c840x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b2db80x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b2eec0x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b30200x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b31540x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b32880x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b33bc0x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b34f00x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b36240x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b37580x134dataEnglishUnited States
                                                                          RT_CURSOR0x4b388c0x134dataEnglishUnited States
                                                                          RT_BITMAP0x4b39c00x3e8dataEnglishUnited States
                                                                          RT_BITMAP0x4b3da80x3e8dataEnglishUnited States
                                                                          RT_BITMAP0x4b41900x1328dataEnglishUnited States
                                                                          RT_BITMAP0x4b54b80x1328dataEnglishUnited States
                                                                          RT_BITMAP0x4b67e00x3e8dataEnglishUnited States
                                                                          RT_BITMAP0x4b6bc80x1328dataEnglishUnited States
                                                                          RT_BITMAP0x4b7ef00x1328dataEnglishUnited States
                                                                          RT_BITMAP0x4b92180x1328dataEnglishUnited States
                                                                          RT_BITMAP0x4ba5400x1328dataEnglishUnited States
                                                                          RT_BITMAP0x4bb8680x3e8dataEnglishUnited States
                                                                          RT_BITMAP0x4bbc500xb8dataEnglishUnited States
                                                                          RT_BITMAP0x4bbd080x144dataEnglishUnited States
                                                                          RT_ICON0x5117040x128GLS_BINARY_LSB_FIRSTEnglishUnited States
                                                                          RT_ICON0x5118300x568GLS_BINARY_LSB_FIRSTEnglishUnited States
                                                                          RT_ICON0x4bc4dc0x8a8dataEnglishUnited States
                                                                          RT_ICON0x4bcd840x568dataEnglishUnited States
                                                                          RT_ICON0x4bd2ec0xca8dataEnglishUnited States
                                                                          RT_ICON0x4bdf940x368dataEnglishUnited States
                                                                          RT_ICON0x4be2fc0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4be4a40x1a8MPEG-4 LOAS, 4 or more streams, 8 or more streamsEnglishUnited States
                                                                          RT_ICON0x4be64c0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4be7f40x1a8dataEnglishUnited States
                                                                          RT_ICON0x4be99c0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4beb440x1a8dataEnglishUnited States
                                                                          RT_ICON0x4becec0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bee940x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bf03c0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bf1e40x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bf38c0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bf5340x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bf6dc0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bf8840x1a8dataEnglishUnited States
                                                                          RT_ICON0x4bfa2c0x2e8dataEnglishUnited States
                                                                          RT_ICON0x4bfd140x128dataEnglishUnited States
                                                                          RT_ICON0x4bfe3c0x568dataEnglishUnited States
                                                                          RT_ICON0x4c03a40x1a8dataEnglishUnited States
                                                                          RT_ICON0x4c054c0x2e8dataEnglishUnited States
                                                                          RT_ICON0x4c08340x128dataEnglishUnited States
                                                                          RT_ICON0x4c095c0x568dataEnglishUnited States
                                                                          RT_ICON0x4c0ec40x1a8dataEnglishUnited States
                                                                          RT_ICON0x4c106c0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4c12140x2e8dataEnglishUnited States
                                                                          RT_ICON0x4c14fc0x1ca8dataEnglishUnited States
                                                                          RT_ICON0x4c31a40xca8dataEnglishUnited States
                                                                          RT_ICON0x4c3e4c0x668dataEnglishUnited States
                                                                          RT_ICON0x4c44b40x1ca8COM executable for DOSEnglishUnited States
                                                                          RT_ICON0x4c615c0xca8dataEnglishUnited States
                                                                          RT_ICON0x4c6e040x668dataEnglishUnited States
                                                                          RT_ICON0x4c746c0x1ca8dataEnglishUnited States
                                                                          RT_ICON0x4c91140xca8dataEnglishUnited States
                                                                          RT_ICON0x4c9dbc0x668dataEnglishUnited States
                                                                          RT_ICON0x4ca4240x668dataEnglishUnited States
                                                                          RT_ICON0x4caa8c0x668dataEnglishUnited States
                                                                          RT_ICON0x4cb0f40x668dataEnglishUnited States
                                                                          RT_ICON0x4cb75c0x668dataEnglishUnited States
                                                                          RT_ICON0x4cbdc40x668dataEnglishUnited States
                                                                          RT_ICON0x4cc42c0xca8dataEnglishUnited States
                                                                          RT_ICON0x4cd0d40x1a8dataEnglishUnited States
                                                                          RT_ICON0x4cd27c0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4cd4240x1a8dataEnglishUnited States
                                                                          RT_ICON0x4cd5cc0x1a8dataEnglishUnited States
                                                                          RT_ICON0x4cd7740x468dataEnglishUnited States
                                                                          RT_ICON0x4cdbdc0xca8dataEnglishUnited States
                                                                          RT_ICON0x511d9c0x2e8dBase IV DBT of @.DBF, block length 512, next free block index 40, next free block 2391312520, next used block 2005436558EnglishUnited States
                                                                          RT_ICON0x5120880x8a8dBase IV DBT of @.DBF, block length 1024, next free block index 40, next free block 15134197, next used block 14939634EnglishUnited States
                                                                          RT_ICON0x5129340x668dataEnglishUnited States
                                                                          RT_ICON0x512fa00xea8dataEnglishUnited States
                                                                          RT_ICON0x513e4c0x54f3PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States
                                                                          RT_ICON0x5193440x9381PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States
                                                                          RT_ICON0x5226cc0x468GLS_BINARY_LSB_FIRSTEnglishUnited States
                                                                          RT_ICON0x522b380x10a8dataEnglishUnited States
                                                                          RT_ICON0x523be40x25a8dataEnglishUnited States
                                                                          RT_ICON0x5261900x88fbPNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States
                                                                          RT_DIALOG0x4eb5500x1e0dataEnglishUnited States
                                                                          RT_DIALOG0x4eb7300xe8dataEnglishUnited States
                                                                          RT_DIALOG0x4eb8180x64PGP\011Secret Sub-key -EnglishUnited States
                                                                          RT_DIALOG0x4eb87c0x302dataEnglishUnited States
                                                                          RT_DIALOG0x4ebb800x20dataEnglishUnited States
                                                                          RT_DIALOG0x4ebba00x18dataEnglishUnited States
                                                                          RT_DIALOG0x4ebbb80x144dataEnglishUnited States
                                                                          RT_DIALOG0x4ebcfc0x136SysEx File -EnglishUnited States
                                                                          RT_DIALOG0x4ebe340x32dataEnglishUnited States
                                                                          RT_DIALOG0x4ebe680x1a4dataEnglishUnited States
                                                                          RT_DIALOG0x4ec00c0x296dataEnglishUnited States
                                                                          RT_DIALOG0x4ec2a40x220dataEnglishUnited States
                                                                          RT_DIALOG0x4ec4c40xc0dataEnglishUnited States
                                                                          RT_DIALOG0x4ec5840x238dataEnglishUnited States
                                                                          RT_DIALOG0x4ec7bc0x17edataEnglishUnited States
                                                                          RT_DIALOG0x4ec93c0xe2dataEnglishUnited States
                                                                          RT_DIALOG0x4eca200xd4dataEnglishUnited States
                                                                          RT_DIALOG0x4ecaf40xe2dataEnglishUnited States
                                                                          RT_DIALOG0x4ecbd80x114dataEnglishUnited States
                                                                          RT_DIALOG0x4eccec0x8cdataEnglishUnited States
                                                                          RT_DIALOG0x4ecd780xd8dataEnglishUnited States
                                                                          RT_DIALOG0x4ece500xcadataEnglishUnited States
                                                                          RT_DIALOG0x4ecf1c0x49edataEnglishUnited States
                                                                          RT_DIALOG0x4ed3bc0x5f8dataEnglishUnited States
                                                                          RT_DIALOG0x4ed9b40xe8dataEnglishUnited States
                                                                          RT_DIALOG0x4eda9c0x34dataEnglishUnited States
                                                                          RT_STRING0x4edad00x5b4dataEnglishUnited States
                                                                          RT_STRING0x4ee0840x974dataEnglishUnited States
                                                                          RT_STRING0x4ee9f80x86adataEnglishUnited States
                                                                          RT_STRING0x4ef2640x358dataEnglishUnited States
                                                                          RT_STRING0x4ef5bc0x616dataEnglishUnited States
                                                                          RT_STRING0x4efbd40x2cadataEnglishUnited States
                                                                          RT_STRING0x4efea00x446dataEnglishUnited States
                                                                          RT_STRING0x4f02e80x44adataEnglishUnited States
                                                                          RT_STRING0x4f07340x3e6SysEx File - PassportEnglishUnited States
                                                                          RT_STRING0x4f0b1c0x662dataEnglishUnited States
                                                                          RT_STRING0x4f11800x90edataEnglishUnited States
                                                                          RT_STRING0x4f1a900x67edataEnglishUnited States
                                                                          RT_STRING0x4f21100x5dadataEnglishUnited States
                                                                          RT_STRING0x4f26ec0x7e6dataEnglishUnited States
                                                                          RT_STRING0x4f2ed40x79cdataEnglishUnited States
                                                                          RT_STRING0x4f36700x59edataEnglishUnited States
                                                                          RT_STRING0x4f3c100x540dataEnglishUnited States
                                                                          RT_STRING0x4f41500x580dataEnglishUnited States
                                                                          RT_STRING0x4f46d00xdedataEnglishUnited States
                                                                          RT_STRING0x4f47b00x2f2dataEnglishUnited States
                                                                          RT_STRING0x4f4aa40x4d2dataEnglishUnited States
                                                                          RT_STRING0x4f4f780x288dataGermanGermany
                                                                          RT_STRING0x4f52000x20edataEnglishUnited States
                                                                          RT_STRING0x4f54100x252dataFrenchFrance
                                                                          RT_STRING0x4f56640x148dataJapaneseJapan
                                                                          RT_STRING0x4f57ac0x14adataKoreanNorth Korea
                                                                          RT_STRING0x4f57ac0x14adataKoreanSouth Korea
                                                                          RT_STRING0x4f58f80xe8dataChineseChina
                                                                          RT_STRING0x4f59e00x438dataGermanGermany
                                                                          RT_STRING0x4f5e180x33adataEnglishUnited States
                                                                          RT_STRING0x4f61540x418dataFrenchFrance
                                                                          RT_STRING0x4f656c0x22edataJapaneseJapan
                                                                          RT_STRING0x4f679c0x232dataKoreanNorth Korea
                                                                          RT_STRING0x4f679c0x232dataKoreanSouth Korea
                                                                          RT_STRING0x4f69d00x172dataChineseChina
                                                                          RT_STRING0x4f6b440x124dataGermanGermany
                                                                          RT_STRING0x4f6c680xf0dataEnglishUnited States
                                                                          RT_STRING0x4f6d580x142dataFrenchFrance
                                                                          RT_STRING0x4f6e9c0x9adataJapaneseJapan
                                                                          RT_STRING0x4f6f380xb2dataKoreanNorth Korea
                                                                          RT_STRING0x4f6f380xb2dataKoreanSouth Korea
                                                                          RT_STRING0x4f6fec0x6edataChineseChina
                                                                          RT_STRING0x4f705c0x166dataGermanGermany
                                                                          RT_STRING0x4f71c40x10adataEnglishUnited States
                                                                          RT_STRING0x4f72d00x14adataFrenchFrance
                                                                          RT_STRING0x4f741c0xb2dataJapaneseJapan
                                                                          RT_STRING0x4f74d00xb4dataKoreanNorth Korea
                                                                          RT_STRING0x4f74d00xb4dataKoreanSouth Korea
                                                                          RT_STRING0x4f75840x6edataChineseChina
                                                                          RT_STRING0x4f75f40x1a0dataGermanGermany
                                                                          RT_STRING0x4f77940x16edataEnglishUnited States
                                                                          RT_STRING0x4f79040x1c6dataFrenchFrance
                                                                          RT_STRING0x4f7acc0xccdataJapaneseJapan
                                                                          RT_STRING0x4f7b980xd0dataKoreanNorth Korea
                                                                          RT_STRING0x4f7b980xd0dataKoreanSouth Korea
                                                                          RT_STRING0x4f7c680x78dataChineseChina
                                                                          RT_STRING0x4f7ce00x37edataGermanGermany
                                                                          RT_STRING0x4f80600x294dataEnglishUnited States
                                                                          RT_STRING0x4f82f40x35edataFrenchFrance
                                                                          RT_STRING0x4f86540x184dataJapaneseJapan
                                                                          RT_STRING0x4f87d80x190dataKoreanNorth Korea
                                                                          RT_STRING0x4f87d80x190dataKoreanSouth Korea
                                                                          RT_STRING0x4f89680xdcdataChineseChina
                                                                          RT_STRING0x4f8a440x3b6dataGermanGermany
                                                                          RT_STRING0x4f8dfc0x33adataEnglishUnited States
                                                                          RT_STRING0x4f91380x428dataFrenchFrance
                                                                          RT_STRING0x4f95600x1eedataJapaneseJapan
                                                                          RT_STRING0x4f97500x1eedataKoreanNorth Korea
                                                                          RT_STRING0x4f97500x1eedataKoreanSouth Korea
                                                                          RT_STRING0x4f99400x134dataChineseChina
                                                                          RT_STRING0x4f9a740xb4dataGermanGermany
                                                                          RT_STRING0x4f9b280x88dataEnglishUnited States
                                                                          RT_STRING0x4f9bb00xa0dataFrenchFrance
                                                                          RT_STRING0x4f9c500x4cdataJapaneseJapan
                                                                          RT_STRING0x4f9c9c0x54dataKoreanNorth Korea
                                                                          RT_STRING0x4f9c9c0x54dataKoreanSouth Korea
                                                                          RT_STRING0x4f9cf00x3cdataChineseChina
                                                                          RT_STRING0x4f9d2c0x50dataGermanGermany
                                                                          RT_STRING0x4f9d7c0x48dataEnglishUnited States
                                                                          RT_STRING0x4f9dc40x50PGP\011Secret Key -FrenchFrance
                                                                          RT_STRING0x4f9e140x3edataJapaneseJapan
                                                                          RT_STRING0x4f9e540x46dataKoreanNorth Korea
                                                                          RT_STRING0x4f9e540x46dataKoreanSouth Korea
                                                                          RT_STRING0x4f9e9c0x32dataChineseChina
                                                                          RT_STRING0x4f9ed00x47cdataGermanGermany
                                                                          RT_STRING0x4fa34c0x380dataEnglishUnited States
                                                                          RT_STRING0x4fa6cc0x4f2dataFrenchFrance
                                                                          RT_STRING0x4fabc00x2b6dataJapaneseJapan
                                                                          RT_STRING0x4fae780x2aadataKoreanNorth Korea
                                                                          RT_STRING0x4fae780x2aadataKoreanSouth Korea
                                                                          RT_STRING0x4fb1240x180dataChineseChina
                                                                          RT_STRING0x4fb2a40xa88dataGermanGermany
                                                                          RT_STRING0x4fbd2c0x98cdataEnglishUnited States
                                                                          RT_STRING0x4fc6b80xb36dataFrenchFrance
                                                                          RT_STRING0x4fd1f00x524dataJapaneseJapan
                                                                          RT_STRING0x4fd7140x5eedataKoreanNorth Korea
                                                                          RT_STRING0x4fd7140x5eedataKoreanSouth Korea
                                                                          RT_STRING0x4fdd040x390dataChineseChina
                                                                          RT_STRING0x4fe0940x1dcdataGermanGermany
                                                                          RT_STRING0x4fe2700x18cdataEnglishUnited States
                                                                          RT_STRING0x4fe3fc0x202dataFrenchFrance
                                                                          RT_STRING0x4fe6000xd8dataJapaneseJapan
                                                                          RT_STRING0x4fe6d80xc6dataKoreanNorth Korea
                                                                          RT_STRING0x4fe6d80xc6dataKoreanSouth Korea
                                                                          RT_STRING0x4fe7a00x80dataChineseChina
                                                                          RT_STRING0x4fe8200xa6dataGermanGermany
                                                                          RT_STRING0x4fe8c80x8cdataEnglishUnited States
                                                                          RT_STRING0x4fe9540xa6dataFrenchFrance
                                                                          RT_STRING0x4fe9fc0x6edataJapaneseJapan
                                                                          RT_STRING0x4fea6c0x72dataKoreanNorth Korea
                                                                          RT_STRING0x4fea6c0x72dataKoreanSouth Korea
                                                                          RT_STRING0x4feae00x40dataChineseChina
                                                                          RT_STRING0x4feb200x136dataGermanGermany
                                                                          RT_STRING0x4fec580x11edataEnglishUnited States
                                                                          RT_STRING0x4fed780x11edataFrenchFrance
                                                                          RT_STRING0x4fee980x11edataJapaneseJapan
                                                                          RT_STRING0x4fefb80xf4dataKoreanNorth Korea
                                                                          RT_STRING0x4fefb80xf4dataKoreanSouth Korea
                                                                          RT_STRING0x4ff0ac0x11edataChineseChina
                                                                          RT_STRING0x4ff1cc0x5adataGermanGermany
                                                                          RT_STRING0x4ff2280x52dataEnglishUnited States
                                                                          RT_STRING0x4ff27c0x52dataFrenchFrance
                                                                          RT_STRING0x4ff2d00x52dataJapaneseJapan
                                                                          RT_STRING0x4ff3240x44dataKoreanNorth Korea
                                                                          RT_STRING0x4ff3240x44dataKoreanSouth Korea
                                                                          RT_STRING0x4ff3680x52dataChineseChina
                                                                          RT_STRING0x4ff3bc0x68dataGermanGermany
                                                                          RT_STRING0x4ff4240x6adataEnglishUnited States
                                                                          RT_STRING0x4ff4900x70dataFrenchFrance
                                                                          RT_STRING0x4ff5000x48dataJapaneseJapan
                                                                          RT_STRING0x4ff5480x4adataKoreanNorth Korea
                                                                          RT_STRING0x4ff5480x4adataKoreanSouth Korea
                                                                          RT_STRING0x4ff5940x38dataChineseChina
                                                                          RT_STRING0x4ff5cc0x21adataGermanGermany
                                                                          RT_STRING0x4ff7e80x222dataEnglishUnited States
                                                                          RT_STRING0x4ffa0c0x286dataFrenchFrance
                                                                          RT_STRING0x4ffc940x11cdataJapaneseJapan
                                                                          RT_STRING0x4ffdb00x174dataKoreanNorth Korea
                                                                          RT_STRING0x4ffdb00x174dataKoreanSouth Korea
                                                                          RT_STRING0x4fff240xccdataChineseChina
                                                                          RT_STRING0x4ffff00x2d6dataGermanGermany
                                                                          RT_STRING0x5002c80x270dataEnglishUnited States
                                                                          RT_STRING0x5005380x2cedataFrenchFrance
                                                                          RT_STRING0x5008080x168dataJapaneseJapan
                                                                          RT_STRING0x5009700x198dataKoreanNorth Korea
                                                                          RT_STRING0x5009700x198dataKoreanSouth Korea
                                                                          RT_STRING0x500b080xdedataChineseChina
                                                                          RT_STRING0x500be80x1e0dataGermanGermany
                                                                          RT_STRING0x500dc80x12adataEnglishUnited States
                                                                          RT_STRING0x500ef40x17edataFrenchFrance
                                                                          RT_STRING0x5010740xecdataJapaneseJapan
                                                                          RT_STRING0x5011600xe6dataKoreanNorth Korea
                                                                          RT_STRING0x5011600xe6dataKoreanSouth Korea
                                                                          RT_STRING0x5012480x98dataChineseChina
                                                                          RT_STRING0x5012e00x96dataGermanGermany
                                                                          RT_STRING0x5013780x6cdataEnglishUnited States
                                                                          RT_STRING0x5013e40x80dataFrenchFrance
                                                                          RT_STRING0x5014640x4adataJapaneseJapan
                                                                          RT_STRING0x5014b00x48dataKoreanNorth Korea
                                                                          RT_STRING0x5014b00x48dataKoreanSouth Korea
                                                                          RT_STRING0x5014f80x3adataChineseChina
                                                                          RT_STRING0x5015340x1f2dataGermanGermany
                                                                          RT_STRING0x5017280x196dataEnglishUnited States
                                                                          RT_STRING0x5018c00x21adataFrenchFrance
                                                                          RT_STRING0x501adc0x132dataJapaneseJapan
                                                                          RT_STRING0x501c100x11cdataKoreanNorth Korea
                                                                          RT_STRING0x501c100x11cdataKoreanSouth Korea
                                                                          RT_STRING0x501d2c0xe2dataChineseChina
                                                                          RT_STRING0x501e100x50dataGermanGermany
                                                                          RT_STRING0x501e600x44dataEnglishUnited States
                                                                          RT_STRING0x501ea40x42dataFrenchFrance
                                                                          RT_STRING0x501ee80x2adataJapaneseJapan
                                                                          RT_STRING0x501f140x2edataKoreanNorth Korea
                                                                          RT_STRING0x501f140x2edataKoreanSouth Korea
                                                                          RT_STRING0x501f440x28dataChineseChina
                                                                          RT_STRING0x501f6c0x4aedataEnglishUnited States
                                                                          RT_STRING0x50241c0x3f0dataEnglishUnited States
                                                                          RT_STRING0x50280c0x3e2dataEnglishUnited States
                                                                          RT_STRING0x502bf00x6cdataEnglishUnited States
                                                                          RT_STRING0x502c5c0xbe6PGP\011Secret Sub-key -EnglishUnited States
                                                                          RT_STRING0x5038440x18a2dataEnglishUnited States
                                                                          RT_STRING0x5050e80x478dataEnglishUnited States
                                                                          RT_STRING0x5055600x148dataEnglishUnited States
                                                                          RT_STRING0x5056a80x2e8dataEnglishUnited States
                                                                          RT_STRING0x5059900x220dataEnglishUnited States
                                                                          RT_STRING0x505bb00x22adataEnglishUnited States
                                                                          RT_STRING0x505ddc0x82dataEnglishUnited States
                                                                          RT_STRING0x505e600x2adataEnglishUnited States
                                                                          RT_STRING0x505e8c0x184dataEnglishUnited States
                                                                          RT_STRING0x5060100x4e6dataEnglishUnited States
                                                                          RT_STRING0x5064f80x264dataEnglishUnited States
                                                                          RT_STRING0x50675c0x2dadataEnglishUnited States
                                                                          RT_STRING0x506a380x8adataEnglishUnited States
                                                                          RT_STRING0x506ac40xacdataEnglishUnited States
                                                                          RT_STRING0x506b700xdedataEnglishUnited States
                                                                          RT_STRING0x506c500x4a8dataEnglishUnited States
                                                                          RT_STRING0x5070f80x228dataEnglishUnited States
                                                                          RT_STRING0x5073200x2cdataEnglishUnited States
                                                                          RT_STRING0x50734c0x42dataEnglishUnited States
                                                                          RT_ACCELERATOR0x5073900x10Non-ISO extended-ASCII text, with NEL line terminatorsEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5073a00x22dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5073c40x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5073d80x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5073ec0x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074000x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074140x14Non-ISO extended-ASCII text, with LF, NEL line terminatorsEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074280x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x50743c0x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074500x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074640x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074780x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x50748c0x14dataEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074a00x14unicos (cray) executableEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074b40x14Non-ISO extended-ASCII text, with no line terminators, with escape sequencesEnglishUnited States
                                                                          RT_GROUP_CURSOR0x5074c80x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x52ea900xaedataEnglishUnited States
                                                                          RT_GROUP_ICON0x50758c0x3edataEnglishUnited States
                                                                          RT_GROUP_ICON0x5075cc0x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5075e00x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5075f40x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076080x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x50761c0x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076300x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076440x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076580x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x50766c0x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076800x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076940x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076a80x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076bc0x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076d00x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5076e40x30dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5077140x30dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5077440x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5077580x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x50776c0x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5077800x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5077940x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5077a80x22dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5077cc0x3edataEnglishUnited States
                                                                          RT_GROUP_ICON0x50780c0x22dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5078300x3edataEnglishUnited States
                                                                          RT_GROUP_ICON0x5078700x30dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5078a00x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5078b40x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5078c80x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5078dc0x14dataEnglishUnited States
                                                                          RT_GROUP_ICON0x5078f00x14dataEnglishUnited States
                                                                          RT_VERSION0x52eb440x2f8dataEnglishUnited States
                                                                          RT_MANIFEST0x52ee400x5dcASCII text, with very long lines, with CRLF line terminatorsEnglishUnited States

                                                                          Imports

                                                                          DLLImport
                                                                          KERNEL32.DLLLoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
                                                                          COMDLG32.dllGetFileTitleW
                                                                          GDI32.dllArcTo
                                                                          MPR.dllWNetGetUserW
                                                                          ole32.dllCoInitialize
                                                                          OLEAUT32.dllSafeArrayPutElement
                                                                          PSAPI.DLLGetModuleFileNameExW
                                                                          RPCRT4.dllUuidCreate
                                                                          SHELL32.dllDragFinish
                                                                          USER32.dllGetDC
                                                                          VERSION.dllVerQueryValueW
                                                                          WININET.dllInternetCheckConnectionW
                                                                          WINSPOOL.DRVGetJobW
                                                                          WS2_32.dllclosesocket
                                                                          WTSAPI32.dllWTSFreeMemory

                                                                          Exports

                                                                          NameOrdinalAddress
                                                                          NI_MetaToolbox_MetaOutput_GetSharedGlobalData10x61f710

                                                                          Version Infos

                                                                          DescriptionData
                                                                          LegalCopyrightCopyright 2003-2017. All Rights Reserved.
                                                                          InternalNameMetaInstaller
                                                                          FileVersion17.5.0.170
                                                                          CompanyName
                                                                          ProductNameNational Instruments Installer
                                                                          ProductVersion17.5.0
                                                                          FileDescriptionInstaller
                                                                          OriginalFilenameSetup.exe
                                                                          Translation0x0409 0x04b0

                                                                          Possible Origin

                                                                          Language of compilation systemCountry where language is spokenMap
                                                                          EnglishUnited States
                                                                          GermanGermany
                                                                          FrenchFrance
                                                                          JapaneseJapan
                                                                          KoreanNorth Korea
                                                                          KoreanSouth Korea
                                                                          ChineseChina

                                                                          Network Behavior

                                                                          No network behavior found

                                                                          Code Manipulations

                                                                          Statistics

                                                                          System Behavior

                                                                          General

                                                                          Start time:08:37:47
                                                                          Start date:14/10/2021
                                                                          Path:C:\Users\user\Desktop\setup.exe
                                                                          Wow64 process (32bit):true
                                                                          Commandline:'C:\Users\user\Desktop\setup.exe'
                                                                          Imagebase:0x400000
                                                                          File size:1466368 bytes
                                                                          MD5 hash:FE5C2E1333B4477D029DEDC9C1B5DD4D
                                                                          Has elevated privileges:true
                                                                          Has administrator privileges:true
                                                                          Programmed in:C, C++ or other language
                                                                          Reputation:low

                                                                          Disassembly

                                                                          Code Analysis

                                                                          Reset < >