Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe

Overview

General Information

Sample Name:AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
Analysis ID:694545
MD5:5952de86d1a047feceb4f21828cf0f74
SHA1:5194f085b9374789c3c7760c571f19a4c1b2231b
SHA256:9553b533d1d85c669b6b529506ea25a44a1cd3795f71d61503923e5ce0270ea9
Infos:

Detection

Score:26
Range:0 - 100
Whitelisted:false
Confidence:80%

Signatures

Yara detected Generic Downloader
Uses 32bit PE files
PE file does not import any functions
Sample file is different than original file name gathered from version info
PE file contains strange resources
Drops PE files
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Detected potential crypto function
Found potential string decryption / allocating functions
Contains functionality to dynamically determine API calls
Found dropped PE file which has not been started or loaded
Uses Microsoft's Enhanced Cryptographic Provider

Classification

  • System is w10x64
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Core.dllJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
    C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Controls.DataVisualization.dllJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
      No Sigma rule has matched
      No Snort rule has matched

      Click to jump to signature section

      Show All Signature Results
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0041E7B0 CryptAcquireContextA,0_2_0041E7B0
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrAuditCs\GuiClrAuditCs.pdb$z source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.405595143.00000000029F3000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\If.pdb'' source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.446707299.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBase.pdbdd source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.408765997.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavcodec\avcodec-57.pdb0 source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.323502368.00000000029F5000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavcodec\avcodec-57.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.323502368.00000000029F5000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSystemTree\GuiClrSystemTree.pdb\ source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.431861452.00000000029FB000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrViewWindow.pdb<< source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.435454031.00000000029F1000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrSearch.pdb33 source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.426115847.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBookmarks.pdb!! source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.410434447.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\EagleClr.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.371133006.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBookmarks.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.410434447.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\ExportWriters.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.384340934.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSetupCs\GuiClrSetupCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavutil\avutil-55.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.325675397.00000000029FD000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrImagePanelCs\GuiClrImagePanelCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.414670737.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrAppCs\GuiClrAppCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.401850011.00000000029FF000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrTimelineCs\GuiClrTimelineCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.433239691.00000000029F7000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: c:\jenkins\workspace\SDK - Windows DEVELOP\GEISDK\GEISDK\Release\GEISDK.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.389965476.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrImagePanel.pdb** source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.413615714.00000000029F4000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrImagePanel.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.413615714.00000000029F4000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrMaps.pdb++ source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.416358575.00000000029F2000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\Eagle.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.365069060.0000000002A81000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrSearch.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.426115847.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBase.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.408765997.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\ExportWriters.pdbZ' source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.384340934.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSearchCs\GuiClrSearchCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.427255969.00000000029F3000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrMaps.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.416358575.00000000029F2000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrAuditCs\GuiClrAuditCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.405595143.00000000029F3000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\EagleCs\EagleCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.378234427.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\CmnStor.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.339548112.00000000029FF000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\If.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.446707299.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\Eagle.pdb> source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.365069060.0000000002A81000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrSetup.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.428825437.00000000029FA000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSystemTree\GuiClrSystemTree.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.431861452.00000000029FB000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrMapsCs\GuiClrMapsCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.419243765.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrAudit.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.403459405.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavformat\avformat-57.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.325011536.00000000029F8000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\EagleClr.pdb88 source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.371133006.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrViewWindow.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.435454031.00000000029F1000.00000004.00000800.00020000.00000000.sdmp

      Networking

      barindex
      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Core.dll, type: DROPPED
      Source: Yara matchFile source: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Controls.DataVisualization.dll, type: DROPPED
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://activate.avigilon.com./PublicLicenseInfo/site
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://activate.avigilon.com/activation/activate_autoshttp://activate.avigilon.com/deactivation/deac
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://activate.avigilon.comAGuiClr.Setup.LicensingDialogBaseCGuiClr.Setup.LicensingRequestDemom/Gui
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.445852544.00000000029FF000.00000004.00000800.00020000.00000000.sdmp, AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.444978440.00000000029F6000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://icu-project.org
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.414670737.00000000029FC000.00000004.00000800.00020000.00000000.sdmp, AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.401850011.00000000029FF000.00000004.00000800.00020000.00000000.sdmp, AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.427255969.00000000029F3000.00000004.00000800.00020000.00000000.sdmp, AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.telerik.com/2008/xaml/presentation
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.365069060.0000000002A81000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.winimage.com/zLibDll
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.365069060.0000000002A81000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://www.winimage.com/zLibDll6666666666666666jjjjjjjjjjjjjjjj
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://blue.avigilon.com$Setup/MediaServer/
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://blue.avigilon.comY/GuiClrSetupCs;component/cloudsetupview.xaml%AudioSetupPageText
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
      Source: icudt44.dll.0.drStatic PE information: No import functions for PE file found
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.419243765.00000000029F6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrMapsCs.dll. vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.445852544.00000000029FF000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameicuuc44.dll vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.378234427.00000000029F6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameEagleCs.dll4 vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.444978440.00000000029F6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameicuin44.dll vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.414670737.00000000029FC000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrImagePanelCs.dll6 vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.385327538.00000000029FD000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamefisheye.dllp( vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.401850011.00000000029FF000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrAppCs.dll, vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.431861452.00000000029FB000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrSystemTree.dll4 vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.389965476.00000000029F9000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGEISDK.dll^ vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.433239691.00000000029F7000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrTimelineCs.dllB vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.427255969.00000000029F3000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrSearchCs.dll> vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrSetupCs.dll4 vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.355027924.00000000029F8000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameD3DX9D.dll` vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.405595143.00000000029F3000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenameGuiClrAuditCs.dll4 vs AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeStatic PE information: Resource name: RT_ICON type: GLS_BINARY_LSB_FIRST
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0042A0100_2_0042A010
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_004200200_2_00420020
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_004421DD0_2_004421DD
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0043C42A0_2_0043C42A
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_004224300_2_00422430
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0044C5A00_2_0044C5A0
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0043662E0_2_0043662E
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0044A7200_2_0044A720
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0044A7B00_2_0044A7B0
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0041C8160_2_0041C816
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0044A9800_2_0044A980
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_00432A0C0_2_00432A0C
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0044AC700_2_0044AC70
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_00436CD00_2_00436CD0
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_00448CB00_2_00448CB0
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_00424F400_2_00424F40
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_004490B00_2_004490B0
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0043721A0_2_0043721A
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_004213F00_2_004213F0
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: String function: 004291C0 appears 47 times
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: String function: 004160E0 appears 55 times
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: String function: 00429235 appears 47 times
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: String function: 00429470 appears 42 times
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: String function: 00428DDF appears 353 times
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile read: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeJump to behavior
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZNJump to behavior
      Source: classification engineClassification label: sus26.troj.winEXE@1/179@0/0
      Source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeStatic file information: File size 84607631 > 1048576
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrAuditCs\GuiClrAuditCs.pdb$z source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.405595143.00000000029F3000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\If.pdb'' source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.446707299.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBase.pdbdd source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.408765997.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavcodec\avcodec-57.pdb0 source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.323502368.00000000029F5000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavcodec\avcodec-57.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.323502368.00000000029F5000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSystemTree\GuiClrSystemTree.pdb\ source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.431861452.00000000029FB000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrViewWindow.pdb<< source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.435454031.00000000029F1000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrSearch.pdb33 source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.426115847.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBookmarks.pdb!! source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.410434447.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\EagleClr.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.371133006.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBookmarks.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.410434447.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\ExportWriters.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.384340934.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSetupCs\GuiClrSetupCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.429990990.00000000029F1000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavutil\avutil-55.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.325675397.00000000029FD000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrImagePanelCs\GuiClrImagePanelCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.414670737.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrAppCs\GuiClrAppCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.401850011.00000000029FF000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrTimelineCs\GuiClrTimelineCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.433239691.00000000029F7000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: c:\jenkins\workspace\SDK - Windows DEVELOP\GEISDK\GEISDK\Release\GEISDK.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.389965476.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrImagePanel.pdb** source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.413615714.00000000029F4000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrImagePanel.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.413615714.00000000029F4000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrMaps.pdb++ source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.416358575.00000000029F2000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\Eagle.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.365069060.0000000002A81000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrSearch.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.426115847.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrBase.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.408765997.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\ExportWriters.pdbZ' source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.384340934.00000000029F9000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSearchCs\GuiClrSearchCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.427255969.00000000029F3000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrMaps.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.416358575.00000000029F2000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrAuditCs\GuiClrAuditCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.405595143.00000000029F3000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\EagleCs\EagleCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.378234427.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\CmnStor.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.339548112.00000000029FF000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\If.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.446707299.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\Eagle.pdb> source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.365069060.0000000002A81000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrSetup.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.428825437.00000000029FA000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrSystemTree\GuiClrSystemTree.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.431861452.00000000029FB000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\obj\GuiClrMapsCs\GuiClrMapsCs.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.419243765.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrAudit.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.403459405.00000000029F6000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGEXT-WIN\se\libs\ffmpeg\ffmpeg-3.1.4\build_vc_win32_shared\libavformat\avformat-57.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.325011536.00000000029F8000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\EagleClr.pdb88 source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.371133006.00000000029FC000.00000004.00000800.00020000.00000000.sdmp
      Source: Binary string: C:\bamboo\build-dir\ACC-NGACCWIN56-JOB1\software-internal\Build\Win32-Release\bin\GuiClrViewWindow.pdb source: AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe, 00000000.00000003.435454031.00000000029F1000.00000004.00000800.00020000.00000000.sdmp
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_004291C0 push eax; ret 0_2_004291DE
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_00429440 push eax; ret 0_2_0042946E
      Source: avcodec-57.dll.0.drStatic PE information: section name: .rodata
      Source: avcodec-57.dll.0.drStatic PE information: section name: .rodata
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeCode function: 0_2_0043232C LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,0_2_0043232C
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libssl-1_1.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrAuditCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_iostreams-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Dev.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\EagleClr.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\CmnStor.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrApp.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\d3dx9_34.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrResources.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_serialization-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\ClientEntry.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaPipeline.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSetup.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libquadmath-0.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaProcessor.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GEISDK.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\DevProtoBuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\xerces-c_3_1.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\EagleProtobuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrMaps.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrViewWindow.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSystemTree.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\avformat-57.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SoapCommon.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_log_setup-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\NetCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_chrono-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrDirectory.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Eagle.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SSPI.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Css.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSearchCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Data.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_zlib-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\freetype-6.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\EagleCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_thread-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\swresample-2.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaRendererHardware.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrFormsCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libopenblas.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_log-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\NetClr.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_filesystem-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libgcc_s_sjlj-1.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\If.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\avutil-55.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\icuin44.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Io.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\openh264.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\vrllite.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\avcodec-57.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Model.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaCore.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_date_time-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\msvcp120.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libcrypto-1_1.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\vccorlib120.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Rendering.Wpf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Controls.Input.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_random-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaExecutor.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\fisheyesw.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrBase.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\msvcp80.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\NetCore.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrImagePanelCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Converters.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Core.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\icuuc44.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\opus.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrWpfBase.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaRendererSoftware.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrForms.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\zxcvbn.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrMapsCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaRendererAudio.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSearch.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSetupCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\CmnSysProtoBuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\icudt44.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\protobuf-net.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\IMV1.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrTimelineCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_system-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\AnalyticsProtobuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Controls.Data.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\msvcr80.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Controls.DataVisualization.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\CmnStorProtoBuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Controls.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrBookmarks.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrAudit.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Dom.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\swscale-4.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrAppCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrImagePanel.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\ExportWriters.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\CmnClient.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\pthreadVC2.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\VmsPlayerApp.exeJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\IfSoap.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Runtime.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libxml2.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libgfortran-3.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaCodec.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libprotobuf-2.3.0.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\CmnSys.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaProtobuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\CmnClientProtoBuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\NetProtoBuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Rendering.Gdi.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaRendererWpf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrViewWindowCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\msvcr120.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeFile created: C:\Users\user\AppData\Local\Temp\ckz_5KZN\avfilter-6.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libssl-1_1.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrAuditCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_iostreams-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Dev.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\CmnStor.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\EagleClr.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrApp.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\d3dx9_34.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrResources.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_serialization-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaPipeline.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\ClientEntry.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSetup.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaProcessor.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libquadmath-0.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GEISDK.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\DevProtoBuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\xerces-c_3_1.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\EagleProtobuf.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrMaps.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrViewWindow.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSystemTree.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\avformat-57.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SoapCommon.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_log_setup-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\NetCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrDirectory.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_chrono-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Eagle.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SSPI.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\SharpVectors.Css.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrSearchCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\Telerik.Windows.Data.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_zlib-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\freetype-6.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\EagleCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\swresample-2.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_thread-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\MediaRendererHardware.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\GuiClrFormsCs.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\libopenblas.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\NetClr.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\ckz_5KZN\boost_log-vc120-mt-1_62.dllJump to dropped file
      Source: C:\Users\user\Desktop\AvigilonControlCenterPlayerStandAlone-6.10.0.24.exe