Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
WsiysHggF9.exe

Overview

General Information

Sample Name:WsiysHggF9.exe
Analysis ID:715159
MD5:350ea577229a9518d3b9dcd76d109e14
SHA1:b9431df0ca98d1fa3abeefc92d1bd25e4c8b4e22
SHA256:2c8960c00dfc803bb8175a6833904173b6ff044c7128c24c8de2379b47274c77
Tags:exeRedLineStealer
Infos:

Detection

RedLine
Score:50
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Yara detected RedLine Stealer
Multi AV Scanner detection for submitted file
Malicious sample detected (through community Yara rule)
Snort IDS alert for network traffic
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Tries to detect sandboxes and other dynamic analysis tools (process name or module or function)
Yara detected Generic Downloader
Obfuscated command line found
Tries to detect virtualization through RDTSC time measurements
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Yara signature match
Drops PE files to the application program directory (C:\ProgramData)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query locales information (e.g. system language)
Uses code obfuscation techniques (call, push, ret)
PE file contains sections with non-standard names
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Stores files to the Windows start menu directory
Contains functionality to communicate with device drivers
Found dropped PE file which has not been started or loaded
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
Entry point lies outside standard sections
Sample file is different than original file name gathered from version info
Allocates memory with a write watch (potentially for evading sandboxes)
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
File is packed with WinRar
Binary contains a suspicious time stamp
Creates a process in suspended mode (likely to inject code)

Classification

  • System is w10x64
  • WsiysHggF9.exe (PID: 5904 cmdline: C:\Users\user\Desktop\WsiysHggF9.exe MD5: 350EA577229A9518D3B9DCD76D109E14)
    • audacity-win-3.2.0-64bit.exe (PID: 5640 cmdline: "C:\ProgramData\audacity-win-3.2.0-64bit.exe" MD5: 553B47079E2FD4820EF2F9841297EF97)
      • audacity-win-3.2.0-64bit.tmp (PID: 4432 cmdline: "C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp" /SL5="$5040E,13178964,955904,C:\ProgramData\audacity-win-3.2.0-64bit.exe" MD5: 220722BABC7320F6FF80BB591C9DA719)
        • _setup64.tmp (PID: 3612 cmdline: helper 105 0x420 MD5: E4211D6D009757C078A9FAC7FF4F03D4)
          • conhost.exe (PID: 3792 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
        • Audacity.exe (PID: 1928 cmdline: C:\Program Files\Audacity\audacity.exe MD5: 686920484890800433A208E111666FE1)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
dump.pcapJoeSecurity_RedLineYara detected RedLine StealerJoe Security
    dump.pcapJoeSecurity_RedLine_1Yara detected RedLine StealerJoe Security
      SourceRuleDescriptionAuthorStrings
      1.3.Installation_controller.exe.3fc3a610.0.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
      • 0x694ce:$pat14: , CommandLine:
      • 0x53416:$v2_1: ListOfProcesses
      • 0x50444:$v4_4: stringKey
      • 0x531b0:$v4_8: procName
      • 0x4e6c2:$v5_1: DownloadAndExecuteUpdate
      • 0x4e6ea:$v5_2: ITaskProcessor
      • 0x4e6b0:$v5_3: CommandLineUpdate
      • 0x4e6db:$v5_4: DownloadUpdate
      • 0x4e624:$v5_5: FileScanning
      • 0x4e8c2:$v5_7: RecordHeaderField
      • 0x4e7ec:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
      1.3.Installation_controller.exe.3fc3a610.0.unpackMALWARE_Win_zgRATDetects zgRATditekSHen
      • 0x5c351:$s1: file:///
      • 0x5c261:$s2: {11111-22222-10009-11112}
      • 0x5c2e1:$s3: {11111-22222-50001-00000}
      • 0x579ac:$s4: get_Module
      • 0x51d04:$s5: Reverse
      • 0x5009f:$s6: BlockCopy
      • 0x582f8:$s7: ReadByte
      • 0x5c363:$s8: 4C 00 6F 00 63 00 61 00 74 00 69 00 6F 00 6E 00 00 0B 46 00 69 00 6E 00 64 00 20 00 00 13 52 00 65 00 73 00 6F 00 75 00 72 00 63 00 65 00 41 00 00 11 56 00 69 00 72 00 74 00 75 00 61 00 6C 00 ...
      1.3.Installation_controller.exe.3fc3a610.0.raw.unpackJoeSecurity_GenericDownloader_1Yara detected Generic DownloaderJoe Security
        1.3.Installation_controller.exe.3fc3a610.0.raw.unpackMALWARE_Win_RedLineDetects RedLine infostealerditekSHen
        • 0x6b2ce:$pat14: , CommandLine:
        • 0x55216:$v2_1: ListOfProcesses
        • 0x52244:$v4_4: stringKey
        • 0x54fb0:$v4_8: procName
        • 0x504c2:$v5_1: DownloadAndExecuteUpdate
        • 0x504ea:$v5_2: ITaskProcessor
        • 0x504b0:$v5_3: CommandLineUpdate
        • 0x504db:$v5_4: DownloadUpdate
        • 0x50424:$v5_5: FileScanning
        • 0x506c2:$v5_7: RecordHeaderField
        • 0x505ec:$v5_9: BCRYPT_KEY_LENGTHS_STRUCT
        1.3.Installation_controller.exe.3fc3a610.0.raw.unpackMALWARE_Win_zgRATDetects zgRATditekSHen
        • 0x5e151:$s1: file:///
        • 0x5e061:$s2: {11111-22222-10009-11112}
        • 0x5e0e1:$s3: {11111-22222-50001-00000}
        • 0x597ac:$s4: get_Module
        • 0x53b04:$s5: Reverse
        • 0x51e9f:$s6: BlockCopy
        • 0x5a0f8:$s7: ReadByte
        • 0x5e163:$s8: 4C 00 6F 00 63 00 61 00 74 00 69 00 6F 00 6E 00 00 0B 46 00 69 00 6E 00 64 00 20 00 00 13 52 00 65 00 73 00 6F 00 75 00 72 00 63 00 65 00 41 00 00 11 56 00 69 00 72 00 74 00 75 00 61 00 6C 00 ...
        No Sigma rule has matched
        Timestamp:188.34.179.139192.168.2.610561496932850353 10/03/22-17:32:43.853269
        SID:2850353
        Source Port:10561
        Destination Port:49693
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.6188.34.179.13949693105612850027 10/03/22-17:32:43.736332
        SID:2850027
        Source Port:49693
        Destination Port:10561
        Protocol:TCP
        Classtype:A Network Trojan was detected
        Timestamp:192.168.2.6188.34.179.13949693105612850286 10/03/22-17:32:54.635526
        SID:2850286
        Source Port:49693
        Destination Port:10561
        Protocol:TCP
        Classtype:A Network Trojan was detected

        Click to jump to signature section

        Show All Signature Results

        AV Detection

        barindex
        Source: WsiysHggF9.exeReversingLabs: Detection: 51%
        Source: WsiysHggF9.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audacity_is1Jump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\AudacityJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\unins000.datJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NL931.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-9T84T.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-0UADG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-P90KL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NTE5N.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-9JHT8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-2SCU5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-CV5R1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7U34J.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7F1IJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-EPTFT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-IU3MP.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NKFUD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5OMUN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5LJ3G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-JO5BM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-SO45U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-VGNVB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-E63DL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7BF1G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-MVD1T.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-J5UM8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-OF8N5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-DBS3U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7HBD3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-EE795.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-6S7SN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-V5T2O.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-9K9M7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-UFU1R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-DEMF3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-JALHN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-19I02.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-GCDE1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-1J0J3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-HKQ8J.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-U641C.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-KRBVG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-R9F1C.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-VMF33.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NOB4R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-37ABV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-HKD6O.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-L050V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-GAK9A.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-UR1D7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-3RF3V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-EGO60.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-KJ41F.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-AG00V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-8JNDO.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-0UDPU.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-L0CK2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-TDP90.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-4STCS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-H8I8G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-UJ3RS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-LAIB1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-K3IU2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-32N1E.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-0KP7K.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-8SGGQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-IOAI2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-K8GOH.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-KRBQ3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-6C785.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5BTDL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5AL5G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7A0A0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\LanguagesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\afJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\af\is-HO62N.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\arJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ar\is-T0H9J.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\beJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\be\is-M4P44.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bgJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bg\is-3UN24.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bnJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bn\is-TP6MB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bsJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bs\is-2VUIJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\caJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ca\is-6CEK5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ca_ES@valenciaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ca_ES@valencia\is-MT216.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\coJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\co\is-3NQSM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\csJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\cs\is-T6M9E.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\cyJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\cy\is-H92PA.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\daJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\da\is-L5QPV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\deJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\de\is-52QJJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\elJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\el\is-4K82R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\esJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\es\is-44RRB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\euJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\eu\is-BBOJ7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\eu_ESJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\eu_ES\is-AMHSN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\faJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fa\is-FG87I.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fiJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fi\is-N6N61.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\frJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fr\is-NL67K.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\gaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ga\is-T5ETS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\glJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\gl\is-OKLKC.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\heJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\he\is-O5794.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hiJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hi\is-SQO61.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hrJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hr\is-PHG0Q.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\huJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hu\is-LCVQ1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hyJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hy\is-U2HOB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\idJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\id\is-3J2H4.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\itJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\it\is-E6HJ8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\jaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ja\is-JQCT8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\kaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ka\is-61DBE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\kmJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\km\is-7REVL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\koJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ko\is-J5S6V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ltJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\lt\is-2CVMQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mkJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mk\is-02VU6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mrJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mr\is-NDISD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\myJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\my\is-PIIHM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nbJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nb\is-B1TJE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nlJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nl\is-RTSGB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ocJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\oc\is-FI563.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\plJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pl\is-LEVD6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_BRJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_BR\is-IMKJS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_PTJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_PT\is-CU15K.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\roJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ro\is-F0KFG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ruJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ru\is-DR3N6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\skJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sk\is-N11CT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\slJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sl\is-4TL5P.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RSJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RS\is-PRSVB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RS@latinJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RS@latin\is-644HF.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\svJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sv\is-BSL79.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\taJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ta\is-D76SJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\tgJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\tg\is-KRUGD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\trJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\tr\is-SKP1O.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ukJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\uk\is-1SRVN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\viJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\vi\is-DG9PQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_CNJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_CN\is-5KIHE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_TWJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_TW\is-1MOHQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\NyquistJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-7K270.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-NTKH4.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-D9254.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-IL8FC.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-UVR1R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-PVUQC.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-QSS2A.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-CGAC7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-8A690.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-PPVH8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-RHAJM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-HH9U2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-CFM98.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-EVALG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-L09O0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-5GAUM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-NQM3B.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-ESFAT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-13T21.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-BQNBQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-V3FC0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-BNLP7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-6R5OG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-RAD77.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-G5GC0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-DQTC5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-MROM6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-2UCMK.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-NPI02.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-MMQJF.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwavesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-P0K9Q.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-3463Q.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-E4TOU.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-5EL2U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-05MM5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-727SG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-3DJRE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-RT5IA.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-20JHV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-HJCIF.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-E3H07.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-C2JTA.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-O6A7U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-P38RE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-4EKK3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-InsJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-TBL3M.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-ODRMT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-LRPH6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-II6NQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-11997.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-P00HI.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-EJHHE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-6KU03.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-LHPLL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-V3UUL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-MD7TV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-KU5LN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-02MKN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-SP0OV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-NO5SG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-SO3LD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-BRLM5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-BD9F7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-G1KMP.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-06UFT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-6QFDO.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-P1C46.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-77BQK.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-853A0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-QVTJ7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-591EJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-MQUPM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-LKBSE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-C5P2B.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\modulesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\modules\is-JOTP7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\unins000.msgJump to behavior
        Source: WsiysHggF9.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
        Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb source: WsiysHggF9.exe, 00000000.00000003.245658936.00000000052DC000.00000004.00000800.00020000.00000000.sdmp, WsiysHggF9.exe, 00000000.00000002.303976798.0000000000272000.00000002.00000001.01000000.00000003.sdmp, WsiysHggF9.exe, 00000000.00000003.244701687.00000000052B8000.00000004.00000800.00020000.00000000.sdmp, WsiysHggF9.exe, 00000000.00000000.243769548.0000000000272000.00000002.00000001.01000000.00000003.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\mpg123\1.29.3\_\_\build\9e1553e6621f02c61665c153436b2dfb785b6498\bin\mpg123.pdb00 source: Audacity.exe, 00000010.00000002.583274055.00007FFCFF249000.00000002.00000001.01000000.00000018.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC\RelWithDebInfo\FLAC.pdb11 source: Audacity.exe, 00000010.00000002.580349736.00007FFCFF0A0000.00000002.00000001.01000000.00000013.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\ogg\1.3.4\_\_\build\ad5261bf6074807e7189c351b0f79b113bf2f6c0\build\RelWithDebInfo\ogg.pdb source: Audacity.exe, 00000010.00000002.576735272.00007FFCFEEB9000.00000002.00000001.01000000.00000010.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC++\RelWithDebInfo\FLAC++.pdb!! source: Audacity.exe, 00000010.00000002.583539424.00007FFCFF270000.00000002.00000001.01000000.00000019.sdmp
        Source: Binary string: _.pdb source: Installation_controller.exe, 00000001.00000003.378455694.000000003FC3A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\audacity\audacity\.build.x64\bin\RelWithDebInfo\modules\mod-script-pipe.pdb source: audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.516640303.0000000000198000.00000004.00000010.00020000.00000000.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\vorbis\1.3.7\_\_\build\3b26581a680ab99eb0ef725aa935a0289708df91\build\lib\RelWithDebInfo\vorbis.pdb** source: Audacity.exe, 00000010.00000002.578547685.00007FFCFEFAB000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC\RelWithDebInfo\FLAC.pdb source: Audacity.exe, 00000010.00000002.580349736.00007FFCFF0A0000.00000002.00000001.01000000.00000013.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC++\RelWithDebInfo\FLAC++.pdb source: Audacity.exe, 00000010.00000002.583539424.00007FFCFF270000.00000002.00000001.01000000.00000019.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\vorbis\1.3.7\_\_\build\3b26581a680ab99eb0ef725aa935a0289708df91\build\lib\RelWithDebInfo\vorbis.pdb source: Audacity.exe, 00000010.00000002.578547685.00007FFCFEFAB000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\vorbis\1.3.7\_\_\build\3b26581a680ab99eb0ef725aa935a0289708df91\build\lib\RelWithDebInfo\vorbisenc.pdb source: Audacity.exe, 00000010.00000002.579864349.00007FFCFF065000.00000002.00000001.01000000.00000012.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\mpg123\1.29.3\_\_\build\9e1553e6621f02c61665c153436b2dfb785b6498\bin\mpg123.pdb source: Audacity.exe, 00000010.00000002.583274055.00007FFCFF249000.00000002.00000001.01000000.00000018.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\wxwidgets\3.1.3.3-audacity\_\_\build\f80b0ba6cc698a650654b5966db925c8f7197d7d\build_subfolder\bin\wxbase313u_vc_x64_custom.pdb source: Audacity.exe, 00000010.00000002.593483340.00007FFCFF758000.00000002.00000001.01000000.00000022.sdmp
        Source: Binary string: C:\devel\projects\audacity\audacity\.conan\data\expat\2.2.9\audacity\stable\build\ad5261bf6074807e7189c351b0f79b113bf2f6c0\build_subfolder\bin\libexpat.pdb source: Audacity.exe, 00000010.00000002.585991860.00007FFCFF3A4000.00000002.00000001.01000000.0000001D.sdmp
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024A534 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025B820 SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SetDlgItemTextW,SendDlgItemMessageW,FindFirstFileW,FileTimeToLocalFileTime,FileTimeToSystemTime,GetTimeFormatW,GetDateFormatW,_swprintf,SetDlgItemTextW,FindClose,_swprintf,SetDlgItemTextW,SendDlgItemMessageW,FileTimeToLocalFileTime,FileTimeToSystemTime,GetTimeFormatW,GetDateFormatW,_swprintf,SetDlgItemTextW,_swprintf,SetDlgItemTextW,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0026A928 FindFirstFileExA,

        Networking

        barindex
        Source: TrafficSnort IDS: 2850027 ETPRO TROJAN RedLine Stealer TCP CnC net.tcp Init 192.168.2.6:49693 -> 188.34.179.139:10561
        Source: TrafficSnort IDS: 2850286 ETPRO TROJAN Redline Stealer TCP CnC Activity 192.168.2.6:49693 -> 188.34.179.139:10561
        Source: TrafficSnort IDS: 2850353 ETPRO MALWARE Redline Stealer TCP CnC - Id1Response 188.34.179.139:10561 -> 192.168.2.6:49693
        Source: Yara matchFile source: 1.3.Installation_controller.exe.3fc3a610.0.raw.unpack, type: UNPACKEDPE
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://audacity.sourceforge.net/xml/audacityffmpegpreset-1.0.0.dtd
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://audacity.sourceforge.net/xml/audacityproject-1.3.0.dtd
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://audacity.sourceforge.net/xml/xmlnsDELETE
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://audacityteam.org.http://audacityteam.org.http://audacityteam.org
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://audacityteam.org/about/
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.530283625.0000000002273000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://audacityteam.org03
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://belazar.info/belsoft/
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.516262389.000000000018C000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl04
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningCAR36.crl0y
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.516262389.000000000018C000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningCAR36.crt0#
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://drobilla.net/ns/lilv#dyn-manifest
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://drobilla.net/ns/lilv#filter-lang
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://drobilla.net/ns/lilv#lv2-path
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://forum.audacityteam.org/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://kxstudio.sf.net/ns/lv2ext/external-ui#Host
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://kxstudio.sf.net/ns/lv2ext/external-ui#Widget
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lame.sf.net
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lame.sf.net32bits64bits
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lame.sourceforge.net/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lexvo.org/id/iso639-3/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://ll-plugins.nongnu.org/lv2/namespace#MathConstantPlugin
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://ll-plugins.nongnu.org/lv2/namespace#MathFunctionPlugin
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#AtomPort
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#AtomPorthttp://lv2plug.in/ns/ext/buf-size#maxBlockLengthhttp://lv2plug
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Blank
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Blankhttp://lv2plug.in/ns/ext/atom#Boolhttp://lv2plug.in/ns/ext/atom#C
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Bool
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Chunk
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Double
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Event
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Eventhttp://lv2plug.in/ns/ext/atom#frameTimehttp://lv2plug.in/ns/ext/a
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Float
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Int
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Literal
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Long
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Object
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Path
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Property
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Resource
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Sequence
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#String
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Tuple
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#URI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#URID
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#Vector
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#atomhttp://lv2plug.in/ns/ext/presets#psethttp://lv2plug.in/ns/ext/stat
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#beatTime
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#childType
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#childType%2XFailed
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#eventTransfer
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#frameTime
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/atom#supports
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/buf-size#boundedBlockLength
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/buf-size#fixedBlockLength
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/buf-size#maxBlockLength
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/buf-size#minBlockLength
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/buf-size#nominalBlockLength
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/buf-size#sequenceSize
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/data-access
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/dynmanifest#DynManifest
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/event#supportsEvent
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/event#supportsEventlilv_port_get_valuelilv_port_get_name%s():
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/instance-access
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/log#Error
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/log#Note
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/log#Trace
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/log#Warning
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/log#log
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/midi#MidiEvent
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/options#interface
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/options#interfacehttp://lv2plug.in/ns/ext/state#interfaceCouldn
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/options#options
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/options#optionsLV2InstanceFeaturesList::CheckOptionsD:
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/options#requiredOption
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/options#supportedOption
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/parameters#sampleRate
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-groups#group
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-props#causesArtifacts
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-props#expensive
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-props#logarithmic
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-props#notAutomatic
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-props#notOnGUI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-props#rangeSteps
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/port-props#trigger
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/presets#
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/presets#Preset
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/presets#value
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/resize-port#minimumSize
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/state#
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/state#interface
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/state#makePath
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/state#mapPath
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/state#mapPathhttp://lv2plug.in/ns/ext/state#makePathlilv_state_new_from_ins
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/state#state
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/state#statelilv_state_new_from_world%s():
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/time#Position
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/time#frame
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/time#speed
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/uri-map
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/urid#map
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/urid#unmap
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/worker#interface
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/ext/worker#schedule
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#CocoaUI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#Gtk3UI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#GtkUI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#Qt4UI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#Qt4UIhttp://lv2plug.in/ns/extensions/ui#Qt5UIhttp://lv2plug.in/ns
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#Qt5UI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#WindowsUI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#WindowsUIhttp://lv2plug.in/ns/extensions/ui#showInterface&Duratio
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#X11UI
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#binary
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#external
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#fixedSize
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#idleInterface
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#makeResident
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#noUserResize
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#noUserResizehttp://lv2plug.in/ns/extensions/ui#fixedSizehttp://lv
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#parent
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#portMap
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#portMaphttp://lv2plug.in/ns/extensions/ui#portSubscribehttp://lv2
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#portSubscribe
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#resize
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#resizehttp://lv2plug.in/ns/ext/data-accesshttp://kxstudio.sf.net/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#showInterface
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#touch
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/ui#ui
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/extensions/units#unit
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#AudioPort
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#CVPort
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#ControlPort
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#InputPort
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#InstrumentPlugin
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#MIDIPlugin
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#OutputPort
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#Plugin
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#Specification
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#appliesTo
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#binary
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#control
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#default
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#designation
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#enumeration
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#extensionData
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#index
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#integer
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#latency
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#maximum
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#microVersion
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#minimum
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#minorVersion
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#name
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#optionalFeature
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#port
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#portProperty
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#project
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#projecthttp://usefulinc.com/ns/doap#maintainerhttp://xmlns.com/foaf/0.1
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#prototype
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#reportsLatency
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#requiredFeature
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#sampleRate
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#scalePoint
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#scalePointLANGPOSIXlilv_get_lang%s():
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#symbol
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://lv2plug.in/ns/lv2core#toggled
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://manual.audacityteam.org/o/man/faq_about_audacity.html#free
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.comodoca.com0
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0A
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0C
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.516262389.000000000018C000.00000004.00000010.00020000.00000000.sdmpString found in binary or memory: http://ocsp.digicert.com0X
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://ocsp.sectigo.com0
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://sbsms.sourceforge.net/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://usefulinc.com/ns/doap#
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://usefulinc.com/ns/doap#doaphttp://xmlns.com/foaf/0.1/foafhttp://lv2plug.in/ns/lv2core#lv2http:
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://usefulinc.com/ns/doap#maintainer
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://usefulinc.com/ns/doap#name
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://wiki.audacityteam.org/
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.dk-soft.org/
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.gnu.org/licenses/licenses.html
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.haysoft.org%1-k
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.mega-nerd.com/libsndfile/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.portaudio.com/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.portmedia.sourceforge.net/portmidi/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.twolame.org
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.twolame.org/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://www.vamp-plugins.org/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://xmlns.com/foaf/0.1/
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://xmlns.com/foaf/0.1/homepage
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://xmlns.com/foaf/0.1/mbox
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: http://xmlns.com/foaf/0.1/name
        Source: Audacity.exe, 00000010.00000002.544979137.000001241D121000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://audacityteam.org/3.2.0-video
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://audacityteam.org/errors
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://audacityteam.org/errorshereWould
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://audio.com
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://audio.com/%s/%s
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://audio.com/%s/%sWe
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://audio.comaudio.com%%&Unlink
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.530240715.0000000000A81000.00000004.00000020.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://creativecommons.org/licenses/by/3.0/legalcode
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.530240715.0000000000A81000.00000004.00000020.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://discord.gg/N3XKxzTrq3
        Source: Audacity.exe, 00000010.00000002.544979137.000001241D121000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://forum.audacityteam.org/
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://forum.audacityteam.org/.
        Source: Audacity.exe, 00000010.00000002.537474178.000001241C94E000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://forum.audacityteam.org/dWh//
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://forum.audacityteam.org/viewforum.php?f=19
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://forum.audacityteam.org/viewforum.php?f=25
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://github.com/audacity/audacity/commit/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://github.com/audacity/audacity/commit/Commit
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/audacity/audacity/pulls
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://github.com/audacity/audacity/releases
        Source: WsiysHggF9.exe, 00000000.00000003.251361915.0000000007204000.00000004.00000800.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000000.294843187.0000000000401000.00000020.00000001.01000000.00000007.sdmpString found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://libexpat.github.io/
        Source: Audacity.exe, 00000010.00000002.544979137.000001241D121000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://manual.audacityteam.org/
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://manual.audacityteam.org/man/faq_opening_and_saving_files.html#foreign
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://manual.audacityteam.org/man/faq_opening_and_saving_files.html#fromcd
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://manual.audacityteam.org/man/playing_and_recording.html#midi
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://manual.audacityteam.org/man/unzipping_the_manual.html
        Source: Audacity.exe, 00000010.00000002.544979137.000001241D121000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://manual.audacityteam.org/quick_help.html
        Source: Audacity.exe, 00000010.00000002.544110808.000001241D08B000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://manual.audacityteam.org/quick_help.htmlQ
        Source: Audacity.exe, 00000010.00000002.544979137.000001241D121000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://manual.audacityteam.org/view
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://plugins.audacityteam.org/
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://plugins.audacityteam.org/No
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://quick_helphttp%..
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://sectigo.com/CPS0
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmp, Audacity.exe, 00000010.00000002.574237066.00007FF60E49E000.00000004.00000001.01000000.0000000D.sdmpString found in binary or memory: https://sentry.audacityteam.org/api/2/minidump/?sentry_key=37e6948db02f43ac856bf7edcbe9731d
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://sentry.audacityteam.org/api/2/minidump/?sentry_key=37e6948db02f43ac856bf7edcbe9731dversionse
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://sourceforge.net/p/portmedia/wiki/portsmf/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://sourceforge.net/p/soxr/wiki/Home/
        Source: Audacity.exe, 00000010.00000002.537474178.000001241C94E000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://updates.audacityteam.org/feed/latest.xml
        Source: Audacity.exe, 00000010.00000002.544979137.000001241D121000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://wiki.audacityteam.org/index.php
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://wiki.audacityteam.org/wiki/EQCurvesDownloadEQBackup.xml
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://wiki.audacityteam.org/wiki/User:Galeandrews
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org/
        Source: Audacity.exe, 00000010.00000002.539185569.000001241CA8C000.00000004.00000001.00020000.00000000.sdmp, Audacity.exe, 00000010.00000002.532462677.000001241A7A0000.00000002.00000001.00040000.00000000.sdmp, Audacity.exe, 00000010.00000002.537474178.000001241C94E000.00000004.00000001.00020000.00000000.sdmp, Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org/about/desktop-privacy-notice/
        Source: Audacity.exe, 00000010.00000002.537474178.000001241C94E000.00000004.00000001.00020000.00000000.sdmpString found in binary or memory: https://www.audacityteam.org/about/desktop-privacy-notice/iant;Z/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org/about/desktop-privacy-notice/our
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org/download/?(argtype
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.audacityteam.org/download/source
        Source: Audacity.exe, 00000010.00000002.537474178.000001241C94E000.00000004.00000001.00020000.00000000.sdmp, Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org/realtime-video
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org/realtime-videoWatch
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.org/wiki/index.php?title=file:
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.audacityteam.orgDon
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.cs.cmu.edu/~music/nyquist/
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.gnu.org/licenses/gpl-3.0.en.html
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.530240715.0000000000A81000.00000004.00000020.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://www.gnu.org/licenses/old-licenses/gpl-2.0.html
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.327687716.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.330943901.000000007FB80000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000000.337507251.0000000000401000.00000020.00000001.01000000.00000008.sdmpString found in binary or memory: https://www.innosetup.com/
        Source: audacity-win-3.2.0-64bit.exe, 0000000A.00000003.327687716.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.330943901.000000007FB80000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000000.337507251.0000000000401000.00000020.00000001.01000000.00000008.sdmpString found in binary or memory: https://www.remobjects.com/ps
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.surina.net/soundtouch/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://www.underbit.com/products/mad/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://wxwidgets.org/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://xiph.org/flac/
        Source: Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpString found in binary or memory: https://xiph.org/vorbis/
        Source: unknownDNS traffic detected: queries for: updates.audacityteam.org

        System Summary

        barindex
        Source: 1.3.Installation_controller.exe.3fc3a610.0.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
        Source: 1.3.Installation_controller.exe.3fc3a610.0.unpack, type: UNPACKEDPEMatched rule: Detects zgRAT Author: ditekSHen
        Source: 1.3.Installation_controller.exe.3fc3a610.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects RedLine infostealer Author: ditekSHen
        Source: 1.3.Installation_controller.exe.3fc3a610.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects zgRAT Author: ditekSHen
        Source: WsiysHggF9.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
        Source: 1.3.Installation_controller.exe.3fc3a610.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
        Source: 1.3.Installation_controller.exe.3fc3a610.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
        Source: 1.3.Installation_controller.exe.3fc3a610.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_RedLine snort2_sid = 920072-920073, author = ditekSHen, description = Detects RedLine infostealer, clamav_sig = MALWARE.Win.Trojan.RedLine-1, MALWARE.Win.Trojan.RedLine-2, snort3_sid = 920072-920073
        Source: 1.3.Installation_controller.exe.3fc3a610.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_zgRAT author = ditekSHen, description = Detects zgRAT
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00248525
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_002565B6
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025702F
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024404E
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00260146
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024E1E0
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024326D
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0026457A
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0026055E
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00253731
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_002647A9
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024E7E0
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_002427D4
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024F8A8
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_002539AC
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00260993
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_002569EB
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0026CA20
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00255BE7
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025FC4A
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024EC54
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00253CDD
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024BD53
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024DDAC
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00260DC8
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0026CECE
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00245F0C
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00270FD4
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: String function: 0025EB60 appears 31 times
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: String function: 0025E1C0 appears 52 times
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: String function: 0025E0E4 appears 35 times
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00247165: __EH_prolog,CreateFileW,CloseHandle,CreateDirectoryW,CreateFileW,DeviceIoControl,CloseHandle,GetLastError,RemoveDirectoryW,DeleteFileW,
        Source: audacity-win-3.2.0-64bit.tmp.10.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
        Source: is-NL931.tmp.11.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
        Source: WsiysHggF9.exe, 00000000.00000003.259542463.00000000086D6000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: OriginalFilenamePilferages.exe4 vs WsiysHggF9.exe
        Source: C:\Users\user\Desktop\WsiysHggF9.exeSection loaded: <pi-ms-win-core-synch-l1-2-0.dll
        Source: C:\Users\user\Desktop\WsiysHggF9.exeSection loaded: <pi-ms-win-core-fibers-l1-1-1.dll
        Source: C:\Users\user\Desktop\WsiysHggF9.exeSection loaded: <pi-ms-win-core-synch-l1-2-0.dll
        Source: C:\Users\user\Desktop\WsiysHggF9.exeSection loaded: <pi-ms-win-core-fibers-l1-1-1.dll
        Source: C:\Users\user\Desktop\WsiysHggF9.exeSection loaded: <pi-ms-win-core-localization-l1-2-1.dll
        Source: C:\Users\user\Desktop\WsiysHggF9.exeSection loaded: dxgidebug.dll
        Source: C:\ProgramData\Installation_controller.exeSection loaded: mscoree.dll
        Source: C:\ProgramData\Installation_controller.exeSection loaded: msvcr120_clr0400.dll
        Source: C:\ProgramData\Installation_controller.exeSection loaded: wldp.dll
        Source: C:\ProgramData\Installation_controller.exeSection loaded: cryptsp.dll
        Source: C:\ProgramData\Installation_controller.exeSection loaded: dwrite.dll
        Source: C:\ProgramData\Installation_controller.exeSection loaded: msvcp120_clr0400.dll
        Source: WsiysHggF9.exeReversingLabs: Detection: 51%
        Source: C:\Users\user\Desktop\WsiysHggF9.exeFile read: C:\Users\user\Desktop\WsiysHggF9.exeJump to behavior
        Source: WsiysHggF9.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
        Source: C:\Users\user\Desktop\WsiysHggF9.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
        Source: unknownProcess created: C:\Users\user\Desktop\WsiysHggF9.exe C:\Users\user\Desktop\WsiysHggF9.exe
        Source: C:\Users\user\Desktop\WsiysHggF9.exeProcess created: C:\ProgramData\Installation_controller.exe "C:\ProgramData\Installation_controller.exe"
        Source: C:\Users\user\Desktop\WsiysHggF9.exeProcess created: C:\ProgramData\audacity-win-3.2.0-64bit.exe "C:\ProgramData\audacity-win-3.2.0-64bit.exe"
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp" /SL5="$5040E,13178964,955904,C:\ProgramData\audacity-win-3.2.0-64bit.exe"
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-GK43T.tmp\_isetup\_setup64.tmp helper 105 0x420
        Source: C:\Users\user\AppData\Local\Temp\is-GK43T.tmp\_isetup\_setup64.tmpProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess created: C:\Program Files\Audacity\Audacity.exe C:\Program Files\Audacity\audacity.exe
        Source: C:\Users\user\Desktop\WsiysHggF9.exeProcess created: C:\ProgramData\Installation_controller.exe "C:\ProgramData\Installation_controller.exe"
        Source: C:\Users\user\Desktop\WsiysHggF9.exeProcess created: C:\ProgramData\audacity-win-3.2.0-64bit.exe "C:\ProgramData\audacity-win-3.2.0-64bit.exe"
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp" /SL5="$5040E,13178964,955904,C:\ProgramData\audacity-win-3.2.0-64bit.exe"
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-GK43T.tmp\_isetup\_setup64.tmp helper 105 0x420
        Source: C:\Users\user\Desktop\WsiysHggF9.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{00BB2765-6A77-11D0-A535-00C04FD7D062}\InProcServer32
        Source: Audacity.lnk.11.drLNK file: ..\..\..\..\..\Program Files\Audacity\Audacity.exe
        Source: Audacity.lnk0.11.drLNK file: ..\..\..\Program Files\Audacity\Audacity.exe
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Users\user\AppData\Local\ProgramsJump to behavior
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeFile created: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmpJump to behavior
        Source: classification engineClassification label: mal50.troj.evad.winEXE@11/410@1/0
        Source: C:\Users\user\Desktop\WsiysHggF9.exeFile read: C:\Windows\win.iniJump to behavior
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT blockid FROM sampleblocks;
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT summary64k FROM sampleblocks WHERE blockid = ?1;
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT ROWID FROM main.project WHERE id = 1;
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: UPDATE %Q.sqlite_master SET tbl_name = %Q, name = CASE WHEN type='table' THEN %Q WHEN name LIKE 'sqliteX_autoindex%%' ESCAPE 'X' AND type='index' THEN 'sqlite_autoindex_' || %Q || substr(name,%d+18) ELSE name END WHERE tbl_name=%Q COLLATE nocase AND (type='table' OR type='index' OR type='trigger');
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT ROWID FROM main.autosave WHERE id = 1;
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT samples FROM sampleblocks WHERE blockid = ?1;
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT COUNT(1) FROM main.project;
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT Count(*) FROM project;
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT Count(*) FROM sqlite_master WHERE type='table';
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT sampleformat, summin, summax, sumrms, length(samples) FROM sampleblocks WHERE blockid = ?1;
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: INSERT INTO sampleblocks (sampleformat, summin, summax, sumrms, summary256, summary64k, samples) VALUES(?1,?2,?3,?4,?5,?6,?7);
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: INSERT INTO %s.%s(id, dict, doc) VALUES(1, ?1, ?2) ON CONFLICT(id) DO UPDATE SET dict = ?1, doc = ?2;
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT ROWID FROM %s.%s WHERE id = 1;
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: INSERT INTO %Q.sqlite_master VALUES('index',%Q,%Q,#%d,%Q);
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT Count(*) FROM sampleblocks;
        Source: Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: INSERT INTO outbound.sampleblocks SELECT * FROM main.sampleblocks WHERE blockid = ?;
        Source: Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT summary256 FROM sampleblocks WHERE blockid = ?1;
        Source: Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: SELECT 1 FROM project LIMIT 1;
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00246E5E GetLastError,FormatMessageW,
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales
        Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:3792:120:WilError_01
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00259D9A FindResourceW,SizeofResource,LoadResource,LockResource,GlobalAlloc,GlobalLock,GdipCreateHBITMAPFromBitmap,GlobalUnlock,GlobalFree,
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\AudacityJump to behavior
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCommand line argument: q(
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCommand line argument: sfxname
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCommand line argument: sfxstime
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCommand line argument: STARTDLG
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCommand line argument: pZ)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile written: C:\Program Files\Audacity\FirstTime.iniJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganization
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwner
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpWindow found: window name: TSelectLanguageForm
        Source: C:\ProgramData\Installation_controller.exeAutomated click: OK
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: OK
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Install
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Next
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpAutomated click: Next
        Source: C:\Program Files\Audacity\Audacity.exeAutomated click: OK
        Source: C:\Program Files\Audacity\Audacity.exeAutomated click: OK
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile opened: C:\Windows\SysWOW64\MSFTEDIT.DLL
        Source: Window RecorderWindow detected: More than 3 window changes detected
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Audacity_is1Jump to behavior
        Source: WsiysHggF9.exeStatic file information: File size 21526435 > 1048576
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\AudacityJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\unins000.datJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NL931.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-9T84T.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-0UADG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-P90KL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NTE5N.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-9JHT8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-2SCU5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-CV5R1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7U34J.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7F1IJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-EPTFT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-IU3MP.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NKFUD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5OMUN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5LJ3G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-JO5BM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-SO45U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-VGNVB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-E63DL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7BF1G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-MVD1T.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-J5UM8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-OF8N5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-DBS3U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7HBD3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-EE795.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-6S7SN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-V5T2O.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-9K9M7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-UFU1R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-DEMF3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-JALHN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-19I02.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-GCDE1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-1J0J3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-HKQ8J.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-U641C.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-KRBVG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-R9F1C.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-VMF33.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-NOB4R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-37ABV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-HKD6O.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-L050V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-GAK9A.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-UR1D7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-3RF3V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-EGO60.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-KJ41F.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-AG00V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-8JNDO.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-0UDPU.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-L0CK2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-TDP90.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-4STCS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-H8I8G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-UJ3RS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-LAIB1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-K3IU2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-32N1E.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-0KP7K.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-8SGGQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-IOAI2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-K8GOH.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-KRBQ3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-6C785.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5BTDL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-5AL5G.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\is-7A0A0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\LanguagesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\afJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\af\is-HO62N.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\arJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ar\is-T0H9J.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\beJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\be\is-M4P44.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bgJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bg\is-3UN24.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bnJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bn\is-TP6MB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bsJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\bs\is-2VUIJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\caJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ca\is-6CEK5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ca_ES@valenciaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ca_ES@valencia\is-MT216.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\coJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\co\is-3NQSM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\csJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\cs\is-T6M9E.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\cyJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\cy\is-H92PA.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\daJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\da\is-L5QPV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\deJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\de\is-52QJJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\elJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\el\is-4K82R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\esJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\es\is-44RRB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\euJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\eu\is-BBOJ7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\eu_ESJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\eu_ES\is-AMHSN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\faJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fa\is-FG87I.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fiJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fi\is-N6N61.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\frJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\fr\is-NL67K.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\gaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ga\is-T5ETS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\glJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\gl\is-OKLKC.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\heJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\he\is-O5794.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hiJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hi\is-SQO61.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hrJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hr\is-PHG0Q.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\huJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hu\is-LCVQ1.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hyJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\hy\is-U2HOB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\idJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\id\is-3J2H4.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\itJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\it\is-E6HJ8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\jaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ja\is-JQCT8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\kaJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ka\is-61DBE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\kmJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\km\is-7REVL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\koJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ko\is-J5S6V.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ltJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\lt\is-2CVMQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mkJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mk\is-02VU6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mrJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\mr\is-NDISD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\myJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\my\is-PIIHM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nbJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nb\is-B1TJE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nlJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\nl\is-RTSGB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ocJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\oc\is-FI563.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\plJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pl\is-LEVD6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_BRJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_BR\is-IMKJS.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_PTJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\pt_PT\is-CU15K.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\roJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ro\is-F0KFG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ruJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ru\is-DR3N6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\skJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sk\is-N11CT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\slJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sl\is-4TL5P.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RSJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RS\is-PRSVB.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RS@latinJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sr_RS@latin\is-644HF.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\svJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\sv\is-BSL79.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\taJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ta\is-D76SJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\tgJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\tg\is-KRUGD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\trJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\tr\is-SKP1O.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\ukJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\uk\is-1SRVN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\viJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\vi\is-DG9PQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_CNJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_CN\is-5KIHE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_TWJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Languages\zh_TW\is-1MOHQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\NyquistJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-7K270.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-NTKH4.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-D9254.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-IL8FC.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-UVR1R.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-PVUQC.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-QSS2A.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-CGAC7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-8A690.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-PPVH8.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-RHAJM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-HH9U2.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-CFM98.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-EVALG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-L09O0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-5GAUM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-NQM3B.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-ESFAT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-13T21.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-BQNBQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-V3FC0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-BNLP7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-6R5OG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-RAD77.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-G5GC0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-DQTC5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-MROM6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-2UCMK.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-NPI02.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\is-MMQJF.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwavesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-P0K9Q.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-3463Q.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-E4TOU.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-5EL2U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-05MM5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-727SG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-3DJRE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-RT5IA.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-20JHV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-HJCIF.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-E3H07.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-C2JTA.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-O6A7U.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-P38RE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Nyquist\rawwaves\is-4EKK3.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-InsJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-TBL3M.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-ODRMT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-LRPH6.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-II6NQ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-11997.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-P00HI.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-EJHHE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-6KU03.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-LHPLL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-V3UUL.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-MD7TV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-KU5LN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-02MKN.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-SP0OV.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-NO5SG.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-SO3LD.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-BRLM5.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-BD9F7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-G1KMP.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-06UFT.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-6QFDO.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-P1C46.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-77BQK.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-853A0.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-QVTJ7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-591EJ.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-MQUPM.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-LKBSE.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\Plug-Ins\is-C5P2B.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\modulesJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\modules\is-JOTP7.tmpJump to behavior
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDirectory created: C:\Program Files\Audacity\unins000.msgJump to behavior
        Source: WsiysHggF9.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
        Source: WsiysHggF9.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
        Source: WsiysHggF9.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
        Source: WsiysHggF9.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: WsiysHggF9.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
        Source: WsiysHggF9.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
        Source: WsiysHggF9.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
        Source: WsiysHggF9.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
        Source: Binary string: D:\Projects\WinRAR\sfx\build\sfxrar32\Release\sfxrar.pdb source: WsiysHggF9.exe, 00000000.00000003.245658936.00000000052DC000.00000004.00000800.00020000.00000000.sdmp, WsiysHggF9.exe, 00000000.00000002.303976798.0000000000272000.00000002.00000001.01000000.00000003.sdmp, WsiysHggF9.exe, 00000000.00000003.244701687.00000000052B8000.00000004.00000800.00020000.00000000.sdmp, WsiysHggF9.exe, 00000000.00000000.243769548.0000000000272000.00000002.00000001.01000000.00000003.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\mpg123\1.29.3\_\_\build\9e1553e6621f02c61665c153436b2dfb785b6498\bin\mpg123.pdb00 source: Audacity.exe, 00000010.00000002.583274055.00007FFCFF249000.00000002.00000001.01000000.00000018.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC\RelWithDebInfo\FLAC.pdb11 source: Audacity.exe, 00000010.00000002.580349736.00007FFCFF0A0000.00000002.00000001.01000000.00000013.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\ogg\1.3.4\_\_\build\ad5261bf6074807e7189c351b0f79b113bf2f6c0\build\RelWithDebInfo\ogg.pdb source: Audacity.exe, 00000010.00000002.576735272.00007FFCFEEB9000.00000002.00000001.01000000.00000010.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC++\RelWithDebInfo\FLAC++.pdb!! source: Audacity.exe, 00000010.00000002.583539424.00007FFCFF270000.00000002.00000001.01000000.00000019.sdmp
        Source: Binary string: _.pdb source: Installation_controller.exe, 00000001.00000003.378455694.000000003FC3A000.00000004.00000020.00020000.00000000.sdmp
        Source: Binary string: D:\a\audacity\audacity\.build.x64\bin\RelWithDebInfo\modules\mod-script-pipe.pdb source: audacity-win-3.2.0-64bit.tmp, 0000000B.00000002.516640303.0000000000198000.00000004.00000010.00020000.00000000.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\vorbis\1.3.7\_\_\build\3b26581a680ab99eb0ef725aa935a0289708df91\build\lib\RelWithDebInfo\vorbis.pdb** source: Audacity.exe, 00000010.00000002.578547685.00007FFCFEFAB000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC\RelWithDebInfo\FLAC.pdb source: Audacity.exe, 00000010.00000002.580349736.00007FFCFF0A0000.00000002.00000001.01000000.00000013.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\flac\1.3.3\_\_\build\4fab43cea7baf5ca3c7db544507a05b38a68f73e\build\src\libFLAC++\RelWithDebInfo\FLAC++.pdb source: Audacity.exe, 00000010.00000002.583539424.00007FFCFF270000.00000002.00000001.01000000.00000019.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\vorbis\1.3.7\_\_\build\3b26581a680ab99eb0ef725aa935a0289708df91\build\lib\RelWithDebInfo\vorbis.pdb source: Audacity.exe, 00000010.00000002.578547685.00007FFCFEFAB000.00000002.00000001.01000000.00000011.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\vorbis\1.3.7\_\_\build\3b26581a680ab99eb0ef725aa935a0289708df91\build\lib\RelWithDebInfo\vorbisenc.pdb source: Audacity.exe, 00000010.00000002.579864349.00007FFCFF065000.00000002.00000001.01000000.00000012.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\mpg123\1.29.3\_\_\build\9e1553e6621f02c61665c153436b2dfb785b6498\bin\mpg123.pdb source: Audacity.exe, 00000010.00000002.583274055.00007FFCFF249000.00000002.00000001.01000000.00000018.sdmp
        Source: Binary string: D:\a\audacity\audacity\.conan\data\wxwidgets\3.1.3.3-audacity\_\_\build\f80b0ba6cc698a650654b5966db925c8f7197d7d\build_subfolder\bin\wxbase313u_vc_x64_custom.pdb source: Audacity.exe, 00000010.00000002.593483340.00007FFCFF758000.00000002.00000001.01000000.00000022.sdmp
        Source: Binary string: C:\devel\projects\audacity\audacity\.conan\data\expat\2.2.9\audacity\stable\build\ad5261bf6074807e7189c351b0f79b113bf2f6c0\build_subfolder\bin\libexpat.pdb source: Audacity.exe, 00000010.00000002.585991860.00007FFCFF3A4000.00000002.00000001.01000000.0000001D.sdmp
        Source: WsiysHggF9.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
        Source: WsiysHggF9.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
        Source: WsiysHggF9.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
        Source: WsiysHggF9.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
        Source: WsiysHggF9.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata

        Data Obfuscation

        barindex
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp" /SL5="$5040E,13178964,955904,C:\ProgramData\audacity-win-3.2.0-64bit.exe"
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeProcess created: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp "C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp" /SL5="$5040E,13178964,955904,C:\ProgramData\audacity-win-3.2.0-64bit.exe"
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025E0E4 push eax; ret
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025EBA6 push ecx; ret
        Source: WsiysHggF9.exeStatic PE information: section name: .didat
        Source: audacity-win-3.2.0-64bit.exe.0.drStatic PE information: section name: .didata
        Source: Installation_controller.exe.0.drStatic PE information: section name: .alcjdaw
        Source: Installation_controller.exe.0.drStatic PE information: section name: .alcjdaw
        Source: audacity-win-3.2.0-64bit.tmp.10.drStatic PE information: section name: .didata
        Source: is-CV5R1.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-7U34J.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-7F1IJ.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-EPTFT.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-IU3MP.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-NKFUD.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-5OMUN.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-5LJ3G.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-NL931.tmp.11.drStatic PE information: section name: .didata
        Source: is-NTE5N.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-NTE5N.tmp.11.drStatic PE information: section name: _RDATA
        Source: is-9JHT8.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-JO5BM.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-SO45U.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-VGNVB.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-E63DL.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-7BF1G.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-MVD1T.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-J5UM8.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-OF8N5.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-DBS3U.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-7HBD3.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-EE795.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-6S7SN.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-V5T2O.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-9K9M7.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-UFU1R.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-DEMF3.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-JALHN.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-19I02.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-GCDE1.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-1J0J3.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-HKQ8J.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-U641C.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-KRBVG.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-R9F1C.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-VMF33.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-NOB4R.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-37ABV.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-HKD6O.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-L050V.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-GAK9A.tmp.11.drStatic PE information: section name: .rodata
        Source: is-GAK9A.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-8JNDO.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-0UDPU.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-L0CK2.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-TDP90.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-4STCS.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-H8I8G.tmp.11.drStatic PE information: section name: _RDATA
        Source: is-LAIB1.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-K3IU2.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-32N1E.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-0KP7K.tmp.11.drStatic PE information: section name: asmcode
        Source: is-0KP7K.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-8SGGQ.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-IOAI2.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-K8GOH.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-KRBQ3.tmp.11.drStatic PE information: section name: minATL
        Source: is-KRBQ3.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-6C785.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-5BTDL.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-5AL5G.tmp.11.drStatic PE information: section name: .00cfg
        Source: is-JOTP7.tmp.11.drStatic PE information: section name: .00cfg
        Source: initial sampleStatic PE information: section where entry point is pointing to: .alcjdaw
        Source: C:\Users\user\Desktop\WsiysHggF9.exeFile created: C:\ProgramData\__tmp_rar_sfx_access_check_6416453Jump to behavior
        Source: is-2SCU5.tmp.11.drStatic PE information: 0x6E8BFE97 [Mon Oct 9 01:40:39 2028 UTC]
        Source: C:\Users\user\Desktop\WsiysHggF9.exeFile created: C:\ProgramData\audacity-win-3.2.0-64bit.exe
        Source: C:\Users\user\Desktop\WsiysHggF9.exeFile created: C:\ProgramData\Installation_controller.exe
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-7F1IJ.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\msvcp140_1.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\FLAC.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-sentry-reporting.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-KJ41F.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-UJ3RS.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-TDP90.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-theme-resources.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\zlib1.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\sndfile.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-HKD6O.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-transactions.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-EGO60.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-UR1D7.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\ogg.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-screen-geometry.dll (copy)
        Source: C:\Users\user\Desktop\WsiysHggF9.exeFile created: C:\ProgramData\audacity-win-3.2.0-64bit.exe
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-37ABV.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-5LJ3G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\portaudio_x64.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-preferences.dll (copy)
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeFile created: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\msvcp140.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-K8GOH.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-NOB4R.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-0KP7K.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-audio-graph.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-exceptions.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-basic-ui.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-files.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\libexpat.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-5BTDL.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-SO45U.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\wavpackdll.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-IU3MP.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\modules\is-JOTP7.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-theme.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\vorbisenc.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\msvcp140_codecvt_ids.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-cloud-audiocom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Users\user\AppData\Local\Temp\is-GK43T.tmp\_isetup\_setup64.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-2SCU5.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-graphics.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\libcurl.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-GAK9A.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-EPTFT.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\crashreporter.exe (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-audio-devices.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-project-rate.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-sample-track.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-L050V.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-module-manager.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-L0CK2.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-V5T2O.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\portmidi.dll (copy)
        Source: C:\Users\user\Desktop\WsiysHggF9.exeFile created: C:\ProgramData\Installation_controller.exe
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-9K9M7.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-DEMF3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-UFU1R.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-5AL5G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\opus.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\vcruntime140.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-E63DL.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-JALHN.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-project.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\modules\mod-script-pipe.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-DBS3U.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-uuid.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-J5UM8.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-ffmpeg-support.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\wxmsw313u_aui_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-6C785.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-AG00V.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-9JHT8.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-K3IU2.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-LAIB1.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-string-utils.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\Audacity.exe (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-4STCS.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-R9F1C.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-registries.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-VGNVB.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-OF8N5.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\vcruntime140_1.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\wxmsw313u_html_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\wxmsw313u_qa_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-NTE5N.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-EE795.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\wxbase313u_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\mpg123.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-xml.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\wxmsw313u_core_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-VMF33.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-JO5BM.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-6S7SN.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\vorbisfile.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-track.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-H8I8G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-8SGGQ.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\vorbis.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-ipc.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-KRBVG.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-U641C.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-MVD1T.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-8JNDO.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-utility.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\FLAC++.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-CV5R1.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\msvcp140_atomic_wait.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-7U34J.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\mod-script-pipe.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-7HBD3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-math.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-url-schemes.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-5OMUN.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-3RF3V.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-IOAI2.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-components.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-KRBQ3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-network-manager.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\wxbase313u_xml_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-NKFUD.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-NL931.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-19I02.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-32N1E.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-cloud-upload.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-project-history.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\msvcp140_2.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-7BF1G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\lib-strings.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-1J0J3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-HKQ8J.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-0UDPU.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\is-GCDE1.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\unins000.exe (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\Program Files\Audacity\concrt140.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpFile created: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnkJump to behavior

        Hooking and other Techniques for Hiding and Protection

        barindex
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FA20005 value: E9 CB 98 37 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D998D0 value: E9 3A 67 C8 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FA30005 value: E9 4B 9A 36 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99A50 value: E9 BA 65 C9 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FA40005 value: E9 2B 98 35 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99830 value: E9 DA 67 CA C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FA70005 value: E9 3B 95 32 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99540 value: E9 CA 6A CD C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FB60005 value: E9 EB 95 23 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D995F0 value: E9 1A 6A DC C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FB70005 value: E9 8B 99 22 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99990 value: E9 7A 66 DD C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FB80005 value: E9 6B 97 21 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99770 value: E9 9A 68 DE C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FB90005 value: E9 4B 98 20 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99850 value: E9 BA 67 DF C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FBA0005 value: E9 9B 99 1F 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D999A0 value: E9 6A 66 E0 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FBB0005 value: E9 0B 9A 1E 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99A10 value: E9 FA 65 E1 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FBC0005 value: E9 7B 97 1D 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99780 value: E9 8A 68 E2 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FBD0005 value: E9 9B 97 1C 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D997A0 value: E9 6A 68 E3 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FCE0005 value: E9 2B 97 0B 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99730 value: E9 DA 68 F4 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FCF0005 value: E9 FB 99 0A 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D99A00 value: E9 0A 66 F5 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FD00005 value: E9 CB 95 09 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D995D0 value: E9 3A 6A F6 C7
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 3FD10005 value: E9 DB 95 08 38
        Source: C:\ProgramData\Installation_controller.exeMemory written: PID: 6064 base: 77D995E0 value: E9 2A 6A F7 C7
        Source: C:\Users\user\Desktop\WsiysHggF9.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\Installation_controller.exeProcess information set: NOOPENFILEERRORBOX
        Source: C:\ProgramData\audacity-win-3.2.0-64bit.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOX

        Malware Analysis System Evasion

        barindex
        Source: Installation_controller.exe, 00000001.00000002.517305085.0000000000426000.00000020.00000001.01000000.00000005.sdmpBinary or memory string: EFDXSBIEDLL.DLL
        Source: Installation_controller.exe, 00000001.00000002.517305085.0000000000426000.00000020.00000001.01000000.00000005.sdmpBinary or memory string: EFDXSBIEDLL.DLL!H
        Source: C:\ProgramData\Installation_controller.exeRDTSC instruction interceptor: First address: 000000003F26A70C second address: 000000003F2B4A41 instructions: 0x00000000 rdtsc 0x00000002 seto dl 0x00000005 mov edx, dword ptr [esp+ecx] 0x00000008 sar eax, 6Fh 0x0000000b bswap eax 0x0000000d cmp eax, ebp 0x0000000f sub edi, 00000004h 0x00000015 bsf ax, bx 0x00000019 mov dword ptr [edi], edx 0x0000001b mov eax, dword ptr [esi] 0x0000001d jmp 00007F385D0EF774h 0x00000022 add esi, 00000004h 0x00000028 test ecx, ebx 0x0000002a xor eax, ebx 0x0000002c test sp, dx 0x0000002f clc 0x00000030 add eax, 42893A75h 0x00000035 clc 0x00000036 cmc 0x00000037 rol eax, 02h 0x0000003a jmp 00007F385CFFDF2Fh 0x0000003f dec eax 0x00000040 test bh, 0000001Ch 0x00000043 clc 0x00000044 cmp esp, ebp 0x00000046 not eax 0x00000048 stc 0x00000049 cmp ax, 00007F56h 0x0000004d jmp 00007F385D0AFAA3h 0x00000052 xor ebx, eax 0x00000054 test ah, dl 0x00000056 cmp esi, 13D16209h 0x0000005c jmp 00007F385D782616h 0x00000061 add ebp, eax 0x00000063 jmp 00007F385C960F17h 0x00000068 jmp 00007F385D1D259Ah 0x0000006d lea edx, dword ptr [esp+60h] 0x00000071 cmp edi, edx 0x00000073 jmp 00007F385D059CB4h 0x00000078 ja 00007F385D6558BFh 0x0000007e jmp ebp 0x00000080 movzx ecx, byte ptr [esi] 0x00000083 shrd eax, ecx, 0000004Ah 0x00000087 add dh, bh 0x00000089 lea esi, dword ptr [esi+00000001h] 0x0000008f rcl dh, FFFFFFADh 0x00000092 inc edx 0x00000093 xor cl, bl 0x00000095 rdtsc
        Source: C:\ProgramData\Installation_controller.exeRDTSC instruction interceptor: First address: 000000003F3C0CC8 second address: 000000003F3C0CDC instructions: 0x00000000 rdtsc 0x00000002 pop edi 0x00000003 xor esi, edi 0x00000005 mov ah, bl 0x00000007 pop ebp 0x00000008 adc si, 7F3Fh 0x0000000d btc dx, si 0x00000011 pop esi 0x00000012 cbw 0x00000014 rdtsc
        Source: C:\ProgramData\Installation_controller.exeRDTSC instruction interceptor: First address: 00000000006AEEF5 second address: 000000003EF47073 instructions: 0x00000000 rdtsc 0x00000002 seto dl 0x00000005 mov edx, dword ptr [esp+ecx] 0x00000008 sar eax, 6Fh 0x0000000b bswap eax 0x0000000d cmp eax, ebp 0x0000000f sub edi, 00000004h 0x00000015 bsf ax, bx 0x00000019 mov dword ptr [edi], edx 0x0000001b mov eax, dword ptr [esi] 0x0000001d jmp 00007F385CE63102h 0x00000022 add esi, 00000004h 0x00000028 test ecx, ebx 0x0000002a xor eax, ebx 0x0000002c test sp, dx 0x0000002f clc 0x00000030 add eax, 42893A75h 0x00000035 clc 0x00000036 cmc 0x00000037 rol eax, 02h 0x0000003a jmp 00007F385D1434E5h 0x0000003f dec eax 0x00000040 test bh, 0000001Ch 0x00000043 clc 0x00000044 cmp esp, ebp 0x00000046 not eax 0x00000048 stc 0x00000049 cmp ax, 00007F56h 0x0000004d jmp 00007F385D0D89F5h 0x00000052 xor ebx, eax 0x00000054 test ah, dl 0x00000056 cmp esi, 13D16209h 0x0000005c jmp 00007F385D07F383h 0x00000061 add ebp, eax 0x00000063 jmp 00007F385D12C6D5h 0x00000068 jmp 00007F389B92B14Eh 0x0000006d lea edx, dword ptr [esp+60h] 0x00000071 cmp edi, edx 0x00000073 jmp 00007F381E6953ECh 0x00000078 ja 00007F385CF7D2CBh 0x0000007e jmp ebp 0x00000080 movzx ecx, byte ptr [esi] 0x00000083 shrd eax, ecx, 0000004Ah 0x00000087 add dh, bh 0x00000089 lea esi, dword ptr [esi+00000001h] 0x0000008f rcl dh, FFFFFFADh 0x00000092 inc edx 0x00000093 xor cl, bl 0x00000095 rdtsc
        Source: C:\ProgramData\Installation_controller.exeRDTSC instruction interceptor: First address: 00000000004AE5ED second address: 00000000004AE601 instructions: 0x00000000 rdtsc 0x00000002 pop edi 0x00000003 xor esi, edi 0x00000005 mov ah, bl 0x00000007 pop ebp 0x00000008 adc si, 7F3Fh 0x0000000d btc dx, si 0x00000011 pop esi 0x00000012 cbw 0x00000014 rdtsc
        Source: C:\ProgramData\Installation_controller.exeRDTSC instruction interceptor: First address: 000000003F404373 second address: 000000003F4043A5 instructions: 0x00000000 rdtsc 0x00000002 inc cx 0x00000004 rol eax, FFFFFFF0h 0x00000007 rcr ebx, FFFFFFEBh 0x0000000a inc ecx 0x0000000b pop ebp 0x0000000c pop esi 0x0000000d inc ecx 0x0000000e pop edx 0x0000000f cbw 0x00000011 inc ecx 0x00000012 pop esi 0x00000013 pop edi 0x00000014 rcl dl, cl 0x00000016 inc ecx 0x00000017 pop ecx 0x00000018 adc dh, FFFFFFF0h 0x0000001b inc cx 0x0000001d mov edx, ebp 0x0000001f and bp, 0BE3h 0x00000024 pop ebp 0x00000025 movsx edx, si 0x00000028 inc ecx 0x00000029 and ah, FFFFFFDCh 0x0000002c inc ecx 0x0000002d pop esp 0x0000002e inc ecx 0x0000002f sar ebx, FFFFFF8Eh 0x00000032 rdtsc
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-7F1IJ.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\msvcp140_1.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\FLAC.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-sentry-reporting.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-KJ41F.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-UJ3RS.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-TDP90.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-theme-resources.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\zlib1.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\sndfile.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-HKD6O.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-transactions.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-EGO60.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-UR1D7.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\ogg.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-screen-geometry.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-37ABV.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-5LJ3G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\portaudio_x64.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-preferences.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\msvcp140.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-K8GOH.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-NOB4R.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-0KP7K.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-exceptions.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-audio-graph.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-basic-ui.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-files.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\libexpat.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-5BTDL.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-SO45U.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\wavpackdll.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-IU3MP.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\modules\is-JOTP7.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-theme.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\vorbisenc.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\msvcp140_codecvt_ids.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-cloud-audiocom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-graphics.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-2SCU5.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\libcurl.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-GAK9A.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-EPTFT.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\crashreporter.exe (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-audio-devices.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-project-rate.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-sample-track.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-L050V.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-module-manager.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-L0CK2.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-V5T2O.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\portmidi.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-9K9M7.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-DEMF3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-UFU1R.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\vcruntime140.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\opus.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-5AL5G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-E63DL.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-project.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-JALHN.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\modules\mod-script-pipe.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-DBS3U.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-uuid.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-J5UM8.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-ffmpeg-support.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\wxmsw313u_aui_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-6C785.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-AG00V.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-K3IU2.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-9JHT8.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-LAIB1.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-string-utils.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-4STCS.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-R9F1C.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-registries.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-VGNVB.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-OF8N5.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\wxmsw313u_qa_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\wxmsw313u_html_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\vcruntime140_1.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-EE795.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\wxbase313u_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\mpg123.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-xml.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\wxmsw313u_core_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-VMF33.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-JO5BM.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-6S7SN.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\vorbisfile.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-track.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-H8I8G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-8SGGQ.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\vorbis.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-ipc.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-KRBVG.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-U641C.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-8JNDO.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-MVD1T.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-utility.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\FLAC++.dll (copy)Jump to dropped file
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-CV5R1.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\msvcp140_atomic_wait.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-7U34J.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\mod-script-pipe.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-7HBD3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-math.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-url-schemes.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-5OMUN.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-3RF3V.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-components.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-IOAI2.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-KRBQ3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-network-manager.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\wxbase313u_xml_vc_x64_custom.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-NKFUD.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-19I02.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-32N1E.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-cloud-upload.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-project-history.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\msvcp140_2.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-7BF1G.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\lib-strings.dll (copy)
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-1J0J3.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-HKQ8J.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-0UDPU.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\is-GCDE1.tmp
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpDropped PE file which has not been started: C:\Program Files\Audacity\concrt140.dll (copy)
        Source: C:\ProgramData\Installation_controller.exeMemory allocated: 3FED0000 memory reserve | memory write watch
        Source: C:\ProgramData\Installation_controller.exeMemory allocated: 41AC0000 memory reserve | memory write watch
        Source: C:\ProgramData\Installation_controller.exeMemory allocated: 418B0000 memory reserve | memory write watch
        Source: C:\ProgramData\Installation_controller.exeProcess information queried: ProcessInformation
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025DBC8 VirtualQuery,GetSystemInfo,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024A534 FindFirstFileW,FindFirstFileW,GetLastError,FindNextFileW,GetLastError,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025B820 SendDlgItemMessageW,EndDialog,GetDlgItem,SetFocus,SetDlgItemTextW,SendDlgItemMessageW,FindFirstFileW,FileTimeToLocalFileTime,FileTimeToSystemTime,GetTimeFormatW,GetDateFormatW,_swprintf,SetDlgItemTextW,FindClose,_swprintf,SetDlgItemTextW,SendDlgItemMessageW,FileTimeToLocalFileTime,FileTimeToSystemTime,GetTimeFormatW,GetDateFormatW,_swprintf,SetDlgItemTextW,_swprintf,SetDlgItemTextW,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0026A928 FindFirstFileExA,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeAPI call chain: ExitProcess graph end node
        Source: WsiysHggF9.exe, 00000000.00000002.309826642.0000000009211000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\f
        Source: Audacity.exe, 00000010.00000002.537474178.000001241C94E000.00000004.00000001.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll3
        Source: WsiysHggF9.exe, 00000000.00000002.309826642.0000000009211000.00000004.00000800.00020000.00000000.sdmpBinary or memory string: \??\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_002684EF IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0026B610 GetProcessHeap,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_00267363 mov eax, dword ptr fs:[00000030h]
        Source: C:\ProgramData\Installation_controller.exeMemory allocated: page read and write | page guard
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025EEB3 SetUnhandledExceptionFilter,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025F07B SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_002684EF IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025ED65 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeProcess created: C:\ProgramData\Installation_controller.exe "C:\ProgramData\Installation_controller.exe"
        Source: C:\Users\user\Desktop\WsiysHggF9.exeProcess created: C:\ProgramData\audacity-win-3.2.0-64bit.exe "C:\ProgramData\audacity-win-3.2.0-64bit.exe"
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-GK43T.tmp\_isetup\_setup64.tmp helper 105 0x420
        Source: Audacity.exe, 00000010.00000002.532462677.000001241A7A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: XProgram Manager
        Source: Audacity.exe, 00000010.00000002.532462677.000001241A7A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Shell_TrayWnd
        Source: Audacity.exe, 00000010.00000002.532462677.000001241A7A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progman
        Source: Audacity.exe, 00000010.00000002.532462677.000001241A7A0000.00000002.00000001.00040000.00000000.sdmpBinary or memory string: Progmanlock
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel\v4.0_4.0.0.0__b77a5c561934e089\System.ServiceModel.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.IdentityModel\v4.0_4.0.0.0__b77a5c561934e089\System.IdentityModel.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\SMDiagnostics\v4.0_4.0.0.0__b77a5c561934e089\SMDiagnostics.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.ServiceModel.Internals\v4.0_4.0.0.0__31bf3856ad364e35\System.ServiceModel.Internals.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
        Source: C:\ProgramData\Installation_controller.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_32\System.Transactions\v4.0_4.0.0.0__b77a5c561934e089\System.Transactions.dll VolumeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmpQueries volume information: C:\ VolumeInformation
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: GetLocaleInfoW,GetNumberFormatW,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025EBBB cpuid
        Source: C:\ProgramData\Installation_controller.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuid
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0025D42A GetCommandLineW,OpenFileMappingW,MapViewOfFile,UnmapViewOfFile,CloseHandle,GetModuleFileNameW,SetEnvironmentVariableW,GetLocalTime,_swprintf,SetEnvironmentVariableW,GetModuleHandleW,LoadIconW,DialogBoxParamW,Sleep,DeleteObject,DeleteObject,CloseHandle,
        Source: C:\Users\user\Desktop\WsiysHggF9.exeCode function: 0_2_0024AC35 GetVersionExW,

        Stealing of Sensitive Information

        barindex
        Source: Yara matchFile source: dump.pcap, type: PCAP

        Remote Access Functionality

        barindex
        Source: Yara matchFile source: dump.pcap, type: PCAP
        Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
        Valid Accounts12
        Command and Scripting Interpreter
        1
        Windows Service
        1
        Windows Service
        3
        Masquerading
        1
        Credential API Hooking
        1
        System Time Discovery
        Remote Services1
        Credential API Hooking
        Exfiltration Over Other Network Medium1
        Encrypted Channel
        Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
        Default AccountsScheduled Task/Job1
        Registry Run Keys / Startup Folder
        12
        Process Injection
        1
        Virtualization/Sandbox Evasion
        LSASS Memory221
        Security Software Discovery
        Remote Desktop Protocol1
        Archive Collected Data
        Exfiltration Over Bluetooth1
        Non-Application Layer Protocol
        Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
        Domain AccountsAt (Linux)1
        DLL Side-Loading
        1
        Registry Run Keys / Startup Folder
        1
        Disable or Modify Tools
        Security Account Manager1
        Virtualization/Sandbox Evasion
        SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
        Application Layer Protocol
        Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
        Local AccountsAt (Windows)Logon Script (Mac)1
        DLL Side-Loading
        12
        Process Injection
        NTDS2
        Process Discovery
        Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
        Cloud AccountsCronNetwork Logon ScriptNetwork Logon Script11
        Deobfuscate/Decode Files or Information
        LSA Secrets2
        System Owner/User Discovery
        SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
        Replication Through Removable MediaLaunchdRc.commonRc.common2
        Obfuscated Files or Information
        Cached Domain Credentials3
        File and Directory Discovery
        VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
        External Remote ServicesScheduled TaskStartup ItemsStartup Items1
        Software Packing
        DCSync135
        System Information Discovery
        Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
        Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job1
        Timestomp
        Proc FilesystemNetwork Service ScanningShared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
        Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)1
        DLL Side-Loading
        /etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
        Hide Legend

        Legend:

        • Process
        • Signature
        • Created File
        • DNS/IP Info
        • Is Dropped
        • Is Windows Process
        • Number of created Registry Values
        • Number of created Files
        • Visual Basic
        • Delphi
        • Java
        • .Net C# or VB.NET
        • C, C++ or other language
        • Is malicious
        • Internet
        behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 715159 Sample: WsiysHggF9.exe Startdate: 03/10/2022 Architecture: WINDOWS Score: 50 42 updates.audacityteam.org 2->42 44 Snort IDS alert for network traffic 2->44 46 Malicious sample detected (through community Yara rule) 2->46 48 Multi AV Scanner detection for submitted file 2->48 50 3 other signatures 2->50 10 WsiysHggF9.exe 5 2->10         started        signatures3 process4 file5 36 C:\ProgramData\audacity-win-3.2.0-64bit.exe, PE32 10->36 dropped 38 C:\ProgramData\Installation_controller.exe, PE32 10->38 dropped 13 audacity-win-3.2.0-64bit.exe 2 10->13         started        17 Installation_controller.exe 2 10->17         started        process6 file7 40 C:\Users\...\audacity-win-3.2.0-64bit.tmp, PE32 13->40 dropped 52 Obfuscated command line found 13->52 19 audacity-win-3.2.0-64bit.tmp 35 281 13->19         started        54 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 17->54 56 Tries to detect virtualization through RDTSC time measurements 17->56 signatures8 process9 file10 28 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 19->28 dropped 30 C:\Program Files\Audacity\zlib1.dll (copy), PE32+ 19->30 dropped 32 C:\...\wxmsw313u_qa_vc_x64_custom.dll (copy), PE32+ 19->32 dropped 34 130 other files (none is malicious) 19->34 dropped 22 _setup64.tmp 1 19->22         started        24 Audacity.exe 19->24         started        process11 process12 26 conhost.exe 22->26         started       

        This section contains all screenshots as thumbnails, including those not shown in the slideshow.


        windows-stand
        SourceDetectionScannerLabelLink
        WsiysHggF9.exe51%ReversingLabsWin32.Spyware.RedLine
        WsiysHggF9.exe0%MetadefenderBrowse
        SourceDetectionScannerLabelLink
        C:\Program Files\Audacity\Audacity.exe (copy)0%ReversingLabs
        C:\Program Files\Audacity\FLAC++.dll (copy)0%ReversingLabs
        C:\Program Files\Audacity\FLAC.dll (copy)0%ReversingLabs
        C:\Program Files\Audacity\concrt140.dll (copy)0%ReversingLabs
        C:\Program Files\Audacity\concrt140.dll (copy)0%MetadefenderBrowse
        C:\Program Files\Audacity\crashreporter.exe (copy)0%ReversingLabs
        C:\Program Files\Audacity\is-0KP7K.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-0UDPU.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-19I02.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-1J0J3.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-2SCU5.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-2SCU5.tmp0%MetadefenderBrowse
        C:\Program Files\Audacity\is-32N1E.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-37ABV.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-3RF3V.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-3RF3V.tmp0%MetadefenderBrowse
        C:\Program Files\Audacity\is-4STCS.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-5AL5G.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-5BTDL.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-5LJ3G.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-5OMUN.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-6C785.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-6S7SN.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-7BF1G.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-7F1IJ.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-7HBD3.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-7U34J.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-8JNDO.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-8SGGQ.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-9JHT8.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-9K9M7.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-AG00V.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-AG00V.tmp0%MetadefenderBrowse
        C:\Program Files\Audacity\is-CV5R1.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-DBS3U.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-DEMF3.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-E63DL.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-EE795.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-EGO60.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-EGO60.tmp0%MetadefenderBrowse
        C:\Program Files\Audacity\is-EPTFT.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-GAK9A.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-GCDE1.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-H8I8G.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-H8I8G.tmp0%MetadefenderBrowse
        C:\Program Files\Audacity\is-HKD6O.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-HKQ8J.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-IOAI2.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-IU3MP.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-J5UM8.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-JALHN.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-JO5BM.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-K3IU2.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-K8GOH.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-KJ41F.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-KJ41F.tmp0%MetadefenderBrowse
        C:\Program Files\Audacity\is-KRBQ3.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-KRBVG.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-L050V.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-L0CK2.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-LAIB1.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-MVD1T.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-NKFUD.tmp0%ReversingLabs
        C:\Program Files\Audacity\is-NL931.tmp2%ReversingLabs
        C:\Program Files\Audacity\is-NOB4R.tmp0%ReversingLabs
        No Antivirus matches
        No Antivirus matches
        SourceDetectionScannerLabelLink
        http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl00%URL Reputationsafe
        https://www.remobjects.com/ps0%URL Reputationsafe
        https://www.innosetup.com/0%URL Reputationsafe
        http://www.haysoft.org%1-k0%URL Reputationsafe
        http://ocsp.sectigo.com00%URL Reputationsafe
        http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#0%URL Reputationsafe
        http://lv2plug.in/ns/ext/presets#0%Avira URL Cloudsafe
        http://xmlns.com/foaf/0.1/name0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#noUserResize0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#requiredFeature0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/log#Note0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#X11UI0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#portProperty0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#Chunk0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#project0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/state#makePath0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/port-props#notOnGUI0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#Double0%Avira URL Cloudsafe
        https://audio.com0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#Sequence0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#Property0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#AtomPort0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#InstrumentPlugin0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#maximum0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/log#Warning0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#portMaphttp://lv2plug.in/ns/extensions/ui#portSubscribehttp://lv20%Avira URL Cloudsafe
        https://www.surina.net/soundtouch/0%Avira URL Cloudsafe
        http://xmlns.com/foaf/0.1/homepage0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#projecthttp://usefulinc.com/ns/doap#maintainerhttp://xmlns.com/foaf/0.10%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/options#optionsLV2InstanceFeaturesList::CheckOptionsD:0%Avira URL Cloudsafe
        http://lame.sf.net32bits64bits0%Avira URL Cloudsafe
        https://audio.comaudio.com%%&Unlink0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#GtkUI0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/dynmanifest#DynManifest0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#external0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#URID0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/state#mapPathhttp://lv2plug.in/ns/ext/state#makePathlilv_state_new_from_ins0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#Int0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#Qt4UI0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/parameters#sampleRate0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/buf-size#fixedBlockLength0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#String0%Avira URL Cloudsafe
        http://www.twolame.org/0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#port0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#sampleRate0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/port-props#notAutomatic0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#Long0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/buf-size#minBlockLength0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#scalePoint0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/time#speed0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#name0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/instance-access0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/port-groups#group0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/event#supportsEventlilv_port_get_valuelilv_port_get_name%s():0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/worker#schedule0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#Blankhttp://lv2plug.in/ns/ext/atom#Boolhttp://lv2plug.in/ns/ext/atom#C0%Avira URL Cloudsafe
        http://xmlns.com/foaf/0.1/0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#AudioPort0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/event#supportsEvent0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/log#log0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#noUserResizehttp://lv2plug.in/ns/extensions/ui#fixedSizehttp://lv0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#OutputPort0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/port-props#causesArtifacts0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#symbol0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#touch0%Avira URL Cloudsafe
        https://www.audacityteam.orgDon0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/port-props#rangeSteps0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#enumeration0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/time#Position0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#portMap0%Avira URL Cloudsafe
        http://lv2plug.in/ns/lv2core#prototype0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#childType0%Avira URL Cloudsafe
        http://lv2plug.in/ns/extensions/ui#Gtk3UI0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/port-props#trigger0%Avira URL Cloudsafe
        http://lv2plug.in/ns/ext/atom#childType%2XFailed0%Avira URL Cloudsafe
        NameIPActiveMaliciousAntivirus DetectionReputation
        updates.audacityteam.org
        172.67.74.133
        truefalse
          high
          NameSourceMaliciousAntivirus DetectionReputation
          http://xmlns.com/foaf/0.1/nameAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://lv2plug.in/ns/lv2core#projectAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://crl.sectigo.com/SectigoPublicCodeSigningRootR46.crl0audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpfalse
          • URL Reputation: safe
          unknown
          http://lv2plug.in/ns/ext/presets#Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://lv2plug.in/ns/ext/state#makePathAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://lv2plug.in/ns/ext/log#NoteAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
          • Avira URL Cloud: safe
          unknown
          http://lame.sourceforge.net/Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpfalse
            high
            http://lv2plug.in/ns/lv2core#portPropertyAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            http://lv2plug.in/ns/lv2core#requiredFeatureAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
            • Avira URL Cloud: safe
            unknown
            https://manual.audacityteam.org/quick_help.htmlQAudacity.exe, 00000010.00000002.544110808.000001241D08B000.00000004.00000001.00020000.00000000.sdmpfalse
              high
              https://www.cs.cmu.edu/~music/nyquist/Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpfalse
                high
                http://lv2plug.in/ns/extensions/ui#noUserResizeAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://lv2plug.in/ns/extensions/ui#X11UIAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                • Avira URL Cloud: safe
                unknown
                http://www.portmedia.sourceforge.net/portmidi/Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpfalse
                  high
                  https://www.remobjects.com/psaudacity-win-3.2.0-64bit.exe, 0000000A.00000003.327687716.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.330943901.000000007FB80000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000000.337507251.0000000000401000.00000020.00000001.01000000.00000008.sdmpfalse
                  • URL Reputation: safe
                  unknown
                  http://lv2plug.in/ns/ext/atom#ChunkAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                  • Avira URL Cloud: safe
                  unknown
                  https://wiki.audacityteam.org/wiki/EQCurvesDownloadEQBackup.xmlAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                    high
                    http://audacity.sourceforge.net/xml/xmlnsDELETEAudacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpfalse
                      high
                      http://lv2plug.in/ns/ext/atom#SequenceAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                      • Avira URL Cloud: safe
                      unknown
                      https://plugins.audacityteam.org/NoAudacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpfalse
                        high
                        https://www.innosetup.com/audacity-win-3.2.0-64bit.exe, 0000000A.00000003.327687716.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.330943901.000000007FB80000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000000.337507251.0000000000401000.00000020.00000001.01000000.00000008.sdmpfalse
                        • URL Reputation: safe
                        unknown
                        http://lv2plug.in/ns/lv2core#InstrumentPluginAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        https://audio.comAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://lv2plug.in/ns/ext/atom#DoubleAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://lv2plug.in/ns/ext/log#WarningAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://lv2plug.in/ns/extensions/ui#portMaphttp://lv2plug.in/ns/extensions/ui#portSubscribehttp://lv2Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://lv2plug.in/ns/ext/atom#AtomPortAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://lv2plug.in/ns/ext/port-props#notOnGUIAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                        • Avira URL Cloud: safe
                        unknown
                        http://forum.audacityteam.org/audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpfalse
                          high
                          http://lv2plug.in/ns/lv2core#maximumAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://lv2plug.in/ns/ext/atom#PropertyAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          https://www.surina.net/soundtouch/Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://xmlns.com/foaf/0.1/homepageAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://lv2plug.in/ns/lv2core#projecthttp://usefulinc.com/ns/doap#maintainerhttp://xmlns.com/foaf/0.1Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://lv2plug.in/ns/ext/dynmanifest#DynManifestAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://lv2plug.in/ns/extensions/ui#externalAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                          • Avira URL Cloud: safe
                          unknown
                          http://manual.audacityteam.org/o/man/faq_about_audacity.html#freeaudacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpfalse
                            high
                            https://manual.audacityteam.org/man/unzipping_the_manual.htmlAudacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpfalse
                              high
                              http://lv2plug.in/ns/extensions/ui#GtkUIAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://audio.comaudio.com%%&UnlinkAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                              • Avira URL Cloud: safe
                              low
                              http://lame.sf.net32bits64bitsAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              http://lv2plug.in/ns/ext/options#optionsLV2InstanceFeaturesList::CheckOptionsD:Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                              • Avira URL Cloud: safe
                              unknown
                              https://github.com/audacity/audacity/pullsaudacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                high
                                http://lv2plug.in/ns/ext/atom#URIDAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://lv2plug.in/ns/ext/state#mapPathhttp://lv2plug.in/ns/ext/state#makePathlilv_state_new_from_insAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://lv2plug.in/ns/ext/atom#IntAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://lv2plug.in/ns/ext/parameters#sampleRateAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://lv2plug.in/ns/extensions/ui#Qt4UIAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://lv2plug.in/ns/ext/atom#StringAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://lv2plug.in/ns/ext/buf-size#fixedBlockLengthAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://lv2plug.in/ns/ext/port-props#notAutomaticAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                http://www.twolame.org/Audacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpfalse
                                • Avira URL Cloud: safe
                                unknown
                                https://manual.audacityteam.org/man/faq_opening_and_saving_files.html#fromcdAudacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpfalse
                                  high
                                  http://lv2plug.in/ns/lv2core#sampleRateAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://www.haysoft.org%1-kaudacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                  • URL Reputation: safe
                                  low
                                  http://lv2plug.in/ns/lv2core#portAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://lv2plug.in/ns/ext/atom#LongAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://lv2plug.in/ns/ext/buf-size#minBlockLengthAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://lv2plug.in/ns/ext/time#speedAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  http://lv2plug.in/ns/lv2core#scalePointAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                  • Avira URL Cloud: safe
                                  unknown
                                  https://manual.audacityteam.org/quick_help.htmlAudacity.exe, 00000010.00000002.544979137.000001241D121000.00000004.00000001.00020000.00000000.sdmpfalse
                                    high
                                    http://lv2plug.in/ns/ext/instance-accessAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    http://lv2plug.in/ns/lv2core#nameAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    http://lv2plug.in/ns/ext/port-groups#groupAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    http://lv2plug.in/ns/ext/event#supportsEventlilv_port_get_valuelilv_port_get_name%s():Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                    • Avira URL Cloud: safe
                                    unknown
                                    https://www.audacityteam.org/about/desktop-privacy-notice/ourAudacity.exe, 00000010.00000000.506712370.00007FF60DF0E000.00000002.00000001.01000000.0000000D.sdmpfalse
                                      high
                                      http://lv2plug.in/ns/ext/worker#scheduleAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      http://lv2plug.in/ns/ext/atom#Blankhttp://lv2plug.in/ns/ext/atom#Boolhttp://lv2plug.in/ns/ext/atom#CAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      http://xmlns.com/foaf/0.1/Audacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                      • Avira URL Cloud: safe
                                      unknown
                                      http://kxstudio.sf.net/ns/lv2ext/external-ui#HostAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                        high
                                        http://lv2plug.in/ns/lv2core#AudioPortAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                        • Avira URL Cloud: safe
                                        unknown
                                        https://www.audacityteam.org/wiki/index.php?title=file:Audacity.exe, 00000010.00000000.507856498.00007FF60DF90000.00000002.00000001.01000000.0000000D.sdmpfalse
                                          high
                                          http://lv2plug.in/ns/ext/event#supportsEventAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                          • Avira URL Cloud: safe
                                          unknown
                                          http://ocsp.sectigo.com0audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpfalse
                                          • URL Reputation: safe
                                          unknown
                                          http://ll-plugins.nongnu.org/lv2/namespace#MathFunctionPluginAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                            high
                                            http://lv2plug.in/ns/ext/log#logAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                            • Avira URL Cloud: safe
                                            unknown
                                            https://github.com/audacity/audacity/releasesAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                              high
                                              http://lv2plug.in/ns/lv2core#OutputPortAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://lv2plug.in/ns/extensions/ui#noUserResizehttp://lv2plug.in/ns/extensions/ui#fixedSizehttp://lvAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://lv2plug.in/ns/extensions/ui#touchAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://lv2plug.in/ns/lv2core#symbolAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                              • Avira URL Cloud: safe
                                              unknown
                                              http://crt.sectigo.com/SectigoPublicCodeSigningRootR46.p7c0#audacity-win-3.2.0-64bit.exe, 0000000A.00000003.329484659.00000000025AA000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.336259617.000000007FE76000.00000004.00001000.00020000.00000000.sdmpfalse
                                              • URL Reputation: safe
                                              unknown
                                              http://kxstudio.sf.net/ns/lv2ext/external-ui#WidgetAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                high
                                                http://lv2plug.in/ns/ext/port-props#causesArtifactsAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                https://www.audacityteam.orgDonAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                http://lv2plug.in/ns/ext/port-props#rangeStepsAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                http://lv2plug.in/ns/ext/time#PositionAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                • Avira URL Cloud: safe
                                                unknown
                                                http://www.gnu.org/licenses/licenses.htmlaudacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                  high
                                                  http://lv2plug.in/ns/lv2core#enumerationAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://lv2plug.in/ns/extensions/ui#portMapAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://lv2plug.in/ns/ext/atom#childType%2XFailedAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://lv2plug.in/ns/ext/port-props#triggerAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://lv2plug.in/ns/lv2core#prototypeAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  http://lv2plug.in/ns/ext/atom#childTypeAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                  • Avira URL Cloud: safe
                                                  unknown
                                                  https://forum.audacityteam.org/viewforum.php?f=19audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                    high
                                                    http://lv2plug.in/ns/extensions/ui#Gtk3UIAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                    • Avira URL Cloud: safe
                                                    unknown
                                                    https://audacityteam.org/errorshereWouldAudacity.exe, 00000010.00000002.571515772.00007FF60E079000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                      high
                                                      https://plugins.audacityteam.org/Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                        high
                                                        https://forum.audacityteam.org/.Audacity.exe, 00000010.00000002.571189245.00007FF60DFE2000.00000002.00000001.01000000.0000000D.sdmpfalse
                                                          high
                                                          http://audacityteam.org/about/audacity-win-3.2.0-64bit.exe, 0000000A.00000002.517966675.0000000002150000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.exe, 0000000A.00000003.303356414.00000000024B0000.00000004.00001000.00020000.00000000.sdmp, audacity-win-3.2.0-64bit.tmp, 0000000B.00000003.344545902.00000000035A0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                            high
                                                            No contacted IP infos
                                                            Joe Sandbox Version:36.0.0 Rainbow Opal
                                                            Analysis ID:715159
                                                            Start date and time:2022-10-03 17:29:45 +02:00
                                                            Joe Sandbox Product:CloudBasic
                                                            Overall analysis duration:0h 12m 42s
                                                            Hypervisor based Inspection enabled:false
                                                            Report type:light
                                                            Sample file name:WsiysHggF9.exe
                                                            Cookbook file name:default.jbs
                                                            Analysis system description:Windows 10 64 bit v1803 with Office Professional Plus 2016, Chrome 104, IE 11, Adobe Reader DC 19, Java 8 Update 211
                                                            Number of analysed new started processes analysed:17
                                                            Number of new started drivers analysed:0
                                                            Number of existing processes analysed:0
                                                            Number of existing drivers analysed:0
                                                            Number of injected processes analysed:0
                                                            Technologies:
                                                            • HCA enabled
                                                            • EGA enabled
                                                            • HDC enabled
                                                            • AMSI enabled
                                                            Analysis Mode:default
                                                            Analysis stop reason:Timeout
                                                            Detection:MAL
                                                            Classification:mal50.troj.evad.winEXE@11/410@1/0
                                                            EGA Information:
                                                            • Successful, ratio: 50%
                                                            HDC Information:
                                                            • Successful, ratio: 99.8% (good quality ratio 95%)
                                                            • Quality average: 78.9%
                                                            • Quality standard deviation: 27.9%
                                                            HCA Information:
                                                            • Successful, ratio: 72%
                                                            • Number of executed functions: 0
                                                            • Number of non-executed functions: 0
                                                            Cookbook Comments:
                                                            • Found application associated with file extension: .exe
                                                            • Exclude process from analysis (whitelisted): MpCmdRun.exe, SgrmBroker.exe, conhost.exe, svchost.exe
                                                            • Created / dropped Files have been reduced to 100
                                                            • Excluded domains from analysis (whitelisted): fs.microsoft.com
                                                            • Not all processes where analyzed, report is missing behavior information
                                                            • Report creation exceeded maximum time and may have missing disassembly code information.
                                                            • Report size exceeded maximum capacity and may have missing behavior information.
                                                            • Report size getting too big, too many NtAllocateVirtualMemory calls found.
                                                            • Report size getting too big, too many NtOpenKeyEx calls found.
                                                            • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                            • Report size getting too big, too many NtQueryValueKey calls found.
                                                            • Report size getting too big, too many NtSetInformationFile calls found.
                                                            • VT rate limit hit for: WsiysHggF9.exe
                                                            No simulations
                                                            No context
                                                            No context
                                                            No context
                                                            No context
                                                            No context
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:PE32+ executable (GUI) x86-64, for MS Windows
                                                            Category:dropped
                                                            Size (bytes):18346984
                                                            Entropy (8bit):5.799007831846941
                                                            Encrypted:false
                                                            SSDEEP:98304:Kjzz9bIIQItaxXOK0fSiBSKnDD0S27jAx/wovRsrNnasJvkvNcqC:gX9bqXOK0LBSKnsSGo/L5srNnasVN/
                                                            MD5:686920484890800433A208E111666FE1
                                                            SHA1:C0883885EED96B21802F6AA048F26BE2A0696DC2
                                                            SHA-256:70443B2187A22DFFA90924F089440299514A9604C2AB44482A7002470B286290
                                                            SHA-512:E4A150CE977875B621A8B84CB09D3DF5DC2B7A4B82466BB6EA3CCAFF18D8D4C1B0C53339EEB859C2281F501046625A9053E3EF5830237F71B60F12F0957CB7C6
                                                            Malicious:false
                                                            Antivirus:
                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                            Reputation:low
                                                            Preview:MZ......................@...................................h...........!..L.!This program cannot be run in DOS mode....$.......M.F...(...(...(.......(......(...,...(...+...(...-.&.(...)...(.l.)...(...)...(.h.)...(...)...(.m.)...(...,...(...-...(...-...(.m.,...(..,...(......(..)...(...)...(...,...(...).4.(...)...(...-...(...(...(......(...*...(.Rich..(.PE..d.....,c.........."....!.....v......O.........@..............................".....".....`.........................................P...'....N...................$......./......l*......8....................T..(.......@............p...............................text............................. ..`.rdata..w.L......L................@..@.data...)...........................@....pdata..$...........................@..@.idata.......p......................@..@.tls................................@....00cfg..u...........................@..@_RDATA..Z...........................@..@.rsrc...............................@..@.reloc..nD......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:exported SGML document, ASCII text, with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):3135
                                                            Entropy (8bit):4.118243114663798
                                                            Encrypted:false
                                                            SSDEEP:24:/FiVGnSelecVMFum4rq41b5JDpprkwPdTnRxKqiwh:951ecQMTcwPdzRxK98
                                                            MD5:2BF19AD3B70F5FEE5BE2A533AAC1B8D7
                                                            SHA1:6DBEC2D105339B67DDD09B5574A386AC1AA4A360
                                                            SHA-256:ACCA4F46F6A9A0C9887650FC0B63544EEC4187C7B3F351310D20ECBEAFEA9E8A
                                                            SHA-512:30250D32DF6A0430F68EDE9307456489D988D5DF88583D373C4832455C58C55C3DCCE04E0CD49A270A00B863B364281DE30AA1ED1EBE952215E88504A8AEDFE8
                                                            Malicious:false
                                                            Reputation:low
                                                            Preview:<EffectMenuList>.. <Group>.. Effects menu group name; audio dynamics compression, not data compression -->.. <Name>Volume and Compression</Name>.. <Effects>.. <Effect>Amplify</Effect>.. <Effect>Compressor</Effect>.. <Effect>Limiter</Effect>.. <Effect>Normalize</Effect>.. <Effect>Loudness Normalization</Effect>.. <Effect>Auto Duck</Effect>.. </Effects>.. </Group>.. <Group>.. Effects menu group name -->.. <Name>Fading</Name>.. <Effects>.. <Effect>Fade In</Effect>.. <Effect>Fade Out</Effect>.. <Effect>Studio Fade Out</Effect>.. <Effect>Adjustable Fade</Effect>.. <Effect>Crossfade Clips</Effect>.. <Effect>Crossfade Tracks</Effect>.. </Effects>.. </Group>.. <Group>.. <Name>Pitch and Tempo</Name>.. <Effects>.. <Effect>Change Pitch</Effect>.. <Effe
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                            Category:dropped
                                                            Size (bytes):163304
                                                            Entropy (8bit):5.2787590433466605
                                                            Encrypted:false
                                                            SSDEEP:1536:+7gYw7uaHb0JVXTyYHTYc5r7dnW8aetBg/nlXH:FYmuaH2xTyYzYc5s8aetBSnhH
                                                            MD5:8FBE5290565F390AA3A58CBBED175276
                                                            SHA1:34C241349D8A954D68E332B2D17DA7DA5BFF1AB9
                                                            SHA-256:3CEC5CF1C56B0A268CEF01E10BC31D63E5E64E31AA59714E26BA57AB5B4E5561
                                                            SHA-512:19C093C351F7D075D57659A436EC65CD60ED04550615C286F3EA4A87A1ABBBA19BC9EE0669C34101CCABE27082F65A2CD32B6BC23F0EF33F34D5FAC0D67FB333
                                                            Malicious:false
                                                            Antivirus:
                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........).9.H.j.H.j.H.j.0Vj.H.j$3.k.H.j$38j.H.j$3.k.H.j$3.k.H.j$3.k.H.j@8.k.H.j)3.k.H.j.H.jUH.j)3.k.H.j)3.k.H.j)3.k.H.j)3:j.H.j)3.k.H.jRich.H.j........................PE..d......c.........." ...!.....f......7................................................e....`.........................................`F......X,..........<............N.../......\...0...8...............................@............ ..X............................text...2........................... ..`.rdata..............................@..@.data...y...........................@....pdata..@...........................@..@.idata..UB... ...D..................@..@.00cfg..u....p.......@..............@..@.rsrc...<............B..............@..@.reloc...............H..............@..B................................................................................................................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                            Category:dropped
                                                            Size (bytes):275944
                                                            Entropy (8bit):5.75829192222849
                                                            Encrypted:false
                                                            SSDEEP:3072:Jwa20khRG66NAjLzwJyVTe2e/B9RjhsqmTcmZk+CGYnhB8:JwJPh466AzL5SZOcVlnT8
                                                            MD5:4CB24B18EE80396059FEC2C5FEF1B28C
                                                            SHA1:B11EF4C9099ED511ACD286BFAF7BEA115349E4A2
                                                            SHA-256:CCD217E75C844543F99CF33FF7D8CDF7FE892BD7D94851D7D9DC6B5918284DD6
                                                            SHA-512:79FEAF95AE2E69968B7F8779B3BBD08A887AF66ED5DFC9EFB6BE75A0277C3E1AECFB9EBC305A1E55B7A7E4DE5E8A465279DAABD6226563A05A1D59A7089E6A75
                                                            Malicious:false
                                                            Antivirus:
                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........A.............!.....U.......U.O.....U.......U.......U.......1...............X.......X.......X.M.....X.......Rich............PE..d......c.........." ...!.....(......#........................................p.......^....`.........................................0....F...&.......P..<.......@......../...`..x...0K..8............................I..@............ ...............................text............................... ..`.rdata..............................@..@.data...............................@....pdata..T!......."..................@..@.idata....... ......................@..@.00cfg..u....@......................@..@.rsrc...<....P......................@..@.reloc.......`......................@..B................................................................................................................................................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:ASCII text, with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):27
                                                            Entropy (8bit):3.8100810205217304
                                                            Encrypted:false
                                                            SSDEEP:3:qs/KM3REnvn:X/KMMvn
                                                            MD5:2C57C2B7EE5C25E906CF47DD56B21CF3
                                                            SHA1:B64A10726A200961E68787793377AE5362735412
                                                            SHA-256:42F8A06D23872031B9D6E4722FF8B42DE398777A58927C44C608743C38EE9340
                                                            SHA-512:9A8E53D442386A86A54DDEA3EA28ECD49118236F95C4CFEA22D3B4D6FD15D81320C800FA505854CFAEC2BF4B5FBACAD4E2B0D41347A39DBCD273A2BB68F8BBB3
                                                            Malicious:false
                                                            Preview:[FromInno]....Language=en..
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:ASCII text, with CRLF line terminators
                                                            Category:dropped
                                                            Size (bytes):74895
                                                            Entropy (8bit):4.705526648142378
                                                            Encrypted:false
                                                            SSDEEP:768:2pzun1iYWrTXo0HDOc7Y+tNdSz3ZlqXOWoInuzx3Y8N3WiYD9P1GKQwq1Fl+bzg:A+8TXoWVtNIq1uzZY13oKQT1+3g
                                                            MD5:AF89B6DEF149203612F56EF0F3B6F5A1
                                                            SHA1:CD7C4313C3DFBB54F344C1946A5E2E523A7DC0AB
                                                            SHA-256:F6D3C12A6845004F3B8CD53A3CB09DF58F30CC920AFA98C380AA6FBD71B9A4DC
                                                            SHA-512:DC3212F0E8AECEC438B89BA7F8A4EE785D90909E8AFB04811BC6E1943A425577FA88CDE795BCA6749825A8BB408E3ECEB26D9C69B194903F0DE36FE56311788E
                                                            Malicious:false
                                                            Preview:Audacity is released under the GNU General Public License version 3 (GPLv3). ..Individual source files may be available under other licenses as specified ..in those files or an accompanying file. In particular, many source files are ..available under GPL version 2 (GPLv2) or (at your option) any later version, ..and this is the default license used where no other license is specified.....Documentation is distributed under a Creative Commons-Attribution license...(CC-BY 3.0)....Following are the full license texts of the...* GNU General Public License Version 2 (GPLv2), ...* GNU General Public License Version 3 (GPLv3), and...* Creative Commons-Attribution 3.0 Unported (CC-BY 3.0)..licenses. ....###############################################################################...... GNU GENERAL PUBLIC LICENSE.... Version 2, June 1991.... Copyright (C) 1989, 1991 Free Software Foundation, Inc... 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.. Everyone is permitted to
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 487 messages, Project-Id-Version: audacity 3.0.3 '"%s" bestaan nie.'
                                                            Category:dropped
                                                            Size (bytes):29840
                                                            Entropy (8bit):5.077796478193377
                                                            Encrypted:false
                                                            SSDEEP:768:CMZ2sfpnvRpw39KZo4hBKf3v8EOq125og2sEH08Uo:fjfFo9KZocKf3vFOB5oWEH4o
                                                            MD5:68F835F07E00377A78035F3BFBD7D758
                                                            SHA1:6A2161219AAA5E2A304D5C0E7F7BF996FA39F881
                                                            SHA-256:F711815D1F2EC34CE023C3E3732C5A2C1BFC0E8D0C958D0F8C333F70424C8553
                                                            SHA-512:4B0864C5916EF0386E7010FEF183EA950F4B3F8E902DB2B575DC3779086FA080D95E4E388CC38E2A02BC364E201D3589BD14A33A3B523DBFF51499462E21BA06
                                                            Malicious:false
                                                            Preview:................T................(..1....(.......(.......).......)..%...%)......K)......^)......c)......h)......q)......{).......).......).......).......).......).......).......).......).......).......).......).......).......).......).......).......*.......*.......*.......*......$*......-*......6*......;*......A*......E*......N*......Z*......a*......q*......{*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......+......%+..,...-+..%...Z+..1....+..#....+..$....+.......+.......,.......,.......,......#,......*,......5,......7,......B,......V,......],......h,......j,......w,......y,......{,......},.......,.......,.......,.......,.......,.......,.......,.......,.......,.......,.......,.......-.......-.. ...:-......[-......v-..#....-..:....-.......-.......-.......-..................z...3..........._.......*...*/..t...U/......./......./......./......./.......0.......0.......0......"0......,0......30......;0......S0..4..._0..#....0......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 487 messages, Project-Id-Version: audacity 3.0.3 '"%s" bestaan nie.'
                                                            Category:dropped
                                                            Size (bytes):29840
                                                            Entropy (8bit):5.077796478193377
                                                            Encrypted:false
                                                            SSDEEP:768:CMZ2sfpnvRpw39KZo4hBKf3v8EOq125og2sEH08Uo:fjfFo9KZocKf3vFOB5oWEH4o
                                                            MD5:68F835F07E00377A78035F3BFBD7D758
                                                            SHA1:6A2161219AAA5E2A304D5C0E7F7BF996FA39F881
                                                            SHA-256:F711815D1F2EC34CE023C3E3732C5A2C1BFC0E8D0C958D0F8C333F70424C8553
                                                            SHA-512:4B0864C5916EF0386E7010FEF183EA950F4B3F8E902DB2B575DC3779086FA080D95E4E388CC38E2A02BC364E201D3589BD14A33A3B523DBFF51499462E21BA06
                                                            Malicious:false
                                                            Preview:................T................(..1....(.......(.......).......)..%...%)......K)......^)......c)......h)......q)......{).......).......).......).......).......).......).......).......).......).......).......).......).......).......).......).......*.......*.......*.......*......$*......-*......6*......;*......A*......E*......N*......Z*......a*......q*......{*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......*.......+......%+..,...-+..%...Z+..1....+..#....+..$....+.......+.......,.......,.......,......#,......*,......5,......7,......B,......V,......],......h,......j,......w,......y,......{,......},.......,.......,.......,.......,.......,.......,.......,.......,.......,.......,.......,.......-.......-.. ...:-......[-......v-..#....-..:....-.......-.......-.......-..................z...3..........._.......*...*/..t...U/......./......./......./......./.......0.......0.......0......"0......,0......30......;0......S0..4..._0..#....0......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3170 messages, Project-Id-Version: audacity 3.0.3 '\330\247\331\204\331\205\331\204\331\201\330\247\330\252 \330\247\331\204\331\205\330\270\331\207\330\261\330\251 \331\203\331\205\331\201\331\202\331\210\330\257 \330\252\331\205 \331\206\331\202\331\204\331\207\330\247 \330\243\331\210 \330\255\330\260\331\201\330\252 \331\210 \331\204\330\247 \331\212\331\205\331\203\331\206 \331\206\330\263\330\256\331\207\330\247.'
                                                            Category:dropped
                                                            Size (bytes):271446
                                                            Entropy (8bit):5.633438263939798
                                                            Encrypted:false
                                                            SSDEEP:6144:KXR9XhRDxQoszZOfc+uA9U4jR1IGMC/r7:CxKZA9U4t1IGMC/P
                                                            MD5:D6877A0011173842C41594E28223099F
                                                            SHA1:D3D0C701858F6869F92E1CF0A6816D57241CCEC1
                                                            SHA-256:26EA072B6E1E922AB4CC4D2A92BF2C37101E8DE4D7C19B42AD4F249107DD8C76
                                                            SHA-512:CD7432F9D98A48D2DAC396038F23B429047C5FFAAA5BE5C70A2226BED9162E5E07B993CC92355D828E0DBA77FEDA3C2FD8CB08D3C8E34E5BBE20E1460C89FDDF
                                                            Malicious:false
                                                            Preview:........b.......,c......<.......P.......Q...'.......6...........C...............................................................'.......2.......<.......E.......M...g...Z...P.......................1...................................)...............l.......-...............{.......C...................................4........................... .......(.......4.......A.......H.......R.......Y.......a.......m.......w.......................................................................................%.......>.......D.......U.......].......r...8...y...;...........................).......D...(...\...................................................J.......................%.......$...;.......`.......h.......q...F...............................................%...3.......Y.......l.......w...E...~.......................................................!.......4.......@.......R.......`.......e.......w...........................................................(...............................$...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3170 messages, Project-Id-Version: audacity 3.0.3 '\330\247\331\204\331\205\331\204\331\201\330\247\330\252 \330\247\331\204\331\205\330\270\331\207\330\261\330\251 \331\203\331\205\331\201\331\202\331\210\330\257 \330\252\331\205 \331\206\331\202\331\204\331\207\330\247 \330\243\331\210 \330\255\330\260\331\201\330\252 \331\210 \331\204\330\247 \331\212\331\205\331\203\331\206 \331\206\330\263\330\256\331\207\330\247.'
                                                            Category:dropped
                                                            Size (bytes):271446
                                                            Entropy (8bit):5.633438263939798
                                                            Encrypted:false
                                                            SSDEEP:6144:KXR9XhRDxQoszZOfc+uA9U4jR1IGMC/r7:CxKZA9U4t1IGMC/P
                                                            MD5:D6877A0011173842C41594E28223099F
                                                            SHA1:D3D0C701858F6869F92E1CF0A6816D57241CCEC1
                                                            SHA-256:26EA072B6E1E922AB4CC4D2A92BF2C37101E8DE4D7C19B42AD4F249107DD8C76
                                                            SHA-512:CD7432F9D98A48D2DAC396038F23B429047C5FFAAA5BE5C70A2226BED9162E5E07B993CC92355D828E0DBA77FEDA3C2FD8CB08D3C8E34E5BBE20E1460C89FDDF
                                                            Malicious:false
                                                            Preview:........b.......,c......<.......P.......Q...'.......6...........C...............................................................'.......2.......<.......E.......M...g...Z...P.......................1...................................)...............l.......-...............{.......C...................................4........................... .......(.......4.......A.......H.......R.......Y.......a.......m.......w.......................................................................................%.......>.......D.......U.......].......r...8...y...;...........................).......D...(...\...................................................J.......................%.......$...;.......`.......h.......q...F...............................................%...3.......Y.......l.......w...E...~.......................................................!.......4.......@.......R.......`.......e.......w...........................................................(...............................$...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 996 messages, Project-Id-Version: audacity 3.0.3 '\320\232\320\260\320\273\321\226 \320\267\320\260\321\205\320\260\320\262\320\260\321\206\321\214, \321\203 \320\277\321\200\320\260\320\265\320\272\321\206\320\265 \320\275\320\265 \320\261\321\203\320\264\320\267\320\265'
                                                            Category:dropped
                                                            Size (bytes):86428
                                                            Entropy (8bit):5.4901962318832105
                                                            Encrypted:false
                                                            SSDEEP:1536:XwDbHSdiG2JYxw6ZoLgHnNGBLoAx4HwCnJbb9ujg56Y9tiYpn0Q:i6owZoLgHn4BLoA+qbYzp0Q
                                                            MD5:A2A761DE6451A37742C174AA7F5BD0F0
                                                            SHA1:306B7E969596889FBD6AA93B1AE7A7D7A94C0525
                                                            SHA-256:978466923FC33D8343EF1821040E5F1E35A3B0BFCC8CCDAAC285B30B76C30566
                                                            SHA-512:1A804BDEED6C351F06A51B3BB9A5FC84F7594E01C1E45D010935A4662A3752AF3073DF46998CF59F725000B7FBA0B73C33EE099A56E0982E0336A3F6A125ECD6
                                                            Malicious:false
                                                            Preview:................<...Q...\>.......S.......S......;T......DT......MT.......T.......U.......V.......W.......W......\X.......X..4....Y.......Y.......Y.......Y.......Y.......Y.......Y..J....Z..%...UZ......{Z.......Z.......Z.......Z.......Z.......Z..(....Z.......Z.......Z.......Z.......Z.......[.......[.......[......![......+[......3[......C[......L[.."...U[......x[......~[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......\.......\.......\......5\......>\......I\......R\......c\......h\......n\......r\......{\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......]......!]......3]......A]......J]......R]......e]......t].......].......].......].......].......].......].......].......].......].......].......].......^..,....^..%...8^..1...^^..#....^..$....^..$....^.......^......._......._......0_......C_..*...a_......._......._......._......._.......`.......`......7`......M`......c`.......`......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 996 messages, Project-Id-Version: audacity 3.0.3 '\320\232\320\260\320\273\321\226 \320\267\320\260\321\205\320\260\320\262\320\260\321\206\321\214, \321\203 \320\277\321\200\320\260\320\265\320\272\321\206\320\265 \320\275\320\265 \320\261\321\203\320\264\320\267\320\265'
                                                            Category:dropped
                                                            Size (bytes):86428
                                                            Entropy (8bit):5.4901962318832105
                                                            Encrypted:false
                                                            SSDEEP:1536:XwDbHSdiG2JYxw6ZoLgHnNGBLoAx4HwCnJbb9ujg56Y9tiYpn0Q:i6owZoLgHn4BLoA+qbYzp0Q
                                                            MD5:A2A761DE6451A37742C174AA7F5BD0F0
                                                            SHA1:306B7E969596889FBD6AA93B1AE7A7D7A94C0525
                                                            SHA-256:978466923FC33D8343EF1821040E5F1E35A3B0BFCC8CCDAAC285B30B76C30566
                                                            SHA-512:1A804BDEED6C351F06A51B3BB9A5FC84F7594E01C1E45D010935A4662A3752AF3073DF46998CF59F725000B7FBA0B73C33EE099A56E0982E0336A3F6A125ECD6
                                                            Malicious:false
                                                            Preview:................<...Q...\>.......S.......S......;T......DT......MT.......T.......U.......V.......W.......W......\X.......X..4....Y.......Y.......Y.......Y.......Y.......Y.......Y..J....Z..%...UZ......{Z.......Z.......Z.......Z.......Z.......Z..(....Z.......Z.......Z.......Z.......Z.......[.......[.......[......![......+[......3[......C[......L[.."...U[......x[......~[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......[.......\.......\.......\......5\......>\......I\......R\......c\......h\......n\......r\......{\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......\.......]......!]......3]......A]......J]......R]......e]......t].......].......].......].......].......].......].......].......].......].......].......].......^..,....^..%...8^..1...^^..#....^..$....^..$....^.......^......._......._......0_......C_..*...a_......._......._......._......._.......`.......`......7`......M`......c`.......`......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1325 messages, Project-Id-Version: audacity 3.0.3 '\320\244\320\260\320\271\320\273\320\276\320\262\320\265\321\202\320\265, \320\277\320\276\320\272\320\260\320\267\320\260\320\275\320\270 \320\272\320\260\321\202\320\276 \342\200\236\320\273\320\270\320\277\321\201\320\262\320\260\321\211\320\270\342\200\234, \321\201\320\260 \320\277\321\200\320\265\320\274\320\265\321\201\321\202\320\265\320\275\320\270 \320\270\320\273\320\270 \320\270\320\267\321\202\321\200\320\270\321\202\320\270 \320\270 \320\275\320\265 \320'
                                                            Category:dropped
                                                            Size (bytes):135847
                                                            Entropy (8bit):5.425765802901142
                                                            Encrypted:false
                                                            SSDEEP:3072:R6hYw/slTPvPAZogCd4RDapnmjLBALSey0Pvx8TymYb2uVNxQN00PDy2uq:RiY9vPnyRDMn8LBAdhP5vmzDNuq
                                                            MD5:A2ABD25FA631E015F37F32DA9FC0404E
                                                            SHA1:C70839BC6A8D0DC04F598CAA9E41F000BFABCFF4
                                                            SHA-256:D166BDEE57F0DF35F961C7C6D7832CED543962ACE0220CB9B342DD066B9FD24E
                                                            SHA-512:1CE5D2818184A36F46083F78F76FC4818241ACCAAD1C51906E5B0A70CA5C5CF88CCB80C5497AFA47BC9AD698E8A197232E8AEB93758419BBE78F1513BBDD68D3
                                                            Malicious:false
                                                            Preview:........-........).......R.......n.......n......Do.......o.......o.......o.......o..1....p.......p......bq......_r.......r.......s......<t.......t.......u......Kv.......v.......w.......x..4....x.......x.......y.......y.......y.......y......%y......*y......1y......=y......Vy..J...ay..%....y.......y.......y.......y.......y.......z.......z.......z..(....z......Gz......Oz......Vz......]z......rz......{z.......z.......z.......z.......z.......z.......z.......z.."....z.......z.......z.......z.......{.......{......%{......+{......7{......@{......L{......V{......c{......v{......|{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......|.......|.......|.......|......%|......)|......2|......<|......N|......Z|......a|......h|......x|.......|.......|.......|.......|.......|.......|.......|.......|.......|.......|.......|.......}.......}......(}......0}......?}......R}......e}......t}.......}.......}.......}.......}.......}.......}.......}.......}.......}......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1325 messages, Project-Id-Version: audacity 3.0.3 '\320\244\320\260\320\271\320\273\320\276\320\262\320\265\321\202\320\265, \320\277\320\276\320\272\320\260\320\267\320\260\320\275\320\270 \320\272\320\260\321\202\320\276 \342\200\236\320\273\320\270\320\277\321\201\320\262\320\260\321\211\320\270\342\200\234, \321\201\320\260 \320\277\321\200\320\265\320\274\320\265\321\201\321\202\320\265\320\275\320\270 \320\270\320\273\320\270 \320\270\320\267\321\202\321\200\320\270\321\202\320\270 \320\270 \320\275\320\265 \320'
                                                            Category:dropped
                                                            Size (bytes):135847
                                                            Entropy (8bit):5.425765802901142
                                                            Encrypted:false
                                                            SSDEEP:3072:R6hYw/slTPvPAZogCd4RDapnmjLBALSey0Pvx8TymYb2uVNxQN00PDy2uq:RiY9vPnyRDMn8LBAdhP5vmzDNuq
                                                            MD5:A2ABD25FA631E015F37F32DA9FC0404E
                                                            SHA1:C70839BC6A8D0DC04F598CAA9E41F000BFABCFF4
                                                            SHA-256:D166BDEE57F0DF35F961C7C6D7832CED543962ACE0220CB9B342DD066B9FD24E
                                                            SHA-512:1CE5D2818184A36F46083F78F76FC4818241ACCAAD1C51906E5B0A70CA5C5CF88CCB80C5497AFA47BC9AD698E8A197232E8AEB93758419BBE78F1513BBDD68D3
                                                            Malicious:false
                                                            Preview:........-........).......R.......n.......n......Do.......o.......o.......o.......o..1....p.......p......bq......_r.......r.......s......<t.......t.......u......Kv.......v.......w.......x..4....x.......x.......y.......y.......y.......y......%y......*y......1y......=y......Vy..J...ay..%....y.......y.......y.......y.......y.......z.......z.......z..(....z......Gz......Oz......Vz......]z......rz......{z.......z.......z.......z.......z.......z.......z.......z.."....z.......z.......z.......z.......{.......{......%{......+{......7{......@{......L{......V{......c{......v{......|{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......|.......|.......|.......|......%|......)|......2|......<|......N|......Z|......a|......h|......x|.......|.......|.......|.......|.......|.......|.......|.......|.......|.......|.......|.......}.......}......(}......0}......?}......R}......e}......t}.......}.......}.......}.......}.......}.......}.......}.......}.......}......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 70 messages, Project-Id-Version: audacity 3.0.3 '%d \340\246\232\340\247\215\340\246\257\340\246\276\340\246\250\340\247\207\340\246\262'
                                                            Category:dropped
                                                            Size (bytes):4218
                                                            Entropy (8bit):4.971887850240577
                                                            Encrypted:false
                                                            SSDEEP:96:RM1JCuhzgjLRORUeMmlMykLFkUIEQK1HpVQmEPhhWOWapg:KJCcgjLRO2eMmRK1JONPyrF
                                                            MD5:DD106BB851D2B08EA97A556F72D63373
                                                            SHA1:984BEB916B82C6AF4343242DC4F0AC785FEB8728
                                                            SHA-256:2AEC4444F35A6E2DDA334D38FD0105359D0A9B167C80F18E7A74E0837C50EA80
                                                            SHA-512:569BB58026AFAFF474043BF5ADF637E9DF595A68356B10A9CD6FB47F53AF389AE063965E120EB3DCE669F3FE9C1611760F88B58713EAC425DDEA21453ED0A438
                                                            Malicious:false
                                                            Preview:........F.......L...a...|...................%...........3.......F.......O.......U.......[.......b.......q.......u.......}............................................................................................................................... .......*.......5.......:.......B.......K.......Y.......f.......l.......q.......t.......{...............................................................................................................................................................................................................!.......).......2.......9.......=.......J...K...]...........M.......2...........C.......Z.......h.......v...........................................;.......(.......A...6..."...x.......................................................................;.......H.......d...2...}...........................;.......*...(.......S.......f.......p.......................................................................................+.......8.......R.......f.......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 70 messages, Project-Id-Version: audacity 3.0.3 '%d \340\246\232\340\247\215\340\246\257\340\246\276\340\246\250\340\247\207\340\246\262'
                                                            Category:dropped
                                                            Size (bytes):4218
                                                            Entropy (8bit):4.971887850240577
                                                            Encrypted:false
                                                            SSDEEP:96:RM1JCuhzgjLRORUeMmlMykLFkUIEQK1HpVQmEPhhWOWapg:KJCcgjLRO2eMmRK1JONPyrF
                                                            MD5:DD106BB851D2B08EA97A556F72D63373
                                                            SHA1:984BEB916B82C6AF4343242DC4F0AC785FEB8728
                                                            SHA-256:2AEC4444F35A6E2DDA334D38FD0105359D0A9B167C80F18E7A74E0837C50EA80
                                                            SHA-512:569BB58026AFAFF474043BF5ADF637E9DF595A68356B10A9CD6FB47F53AF389AE063965E120EB3DCE669F3FE9C1611760F88B58713EAC425DDEA21453ED0A438
                                                            Malicious:false
                                                            Preview:........F.......L...a...|...................%...........3.......F.......O.......U.......[.......b.......q.......u.......}............................................................................................................................... .......*.......5.......:.......B.......K.......Y.......f.......l.......q.......t.......{...............................................................................................................................................................................................................!.......).......2.......9.......=.......J...K...]...........M.......2...........C.......Z.......h.......v...........................................;.......(.......A...6..."...x.......................................................................;.......H.......d...2...}...........................;.......*...(.......S.......f.......p.......................................................................................+.......8.......R.......f.......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 695 messages, Project-Id-Version: audacity 3.0.3 ' Nijemo uklju\304\215eno'
                                                            Category:dropped
                                                            Size (bytes):47256
                                                            Entropy (8bit):5.262920147681837
                                                            Encrypted:false
                                                            SSDEEP:768:ySLmNwLE6W2qS7m3iVd8vnZoyjgK0kFjeeoaA1+gkXe2zMmgVDmoNEKe8TZCz/CT:UjAmpZoJK0kRelaA1+5egxESoNEITZCO
                                                            MD5:8D366C8056A8025CC4187AE142535B1F
                                                            SHA1:C52B7E435A331328D54955AE2C82A56E1135DE2C
                                                            SHA-256:BFCBB616BB629BCABBD67CFC91EA63AFCF0944409F489F6799B4394ADAF0A2C2
                                                            SHA-512:E78442096DB7474458FC3AAE4D969E08A888314D9FEF1920BB5912B631D1D1383CD1B88101B228CB1B9880DB5CD874E3AEA7D7D71264C2F4C62D874E5C852630
                                                            Malicious:false
                                                            Preview:.........................+.......:.......:.......:......%:..1....:......`:.......:.......;......f<.......=......&=......2=..%...==......c=......v=......{=.......=.......=..(....=.......=.......=.......=.......=.......=.......=.......=.......=.......>.......>.."....>......9>......?>......P>......[>......a>......k>......q>......y>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......?.......?.......?.......?......%?......2?......D?......R?......[?......f?......t?.......?.......?.......?.......?.......?.......?.......?.......?..,....?..%....@..1...*@..#...\@..$....@.......@.......@.......@.......@..*....@......)A......GA......eA.......A.......A.......A.......A.......A.......B.......B......1B......MB......OB......XB......iB......pB......{B......}B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......C.......C......#C......1C......IC......UC......dC......vC......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 695 messages, Project-Id-Version: audacity 3.0.3 ' Nijemo uklju\304\215eno'
                                                            Category:dropped
                                                            Size (bytes):47256
                                                            Entropy (8bit):5.262920147681837
                                                            Encrypted:false
                                                            SSDEEP:768:ySLmNwLE6W2qS7m3iVd8vnZoyjgK0kFjeeoaA1+gkXe2zMmgVDmoNEKe8TZCz/CT:UjAmpZoJK0kRelaA1+5egxESoNEITZCO
                                                            MD5:8D366C8056A8025CC4187AE142535B1F
                                                            SHA1:C52B7E435A331328D54955AE2C82A56E1135DE2C
                                                            SHA-256:BFCBB616BB629BCABBD67CFC91EA63AFCF0944409F489F6799B4394ADAF0A2C2
                                                            SHA-512:E78442096DB7474458FC3AAE4D969E08A888314D9FEF1920BB5912B631D1D1383CD1B88101B228CB1B9880DB5CD874E3AEA7D7D71264C2F4C62D874E5C852630
                                                            Malicious:false
                                                            Preview:.........................+.......:.......:.......:......%:..1....:......`:.......:.......;......f<.......=......&=......2=..%...==......c=......v=......{=.......=.......=..(....=.......=.......=.......=.......=.......=.......=.......=.......=.......>.......>.."....>......9>......?>......P>......[>......a>......k>......q>......y>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......>.......?.......?.......?.......?......%?......2?......D?......R?......[?......f?......t?.......?.......?.......?.......?.......?.......?.......?.......?..,....?..%....@..1...*@..#...\@..$....@.......@.......@.......@.......@..*....@......)A......GA......eA.......A.......A.......A.......A.......A.......B.......B......1B......MB......OB......XB......iB......pB......{B......}B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......C.......C......#C......1C......IC......UC......dC......vC......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 2886 messages, Project-Id-Version: audacity 3.0.3 'Els fitxers etiquetats amb l'expressi\303\263 DESAPAREGUT han estat moguts o eliminats i no es poden copiar.'
                                                            Category:dropped
                                                            Size (bytes):220954
                                                            Entropy (8bit):5.400772098596046
                                                            Encrypted:false
                                                            SSDEEP:6144:YTTgPZAf5urmNgDKoCnuL/cC6A9fWOibwLMl9oV6sJabfq45r5anvh036c:WgA7BA9fWO2wLMl9oV6sJabf9N5anJS
                                                            MD5:B58407E26D05E6C310DE0486BE9890CF
                                                            SHA1:8F91D6FBC8B3A34D095483C9DC0EC50ABBADAF89
                                                            SHA-256:D0AAD2ACCFFAAD04FC9D2D197AFE7AA1D768376072B3A2D054CBBD5E9A12E87A
                                                            SHA-512:AF8BA73593EF77E0E8AC8746B98195E095C9221EEA0EBCB8179FDFCEEDD14D2A34D9C470F497C0C70B435C608E8AC5D4B3E683D2CA9AF06D7F1E7ACD75321B82
                                                            Malicious:false
                                                            Preview:........F.......LZ......|...................'...<.......d.......................................'...............:.......H.......S.......]...P...f...........1...K.......}...............................F.......................s.......................J.......e...........4...................................................................................%.......1.......;.......E.......J.......g...............................................................................................................&.......-.......8...J...C...........%...................................................................).......0.......C.......H.......V.......i.......u...................................................................................(...................(......./...$...C.......h.......x...................................................................................%...........1.......9.......D.......L.......Q.......j.......................................................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 2886 messages, Project-Id-Version: audacity 3.0.3 'Els fitxers etiquetats amb l'expressi\303\263 DESAPAREGUT han estat moguts o eliminats i no es poden copiar.'
                                                            Category:dropped
                                                            Size (bytes):220954
                                                            Entropy (8bit):5.400772098596046
                                                            Encrypted:false
                                                            SSDEEP:6144:YTTgPZAf5urmNgDKoCnuL/cC6A9fWOibwLMl9oV6sJabfq45r5anvh036c:WgA7BA9fWO2wLMl9oV6sJabf9N5anJS
                                                            MD5:B58407E26D05E6C310DE0486BE9890CF
                                                            SHA1:8F91D6FBC8B3A34D095483C9DC0EC50ABBADAF89
                                                            SHA-256:D0AAD2ACCFFAAD04FC9D2D197AFE7AA1D768376072B3A2D054CBBD5E9A12E87A
                                                            SHA-512:AF8BA73593EF77E0E8AC8746B98195E095C9221EEA0EBCB8179FDFCEEDD14D2A34D9C470F497C0C70B435C608E8AC5D4B3E683D2CA9AF06D7F1E7ACD75321B82
                                                            Malicious:false
                                                            Preview:........F.......LZ......|...................'...<.......d.......................................'...............:.......H.......S.......]...P...f...........1...K.......}...............................F.......................s.......................J.......e...........4...................................................................................%.......1.......;.......E.......J.......g...............................................................................................................&.......-.......8...J...C...........%...................................................................).......0.......C.......H.......V.......i.......u...................................................................................(...................(......./...$...C.......h.......x...................................................................................%...........1.......9.......D.......L.......Q.......j.......................................................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3382 messages, Project-Id-Version: audacity 3.0.3 'Els fitxers mostrats com DESAPAREGUTS s'han mogut o eliminat i no es poden copiar.'
                                                            Category:dropped
                                                            Size (bytes):275091
                                                            Entropy (8bit):5.401967372777679
                                                            Encrypted:false
                                                            SSDEEP:6144:6/tRQpn/ZqjDjJoSqTrac+UA957eQi8IHUWWCEXiuwXGz6x1MJabOi1n/1MZ3elY:6/bQGl6A957eQBIHUWWCEXiuwXGz6x14
                                                            MD5:857B1D57F8544F0BCF285D906ED36717
                                                            SHA1:3B8390EA372E453219404F05A5DE86262E509F7C
                                                            SHA-256:77D20E85CB674B0E63E2D5B3F349D5F47A1A6AEA7CCEC3B68D5ECEF42310F191
                                                            SHA-512:640FC50B671DC38D7FC73E64D1F62AAC5C442A0079FB12CBF8DDED67BB4D37A02248926438263D1C834A080FB5929CFC797EF78451CF3B118335B011FD6E2475
                                                            Malicious:false
                                                            Preview:........6........i......|...................'...............K...V...................................................................................................g.......P...............1...l...............?.......<...............g .......!.......!......."......(#.......#.......$......3%......N&..0...m&.......&..4....&.......&.......&.......&.......'.......'.......'......&'......0'......7'......?'......K'......U'......_'......d'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......(.......(.......(......3(..8...:(..;...s(.......(.......(.......(.......).......)......%)......,)......3)......?)......J)..J...U).......).......)..%....)..$....).......).......*.......*..F...)*......p*......w*..E...~*.......*.......*.......*.......*.......+.......+......!+......4+......@+......R+......`+......e+......n+......}+.......+.......+.......+.......+.......+..(....+.......+.......+.......+..$....,......3,......C,......K,......S,......i,......p,......w,.......,.......,......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3382 messages, Project-Id-Version: audacity 3.0.3 'Els fitxers mostrats com DESAPAREGUTS s'han mogut o eliminat i no es poden copiar.'
                                                            Category:dropped
                                                            Size (bytes):275091
                                                            Entropy (8bit):5.401967372777679
                                                            Encrypted:false
                                                            SSDEEP:6144:6/tRQpn/ZqjDjJoSqTrac+UA957eQi8IHUWWCEXiuwXGz6x1MJabOi1n/1MZ3elY:6/bQGl6A957eQBIHUWWCEXiuwXGz6x14
                                                            MD5:857B1D57F8544F0BCF285D906ED36717
                                                            SHA1:3B8390EA372E453219404F05A5DE86262E509F7C
                                                            SHA-256:77D20E85CB674B0E63E2D5B3F349D5F47A1A6AEA7CCEC3B68D5ECEF42310F191
                                                            SHA-512:640FC50B671DC38D7FC73E64D1F62AAC5C442A0079FB12CBF8DDED67BB4D37A02248926438263D1C834A080FB5929CFC797EF78451CF3B118335B011FD6E2475
                                                            Malicious:false
                                                            Preview:........6........i......|...................'...............K...V...................................................................................................g.......P...............1...l...............?.......<...............g .......!.......!......."......(#.......#.......$......3%......N&..0...m&.......&..4....&.......&.......&.......&.......'.......'.......'......&'......0'......7'......?'......K'......U'......_'......d'.......'.......'.......'.......'.......'.......'.......'.......'.......'.......(.......(.......(......3(..8...:(..;...s(.......(.......(.......(.......).......)......%)......,)......3)......?)......J)..J...U).......).......)..%....)..$....).......).......*.......*..F...)*......p*......w*..E...~*.......*.......*.......*.......*.......+.......+......!+......4+......@+......R+......`+......e+......n+......}+.......+.......+.......+.......+.......+..(....+.......+.......+.......+..$....,......3,......C,......K,......S,......i,......p,......w,.......,.......,......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 \303\250'
                                                            Category:dropped
                                                            Size (bytes):376833
                                                            Entropy (8bit):5.457322037273507
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UlyUk9CD2PsYRDjIoj5/asc+1A7MY89yazDk/neY:6DtVVA7MY89j8H
                                                            MD5:9AEBB29DCE01C5BBBF23986C76A38E02
                                                            SHA1:142E47AE5C113F81530A760A0753E97B72749683
                                                            SHA-256:CF6DBDDEE0CD790CFEB533DA0B5DF4ABB1F381766F843305B4E34ED44CACDE6A
                                                            SHA-512:296A61404D2FBB72D726144DF4F59F831923F261988629ED5F8E278542C652609010D12FFEB4477A593D931CB7EAF7DF14FCF1CAB8C81327C230667D812A8993
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 \303\250'
                                                            Category:dropped
                                                            Size (bytes):376833
                                                            Entropy (8bit):5.457322037273507
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UlyUk9CD2PsYRDjIoj5/asc+1A7MY89yazDk/neY:6DtVVA7MY89j8H
                                                            MD5:9AEBB29DCE01C5BBBF23986C76A38E02
                                                            SHA1:142E47AE5C113F81530A760A0753E97B72749683
                                                            SHA-256:CF6DBDDEE0CD790CFEB533DA0B5DF4ABB1F381766F843305B4E34ED44CACDE6A
                                                            SHA-512:296A61404D2FBB72D726144DF4F59F831923F261988629ED5F8E278542C652609010D12FFEB4477A593D931CB7EAF7DF14FCF1CAB8C81327C230667D812A8993
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4032 messages, Project-Id-Version: audacity 3.0.3 '\011 a'
                                                            Category:dropped
                                                            Size (bytes):333409
                                                            Entropy (8bit):5.639759719225201
                                                            Encrypted:false
                                                            SSDEEP:6144:TAQi7ZcyaZURDj1oCULeoc+9A7jiGrP8QCID:Ts5LeA7ji/Na
                                                            MD5:E2B2B5D1A08324F0360413D8A901EC8F
                                                            SHA1:FBC7B48A5B46B26EA6AAC62002CF8B9A128FF9C9
                                                            SHA-256:986A01BB01B71176C2C37468B8E1DE52AD7AD40D31DAB08114126D29EE5D8C77
                                                            SHA-512:154852ECA8DA498DB9C107EBEC60F43DB5C34232A14C2C9BEE8FE47E70862D873C06B8C7ACBC95C9030DBEA23DB236BC48970C0C57B24EF0D0E68C76B2BB42AC
                                                            Malicious:false
                                                            Preview:.................~..............0P......1P......<P..'....P..:....P..6...2Q......iQ.......R..|....R..S....S..G...hS..*....S..K....S......'T..m....T......EU.......U.......V......HW......OX......XX......bX......oX......xX.......X.......X.......X.......X.......X.......X.......X..g....X..P...4Y.......Y..F....Z......`Z..1...xZ.......Z......K[......H\.......\......s]......%^.......^......._......4`.......`.......a......?b......Zc..0...yc.......c.......c..4....c.......d.......d.......d......%d......-d......9d......Fd......Md......Ud......_d......fd......nd......zd.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e.......e......-e......@e......Ye......_e......pe......xe.......e.......e.......e..8....e..;....e.......f......2f..7...Nf.......f.......f.......f.......f..(....f.......f.......f.......g.......g.......g.......g......$g......*g......5g......Eg......Pg......Yg..J...dg.......g.......g.......g..-....g..%....g..$....h......>h......Fh..S...Oh.......h..F...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4032 messages, Project-Id-Version: audacity 3.0.3 '\011 a'
                                                            Category:dropped
                                                            Size (bytes):333409
                                                            Entropy (8bit):5.639759719225201
                                                            Encrypted:false
                                                            SSDEEP:6144:TAQi7ZcyaZURDj1oCULeoc+9A7jiGrP8QCID:Ts5LeA7ji/Na
                                                            MD5:E2B2B5D1A08324F0360413D8A901EC8F
                                                            SHA1:FBC7B48A5B46B26EA6AAC62002CF8B9A128FF9C9
                                                            SHA-256:986A01BB01B71176C2C37468B8E1DE52AD7AD40D31DAB08114126D29EE5D8C77
                                                            SHA-512:154852ECA8DA498DB9C107EBEC60F43DB5C34232A14C2C9BEE8FE47E70862D873C06B8C7ACBC95C9030DBEA23DB236BC48970C0C57B24EF0D0E68C76B2BB42AC
                                                            Malicious:false
                                                            Preview:.................~..............0P......1P......<P..'....P..:....P..6...2Q......iQ.......R..|....R..S....S..G...hS..*....S..K....S......'T..m....T......EU.......U.......V......HW......OX......XX......bX......oX......xX.......X.......X.......X.......X.......X.......X.......X..g....X..P...4Y.......Y..F....Z......`Z..1...xZ.......Z......K[......H\.......\......s]......%^.......^......._......4`.......`.......a......?b......Zc..0...yc.......c.......c..4....c.......d.......d.......d......%d......-d......9d......Fd......Md......Ud......_d......fd......nd......zd.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e.......e......-e......@e......Ye......_e......pe......xe.......e.......e.......e..8....e..;....e.......f......2f..7...Nf.......f.......f.......f.......f..(....f.......f.......f.......g.......g.......g.......g......$g......*g......5g......Eg......Pg......Yg..J...dg.......g.......g.......g..-....g..%....g..$....h......>h......Fh..S...Oh.......h..F...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 314 messages, Project-Id-Version: audacity 3.0.3 '%d Sianel'
                                                            Category:dropped
                                                            Size (bytes):19555
                                                            Entropy (8bit):5.119843426705521
                                                            Encrypted:false
                                                            SSDEEP:384:xI2OdWjtkt9DXFt1oQ/2JM83yyX/Wej6dwFh2wBGA7f99ylsNzBHUxIZ7:cWZefoQqyyn8k9BGk9ylGhUxIZ7
                                                            MD5:B522AA1FC3AE91994560EF3B61826A0E
                                                            SHA1:1AC146006E19C1D9B4B56E330E0DC404618761CA
                                                            SHA-256:8782B0FE1156627DFFA1BF6C5465A43198CFBC2F86EFCF766ECA651E78A7C510
                                                            SHA-512:B1345EE8BCBD1BA9E35C22A57381922E793293E1E4F42DFD6B834163BDD965B1553576FDB818C63E22CBEB5CB3E4658844E665027E0AB94E681570080DAB4989
                                                            Malicious:false
                                                            Preview:........:.......................H.......I...%...U.......{....................................................................................................................................................... .......&...,...9...%...f...1.......#.......$...........................!.......,.......@.......G.......S.......f.......u...........................................................z...........{...........................................#...................................&.......D.......[...#...h...........................,...............#....... ....... ...=.......^.......q...O...............$.......2.... ..,...7 ......d ..-...n ..".... ..&.... ../.... ..0....!..#...G!......k!..)....!.......!.......!.......!..S....!......&"..$...+"......P"..+...j".......".......".......".......".......".......#.......#.......#......6#......:#......O#......]#......p#.......#.......#.......#.......#.......#..1....#......%$....../$......9$......D$......I$......Q$......a$......i$.......$.......$......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 314 messages, Project-Id-Version: audacity 3.0.3 '%d Sianel'
                                                            Category:dropped
                                                            Size (bytes):19555
                                                            Entropy (8bit):5.119843426705521
                                                            Encrypted:false
                                                            SSDEEP:384:xI2OdWjtkt9DXFt1oQ/2JM83yyX/Wej6dwFh2wBGA7f99ylsNzBHUxIZ7:cWZefoQqyyn8k9BGk9ylGhUxIZ7
                                                            MD5:B522AA1FC3AE91994560EF3B61826A0E
                                                            SHA1:1AC146006E19C1D9B4B56E330E0DC404618761CA
                                                            SHA-256:8782B0FE1156627DFFA1BF6C5465A43198CFBC2F86EFCF766ECA651E78A7C510
                                                            SHA-512:B1345EE8BCBD1BA9E35C22A57381922E793293E1E4F42DFD6B834163BDD965B1553576FDB818C63E22CBEB5CB3E4658844E665027E0AB94E681570080DAB4989
                                                            Malicious:false
                                                            Preview:........:.......................H.......I...%...U.......{....................................................................................................................................................... .......&...,...9...%...f...1.......#.......$...........................!.......,.......@.......G.......S.......f.......u...........................................................z...........{...........................................#...................................&.......D.......[...#...h...........................,...............#....... ....... ...=.......^.......q...O...............$.......2.... ..,...7 ......d ..-...n ..".... ..&.... ../.... ..0....!..#...G!......k!..)....!.......!.......!.......!..S....!......&"..$...+"......P"..+...j".......".......".......".......".......".......#.......#.......#......6#......:#......O#......]#......p#.......#.......#.......#.......#.......#..1....#......%$....../$......9$......D$......I$......Q$......a$......i$.......$.......$......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.2.0 '\011 og'
                                                            Category:dropped
                                                            Size (bytes):347992
                                                            Entropy (8bit):5.4414931559385575
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Usdx7pWsYRDjIoj5/asc+1A7MJLXN75gBTqbJmPe:6DMVVA7Mz7a1Pe
                                                            MD5:A3B6AD50B2331CA9D9AC243ACA831C27
                                                            SHA1:BB42D2B63006C6785BE8E39D8A7009F5D9805973
                                                            SHA-256:D7561C786C116E9476714A1540D0D8EC9DE271D22565F6812042348684FAFEFE
                                                            SHA-512:CD453175D4610C702455C30E05DDD7D76F37EAB9B3C70611036582812604C6FD4ED41C222F6BFD8E12ADFB78C478CB99EEC27BDDF96C28CFE25C4D66637DBD27
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.2.0 '\011 og'
                                                            Category:dropped
                                                            Size (bytes):347992
                                                            Entropy (8bit):5.4414931559385575
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Usdx7pWsYRDjIoj5/asc+1A7MJLXN75gBTqbJmPe:6DMVVA7Mz7a1Pe
                                                            MD5:A3B6AD50B2331CA9D9AC243ACA831C27
                                                            SHA1:BB42D2B63006C6785BE8E39D8A7009F5D9805973
                                                            SHA-256:D7561C786C116E9476714A1540D0D8EC9DE271D22565F6812042348684FAFEFE
                                                            SHA-512:CD453175D4610C702455C30E05DDD7D76F37EAB9B3C70611036582812604C6FD4ED41C222F6BFD8E12ADFB78C478CB99EEC27BDDF96C28CFE25C4D66637DBD27
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 und'
                                                            Category:dropped
                                                            Size (bytes):359799
                                                            Entropy (8bit):5.456538351366818
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UbAaQSiDODihIeusYRDjIoj5/asc+1A7M6/Nbj8ARq8CQXbu:66FpDCOVVA7M6Vbj8B8CQXbu
                                                            MD5:0594489B778A25579CE5EF6E1F01ECCD
                                                            SHA1:7CCD37CB18B6BB43C4EF51D336B1BD1B479D1106
                                                            SHA-256:A6C5346CACD772616D9805FBC60CFCF0F900DB9270B20BBBCE1B1F470F8BC36E
                                                            SHA-512:D3F1925F65841F0190AE9204CEAE1FCE07227516DBDF5BE94FE671E59DD68F3B99F5DA62E9C089CE0DD189CD62CEB13B658824242447D357FDB11B7F2ECAEA42
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 und'
                                                            Category:dropped
                                                            Size (bytes):359799
                                                            Entropy (8bit):5.456538351366818
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UbAaQSiDODihIeusYRDjIoj5/asc+1A7M6/Nbj8ARq8CQXbu:66FpDCOVVA7M6Vbj8B8CQXbu
                                                            MD5:0594489B778A25579CE5EF6E1F01ECCD
                                                            SHA1:7CCD37CB18B6BB43C4EF51D336B1BD1B479D1106
                                                            SHA-256:A6C5346CACD772616D9805FBC60CFCF0F900DB9270B20BBBCE1B1F470F8BC36E
                                                            SHA-512:D3F1925F65841F0190AE9204CEAE1FCE07227516DBDF5BE94FE671E59DD68F3B99F5DA62E9C089CE0DD189CD62CEB13B658824242447D357FDB11B7F2ECAEA42
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4304 messages, Project-Id-Version: audacity 3.0.3 '\011 \316\272\316\261\316\271'
                                                            Category:dropped
                                                            Size (bytes):474186
                                                            Entropy (8bit):5.580974353473279
                                                            Encrypted:false
                                                            SSDEEP:12288:nsLJgA70aF11BMHOA3UgDLmP/4V5gT8AiANB3S09P2++ia3Omp7ufleTSPg:GyA70U1BMlDKP45gT8AHNB3SYP2++iaj
                                                            MD5:908C365EF7D34419198EA4DB78A033BE
                                                            SHA1:2030C6C72FBB5C524DBFC205F85DA3E2ED6EE34F
                                                            SHA-256:2F3949B1C10167CC0AE8A979FFCCF956EDA49905B81E052F643695318B00577E
                                                            SHA-512:927F4667AC4735BDB719BF39D14D096D57013909519AE7CC0DB7680119DAE488446C1A2F3112736A6A82EA1C3B6B3F6FF2EEF8EA66D24756ABC38A344E113609
                                                            Malicious:false
                                                            Preview:....................m............f.......f.......f..'...og..:....g.......g..$....g..6....g..(...2h......[h.......h..|....i..S....j..G...Zj..*....j..K....j.......k..m....k......7l.......l.......m......:n......Ao......Jo......To......ao......jo......qo......}o.......o.......o.......o.......o.......o..g....o..P...&p......wp..F....q......Rq..1...jq.......q......=r......:s.......s......et.......u.......u.......v......&w.......w.......x......1y......Lz..0...kz.......z.......z..4....z.......z.......{.......{.......{.......{......+{......8{......?{......G{......Q{......X{......`{......l{......v{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......|.......|.......|......2|......K|......Q|......b|......j|.......|.......|.......|..8....|..;....|.......}......$}..7...@}......x}.......}.......}..R....}..0....~......;~..(...C~......l~......s~......z~.......~.......~.......~.......~.......~.......~.......~.......~..J....~..............#.......,...-...3.......a...%.......$...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4304 messages, Project-Id-Version: audacity 3.0.3 '\011 \316\272\316\261\316\271'
                                                            Category:dropped
                                                            Size (bytes):474186
                                                            Entropy (8bit):5.580974353473279
                                                            Encrypted:false
                                                            SSDEEP:12288:nsLJgA70aF11BMHOA3UgDLmP/4V5gT8AiANB3S09P2++ia3Omp7ufleTSPg:GyA70U1BMlDKP45gT8AHNB3SYP2++iaj
                                                            MD5:908C365EF7D34419198EA4DB78A033BE
                                                            SHA1:2030C6C72FBB5C524DBFC205F85DA3E2ED6EE34F
                                                            SHA-256:2F3949B1C10167CC0AE8A979FFCCF956EDA49905B81E052F643695318B00577E
                                                            SHA-512:927F4667AC4735BDB719BF39D14D096D57013909519AE7CC0DB7680119DAE488446C1A2F3112736A6A82EA1C3B6B3F6FF2EEF8EA66D24756ABC38A344E113609
                                                            Malicious:false
                                                            Preview:....................m............f.......f.......f..'...og..:....g.......g..$....g..6....g..(...2h......[h.......h..|....i..S....j..G...Zj..*....j..K....j.......k..m....k......7l.......l.......m......:n......Ao......Jo......To......ao......jo......qo......}o.......o.......o.......o.......o.......o..g....o..P...&p......wp..F....q......Rq..1...jq.......q......=r......:s.......s......et.......u.......u.......v......&w.......w.......x......1y......Lz..0...kz.......z.......z..4....z.......z.......{.......{.......{.......{......+{......8{......?{......G{......Q{......X{......`{......l{......v{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......|.......|.......|......2|......K|......Q|......b|......j|.......|.......|.......|..8....|..;....|.......}......$}..7...@}......x}.......}.......}..R....}..0....~......;~..(...C~......l~......s~......z~.......~.......~.......~.......~.......~.......~.......~.......~..J....~..............#.......,...-...3.......a...%.......$...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 y'
                                                            Category:dropped
                                                            Size (bytes):364815
                                                            Entropy (8bit):5.357333136836256
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UYDK2q/CsYRDjIoj5/asc+1A7MJz2Euz+:6TDKGVVA7MF/uK
                                                            MD5:DC7116FB733FAAE41A489C3ABF66AF93
                                                            SHA1:19874A34181D9008D7ADCFC9719FFB8A6DF543CB
                                                            SHA-256:10E79201F214CE7FBDCEECF8BD6EC2F5A2C7DBE719AEE6BDFF42F0E1E80D9751
                                                            SHA-512:4CFF4249B2A5A69F9DBA48DBBDBDECB19AD729CA278A30D900ED809ECC42159E1168DC136164BBAD801C5094F6010C61B44C15A042E5A1FBA2A4BD8F730B7775
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 y'
                                                            Category:dropped
                                                            Size (bytes):364815
                                                            Entropy (8bit):5.357333136836256
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UYDK2q/CsYRDjIoj5/asc+1A7MJz2Euz+:6TDKGVVA7MF/uK
                                                            MD5:DC7116FB733FAAE41A489C3ABF66AF93
                                                            SHA1:19874A34181D9008D7ADCFC9719FFB8A6DF543CB
                                                            SHA-256:10E79201F214CE7FBDCEECF8BD6EC2F5A2C7DBE719AEE6BDFF42F0E1E80D9751
                                                            SHA-512:4CFF4249B2A5A69F9DBA48DBBDBDECB19AD729CA278A30D900ED809ECC42159E1168DC136164BBAD801C5094F6010C61B44C15A042E5A1FBA2A4BD8F730B7775
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3831 messages, Project-Id-Version: audacity 3.0.3 '\011 eta'
                                                            Category:dropped
                                                            Size (bytes):299054
                                                            Entropy (8bit):5.379575700457028
                                                            Encrypted:false
                                                            SSDEEP:6144:PHqv047m9vu5mo1URDjmortOKoc+9A9GuVe4+PsIsKMDNNk9zcUaN6he2anDM6rz:c04OFRXeA9GBPsIsKMDNNksv8kCTBzts
                                                            MD5:32D0A3F08C3D7AC881C362CA31F57F6E
                                                            SHA1:25FE3093611CC06004E949B25899E153B93819EF
                                                            SHA-256:8E70E7BAC30A36EE71AE67058F1A289340F858B1519B2F11DC1BBD5C9DADC755
                                                            SHA-512:1025FAAA6532B8254E45014E5A9CD9FDA35C69C0EE55C34EB76B7F7E6341BD62EDC05DED7DC3A0D58532FF308E8F2E4F999F9DA891E179484A099A618242FD99
                                                            Malicious:false
                                                            Preview:.................w..............p?......q?......|?..'....@..:...7@..6...r@.......@......CA..S....A..G...+B..*...sB..K....B.......B..m....C.......D.......D......aE.......F.......G.......G......%G......2G......;G......BG......NG......\G......gG......qG......zG.......G..g....G..P....G......HH.......H..1....H......&I.......I.......J......^K.......K.......L......bM.......N.......N......xO.......P.......P.......Q..0....Q......&R......AR..4...SR.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......S.......S.......S.......S......2S......MS......US......\S......yS.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T.......T..8....T..;...ST.......T.......T.......T.......T.......T.......U..(....U......:U......BU......IU......PU......\U......bU......hU......nU......yU.......U.......U.......U..J....U.......U.......U.......V..-....V..%...7V..$...]V.......V.......V..S....V.......V..F....W......NW......[W......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3831 messages, Project-Id-Version: audacity 3.0.3 '\011 eta'
                                                            Category:dropped
                                                            Size (bytes):299054
                                                            Entropy (8bit):5.379575700457028
                                                            Encrypted:false
                                                            SSDEEP:6144:PHqv047m9vu5mo1URDjmortOKoc+9A9GuVe4+PsIsKMDNNk9zcUaN6he2anDM6rz:c04OFRXeA9GBPsIsKMDNNksv8kCTBzts
                                                            MD5:32D0A3F08C3D7AC881C362CA31F57F6E
                                                            SHA1:25FE3093611CC06004E949B25899E153B93819EF
                                                            SHA-256:8E70E7BAC30A36EE71AE67058F1A289340F858B1519B2F11DC1BBD5C9DADC755
                                                            SHA-512:1025FAAA6532B8254E45014E5A9CD9FDA35C69C0EE55C34EB76B7F7E6341BD62EDC05DED7DC3A0D58532FF308E8F2E4F999F9DA891E179484A099A618242FD99
                                                            Malicious:false
                                                            Preview:.................w..............p?......q?......|?..'....@..:...7@..6...r@.......@......CA..S....A..G...+B..*...sB..K....B.......B..m....C.......D.......D......aE.......F.......G.......G......%G......2G......;G......BG......NG......\G......gG......qG......zG.......G..g....G..P....G......HH.......H..1....H......&I.......I.......J......^K.......K.......L......bM.......N.......N......xO.......P.......P.......Q..0....Q......&R......AR..4...SR.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......S.......S.......S.......S......2S......MS......US......\S......yS.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T.......T..8....T..;...ST.......T.......T.......T.......T.......T.......U..(....U......:U......BU......IU......PU......\U......bU......hU......nU......yU.......U.......U.......U..J....U.......U.......U.......V..-....V..%...7V..$...]V.......V.......V..S....V.......V..F....W......NW......[W......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4086 messages, Project-Id-Version: audacity 3.0.3 '\011 eta'
                                                            Category:dropped
                                                            Size (bytes):333356
                                                            Entropy (8bit):5.356088937988997
                                                            Encrypted:false
                                                            SSDEEP:6144:woRYlyQhJtMRDjeo4aLYoc+dA7B4/xgzHiPQN7MK9HK4BKrlGVXOtV83FSZBEhgo:0DI0+A7BmgriPiK4BKrlGVk8VSZBEhgo
                                                            MD5:6F42DB245092349B9F566B2FA8D75C5D
                                                            SHA1:8B2FA36EFB4309669723333E6F8AA21A0E131407
                                                            SHA-256:B830D6F98BB03058369961D4D2FB5CB70FBBDA8136994DCA664CAF3EA1150820
                                                            SHA-512:71C5723F6F6F717489F71B31D4256F96F28DFA92BDFF9FE5C8160BDCCB576615EB6D703210AC61CECFFA0A40FE0AFD6868AC4B57F988CE96F707781B4A4CE766
                                                            Malicious:false
                                                            Preview:....................I...|........T.......T.......T..'...?U..:...gU..6....U.......U......sV..|....W..S....W..G....W..*... X..K...KX.......X..m...GY.......Y......FZ.......[.......[.......\.......\.......\.......\.......\.......\.......\.......].......].......]......']....../]..g...<]..P....].......]..F....^.......^..1....^......._......._.......`......Ra.......a.......b......Vc.......d.......d......le.......f.......f.......g..0....g.......h......5h..4...Gh......|h......~h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......i.......i......&i......Ai......Ii......Pi......mi......vi.......i.......i.......i.......i.......i.......i.......i.......i.......i.......j.......j..8....j..;...Gj.......j.......j..7....j.......j.......k......)k......5k..(...=k......fk......mk......tk.......k.......k.......k.......k.......k.......k.......k.......k..J....k.......l.......l......&l..-...-l..%...[l..$....l.......l.......l.......l..S....l......:m..F...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4086 messages, Project-Id-Version: audacity 3.0.3 '\011 eta'
                                                            Category:dropped
                                                            Size (bytes):333356
                                                            Entropy (8bit):5.356088937988997
                                                            Encrypted:false
                                                            SSDEEP:6144:woRYlyQhJtMRDjeo4aLYoc+dA7B4/xgzHiPQN7MK9HK4BKrlGVXOtV83FSZBEhgo:0DI0+A7BmgriPiK4BKrlGVk8VSZBEhgo
                                                            MD5:6F42DB245092349B9F566B2FA8D75C5D
                                                            SHA1:8B2FA36EFB4309669723333E6F8AA21A0E131407
                                                            SHA-256:B830D6F98BB03058369961D4D2FB5CB70FBBDA8136994DCA664CAF3EA1150820
                                                            SHA-512:71C5723F6F6F717489F71B31D4256F96F28DFA92BDFF9FE5C8160BDCCB576615EB6D703210AC61CECFFA0A40FE0AFD6868AC4B57F988CE96F707781B4A4CE766
                                                            Malicious:false
                                                            Preview:....................I...|........T.......T.......T..'...?U..:...gU..6....U.......U......sV..|....W..S....W..G....W..*... X..K...KX.......X..m...GY.......Y......FZ.......[.......[.......\.......\.......\.......\.......\.......\.......\.......].......].......]......']....../]..g...<]..P....].......]..F....^.......^..1....^......._......._.......`......Ra.......a.......b......Vc.......d.......d......le.......f.......f.......g..0....g.......h......5h..4...Gh......|h......~h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......i.......i......&i......Ai......Ii......Pi......mi......vi.......i.......i.......i.......i.......i.......i.......i.......i.......i.......j.......j..8....j..;...Gj.......j.......j..7....j.......j.......k......)k......5k..(...=k......fk......mk......tk.......k.......k.......k.......k.......k.......k.......k.......k..J....k.......l.......l......&l..-...-l..%...[l..$....l.......l.......l.......l..S....l......:m..F...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 1.1, 567 messages, 17 sysdep messages, Project-Id-Version: audacity 3.0.3 ' \330\255\330\247\331\204\330\252 \330\250\333\214\342\200\214\330\265\330\257\330\247 \330\261\331\210\330\264\331\206'
                                                            Category:dropped
                                                            Size (bytes):48292
                                                            Entropy (8bit):5.501785498653541
                                                            Encrypted:false
                                                            SSDEEP:768:F62klauaZFky4k25ZoIdKYk3rEThbsbt2AyJvKJ/gFdUkZGuTJ:F9klCZF3kZomKYkbENbgt+GgUkZGuTJ
                                                            MD5:B1C7A78290DCF3AB57F4319D7C4B14B2
                                                            SHA1:C3101A38F5C03C7EAA1722DCB9691B56C1AAC9D6
                                                            SHA-256:72EFA77843CBFBC1937D933A53C21413A7B8E5C0D267BD50717E77C638AFD28D
                                                            SHA-512:4B37DF4FD45B0DE20D74A88B58E89790C41D641B27D236FE565725B4B98F71A1B619C75536CD0D225F464AB919CE9AC76A21D40EAD76EFE06C6A6F3E47255DA1
                                                            Malicious:false
                                                            Preview:........7...0............#......./......./..80.......2.......2.......2.......2.......2..%....2......#3......63......;3......@3......I3......S3......[3......b3......i3......~3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4......(4......-4......14......:4......F4......M4......]4......g4......t4......z4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......5.......5......"5..,...*5..%...W5..1...}5..#....5..$....5.......5.......6......'6..*...E6......p6.......6.......6.......6.......6.......7.......7......17......G7......f7......|7.......7.......7.......7.......7.......7.......7.......7.......7.......8.......8.......8......%8......88......F8......^8......m8.......8.......8.......8.. ....8.......8.......8..#....8.......9.......9......$9......99......P9..z...f9..5....9..;....:../...S:..E....:.."....:..$....:.......;......@;.._...\;..t....;......1<..
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 1.1, 567 messages, 17 sysdep messages, Project-Id-Version: audacity 3.0.3 ' \330\255\330\247\331\204\330\252 \330\250\333\214\342\200\214\330\265\330\257\330\247 \330\261\331\210\330\264\331\206'
                                                            Category:dropped
                                                            Size (bytes):48292
                                                            Entropy (8bit):5.501785498653541
                                                            Encrypted:false
                                                            SSDEEP:768:F62klauaZFky4k25ZoIdKYk3rEThbsbt2AyJvKJ/gFdUkZGuTJ:F9klCZF3kZomKYkbENbgt+GgUkZGuTJ
                                                            MD5:B1C7A78290DCF3AB57F4319D7C4B14B2
                                                            SHA1:C3101A38F5C03C7EAA1722DCB9691B56C1AAC9D6
                                                            SHA-256:72EFA77843CBFBC1937D933A53C21413A7B8E5C0D267BD50717E77C638AFD28D
                                                            SHA-512:4B37DF4FD45B0DE20D74A88B58E89790C41D641B27D236FE565725B4B98F71A1B619C75536CD0D225F464AB919CE9AC76A21D40EAD76EFE06C6A6F3E47255DA1
                                                            Malicious:false
                                                            Preview:........7...0............#......./......./..80.......2.......2.......2.......2.......2..%....2......#3......63......;3......@3......I3......S3......[3......b3......i3......~3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4......(4......-4......14......:4......F4......M4......]4......g4......t4......z4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......5.......5......"5..,...*5..%...W5..1...}5..#....5..$....5.......5.......6......'6..*...E6......p6.......6.......6.......6.......6.......7.......7......17......G7......f7......|7.......7.......7.......7.......7.......7.......7.......7.......7.......8.......8.......8......%8......88......F8......^8......m8.......8.......8.......8.. ....8.......8.......8..#....8.......9.......9......$9......99......P9..z...f9..5....9..;....:../...S:..E....:.."....:..$....:.......;......@;.._...\;..t....;......1<..
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4086 messages, Project-Id-Version: audacity 3.0.3 '\011 ja'
                                                            Category:dropped
                                                            Size (bytes):328001
                                                            Entropy (8bit):5.436476684935239
                                                            Encrypted:false
                                                            SSDEEP:6144:t1F/uk0QhJtMRDjeo4aLYoc+dA7BtqIQ3f+EFCL6Kqc1:t1FuII0+A7Btqb+v
                                                            MD5:1C52B330172918B61DB104AEDE61768B
                                                            SHA1:25F83FBC7C79D1500299A5BAC5158A6C06E7C303
                                                            SHA-256:6B042E4C5E15A6D390D49437E91971C86482DB536A09A2130BD7DA6354C1D745
                                                            SHA-512:FD681922C6FEAD5574746AC9A7F17A026C80BE1A786B3ADA11EACA63225B8366212C95764F687C36E0D181DB1BD3CE2B400BB34F72355C05FA3F3A025F666AF0
                                                            Malicious:false
                                                            Preview:....................I...|........T.......T.......T..'...?U..:...gU..6....U.......U......sV..|....W..S....W..G....W..*... X..K...KX.......X..m...GY.......Y......FZ.......[.......[.......\.......\.......\.......\.......\.......\.......\.......].......].......]......']....../]..g...<]..P....].......]..F....^.......^..1....^......._......._.......`......Ra.......a.......b......Vc.......d.......d......le.......f.......f.......g..0....g.......h......5h..4...Gh......|h......~h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......i.......i......&i......Ai......Ii......Pi......mi......vi.......i.......i.......i.......i.......i.......i.......i.......i.......i.......j.......j..8....j..;...Gj.......j.......j..7....j.......j.......k......)k......5k..(...=k......fk......mk......tk.......k.......k.......k.......k.......k.......k.......k.......k..J....k.......l.......l......&l..-...-l..%...[l..$....l.......l.......l.......l..S....l......:m..F...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4086 messages, Project-Id-Version: audacity 3.0.3 '\011 ja'
                                                            Category:dropped
                                                            Size (bytes):328001
                                                            Entropy (8bit):5.436476684935239
                                                            Encrypted:false
                                                            SSDEEP:6144:t1F/uk0QhJtMRDjeo4aLYoc+dA7BtqIQ3f+EFCL6Kqc1:t1FuII0+A7Btqb+v
                                                            MD5:1C52B330172918B61DB104AEDE61768B
                                                            SHA1:25F83FBC7C79D1500299A5BAC5158A6C06E7C303
                                                            SHA-256:6B042E4C5E15A6D390D49437E91971C86482DB536A09A2130BD7DA6354C1D745
                                                            SHA-512:FD681922C6FEAD5574746AC9A7F17A026C80BE1A786B3ADA11EACA63225B8366212C95764F687C36E0D181DB1BD3CE2B400BB34F72355C05FA3F3A025F666AF0
                                                            Malicious:false
                                                            Preview:....................I...|........T.......T.......T..'...?U..:...gU..6....U.......U......sV..|....W..S....W..G....W..*... X..K...KX.......X..m...GY.......Y......FZ.......[.......[.......\.......\.......\.......\.......\.......\.......\.......].......].......]......']....../]..g...<]..P....].......]..F....^.......^..1....^......._......._.......`......Ra.......a.......b......Vc.......d.......d......le.......f.......f.......g..0....g.......h......5h..4...Gh......|h......~h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......h.......i.......i......&i......Ai......Ii......Pi......mi......vi.......i.......i.......i.......i.......i.......i.......i.......i.......i.......j.......j..8....j..;...Gj.......j.......j..7....j.......j.......k......)k......5k..(...=k......fk......mk......tk.......k.......k.......k.......k.......k.......k.......k.......k..J....k.......l.......l......&l..-...-l..%...[l..$....l.......l.......l.......l..S....l......:m..F...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3974 messages, Project-Id-Version: audacity 3.0.3 '\011 et'
                                                            Category:dropped
                                                            Size (bytes):344071
                                                            Entropy (8bit):5.419584478237276
                                                            Encrypted:false
                                                            SSDEEP:6144:+sYSjDv/IcMRDjeo4/gboc+dA7v9dglyBMMevHeKorksmiq7:48VA7v9dgQUv+Lrksmh7
                                                            MD5:089EFA8F3F2955C46D0B42B7DD72F589
                                                            SHA1:0C6078B58920F44F17780B5CAE944BC7E5B68200
                                                            SHA-256:16F2C63F653627A0A9524D768C67F90FDA3A8225CA5D30BBC0B7C66473E9F041
                                                            SHA-512:BF88868E88AB1134ED7469ABD2759EE91EAF059B51A9E43E2EE94B8B2EED9DCD37DE46AFE30066D0B3651465DCE5030B8C91C8300AC18016666832ED806604C5
                                                            Malicious:false
                                                            Preview:................L|......|.......XK......YK......dK..'....K..:....L..6...ZL.......L......+M..|....M..S...<N..G....N..*....N..K....O......OO..m....O......mP.......P.......Q......pR......wS.......S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......S..g....S..P...\T.......T..F...AU.......U..1....U.......U......sV......pW.......X.......X......MY.......Z.......Z......\[......$\.......\......g].......^..0....^.......^..4....^......"_......$_......2_......:_......F_......S_......Z_......d_......k_......s_......._......._......._......._......._......._......._......._......._.......`.......`.......`......4`......E`......M`......b`..8...i`..;....`.......`.......`..7....a......Qa......la.......a..(....a.......a.......a.......a.......a.......a.......a.......a.......b..J....b......Xb......^b......gb..-...nb..%....b..$....b.......b.......b.......b..S...'c......{c..F....c.......c.......c.......c.......d.......d..(...!d......Jd......dd.......d.......d.......d.......d..%...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3974 messages, Project-Id-Version: audacity 3.0.3 '\011 et'
                                                            Category:dropped
                                                            Size (bytes):344071
                                                            Entropy (8bit):5.419584478237276
                                                            Encrypted:false
                                                            SSDEEP:6144:+sYSjDv/IcMRDjeo4/gboc+dA7v9dglyBMMevHeKorksmiq7:48VA7v9dgQUv+Lrksmh7
                                                            MD5:089EFA8F3F2955C46D0B42B7DD72F589
                                                            SHA1:0C6078B58920F44F17780B5CAE944BC7E5B68200
                                                            SHA-256:16F2C63F653627A0A9524D768C67F90FDA3A8225CA5D30BBC0B7C66473E9F041
                                                            SHA-512:BF88868E88AB1134ED7469ABD2759EE91EAF059B51A9E43E2EE94B8B2EED9DCD37DE46AFE30066D0B3651465DCE5030B8C91C8300AC18016666832ED806604C5
                                                            Malicious:false
                                                            Preview:................L|......|.......XK......YK......dK..'....K..:....L..6...ZL.......L......+M..|....M..S...<N..G....N..*....N..K....O......OO..m....O......mP.......P.......Q......pR......wS.......S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......S..g....S..P...\T.......T..F...AU.......U..1....U.......U......sV......pW.......X.......X......MY.......Z.......Z......\[......$\.......\......g].......^..0....^.......^..4....^......"_......$_......2_......:_......F_......S_......Z_......d_......k_......s_......._......._......._......._......._......._......._......._......._.......`.......`.......`......4`......E`......M`......b`..8...i`..;....`.......`.......`..7....a......Qa......la.......a..(....a.......a.......a.......a.......a.......a.......a.......a.......b..J....b......Xb......^b......gb..-...nb..%....b..$....b.......b.......b.......b..S...'c......{c..F....c.......c.......c.......c.......d.......d..(...!d......Jd......dd.......d.......d.......d.......d..%...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 2001 messages, Project-Id-Version: audacity 3.0.3 '\011 agus'
                                                            Category:dropped
                                                            Size (bytes):111479
                                                            Entropy (8bit):5.41588775035177
                                                            Encrypted:false
                                                            SSDEEP:3072:72dwyB1I5/FLJyWsopa1e2zMV2vAYdxOfllWeovjDUwjN6rnHcpCX3Kg8u3dbdym:adwyofLJX0Q2zMcvQsP8czSb
                                                            MD5:7764C3C9F02A9BFBCCB93173FC559C55
                                                            SHA1:873CCC5D8865A7590522BBCF7F66FF831F2CA207
                                                            SHA-256:677C07DD0D3F70015AFF3FFED39F2146CE52B5ED116C744CF46169427410535D
                                                            SHA-512:D1E35C4495F5191F85662E422EFAB9F28F0829650F51A935D625B887CC40BB87BC53DE3CABFDDA6D37EA843A5DD624E087609CAAC39E3FE4D16F7ED04E45FCBC
                                                            Malicious:false
                                                            Preview:.................>..o...,}............................................................$.......0.......>.......I.......S.......\...P...d...........1..........................9.......K.......M.......V.......^.......j.......w.......~....................................................................................................................7.......C.......I.......^.......q.......w...........................................(......................................................................................'.......0.......;.......A.......J...%...Q.......w...........S..................................................&.......;.......U.......r...................%........................................!.......,.......>.......B.......F.......M.......T.......g.......l.......z..............................................................................................$...........@.......P.......X.......`.......v.......}...............................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 2001 messages, Project-Id-Version: audacity 3.0.3 '\011 agus'
                                                            Category:dropped
                                                            Size (bytes):111479
                                                            Entropy (8bit):5.41588775035177
                                                            Encrypted:false
                                                            SSDEEP:3072:72dwyB1I5/FLJyWsopa1e2zMV2vAYdxOfllWeovjDUwjN6rnHcpCX3Kg8u3dbdym:adwyofLJX0Q2zMcvQsP8czSb
                                                            MD5:7764C3C9F02A9BFBCCB93173FC559C55
                                                            SHA1:873CCC5D8865A7590522BBCF7F66FF831F2CA207
                                                            SHA-256:677C07DD0D3F70015AFF3FFED39F2146CE52B5ED116C744CF46169427410535D
                                                            SHA-512:D1E35C4495F5191F85662E422EFAB9F28F0829650F51A935D625B887CC40BB87BC53DE3CABFDDA6D37EA843A5DD624E087609CAAC39E3FE4D16F7ED04E45FCBC
                                                            Malicious:false
                                                            Preview:.................>..o...,}............................................................$.......0.......>.......I.......S.......\...P...d...........1..........................9.......K.......M.......V.......^.......j.......w.......~....................................................................................................................7.......C.......I.......^.......q.......w...........................................(......................................................................................'.......0.......;.......A.......J...%...Q.......w...........S..................................................&.......;.......U.......r...................%........................................!.......,.......>.......B.......F.......M.......T.......g.......l.......z..............................................................................................$...........@.......P.......X.......`.......v.......}...............................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1695 messages, Project-Id-Version: audacity 3.0.3 'Os ficheiros amosados como PERDIDOS foron movidos ou eliminados e non \303\251 pos\303\255bel copialos.'
                                                            Category:dropped
                                                            Size (bytes):137309
                                                            Entropy (8bit):5.315607729059806
                                                            Encrypted:false
                                                            SSDEEP:3072:AAPtr/VrZo1x//Y9RDaNoJe6Wn0eAlf7h56kiTWpVjy:A+HEQ9RDYo86O0eAkTL
                                                            MD5:CA2781778C94A810B97B664A5754B4F2
                                                            SHA1:619404C4DA37C0553D8BF55CC23CF8684A48EFD0
                                                            SHA-256:45F77BE87B20C19BDBBDF70F2CCD68FFB21512489307FBB32CC49EB9186BE5D3
                                                            SHA-512:B04B6E88236BFA683F010DB2C12DFA7ED16A624B66839779D50D3302B9DC1F12CFCCE9E7BFAA182E17EAFA95249872BB0CDC6906E625CB7E6770874B2909A6AB
                                                            Malicious:false
                                                            Preview:.................5.......j......x.......y...'...........4...................................................................%...1..................................#...............f.......'..............u..........................4..........#.......*.......4.......;.......E.......O.......T.......[.......g...........J.......%..................................".......4.......B.......G.......P.......W.......a...(...n...........$..............................................................................................*.......:.......G.......P..."...Y.......|...................................................................................................).......5.......?.......L......._.......e.......n.......v....................................................................................................................$.......*......./.......F.......L.......P.......Y.......c.......u...........................................................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1695 messages, Project-Id-Version: audacity 3.0.3 'Os ficheiros amosados como PERDIDOS foron movidos ou eliminados e non \303\251 pos\303\255bel copialos.'
                                                            Category:dropped
                                                            Size (bytes):137309
                                                            Entropy (8bit):5.315607729059806
                                                            Encrypted:false
                                                            SSDEEP:3072:AAPtr/VrZo1x//Y9RDaNoJe6Wn0eAlf7h56kiTWpVjy:A+HEQ9RDYo86O0eAkTL
                                                            MD5:CA2781778C94A810B97B664A5754B4F2
                                                            SHA1:619404C4DA37C0553D8BF55CC23CF8684A48EFD0
                                                            SHA-256:45F77BE87B20C19BDBBDF70F2CCD68FFB21512489307FBB32CC49EB9186BE5D3
                                                            SHA-512:B04B6E88236BFA683F010DB2C12DFA7ED16A624B66839779D50D3302B9DC1F12CFCCE9E7BFAA182E17EAFA95249872BB0CDC6906E625CB7E6770874B2909A6AB
                                                            Malicious:false
                                                            Preview:.................5.......j......x.......y...'...........4...................................................................%...1..................................#...............f.......'..............u..........................4..........#.......*.......4.......;.......E.......O.......T.......[.......g...........J.......%..................................".......4.......B.......G.......P.......W.......a...(...n...........$..............................................................................................*.......:.......G.......P..."...Y.......|...................................................................................................).......5.......?.......L......._.......e.......n.......v....................................................................................................................$.......*......./.......F.......L.......P.......Y.......c.......u...........................................................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 736 messages, Project-Id-Version: audacity 3.0.3 '\327\224\327\247\327\221\327\246\327\231\327\235 \327\251\327\236\327\225\327\246\327\222\327\231\327\235 \327\233\327\227\327\241\327\250\327\231\327\235 \327\224\327\225\327\242\327\221\327\250\327\225 \327\220\327\225 \327\240\327\236\327\227\327\247\327\225 \327\225\327\234\327\220 \327\240\327\231\327\252\327\240\327\231\327\235 \327\234\327\224\327\242\327\252\327\247\327\224.'
                                                            Category:dropped
                                                            Size (bytes):53648
                                                            Entropy (8bit):5.256203369943165
                                                            Encrypted:false
                                                            SSDEEP:1536:r5yqB+8BaFhZoS420oadA0b5yGSiF86fG2OAWJH:9b6hZoS4HoadAC5NoBJH
                                                            MD5:FAD1CD277258D08BD3D3741D0A28D946
                                                            SHA1:C65F5463B8D20D0B3B6DABD0D13743F2C484961B
                                                            SHA-256:DAD9033277111119DEB0DA2062173B3F8EA631F8506D084906E6A1973B2F4547
                                                            SHA-512:DAADFDE74E735247AC412D57E3D5E01755F72A2D643F0108C1AC2C93B931996D2035B68BB37F959AB94EE5D25B7E07FB102BF5086F09FBC37F978BCAF502385D
                                                            Malicious:false
                                                            Preview:................................x=......y=.......>.......>...... >......)>.......>......u?.......@......5@......A@..J...L@..%....@.......@.......@.......@.......@.......@.......@.......@.......@.......A.......A......!A......'A......,A......6A......>A......GA......MA......^A......iA......oA......{A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......B.......B.......B.......B......)B......5B......<B......LB......VB......cB......iB......rB......zB.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......C.......C......$C..,...,C..%...YC..1....C..#....C..$....C.......C.......D......!D......3D......5D......>D......OD......VD......aD......cD......nD.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D../....D.......E...... E......0E......<E......IE......\E......jE.......E.......E.......E.......E.......E.......E.......E.......F.......F.......F......'F.. ...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 736 messages, Project-Id-Version: audacity 3.0.3 '\327\224\327\247\327\221\327\246\327\231\327\235 \327\251\327\236\327\225\327\246\327\222\327\231\327\235 \327\233\327\227\327\241\327\250\327\231\327\235 \327\224\327\225\327\242\327\221\327\250\327\225 \327\220\327\225 \327\240\327\236\327\227\327\247\327\225 \327\225\327\234\327\220 \327\240\327\231\327\252\327\240\327\231\327\235 \327\234\327\224\327\242\327\252\327\247\327\224.'
                                                            Category:dropped
                                                            Size (bytes):53648
                                                            Entropy (8bit):5.256203369943165
                                                            Encrypted:false
                                                            SSDEEP:1536:r5yqB+8BaFhZoS420oadA0b5yGSiF86fG2OAWJH:9b6hZoS4HoadAC5NoBJH
                                                            MD5:FAD1CD277258D08BD3D3741D0A28D946
                                                            SHA1:C65F5463B8D20D0B3B6DABD0D13743F2C484961B
                                                            SHA-256:DAD9033277111119DEB0DA2062173B3F8EA631F8506D084906E6A1973B2F4547
                                                            SHA-512:DAADFDE74E735247AC412D57E3D5E01755F72A2D643F0108C1AC2C93B931996D2035B68BB37F959AB94EE5D25B7E07FB102BF5086F09FBC37F978BCAF502385D
                                                            Malicious:false
                                                            Preview:................................x=......y=.......>.......>...... >......)>.......>......u?.......@......5@......A@..J...L@..%....@.......@.......@.......@.......@.......@.......@.......@.......@.......A.......A......!A......'A......,A......6A......>A......GA......MA......^A......iA......oA......{A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......A.......B.......B.......B.......B......)B......5B......<B......LB......VB......cB......iB......rB......zB.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......B.......C.......C......$C..,...,C..%...YC..1....C..#....C..$....C.......C.......D......!D......3D......5D......>D......OD......VD......aD......cD......nD.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D../....D.......E...... E......0E......<E......IE......\E......jE.......E.......E.......E.......E.......E.......E.......E.......F.......F.......F......'F.. ...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 \340\244\224\340\244\260'
                                                            Category:dropped
                                                            Size (bytes):518134
                                                            Entropy (8bit):5.297074821332897
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Up8Fxr6sYRDjIoj5/asc+1A7MwpcXWGacb4:6R+VVA7MwpcyX
                                                            MD5:ED73E2DD866FA3B785A8E53D6C5D04C9
                                                            SHA1:D0F687C7DD6ADB6802CA6611505A37B98C0C4650
                                                            SHA-256:0F51009F014DEA902E4E312E1AD59F11334569434B3C22DC29F96289565BAF35
                                                            SHA-512:96C6246A9064E8F1C0C0B5224C71F5E3DA83CD0E908BD575EF880D4966B9C12908C41F734EBFB33D088F4D81A578AF41F33F075B3C04818EB27D4EDC0AB50D11
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 \340\244\224\340\244\260'
                                                            Category:dropped
                                                            Size (bytes):518134
                                                            Entropy (8bit):5.297074821332897
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Up8Fxr6sYRDjIoj5/asc+1A7MwpcXWGacb4:6R+VVA7MwpcyX
                                                            MD5:ED73E2DD866FA3B785A8E53D6C5D04C9
                                                            SHA1:D0F687C7DD6ADB6802CA6611505A37B98C0C4650
                                                            SHA-256:0F51009F014DEA902E4E312E1AD59F11334569434B3C22DC29F96289565BAF35
                                                            SHA-512:96C6246A9064E8F1C0C0B5224C71F5E3DA83CD0E908BD575EF880D4966B9C12908C41F734EBFB33D088F4D81A578AF41F33F075B3C04818EB27D4EDC0AB50D11
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1395 messages, Project-Id-Version: audacity 3.0.3 'Datoteke s pridjevom NEDOSTAJE premje\305\241tene su ili izbrisane i ne mogu se kopirati.'
                                                            Category:dropped
                                                            Size (bytes):106809
                                                            Entropy (8bit):5.387744707386487
                                                            Encrypted:false
                                                            SSDEEP:3072:BAts6w+O9jn9PSZoKeyoBRD2cnIP+YAoUiZ6IPU9yM2XlqqRtbi2ELM29Ab42:BAtjwr9u+RDzn++YADIPUIMgqqRtbi2J
                                                            MD5:A10E4E94831D9FDCE5DD19BDD8EA8223
                                                            SHA1:79039E58464688BE59F7B66D7373B9E6546493EA
                                                            SHA-256:5B4F326D9EEFF320C78C1A9F059F4F3A5CE96D1CCAE09622DE18C80B0F4B275C
                                                            SHA-512:1F02232B6266BC3C62155BD843E1046D4A588441A1F0DEBB80B342FC5CC983CC14B0B75A10F04478A8238FBDF00F1948E4DCFE1D38E13BC0D1B2BADEF13F2015
                                                            Malicious:false
                                                            Preview:........s........+..E...LW......`t......at..'....t.......u.......u.......u.......u.......u..1...gv.......v......:w......7x.......x......by.......z.......z.......{......#|.......|......f}.......~..4....~.......~.......~.......~.......~.......~.......~..................................J...9...%.......................................................................(...........1.......9.......@.......G.......\.......e.......k.......s.......x..................................."................................................................!.......*.......6.......@.......M.......`.......f.......n.......y...................................................................................................................................&.......8.......D.......K.......R.......b.......l.......|.............................................................................................................).......<.......O.......^.......k.......v...............................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1395 messages, Project-Id-Version: audacity 3.0.3 'Datoteke s pridjevom NEDOSTAJE premje\305\241tene su ili izbrisane i ne mogu se kopirati.'
                                                            Category:dropped
                                                            Size (bytes):106809
                                                            Entropy (8bit):5.387744707386487
                                                            Encrypted:false
                                                            SSDEEP:3072:BAts6w+O9jn9PSZoKeyoBRD2cnIP+YAoUiZ6IPU9yM2XlqqRtbi2ELM29Ab42:BAtjwr9u+RDzn++YADIPUIMgqqRtbi2J
                                                            MD5:A10E4E94831D9FDCE5DD19BDD8EA8223
                                                            SHA1:79039E58464688BE59F7B66D7373B9E6546493EA
                                                            SHA-256:5B4F326D9EEFF320C78C1A9F059F4F3A5CE96D1CCAE09622DE18C80B0F4B275C
                                                            SHA-512:1F02232B6266BC3C62155BD843E1046D4A588441A1F0DEBB80B342FC5CC983CC14B0B75A10F04478A8238FBDF00F1948E4DCFE1D38E13BC0D1B2BADEF13F2015
                                                            Malicious:false
                                                            Preview:........s........+..E...LW......`t......at..'....t.......u.......u.......u.......u.......u..1...gv.......v......:w......7x.......x......by.......z.......z.......{......#|.......|......f}.......~..4....~.......~.......~.......~.......~.......~.......~..................................J...9...%.......................................................................(...........1.......9.......@.......G.......\.......e.......k.......s.......x..................................."................................................................!.......*.......6.......@.......M.......`.......f.......n.......y...................................................................................................................................&.......8.......D.......K.......R.......b.......l.......|.............................................................................................................).......<.......O.......^.......k.......v...............................................
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3791 messages, Project-Id-Version: audacity 3.0.3 '\011 \303\251s'
                                                            Category:dropped
                                                            Size (bytes):293251
                                                            Entropy (8bit):5.6075761521711165
                                                            Encrypted:false
                                                            SSDEEP:6144:35p2X8wDyatrNRLlRD2oI4VYqMA70YEKGiTWSaIu2w3:3/r7pA7Lj4
                                                            MD5:BA096BD0B692397AC8492831204C5E51
                                                            SHA1:BD6D58E8BB66B245EA034B9192E3F44DE07E624A
                                                            SHA-256:E504C38FAA11F3F09CF2B0DAB465E7C8ED1D2609902F9788BE70A17305E5D884
                                                            SHA-512:F5853C999BBD1FCA27A5C8AD8AB596578448F9060002C311515AB699621546C5527888217705DE32AE55B668ABCE5F5A6C33349C633F9B925145AA79D38EE8D9
                                                            Malicious:false
                                                            Preview:.................v...............<.......<......$<..'....<..:....<.......=..$....=..6...C=..(...z=.......=......=>..|....>..S...N?..G....?..*....?..K....@......a@..m....A.......A.......B.......B.......C.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D..g....E..P...nE.......E..F...SF.......F..1....F.......F.......G.......H.......I.......I......_J...... K.......K......nL......6M.......M......yN.......O..0....O.......O.......O..4....P......FP......HP......VP......_P......gP......sP.......P.......P.......P.......P.......P.......P.......P.......P.......P.......P.......P.......P.......Q.......Q.......Q......7Q......@Q......LQ......RQ......gQ......zQ.......Q.......Q.......Q.......Q.......Q.......Q.......Q..8....Q..;....R......MR......lR..7....R.......R.......R.......R..R....R..0...RS.......S..(....S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T..J....T......eT......kT......tT..-...{T..%....T..$....T......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3791 messages, Project-Id-Version: audacity 3.0.3 '\011 \303\251s'
                                                            Category:dropped
                                                            Size (bytes):293251
                                                            Entropy (8bit):5.6075761521711165
                                                            Encrypted:false
                                                            SSDEEP:6144:35p2X8wDyatrNRLlRD2oI4VYqMA70YEKGiTWSaIu2w3:3/r7pA7Lj4
                                                            MD5:BA096BD0B692397AC8492831204C5E51
                                                            SHA1:BD6D58E8BB66B245EA034B9192E3F44DE07E624A
                                                            SHA-256:E504C38FAA11F3F09CF2B0DAB465E7C8ED1D2609902F9788BE70A17305E5D884
                                                            SHA-512:F5853C999BBD1FCA27A5C8AD8AB596578448F9060002C311515AB699621546C5527888217705DE32AE55B668ABCE5F5A6C33349C633F9B925145AA79D38EE8D9
                                                            Malicious:false
                                                            Preview:.................v...............<.......<......$<..'....<..:....<.......=..$....=..6...C=..(...z=.......=......=>..|....>..S...N?..G....?..*....?..K....@......a@..m....A.......A.......B.......B.......C.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D.......D..g....E..P...nE.......E..F...SF.......F..1....F.......F.......G.......H.......I.......I......_J...... K.......K......nL......6M.......M......yN.......O..0....O.......O.......O..4....P......FP......HP......VP......_P......gP......sP.......P.......P.......P.......P.......P.......P.......P.......P.......P.......P.......P.......P.......Q.......Q.......Q......7Q......@Q......LQ......RQ......gQ......zQ.......Q.......Q.......Q.......Q.......Q.......Q.......Q..8....Q..;....R......MR......lR..7....R.......R.......R.......R..R....R..0...RS.......S..(....S.......S.......S.......S.......S.......S.......S.......S.......S.......S.......T.......T..J....T......eT......kT......tT..-...{T..%....T..$....T......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1485 messages, Project-Id-Version: audacity 3.0.3 '\325\226\325\241\325\265\325\254\325\245\326\200\325\250 \325\270\326\200\325\272\325\245\325\275 \324\262\324\261\325\221\324\261\324\277\324\261 \325\277\325\245\325\262\325\241\326\203\325\270\325\255\325\276\325\245\325\254 \325\257\325\241\325\264 \325\273\325\266\325\273\325\276\325\245\325\254 \325\245\325\266 \326\207 \325\271\325\245\325\266 \325\257\325\241\326\200\325\270\325\262 \325\272\325\241\325\277\325\263\325\245\325\266\325\276\325\245\325\254:'
                                                            Category:dropped
                                                            Size (bytes):144869
                                                            Entropy (8bit):5.471348376301057
                                                            Encrypted:false
                                                            SSDEEP:3072:uJnyCpQMRZoynl//RDD7j3hIXA0o8bW5PJL:snZpD3RDfjRIXAYbAPZ
                                                            MD5:01CAD7A6DB18C3D4FC43C8E5894D618D
                                                            SHA1:283D9FC8C8EA9897FF3EFA43D0F76BCC8C30F842
                                                            SHA-256:BCAAAA114701ADB167FE28D51BCEA1FA801976370ED929138B2B3B6BEA9EAC5F
                                                            SHA-512:C880FF6CC845CCB46BEFBFB2724A706CAADD6B6466623AB8C9F32021178913CC64F59233D6B2C67AFD6D690706F2259928D3F1CE572B45C8F8235521492EDE75
                                                            Malicious:false
                                                            Preview:.........................\.......{.......{..'....|.......|......N}......W}......b}......k}..1....}......1~.......~..............i.......................m.......'...............Y...................4...4.......i.......p.......z...........................................J......%...........3.......F.......K.......Y.......k.......y.......~...................(..............$.................................................'.......-.......5.......:.......D.......L.......Z.......j.......w...........".......................................................................................&.......3.......?.......I.......V.......i.......o.......x...........................................................................................................................#.......4.......:.......?.......E.......I.......R.......\.......n.......z....................................................................................................................'.......4.......P.......`.......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1485 messages, Project-Id-Version: audacity 3.0.3 '\325\226\325\241\325\265\325\254\325\245\326\200\325\250 \325\270\326\200\325\272\325\245\325\275 \324\262\324\261\325\221\324\261\324\277\324\261 \325\277\325\245\325\262\325\241\326\203\325\270\325\255\325\276\325\245\325\254 \325\257\325\241\325\264 \325\273\325\266\325\273\325\276\325\245\325\254 \325\245\325\266 \326\207 \325\271\325\245\325\266 \325\257\325\241\326\200\325\270\325\262 \325\272\325\241\325\277\325\263\325\245\325\266\325\276\325\245\325\254:'
                                                            Category:dropped
                                                            Size (bytes):144869
                                                            Entropy (8bit):5.471348376301057
                                                            Encrypted:false
                                                            SSDEEP:3072:uJnyCpQMRZoynl//RDD7j3hIXA0o8bW5PJL:snZpD3RDfjRIXAYbAPZ
                                                            MD5:01CAD7A6DB18C3D4FC43C8E5894D618D
                                                            SHA1:283D9FC8C8EA9897FF3EFA43D0F76BCC8C30F842
                                                            SHA-256:BCAAAA114701ADB167FE28D51BCEA1FA801976370ED929138B2B3B6BEA9EAC5F
                                                            SHA-512:C880FF6CC845CCB46BEFBFB2724A706CAADD6B6466623AB8C9F32021178913CC64F59233D6B2C67AFD6D690706F2259928D3F1CE572B45C8F8235521492EDE75
                                                            Malicious:false
                                                            Preview:.........................\.......{.......{..'....|.......|......N}......W}......b}......k}..1....}......1~.......~..............i.......................m.......'...............Y...................4...4.......i.......p.......z...........................................J......%...........3.......F.......K.......Y.......k.......y.......~...................(..............$.................................................'.......-.......5.......:.......D.......L.......Z.......j.......w...........".......................................................................................&.......3.......?.......I.......V.......i.......o.......x...........................................................................................................................#.......4.......:.......?.......E.......I.......R.......\.......n.......z....................................................................................................................'.......4.......P.......`.......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1130 messages, Project-Id-Version: audacity 3.0.3 'Jika disimpan, proyek tidak akan punya trek.'
                                                            Category:dropped
                                                            Size (bytes):81437
                                                            Entropy (8bit):5.281940335475547
                                                            Encrypted:false
                                                            SSDEEP:1536:SAopKQRJxXIdnkqTZoL6H5RTzmgXLNANJ4WdGe7cVZ1SZX:SAW1fqTZoL6H5dmgXLNA7GXZ1SZX
                                                            MD5:BADD6868EE0847C3DC4AC237118F226B
                                                            SHA1:063178CB6A60BB1AF45048EF996EFEE2550BE99E
                                                            SHA-256:288E1910B5CCA9273DC9E124F2BC167C7DB718FA292709D302BACE5EB4F34128
                                                            SHA-512:65F6CF5A57AE46541082A314F2E931D40215B92DF76E86946318F849956B6E1C48D5085C8F125063A9D7592140BDBAE0851741B55CE8A66661EB81906BC78F42
                                                            Malicious:false
                                                            Preview:........j.......l#.......F......X^......Y^.......^.......^......._......._..1...._......._......w`......ta.......b.......b......Qc.......d.......d......`e.......e.......f.......g..4....g.......h.......h.......h......&h......-h......9h..J...Dh..%....h.......h.......h.......h.......h.......h.......h..(....h.......i......$i......+i......2i......Gi......Pi......Vi......[i......ei......mi......}i.......i.."....i.......i.......i.......i.......i.......i.......i.......i.......j.......j.......j.......j......#j......+j......1j......>j......Ij......Tj......oj......xj.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......k.......k.......k......!k......*k......2k......?k......[k......mk......{k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......l.......l.......l......*l......=l..,...El..%...rl..1....l..#....l..$....l..$....m......8m......Bm......Nm......^m......zm.......m..*....m.......m.......m......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1130 messages, Project-Id-Version: audacity 3.0.3 'Jika disimpan, proyek tidak akan punya trek.'
                                                            Category:dropped
                                                            Size (bytes):81437
                                                            Entropy (8bit):5.281940335475547
                                                            Encrypted:false
                                                            SSDEEP:1536:SAopKQRJxXIdnkqTZoL6H5RTzmgXLNANJ4WdGe7cVZ1SZX:SAW1fqTZoL6H5dmgXLNA7GXZ1SZX
                                                            MD5:BADD6868EE0847C3DC4AC237118F226B
                                                            SHA1:063178CB6A60BB1AF45048EF996EFEE2550BE99E
                                                            SHA-256:288E1910B5CCA9273DC9E124F2BC167C7DB718FA292709D302BACE5EB4F34128
                                                            SHA-512:65F6CF5A57AE46541082A314F2E931D40215B92DF76E86946318F849956B6E1C48D5085C8F125063A9D7592140BDBAE0851741B55CE8A66661EB81906BC78F42
                                                            Malicious:false
                                                            Preview:........j.......l#.......F......X^......Y^.......^.......^......._......._..1...._......._......w`......ta.......b.......b......Qc.......d.......d......`e.......e.......f.......g..4....g.......h.......h.......h......&h......-h......9h..J...Dh..%....h.......h.......h.......h.......h.......h.......h..(....h.......i......$i......+i......2i......Gi......Pi......Vi......[i......ei......mi......}i.......i.."....i.......i.......i.......i.......i.......i.......i.......i.......j.......j.......j.......j......#j......+j......1j......>j......Ij......Tj......oj......xj.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......j.......k.......k.......k......!k......*k......2k......?k......[k......mk......{k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......l.......l.......l......*l......=l..,...El..%...rl..1....l..#....l..$....l..$....m......8m......Bm......Nm......^m......zm.......m..*....m.......m.......m......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 e'
                                                            Category:dropped
                                                            Size (bytes):361481
                                                            Entropy (8bit):5.336068376224258
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UUx/YopsYRDjIoj5/asc+1A7MS0SSecSJgUPYSKsAFhEKuRiqFy+TsViW:6f9VVA7MReFmq0R
                                                            MD5:5114CC8B838CE076B28DE9860F90B0CE
                                                            SHA1:431D17A701F332CF4C26B3E9D7031C10CE7695A9
                                                            SHA-256:5FF79175355A9D4D44A1E769788B4E12C0C554CAB92D97E1C153FF9F489E34B5
                                                            SHA-512:C893BA08FE07799B3390151BE75479B05C725AB75DD43AA04DAB9F14FF852E9D6B0D36D5B6BF0ABFBA1112EC5C2E97F6D0289DCF8A6230987F81B6EE4157821F
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 e'
                                                            Category:dropped
                                                            Size (bytes):361481
                                                            Entropy (8bit):5.336068376224258
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UUx/YopsYRDjIoj5/asc+1A7MS0SSecSJgUPYSKsAFhEKuRiqFy+TsViW:6f9VVA7MReFmq0R
                                                            MD5:5114CC8B838CE076B28DE9860F90B0CE
                                                            SHA1:431D17A701F332CF4C26B3E9D7031C10CE7695A9
                                                            SHA-256:5FF79175355A9D4D44A1E769788B4E12C0C554CAB92D97E1C153FF9F489E34B5
                                                            SHA-512:C893BA08FE07799B3390151BE75479B05C725AB75DD43AA04DAB9F14FF852E9D6B0D36D5B6BF0ABFBA1112EC5C2E97F6D0289DCF8A6230987F81B6EE4157821F
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4113 messages, Project-Id-Version: audacity 3.0.3 '\011'
                                                            Category:dropped
                                                            Size (bytes):375592
                                                            Entropy (8bit):6.102325041233545
                                                            Encrypted:false
                                                            SSDEEP:6144:sY0rgUc6md/wCQRDjwoDbGyoc+HA7+Ol84cARHncXFi:tYAYLxUA7+OVcARHncXFi
                                                            MD5:F6A5D8884BC4E19DAFCF1A5241F0E74C
                                                            SHA1:29AF087C83EED4932BC8F695A9103DB1EE99F729
                                                            SHA-256:BA544D94DAB7E9D244A0A4EFF9AB7DB283917113D2A1155C9650C76606AD94F3
                                                            SHA-512:CC1CA603162F62B3EE0A06537F4B98879720A8C41013AB9A8B42DBC1B32134B164912BA5CD6F3D3C203CB87895DC148A21E098F986CD89915BC7F69B34624005
                                                            Malicious:false
                                                            Preview:....................}...,....... W......!W......,W..'....W..:....W......"X..$...&X..6...KX..(....X.......X......EY..|....Y..S...VZ..G....Z..*....Z..K....[......i[..m....\.......\.......].......].......^......._......._......._......._......._......._......._......._......._......._......._.......`..g....`..P...v`.......`..F...[a.......a..1....a.......a.......b.......c......$d.......d......ge......(f.......f......vg......>h.......h.......i.......j..0....j.......j..4....k......<k......>k......Lk......Uk......]k......ik......vk......}k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......l.......l......(l......1l......=l......Cl......Xl......kl.......l.......l.......l.......l.......l.......l.......l..8....l..;....m......>m......]m..7...ym.......m.......m.......m..R....m..0...Cn......tn..(...|n.......n.......n.......n.......n.......n.......n.......n.......n.......n.......n.......n.......o..J....o......^o......do......mo..-...to..%....o..$....o.......o......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4113 messages, Project-Id-Version: audacity 3.0.3 '\011'
                                                            Category:dropped
                                                            Size (bytes):375592
                                                            Entropy (8bit):6.102325041233545
                                                            Encrypted:false
                                                            SSDEEP:6144:sY0rgUc6md/wCQRDjwoDbGyoc+HA7+Ol84cARHncXFi:tYAYLxUA7+OVcARHncXFi
                                                            MD5:F6A5D8884BC4E19DAFCF1A5241F0E74C
                                                            SHA1:29AF087C83EED4932BC8F695A9103DB1EE99F729
                                                            SHA-256:BA544D94DAB7E9D244A0A4EFF9AB7DB283917113D2A1155C9650C76606AD94F3
                                                            SHA-512:CC1CA603162F62B3EE0A06537F4B98879720A8C41013AB9A8B42DBC1B32134B164912BA5CD6F3D3C203CB87895DC148A21E098F986CD89915BC7F69B34624005
                                                            Malicious:false
                                                            Preview:....................}...,....... W......!W......,W..'....W..:....W......"X..$...&X..6...KX..(....X.......X......EY..|....Y..S...VZ..G....Z..*....Z..K....[......i[..m....\.......\.......].......].......^......._......._......._......._......._......._......._......._......._......._......._.......`..g....`..P...v`.......`..F...[a.......a..1....a.......a.......b.......c......$d.......d......ge......(f.......f......vg......>h.......h.......i.......j..0....j.......j..4....k......<k......>k......Lk......Uk......]k......ik......vk......}k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......k.......l.......l......(l......1l......=l......Cl......Xl......kl.......l.......l.......l.......l.......l.......l.......l..8....l..;....m......>m......]m..7...ym.......m.......m.......m..R....m..0...Cn......tn..(...|n.......n.......n.......n.......n.......n.......n.......n.......n.......n.......n.......n.......o..J....o......^o......do......mo..-...to..%....o..$....o.......o......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3520 messages, Project-Id-Version: audacity 3.0.3 '\011 \341\203\223\341\203\220'
                                                            Category:dropped
                                                            Size (bytes):372728
                                                            Entropy (8bit):5.0538744931031045
                                                            Encrypted:false
                                                            SSDEEP:6144:zSrZnFO78XAtRDjeiRIDc+nAibAbn5dYLdtH2c+5Atf666J:yae7AiM
                                                            MD5:C1B5E24889EB3780DD62DFC38D8B8B3B
                                                            SHA1:C325205526C5F3A3498B4B001F2F808E4197B45F
                                                            SHA-256:574010B62F4AEA7B5C814361A9D1FAEABB763DA3611A729E66F5C6E6849CCEC9
                                                            SHA-512:0A256CACD7C97B08FD66CB93DEBB51B739C8F4028C009266BD731B132D6CB1EBD95986608BA3E6287F5A7ADD517031805BA0A61B2537E9DB6EA952E10D595A33
                                                            Malicious:false
                                                            Preview:.................n.._............%.......%..'....%.......%..$....%..(....%.......&.......&.......&.......&.......&.......&.......&.......&.......'.......'.......'.......'......+'..F....'.......(..1....(......P(.......(.......).......*.......+.......+.......,......F-.......-..............@/......./.......1..0....1......P1......k1..4...}1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......2.......2.......2...... 2......*2......42......:2......?2......\2......w2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3.......3......-3..7...I3.......3.......3.......3.......3..(....3.......3.......3.......3.......4.......4.......4.......4......,4......74......@4......K4......Q4......Z4..-...a4..%....4.......4.......4.......4.......4.......5......"5......,5......85..(...M5......v5.......5.......5.......5.......5..%....5.......6.......6......,6......B6......\6......g6......y6......}6.......6..!....6..!....6.......6......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3520 messages, Project-Id-Version: audacity 3.0.3 '\011 \341\203\223\341\203\220'
                                                            Category:dropped
                                                            Size (bytes):372728
                                                            Entropy (8bit):5.0538744931031045
                                                            Encrypted:false
                                                            SSDEEP:6144:zSrZnFO78XAtRDjeiRIDc+nAibAbn5dYLdtH2c+5Atf666J:yae7AiM
                                                            MD5:C1B5E24889EB3780DD62DFC38D8B8B3B
                                                            SHA1:C325205526C5F3A3498B4B001F2F808E4197B45F
                                                            SHA-256:574010B62F4AEA7B5C814361A9D1FAEABB763DA3611A729E66F5C6E6849CCEC9
                                                            SHA-512:0A256CACD7C97B08FD66CB93DEBB51B739C8F4028C009266BD731B132D6CB1EBD95986608BA3E6287F5A7ADD517031805BA0A61B2537E9DB6EA952E10D595A33
                                                            Malicious:false
                                                            Preview:.................n.._............%.......%..'....%.......%..$....%..(....%.......&.......&.......&.......&.......&.......&.......&.......&.......'.......'.......'.......'......+'..F....'.......(..1....(......P(.......(.......).......*.......+.......+.......,......F-.......-..............@/......./.......1..0....1......P1......k1..4...}1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......2.......2.......2...... 2......*2......42......:2......?2......\2......w2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......2.......3.......3.......3......-3..7...I3.......3.......3.......3.......3..(....3.......3.......3.......3.......4.......4.......4.......4......,4......74......@4......K4......Q4......Z4..-...a4..%....4.......4.......4.......4.......4.......5......"5......,5......85..(...M5......v5.......5.......5.......5.......5..%....5.......6.......6......,6......B6......\6......g6......y6......}6.......6..!....6..!....6.......6......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 688 messages, Project-Id-Version: audacity 3.0.3 '\341\236\237\341\237\222\341\236\204\341\236\266\341\236\217\341\237\213'
                                                            Category:dropped
                                                            Size (bytes):71398
                                                            Entropy (8bit):5.247177538324745
                                                            Encrypted:false
                                                            SSDEEP:1536:Vqx2nQcpZoJKKkReRaA1+Yr1poJcEJI7LQakxP6pc/:rZoJKKWeRaA1NRpobI7LQakxypc/
                                                            MD5:D8724AAF15120878B95DFF3D17B2482D
                                                            SHA1:890BDD6A3BA15C44CAD80D0760B11E8A91F24924
                                                            SHA-256:85A68892778183A3FF74E9A4E930B530E2506C841514D9F39DEADF9DB9DEE10A
                                                            SHA-512:036BDF0639CCDECC2CF9F92750FB19ABCE6095AC4B18C590A7FA3F1F4865D11ACBB2BA3BCA90B90390EC012A006EA06723DA239E731636DD8B6B7DD392166556
                                                            Malicious:false
                                                            Preview:.........................+......x9......y9.......9.......9..1....9.......9.......9.......9..%....9...... :......3:......8:......=:......F:..(...P:......y:.......:.......:.......:.......:.......:.......:.......:.......:.......:.."....:.......:.......:.......;.......;.......;......(;.......;......6;......A;......I;......O;......\;......g;......p;......y;......~;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......<.......<.......<......#<......1<......=<......E<......K<......T<......Z<......m<......y<.......<..,....<..%....<..1....<..#....=..$...==......b=......n=.......=.......=..*....=.......=.......>......">......B>......`>......y>.......>.......>.......>.......>.......>.......?.......?.......?......&?......-?......8?......:?......E?......Y?......`?......k?......m?......z?......|?......~?.......?.......?.......?.......?.......?.......?.......?.......?.......?.......?.......@.......@......!@......3@......;@......?@......R@......[@.. ...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 688 messages, Project-Id-Version: audacity 3.0.3 '\341\236\237\341\237\222\341\236\204\341\236\266\341\236\217\341\237\213'
                                                            Category:dropped
                                                            Size (bytes):71398
                                                            Entropy (8bit):5.247177538324745
                                                            Encrypted:false
                                                            SSDEEP:1536:Vqx2nQcpZoJKKkReRaA1+Yr1poJcEJI7LQakxP6pc/:rZoJKKWeRaA1NRpobI7LQakxypc/
                                                            MD5:D8724AAF15120878B95DFF3D17B2482D
                                                            SHA1:890BDD6A3BA15C44CAD80D0760B11E8A91F24924
                                                            SHA-256:85A68892778183A3FF74E9A4E930B530E2506C841514D9F39DEADF9DB9DEE10A
                                                            SHA-512:036BDF0639CCDECC2CF9F92750FB19ABCE6095AC4B18C590A7FA3F1F4865D11ACBB2BA3BCA90B90390EC012A006EA06723DA239E731636DD8B6B7DD392166556
                                                            Malicious:false
                                                            Preview:.........................+......x9......y9.......9.......9..1....9.......9.......9.......9..%....9...... :......3:......8:......=:......F:..(...P:......y:.......:.......:.......:.......:.......:.......:.......:.......:.......:.."....:.......:.......:.......;.......;.......;......(;.......;......6;......A;......I;......O;......\;......g;......p;......y;......~;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......;.......<.......<.......<......#<......1<......=<......E<......K<......T<......Z<......m<......y<.......<..,....<..%....<..1....<..#....=..$...==......b=......n=.......=.......=..*....=.......=.......>......">......B>......`>......y>.......>.......>.......>.......>.......>.......?.......?.......?......&?......-?......8?......:?......E?......Y?......`?......k?......m?......z?......|?......~?.......?.......?.......?.......?.......?.......?.......?.......?.......?.......?.......@.......@......!@......3@......;@......?@......R@......[@.. ...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4352 messages, Project-Id-Version: audacity 3.0.3 '\011 \352\267\270\353\246\254\352\263\240'
                                                            Category:dropped
                                                            Size (bytes):368685
                                                            Entropy (8bit):6.118476253055392
                                                            Encrypted:false
                                                            SSDEEP:6144:fbOPOQ1BahHbe/P9YRDjIoj5/asc+1A7MNUc0RjAv:j0BGeqVVA7MNUBZi
                                                            MD5:0408741D58C5467D3623A75C1AA29A88
                                                            SHA1:C3ED1B6E6221D371C90DA87429B388E539651D8B
                                                            SHA-256:96D27A28D6A805F5AE554753CDE12DCA3DB1CCF62ACEB87F8FA4C696A0E5CCE0
                                                            SHA-512:753AFCC30ED834D8BC02E595E19F53C53826E49D453030EBBC58EB4D5FB8ED2001687AFC603F946463717B26836127386C36A77C1A9152F78D14766C40CA1692
                                                            Malicious:false
                                                            Preview:.................................j.......j.......j..'...wk..:....k.......k..$....k..6....l..(...:l......cl.......l..|....m..S....n..G...bn..*....n..K....n......!o..m....o......?p.......p.......q......Br......Is......Rs......\s......is......rs......ys.......s.......s.......s.......s.......s.......s..g....s..P....t.......t..F....u......Zu..1...ru.......u......Ev......Bw.......w......mx.......y.......y.......z.......{.......{.......|......9}......T~..0...s~.......~.......~..4....~......................................'.......3.......@.......G.......O.......X.......b.......i.......q.......}.......................................................................................................0.......C.......\.......b.......s.......{...........................8.......;..................5...7...Q...........................R......0...........L...(...T.......}...............................................................................................J...........C.......I.......R...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4352 messages, Project-Id-Version: audacity 3.0.3 '\011 \352\267\270\353\246\254\352\263\240'
                                                            Category:dropped
                                                            Size (bytes):368685
                                                            Entropy (8bit):6.118476253055392
                                                            Encrypted:false
                                                            SSDEEP:6144:fbOPOQ1BahHbe/P9YRDjIoj5/asc+1A7MNUc0RjAv:j0BGeqVVA7MNUBZi
                                                            MD5:0408741D58C5467D3623A75C1AA29A88
                                                            SHA1:C3ED1B6E6221D371C90DA87429B388E539651D8B
                                                            SHA-256:96D27A28D6A805F5AE554753CDE12DCA3DB1CCF62ACEB87F8FA4C696A0E5CCE0
                                                            SHA-512:753AFCC30ED834D8BC02E595E19F53C53826E49D453030EBBC58EB4D5FB8ED2001687AFC603F946463717B26836127386C36A77C1A9152F78D14766C40CA1692
                                                            Malicious:false
                                                            Preview:.................................j.......j.......j..'...wk..:....k.......k..$....k..6....l..(...:l......cl.......l..|....m..S....n..G...bn..*....n..K....n......!o..m....o......?p.......p.......q......Br......Is......Rs......\s......is......rs......ys.......s.......s.......s.......s.......s.......s..g....s..P....t.......t..F....u......Zu..1...ru.......u......Ev......Bw.......w......mx.......y.......y.......z.......{.......{.......|......9}......T~..0...s~.......~.......~..4....~......................................'.......3.......@.......G.......O.......X.......b.......i.......q.......}.......................................................................................................0.......C.......\.......b.......s.......{...........................8.......;..................5...7...Q...........................R......0...........L...(...T.......}...............................................................................................J...........C.......I.......R...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1510 messages, Project-Id-Version: audacity 3.0.3 'Failas rodomas kaip MISSING buvo perkeltas arba i\305\241trintas ir negali b\305\253ti nukopijuotas.'
                                                            Category:dropped
                                                            Size (bytes):114347
                                                            Entropy (8bit):5.409178326762448
                                                            Encrypted:false
                                                            SSDEEP:3072:zmDpL4dDBguuoEy6xDXQwNc/c6vQ6EsLhrtIS3mH:C9LUDBtWDXLNc/c6v3qn
                                                            MD5:B18305650617D59208857FD94C1740E3
                                                            SHA1:7049304958918C22BB34A9D8A3A7707A06E8B2C6
                                                            SHA-256:3438CFE526C90F50608F79D0BD347843526AA141DA333DD91AF4C911024F4D32
                                                            SHA-512:5C3DDB38194C310DE46500078E943A004BC14BBB460D8714B9B6B432226ECB8158B0A17F0411B270AD9AE4455C2DFA54A7AD1BFFA63538F8D121199D6990B7ED
                                                            Malicious:false
                                                            Preview:................L/......|^.......~.......~..'....~.......~......V......._.......j.......s.......{...............................................................................................$.......5...8...J...;..........................................-.......8...J...C...........%...........................................E...........?.......Y.......o.......v.......................................................................................................... .......(.......0.......F.......M.......b.......k.......q.......~..................................................................................................................#.......1.......:.......B.......Q.......Y.......j.......u....................................................................................................................*.......2.......8.......E.......M.......X.......e.......k...%....................................................................$...........D.......P.......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1510 messages, Project-Id-Version: audacity 3.0.3 'Failas rodomas kaip MISSING buvo perkeltas arba i\305\241trintas ir negali b\305\253ti nukopijuotas.'
                                                            Category:dropped
                                                            Size (bytes):114347
                                                            Entropy (8bit):5.409178326762448
                                                            Encrypted:false
                                                            SSDEEP:3072:zmDpL4dDBguuoEy6xDXQwNc/c6vQ6EsLhrtIS3mH:C9LUDBtWDXLNc/c6v3qn
                                                            MD5:B18305650617D59208857FD94C1740E3
                                                            SHA1:7049304958918C22BB34A9D8A3A7707A06E8B2C6
                                                            SHA-256:3438CFE526C90F50608F79D0BD347843526AA141DA333DD91AF4C911024F4D32
                                                            SHA-512:5C3DDB38194C310DE46500078E943A004BC14BBB460D8714B9B6B432226ECB8158B0A17F0411B270AD9AE4455C2DFA54A7AD1BFFA63538F8D121199D6990B7ED
                                                            Malicious:false
                                                            Preview:................L/......|^.......~.......~..'....~.......~......V......._.......j.......s.......{...............................................................................................$.......5...8...J...;..........................................-.......8...J...C...........%...........................................E...........?.......Y.......o.......v.......................................................................................................... .......(.......0.......F.......M.......b.......k.......q.......~..................................................................................................................#.......1.......:.......B.......Q.......Y.......j.......u....................................................................................................................*.......2.......8.......E.......M.......X.......e.......k...%....................................................................$...........D.......P.......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 242 messages, Project-Id-Version: audacity 3.0.3 '\320\227&\320\260 Audacity...'
                                                            Category:dropped
                                                            Size (bytes):18821
                                                            Entropy (8bit):5.275982877855045
                                                            Encrypted:false
                                                            SSDEEP:384:syYU/3G9z1OQtyovQ0JMoAYnDg/NX/rvWLirjXrTqggJGEaMK:VYNzQ7oYLYuXz8Oig4XK
                                                            MD5:231AB61DFBC7FD71FD71DE3E31D19FF8
                                                            SHA1:5790F38B62478A214E96CD576D74FB95B6FD386A
                                                            SHA-256:693C3D4B73109025B2D103628E97C153EF3F931DCDCA63853536AB8E73BFE616
                                                            SHA-512:D547F8783388D5429EACA5D7DCDC1168A17727F6F8913BFF067CFFB3F25B0626726EC4623653D053CE68EEAE7B0D3832BA37AE3F6A00B1DA80A1A4759727FF67
                                                            Malicious:false
                                                            Preview:....................K...<.......h.......i.......|.......................................................................................................................................................%.......0.......7.......C.......V.......e.......w...........................................z...........T.......`.......k.......u...#...}...................................................#...........1.......?.......V...,...c...........#....... ....... .......................O...,...$...|...2...............-.......".......&.../.../...V...0.......#...............)...........$.......*...S...9...........$...............+...........................-.......A.......`.......w...................................................................1...........C.......M.......X.......].......e.......~...........................................................................*...........Y.......p.......x.......................................................................................".......B...!...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 242 messages, Project-Id-Version: audacity 3.0.3 '\320\227&\320\260 Audacity...'
                                                            Category:dropped
                                                            Size (bytes):18821
                                                            Entropy (8bit):5.275982877855045
                                                            Encrypted:false
                                                            SSDEEP:384:syYU/3G9z1OQtyovQ0JMoAYnDg/NX/rvWLirjXrTqggJGEaMK:VYNzQ7oYLYuXz8Oig4XK
                                                            MD5:231AB61DFBC7FD71FD71DE3E31D19FF8
                                                            SHA1:5790F38B62478A214E96CD576D74FB95B6FD386A
                                                            SHA-256:693C3D4B73109025B2D103628E97C153EF3F931DCDCA63853536AB8E73BFE616
                                                            SHA-512:D547F8783388D5429EACA5D7DCDC1168A17727F6F8913BFF067CFFB3F25B0626726EC4623653D053CE68EEAE7B0D3832BA37AE3F6A00B1DA80A1A4759727FF67
                                                            Malicious:false
                                                            Preview:....................K...<.......h.......i.......|.......................................................................................................................................................%.......0.......7.......C.......V.......e.......w...........................................z...........T.......`.......k.......u...#...}...................................................#...........1.......?.......V...,...c...........#....... ....... .......................O...,...$...|...2...............-.......".......&.../.../...V...0.......#...............)...........$.......*...S...9...........$...............+...........................-.......A.......`.......w...................................................................1...........C.......M.......X.......].......e.......~...........................................................................*...........Y.......p.......x.......................................................................................".......B...!...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3819 messages, Project-Id-Version: audacity 3.0.3 '\011 \340\244\206\340\244\243\340\244\277'
                                                            Category:dropped
                                                            Size (bytes):470089
                                                            Entropy (8bit):5.210610613201499
                                                            Encrypted:false
                                                            SSDEEP:3072:Jt7mEdHRygQQ02+cWE0sZoa3VAKxVRDj4BvowstO8SIoc+9A9+qEtCdLAs0n/W4M:XmpQHW9URDjmortOKoc+9A9t081pXamp
                                                            MD5:F3DE73D5E3E0CA5466B42B1B9B04C4F9
                                                            SHA1:BC7522D4488B2D2D3D0A7D58F4BE10D160F9C93B
                                                            SHA-256:046451C926DAF499A1AE94DF113A5BDD49E6B44CD7E477181A61900DECA59CF2
                                                            SHA-512:FF64FE9281D1B3C9B6B25D590B60206C6C0626278A70E3F5869EFFC0B4CD161B6A371F175325C29AC95C3704D84110906EDC33CCAD1553090C205A63F4614EBC
                                                            Malicious:false
                                                            Preview:................tw..............x>......y>.......>..'....?..:...??..6...z?.......?......K@..S....@..G...3A..*...{A..K....A.......A..m....B.......C.......C......iD.......E.......F......#F......-F......:F......CF......JF......VF......dF......oF......yF.......F.......F..g....F..P....F......PG.......G..1....G.......H.......H.......I......fJ.......J.......K......jL......$M.......M.......N.......O.......O.......P..0....P.......Q......IQ..4...[Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......R.......R.......R.......R......:R......UR......]R......dR.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......S.......S.......S..8..."S..;...[S.......S.......S.......S.......S.......T.......T..(....T......BT......IT......PT......\T......bT......hT......nT......yT.......T.......T.......T..J....T.......T.......T.......U..-....U..%...7U..$...]U.......U.......U..S....U.......U..F....V......NV......[V......eV......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 3819 messages, Project-Id-Version: audacity 3.0.3 '\011 \340\244\206\340\244\243\340\244\277'
                                                            Category:dropped
                                                            Size (bytes):470089
                                                            Entropy (8bit):5.210610613201499
                                                            Encrypted:false
                                                            SSDEEP:3072:Jt7mEdHRygQQ02+cWE0sZoa3VAKxVRDj4BvowstO8SIoc+9A9+qEtCdLAs0n/W4M:XmpQHW9URDjmortOKoc+9A9t081pXamp
                                                            MD5:F3DE73D5E3E0CA5466B42B1B9B04C4F9
                                                            SHA1:BC7522D4488B2D2D3D0A7D58F4BE10D160F9C93B
                                                            SHA-256:046451C926DAF499A1AE94DF113A5BDD49E6B44CD7E477181A61900DECA59CF2
                                                            SHA-512:FF64FE9281D1B3C9B6B25D590B60206C6C0626278A70E3F5869EFFC0B4CD161B6A371F175325C29AC95C3704D84110906EDC33CCAD1553090C205A63F4614EBC
                                                            Malicious:false
                                                            Preview:................tw..............x>......y>.......>..'....?..:...??..6...z?.......?......K@..S....@..G...3A..*...{A..K....A.......A..m....B.......C.......C......iD.......E.......F......#F......-F......:F......CF......JF......VF......dF......oF......yF.......F.......F..g....F..P....F......PG.......G..1....G.......H.......H.......I......fJ.......J.......K......jL......$M.......M.......N.......O.......O.......P..0....P.......Q......IQ..4...[Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......Q.......R.......R.......R.......R......:R......UR......]R......dR.......R.......R.......R.......R.......R.......R.......R.......R.......R.......R.......S.......S.......S..8..."S..;...[S.......S.......S.......S.......S.......T.......T..(....T......BT......IT......PT......\T......bT......hT......nT......yT.......T.......T.......T..J....T.......T.......T.......U..-....U..%...7U..$...]U.......U.......U..S....U.......U..F....V......NV......[V......eV......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1012 messages, Project-Id-Version: audacity 3.0.3 '\341\200\236\341\200\255\341\200\231\341\200\272\341\200\270\341\200\206\341\200\212\341\200\272\341\200\270\341\200\201\341\200\262\341\200\267\341\200\233\341\200\204\341\200\272\341\201\212 \341\200\205\341\200\256\341\200\231\341\200\266\341\200\201\341\200\273\341\200\200\341\200\272\341\200\231\341\200\276\341\200\254 \341\200\241\341\200\236\341\200\266\341\200\234\341\200\231\341\200\272\341\200\270\341\200\200\341\200\274\341\200\261\341\200\254 \341\200\233\341\200\276\341\200\255\341'
                                                            Category:dropped
                                                            Size (bytes):134237
                                                            Entropy (8bit):4.844621521824231
                                                            Encrypted:false
                                                            SSDEEP:3072:hWbXVopmZZozKvvCrxbA0GqNBEP29Q4IMZeYRsk+I6a0egtt7mautd3i5zclyfF9:cXVk0ClbAYSsoV
                                                            MD5:BBEE571ADA8CFDF1A08739C0F904386C
                                                            SHA1:935802CA6F79394AA6766DAC33C0F028C490509B
                                                            SHA-256:9EC01365A412C19E0D246F5A4C766CD30B9186080DF776828CBC410C5A9F725E
                                                            SHA-512:3E10BA3EC97B7F29EFEE9ED425885A350655E1ECE1E0C1953CCA96CA686A705129397F29E556F9AB327B390E80673777939AB1E84E7D1FE6702A99E9A6F9217A
                                                            Malicious:false
                                                            Preview:....................Q...\?.......T.......T......;U......DU......OU......XU..1....U.......V.......V.......W......VX.......X.......Y......ZZ.......[.......[......F\.......\.......^..4...!^......V^......]^......g^......n^......u^.......^..%....^.......^.......^.......^.......^.......^.......^..(....^......._......!_......(_....../_......D_......M_......S_......X_......b_......j_......z_.."...._......._......._......._......._......._......._......._......._......._.......`.......`.......`.......`......&`......1`......L`......U`......^`......o`......t`......z`......~`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......a...... a......2a......@a......Ia......Qa......da......oa......}a.......a.......a.......a.......a.......a.......a.......a.......a.......a.......a..,....a..%...(b..1...Nb..#....b..$....b..$....b.......b.......b.......c...... c......3c..*...Qc......|c.......c.......c.......c.......c.......d......'d......=d......Sd......rd......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 1012 messages, Project-Id-Version: audacity 3.0.3 '\341\200\236\341\200\255\341\200\231\341\200\272\341\200\270\341\200\206\341\200\212\341\200\272\341\200\270\341\200\201\341\200\262\341\200\267\341\200\233\341\200\204\341\200\272\341\201\212 \341\200\205\341\200\256\341\200\231\341\200\266\341\200\201\341\200\273\341\200\200\341\200\272\341\200\231\341\200\276\341\200\254 \341\200\241\341\200\236\341\200\266\341\200\234\341\200\231\341\200\272\341\200\270\341\200\200\341\200\274\341\200\261\341\200\254 \341\200\233\341\200\276\341\200\255\341'
                                                            Category:dropped
                                                            Size (bytes):134237
                                                            Entropy (8bit):4.844621521824231
                                                            Encrypted:false
                                                            SSDEEP:3072:hWbXVopmZZozKvvCrxbA0GqNBEP29Q4IMZeYRsk+I6a0egtt7mautd3i5zclyfF9:cXVk0ClbAYSsoV
                                                            MD5:BBEE571ADA8CFDF1A08739C0F904386C
                                                            SHA1:935802CA6F79394AA6766DAC33C0F028C490509B
                                                            SHA-256:9EC01365A412C19E0D246F5A4C766CD30B9186080DF776828CBC410C5A9F725E
                                                            SHA-512:3E10BA3EC97B7F29EFEE9ED425885A350655E1ECE1E0C1953CCA96CA686A705129397F29E556F9AB327B390E80673777939AB1E84E7D1FE6702A99E9A6F9217A
                                                            Malicious:false
                                                            Preview:....................Q...\?.......T.......T......;U......DU......OU......XU..1....U.......V.......V.......W......VX.......X.......Y......ZZ.......[.......[......F\.......\.......^..4...!^......V^......]^......g^......n^......u^.......^..%....^.......^.......^.......^.......^.......^.......^..(....^......._......!_......(_....../_......D_......M_......S_......X_......b_......j_......z_.."...._......._......._......._......._......._......._......._......._......._.......`.......`.......`.......`......&`......1`......L`......U`......^`......o`......t`......z`......~`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......`.......a...... a......2a......@a......Ia......Qa......da......oa......}a.......a.......a.......a.......a.......a.......a.......a.......a.......a.......a..,....a..%...(b..1...Nb..#....b..$....b..$....b.......b.......b.......c...... c......3c..*...Qc......|c.......c.......c.......c.......c.......d......'d......=d......Sd......rd......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4325 messages, Project-Id-Version: audacity 3.2 '\011 og'
                                                            Category:dropped
                                                            Size (bytes):342703
                                                            Entropy (8bit):5.435149261095542
                                                            Encrypted:false
                                                            SSDEEP:6144:iy5UeLyoGlSXkVRDj0ojitnsc+XA7fqvHcWO0LXAKOWX+NoIU:QmGY2xnA7fk1ONoIU
                                                            MD5:ECB024A09BBDDD51E1601E41978807C7
                                                            SHA1:095B34D49D699E1931502E66B588D681034A4577
                                                            SHA-256:91367AACC0FB6CB30289BE1A0A92E0D55E6CEF468ACF16D447E42EAC087C855E
                                                            SHA-512:E1798CDF84EDD02F8E3FF9B38105A3C2A349E5DC4058F91F2ABED3684936B8380372E97C95E5948B77C7EA90996B5C881592B8D0B7704D6A7523F8785C7CC594
                                                            Malicious:false
                                                            Preview:................D.......l........h.......h.......h..'...Wi..:....i.......i..$....i..6....i..(....j......Cj.......j..|...qk..S....k..G...Bl..*....l..K....l.......m..m....m.......n.......n......xo......"p......)q......2q......<q......Iq......Rq......Yq......eq......sq......~q.......q.......q.......q..g....q..P....r......_r..F....r......:s..1...Rs.......s......%t......"u.......u......Mv.......v.......w......zx.......y.......y......tz.......{......4|..0...S|.......|.......|..4....|.......|.......|.......|.......|.......}.......}...... }......'}....../}......9}......@}......H}......T}......^}......h}......n}......s}.......}.......}.......}.......}.......}.......}.......}.......}.......~.......~......3~......9~......J~......R~......g~......n~......r~..8...x~..;....~.......~..........7...(.......`.......{...........R.......0...........#...(...+.......T.......\.......c.......j.......v.......|...................................................J..............................-...#.......Q...%...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4325 messages, Project-Id-Version: audacity 3.2 '\011 og'
                                                            Category:dropped
                                                            Size (bytes):342703
                                                            Entropy (8bit):5.435149261095542
                                                            Encrypted:false
                                                            SSDEEP:6144:iy5UeLyoGlSXkVRDj0ojitnsc+XA7fqvHcWO0LXAKOWX+NoIU:QmGY2xnA7fk1ONoIU
                                                            MD5:ECB024A09BBDDD51E1601E41978807C7
                                                            SHA1:095B34D49D699E1931502E66B588D681034A4577
                                                            SHA-256:91367AACC0FB6CB30289BE1A0A92E0D55E6CEF468ACF16D447E42EAC087C855E
                                                            SHA-512:E1798CDF84EDD02F8E3FF9B38105A3C2A349E5DC4058F91F2ABED3684936B8380372E97C95E5948B77C7EA90996B5C881592B8D0B7704D6A7523F8785C7CC594
                                                            Malicious:false
                                                            Preview:................D.......l........h.......h.......h..'...Wi..:....i.......i..$....i..6....i..(....j......Cj.......j..|...qk..S....k..G...Bl..*....l..K....l.......m..m....m.......n.......n......xo......"p......)q......2q......<q......Iq......Rq......Yq......eq......sq......~q.......q.......q.......q..g....q..P....r......_r..F....r......:s..1...Rs.......s......%t......"u.......u......Mv.......v.......w......zx.......y.......y......tz.......{......4|..0...S|.......|.......|..4....|.......|.......|.......|.......|.......}.......}...... }......'}....../}......9}......@}......H}......T}......^}......h}......n}......s}.......}.......}.......}.......}.......}.......}.......}.......}.......~.......~......3~......9~......J~......R~......g~......n~......r~..8...x~..;....~.......~..........7...(.......`.......{...........R.......0...........#...(...+.......T.......\.......c.......j.......v.......|...................................................J..............................-...#.......Q...%...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 en'
                                                            Category:dropped
                                                            Size (bytes):351801
                                                            Entropy (8bit):5.3677295807376995
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Ut2dpDsYRDjIoj5/asc+1A7MyKORxECaU:6NJVVA7MTCaU
                                                            MD5:537C2F2A7591A5AC8DF904487CCDDB3D
                                                            SHA1:CDE8A4DED0570776C6E8D6B902B377697DDEAF81
                                                            SHA-256:3B43BDC08EBF8932119B27760B922E1BA0BE94CCEFE96FD8392F2815C24408FF
                                                            SHA-512:DD19DB14495F94116F81693B2F8DF34E8291AE3369039BDDA449DDDC053A07A6FADDBEAE70DE05B9A1594D8ABB77607F17ABECA2A0CA7F84CBF4D6BC99052A7D
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 en'
                                                            Category:dropped
                                                            Size (bytes):351801
                                                            Entropy (8bit):5.3677295807376995
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Ut2dpDsYRDjIoj5/asc+1A7MyKORxECaU:6NJVVA7MTCaU
                                                            MD5:537C2F2A7591A5AC8DF904487CCDDB3D
                                                            SHA1:CDE8A4DED0570776C6E8D6B902B377697DDEAF81
                                                            SHA-256:3B43BDC08EBF8932119B27760B922E1BA0BE94CCEFE96FD8392F2815C24408FF
                                                            SHA-512:DD19DB14495F94116F81693B2F8DF34E8291AE3369039BDDA449DDDC053A07A6FADDBEAE70DE05B9A1594D8ABB77607F17ABECA2A0CA7F84CBF4D6BC99052A7D
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 571 messages, Project-Id-Version: audacity 3.0.3 '%d Canals'
                                                            Category:dropped
                                                            Size (bytes):31485
                                                            Entropy (8bit):5.100401528945195
                                                            Encrypted:false
                                                            SSDEEP:768:ELfCLz6m1WMaRb78SKMQpg4n2OAopLf3FwRVrEDU8VajQbaDNj:Eji4R4n2/opb3FI2U8Vaj6aDNj
                                                            MD5:F39EA52F632FBD7CC767D127C7EB9678
                                                            SHA1:4AF61DD1CE373B703C6C3C0D4F70185B797A76B9
                                                            SHA-256:1BE9E33780F55BC81AA5B2B1979884B560A53D5E8E87C7267F27CA4294B2D04A
                                                            SHA-512:C2A2228043743D708B757E504C0208D95FCCC277C64D2192EA9B5DD19BB2479CE832137050D571851B8177D84E82C57DC00C542475AA8280A8052BE2962E8196
                                                            Malicious:false
                                                            Preview:........;................#......./......./......./......./......./......./......./......./......./..%....0......-0......50......<0......O0......T0......]0......d0......l0......s0......z0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1......'1.......1......41......?1......D1......H1......Q1......[1......b1......r1......{1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......2......(2......82..,...C2..%...p2..1....2..#....2..$....2.......3.......3.......3...... 3......13......B3......M3......X3......l3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4......*4......04......?4......Q4......Y4......a4......o4......s4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......5..z...*5.......5.......5.......5.......5.......5.......5.......6......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 571 messages, Project-Id-Version: audacity 3.0.3 '%d Canals'
                                                            Category:dropped
                                                            Size (bytes):31485
                                                            Entropy (8bit):5.100401528945195
                                                            Encrypted:false
                                                            SSDEEP:768:ELfCLz6m1WMaRb78SKMQpg4n2OAopLf3FwRVrEDU8VajQbaDNj:Eji4R4n2/opb3FI2U8Vaj6aDNj
                                                            MD5:F39EA52F632FBD7CC767D127C7EB9678
                                                            SHA1:4AF61DD1CE373B703C6C3C0D4F70185B797A76B9
                                                            SHA-256:1BE9E33780F55BC81AA5B2B1979884B560A53D5E8E87C7267F27CA4294B2D04A
                                                            SHA-512:C2A2228043743D708B757E504C0208D95FCCC277C64D2192EA9B5DD19BB2479CE832137050D571851B8177D84E82C57DC00C542475AA8280A8052BE2962E8196
                                                            Malicious:false
                                                            Preview:........;................#......./......./......./......./......./......./......./......./......./..%....0......-0......50......<0......O0......T0......]0......d0......l0......s0......z0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......0.......1.......1.......1......'1.......1......41......?1......D1......H1......Q1......[1......b1......r1......{1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......1.......2......(2......82..,...C2..%...p2..1....2..#....2..$....2.......3.......3.......3...... 3......13......B3......M3......X3......l3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......3.......4.......4.......4......*4......04......?4......Q4......Y4......a4......o4......s4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......4.......5..z...*5.......5.......5.......5.......5.......5.......5.......6......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.2.0 '\011 i'
                                                            Category:dropped
                                                            Size (bytes):360495
                                                            Entropy (8bit):5.596621261751561
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Ux6xSQAuDsYRDjIoj5/asc+1A7MDHGGeOMeXum9KSDVi6Uzd4BF:6u0zVVA7MDHGGeOMeXum9KKFUzdKF
                                                            MD5:150EC860477DB1A0D88944AC25C4D798
                                                            SHA1:2C3B246E8E54A6DE8BE1296FD9CA1E5BF0069697
                                                            SHA-256:D0B7FA0D1A6DEC14CD200BD3ACF1AED6EAFCA2B1C4E64002BB1DB192363FBBC7
                                                            SHA-512:EA230921D2038EF484114DE4963F19060843F27ABE185BBE323452AD76360BBE30E113406598D62170E666669F0C87DD0BDF0DBBEEC590F2586A16430898C58B
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.2.0 '\011 i'
                                                            Category:dropped
                                                            Size (bytes):360495
                                                            Entropy (8bit):5.596621261751561
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72Ux6xSQAuDsYRDjIoj5/asc+1A7MDHGGeOMeXum9KSDVi6Uzd4BF:6u0zVVA7MDHGGeOMeXum9KKFUzdKF
                                                            MD5:150EC860477DB1A0D88944AC25C4D798
                                                            SHA1:2C3B246E8E54A6DE8BE1296FD9CA1E5BF0069697
                                                            SHA-256:D0B7FA0D1A6DEC14CD200BD3ACF1AED6EAFCA2B1C4E64002BB1DB192363FBBC7
                                                            SHA-512:EA230921D2038EF484114DE4963F19060843F27ABE185BBE323452AD76360BBE30E113406598D62170E666669F0C87DD0BDF0DBBEEC590F2586A16430898C58B
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 e'
                                                            Category:dropped
                                                            Size (bytes):360082
                                                            Entropy (8bit):5.437304336026565
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UOQe5wusYRDjIoj5/asc+1A7M5VPQ4E20F7hXh:63NVVA7M5Dgh
                                                            MD5:6241EA9A3C9C931E324A98AC634E5AD3
                                                            SHA1:E9602818321A0E102722D9EF54C0D76B309F576E
                                                            SHA-256:222131A58B0522BD80424363E7F43F001C966DDA539E385598A44EA0092BECDC
                                                            SHA-512:02075A51E640611A357459F02469F267F895F09845A27AAF742D8F2C80919BCF50E0BEA34DE1349A0476A7112F6062892C9B2B49910AE7F7807A1DC3A1AA0191
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: Audacity '\011 e'
                                                            Category:dropped
                                                            Size (bytes):360082
                                                            Entropy (8bit):5.437304336026565
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UOQe5wusYRDjIoj5/asc+1A7M5VPQ4E20F7hXh:63NVVA7M5Dgh
                                                            MD5:6241EA9A3C9C931E324A98AC634E5AD3
                                                            SHA1:E9602818321A0E102722D9EF54C0D76B309F576E
                                                            SHA-256:222131A58B0522BD80424363E7F43F001C966DDA539E385598A44EA0092BECDC
                                                            SHA-512:02075A51E640611A357459F02469F267F895F09845A27AAF742D8F2C80919BCF50E0BEA34DE1349A0476A7112F6062892C9B2B49910AE7F7807A1DC3A1AA0191
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.2.0 '\011 e'
                                                            Category:dropped
                                                            Size (bytes):355951
                                                            Entropy (8bit):5.441374108083211
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72U3zn08ojKsYRDjIoj5/asc+1A7MfRVUMa:6iznyuVVA7MfTja
                                                            MD5:7E6BE8B7F94F5FE6A016560E4ED362D1
                                                            SHA1:66BF8B6C5DE2757EAD4A125B6212F22C66BB7E17
                                                            SHA-256:F2FB9341DD376797E8E65400BE070670B7F5A37031C2652440BB5944524EA743
                                                            SHA-512:15C7CA97A8FCABD61FCA5F3C4B2AA34ACEC1D0B128DE3F1BAC90865C2C5F010E1BC8AD5D68AAF0F1906E8F9230E14D82DEFBEE98C5331D628255D6A5E19C82FC
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.2.0 '\011 e'
                                                            Category:dropped
                                                            Size (bytes):355951
                                                            Entropy (8bit):5.441374108083211
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72U3zn08ojKsYRDjIoj5/asc+1A7MfRVUMa:6iznyuVVA7MfTja
                                                            MD5:7E6BE8B7F94F5FE6A016560E4ED362D1
                                                            SHA1:66BF8B6C5DE2757EAD4A125B6212F22C66BB7E17
                                                            SHA-256:F2FB9341DD376797E8E65400BE070670B7F5A37031C2652440BB5944524EA743
                                                            SHA-512:15C7CA97A8FCABD61FCA5F3C4B2AA34ACEC1D0B128DE3F1BAC90865C2C5F010E1BC8AD5D68AAF0F1906E8F9230E14D82DEFBEE98C5331D628255D6A5E19C82FC
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 642 messages, Project-Id-Version: audacity 3.0.3 ' Monitorizare '
                                                            Category:dropped
                                                            Size (bytes):39331
                                                            Entropy (8bit):5.1947393204059775
                                                            Encrypted:false
                                                            SSDEEP:768:STbeAmivFL2SQyw+FkB5eoadARyc1vizJhGlcQTyB++p4eh8:WmiBf3SneoadARyS6h6cQmB+Deh8
                                                            MD5:BDE34EABD0E68E4C1797B56B60E8A921
                                                            SHA1:1D78968213BA7F4CFB25F5AE3EAB445204C7A2A7
                                                            SHA-256:2BBAACCBC2185DA23E509034C0DD9D4FC81BEA72731E1BEE02CD23A7A9E66511
                                                            SHA-512:1CB5FC33B77DB3B458CFAB3293C62C9B6B7947B3EE1F42A7B6B0888F02C5E15A46C4AE1CAC30020061AE2F67322B639295A79F751D0B139E75B396F541D8F107
                                                            Malicious:false
                                                            Preview:................,...Y...<(.......5.......5.......5..J....5..%....6......+6......>6......P6......^6......c6......l6......s6......}6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......7.......7...... 7......17......?7......G7......X7......^7......g7......q7......~7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......8.......8......$8......)8....../8......38......<8......H8......O8......V8......n8......~8.......8.......8.......8.......8.......8.......8.......8.......8.......8.......8.......9.......9.......9......&9......09......;9......I9......U9......_9......q9......y9.......9.......9.......9.......9.......9..$....9..,....9.......:...... :......":......+:......F:......W:......\:......`:......c:......j:......u:......{:......}:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......;.......;......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 642 messages, Project-Id-Version: audacity 3.0.3 ' Monitorizare '
                                                            Category:dropped
                                                            Size (bytes):39331
                                                            Entropy (8bit):5.1947393204059775
                                                            Encrypted:false
                                                            SSDEEP:768:STbeAmivFL2SQyw+FkB5eoadARyc1vizJhGlcQTyB++p4eh8:WmiBf3SneoadARyS6h6cQmB+Deh8
                                                            MD5:BDE34EABD0E68E4C1797B56B60E8A921
                                                            SHA1:1D78968213BA7F4CFB25F5AE3EAB445204C7A2A7
                                                            SHA-256:2BBAACCBC2185DA23E509034C0DD9D4FC81BEA72731E1BEE02CD23A7A9E66511
                                                            SHA-512:1CB5FC33B77DB3B458CFAB3293C62C9B6B7947B3EE1F42A7B6B0888F02C5E15A46C4AE1CAC30020061AE2F67322B639295A79F751D0B139E75B396F541D8F107
                                                            Malicious:false
                                                            Preview:................,...Y...<(.......5.......5.......5..J....5..%....6......+6......>6......P6......^6......c6......l6......s6......}6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......6.......7.......7...... 7......17......?7......G7......X7......^7......g7......q7......~7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......7.......8.......8......$8......)8....../8......38......<8......H8......O8......V8......n8......~8.......8.......8.......8.......8.......8.......8.......8.......8.......8.......8.......9.......9.......9......&9......09......;9......I9......U9......_9......q9......y9.......9.......9.......9.......9.......9..$....9..,....9.......:...... :......":......+:......F:......W:......\:......`:......c:......j:......u:......{:......}:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......:.......;.......;......
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4304 messages, Project-Id-Version: audacity 3.2.0 '\011 \320\270'
                                                            Category:dropped
                                                            Size (bytes):442430
                                                            Entropy (8bit):5.597493140209038
                                                            Encrypted:false
                                                            SSDEEP:12288:nsmzn9LJgA70ANmOh00/tZnDlvY0Q4uP3KWf3sn2Ihzg6L9QgLI4AMyUWoZ5Gb7S:bz9LyA70o
                                                            MD5:E55A4FDCDE482628C160109CD392DB2F
                                                            SHA1:AD13906FB5055EFE18530E010412B0E5E429E9EC
                                                            SHA-256:FD0BF89E00E9737D0E97E4A28325E5E43C322979DD6D52AB6981940272285842
                                                            SHA-512:CC0444A1240CC2D462EA299CA27C3DCBA192BF159FFCFCDC9EDF80D4A1EF9C78CA1431776F785DA2336C105D26DA26063EF67CBC4BA565BF65636D0CAED2F9CD
                                                            Malicious:false
                                                            Preview:....................m............f.......f.......f..'...og..:....g.......g..$....g..6....g..(...2h......[h.......h..|....i..S....j..G...Zj..*....j..K....j.......k..m....k......7l.......l.......m......:n......Ao......Jo......To......ao......jo......qo......}o.......o.......o.......o.......o.......o..g....o..P...&p......wp..F....q......Rq..1...jq.......q......=r......:s.......s......et.......u.......u.......v......&w.......w.......x......1y......Lz..0...kz.......z.......z..4....z.......z.......{.......{.......{.......{......+{......8{......?{......G{......Q{......X{......`{......l{......v{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......|.......|.......|......2|......K|......Q|......b|......j|.......|.......|.......|..8....|..;....|.......}......$}..7...@}......x}.......}.......}..R....}..0....~......;~..(...C~......l~......s~......z~.......~.......~.......~.......~.......~.......~.......~.......~..J....~..............#.......,...-...3.......a...%.......$...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4304 messages, Project-Id-Version: audacity 3.2.0 '\011 \320\270'
                                                            Category:dropped
                                                            Size (bytes):442430
                                                            Entropy (8bit):5.597493140209038
                                                            Encrypted:false
                                                            SSDEEP:12288:nsmzn9LJgA70ANmOh00/tZnDlvY0Q4uP3KWf3sn2Ihzg6L9QgLI4AMyUWoZ5Gb7S:bz9LyA70o
                                                            MD5:E55A4FDCDE482628C160109CD392DB2F
                                                            SHA1:AD13906FB5055EFE18530E010412B0E5E429E9EC
                                                            SHA-256:FD0BF89E00E9737D0E97E4A28325E5E43C322979DD6D52AB6981940272285842
                                                            SHA-512:CC0444A1240CC2D462EA299CA27C3DCBA192BF159FFCFCDC9EDF80D4A1EF9C78CA1431776F785DA2336C105D26DA26063EF67CBC4BA565BF65636D0CAED2F9CD
                                                            Malicious:false
                                                            Preview:....................m............f.......f.......f..'...og..:....g.......g..$....g..6....g..(...2h......[h.......h..|....i..S....j..G...Zj..*....j..K....j.......k..m....k......7l.......l.......m......:n......Ao......Jo......To......ao......jo......qo......}o.......o.......o.......o.......o.......o..g....o..P...&p......wp..F....q......Rq..1...jq.......q......=r......:s.......s......et.......u.......u.......v......&w.......w.......x......1y......Lz..0...kz.......z.......z..4....z.......z.......{.......{.......{.......{......+{......8{......?{......G{......Q{......X{......`{......l{......v{.......{.......{.......{.......{.......{.......{.......{.......{.......{.......|.......|.......|......2|......K|......Q|......b|......j|.......|.......|.......|..8....|..;....|.......}......$}..7...@}......x}.......}.......}..R....}..0....~......;~..(...C~......l~......s~......z~.......~.......~.......~.......~.......~.......~.......~.......~..J....~..............#.......,...-...3.......a...%.......$...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4036 messages, Project-Id-Version: audacity 3.0.3 '\011 a'
                                                            Category:dropped
                                                            Size (bytes):324053
                                                            Entropy (8bit):5.616641027793701
                                                            Encrypted:false
                                                            SSDEEP:6144:6vWRqENbXRDjwo4Y92oc+LA9cRgm3cp0/V9Y0yy:qWIsKqA9cRgE5/V97yy
                                                            MD5:3DC4E17721DF3B12CF46DEE2595F8775
                                                            SHA1:7BE224FF038A48B9103D4C0FDA590DBDCB59680C
                                                            SHA-256:E540176DD342327284CE083C3E6F08378AA77448EF3664C2FA2061F202926F16
                                                            SHA-512:25FDA359F1BFEBEC9E346966C477A1E3952958CF153DCB23A2536DF3D44D88909372E52116849DCF6456709DF62F211318C700B4A8F0ABDC439BCC353D23A56B
                                                            Malicious:false
                                                            Preview:................<~......\.......pP......qP......|P..'....Q..:...7Q..6...rQ.......Q......CR..S....R..G...+S..*...sS..K....S.......S..m....T.......U.......U......aV.......W.......X.......X......%X......2X......;X......BX......NX......\X......gX......qX......zX.......X..g....X..P....X......HY.......Y..1....Y......&Z.......Z.......[......^\.......\.......]......b^......._......._......x`.......a.......a.......b..0....b......&c......Ac..4...Sc.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......d.......d.......d.......d......2d......Md......Ud......\d......yd.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e.......e..8....e..;...Se.......e.......e..7....e.......f.......f......5f..R...Af..0....f.......f..(....f.......f.......f.......g.......g.......g.......g......"g......-g......=g......Hg......Qg..J...\g.......g.......g.......g..-....g.......g..%...kh..$....h.......h..#....h.."....h.......i..S...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4036 messages, Project-Id-Version: audacity 3.0.3 '\011 a'
                                                            Category:dropped
                                                            Size (bytes):324053
                                                            Entropy (8bit):5.616641027793701
                                                            Encrypted:false
                                                            SSDEEP:6144:6vWRqENbXRDjwo4Y92oc+LA9cRgm3cp0/V9Y0yy:qWIsKqA9cRgE5/V97yy
                                                            MD5:3DC4E17721DF3B12CF46DEE2595F8775
                                                            SHA1:7BE224FF038A48B9103D4C0FDA590DBDCB59680C
                                                            SHA-256:E540176DD342327284CE083C3E6F08378AA77448EF3664C2FA2061F202926F16
                                                            SHA-512:25FDA359F1BFEBEC9E346966C477A1E3952958CF153DCB23A2536DF3D44D88909372E52116849DCF6456709DF62F211318C700B4A8F0ABDC439BCC353D23A56B
                                                            Malicious:false
                                                            Preview:................<~......\.......pP......qP......|P..'....Q..:...7Q..6...rQ.......Q......CR..S....R..G...+S..*...sS..K....S.......S..m....T.......U.......U......aV.......W.......X.......X......%X......2X......;X......BX......NX......\X......gX......qX......zX.......X..g....X..P....X......HY.......Y..1....Y......&Z.......Z.......[......^\.......\.......]......b^......._......._......x`.......a.......a.......b..0....b......&c......Ac..4...Sc.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......c.......d.......d.......d.......d......2d......Md......Ud......\d......yd.......d.......d.......d.......d.......d.......d.......d.......d.......d.......e.......e.......e..8....e..;...Se.......e.......e..7....e.......f.......f......5f..R...Af..0....f.......f..(....f.......f.......f.......g.......g.......g.......g......"g......-g......=g......Hg......Qg..J...\g.......g.......g.......g..-....g.......g..%...kh..$....h.......h..#....h.."....h.......i..S...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 in'
                                                            Category:dropped
                                                            Size (bytes):350475
                                                            Entropy (8bit):5.47364554362566
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UreeepZsYRDjIoj5/asc+1A7M5Tj7Yj/sDvz8kvCf2OVLQZtHHyD20hJXIz0:6OaVVA7M5Tm/sDvpCf2OVLQZtHHyD203
                                                            MD5:72C8360F162C65FC9D1A7E983E1C9DBA
                                                            SHA1:F8BA2BE34189C58DA6294F2D816FA731D69F8230
                                                            SHA-256:4E6F75F9BD7C76BC72C5C379D1A41050979D22E5BA56D420FDD71066BBA4397A
                                                            SHA-512:81FCC7359F3CB584E4DEDA58906E5E8C9C1E99F146CDF8E1BE595185FBA1B9F18D2BB93C9587A0B0D731635834E1BCE47FB1A80ECC94C54D5B3E5BE108E87981
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            Process:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            File Type:GNU message catalog (little endian), revision 0.0, 4353 messages, Project-Id-Version: audacity 3.0.3 '\011 in'
                                                            Category:dropped
                                                            Size (bytes):350475
                                                            Entropy (8bit):5.47364554362566
                                                            Encrypted:false
                                                            SSDEEP:6144:6m72UreeepZsYRDjIoj5/asc+1A7M5Tj7Yj/sDvz8kvCf2OVLQZtHHyD20hJXIz0:6OaVVA7M5Tm/sDvpCf2OVLQZtHHyD203
                                                            MD5:72C8360F162C65FC9D1A7E983E1C9DBA
                                                            SHA1:F8BA2BE34189C58DA6294F2D816FA731D69F8230
                                                            SHA-256:4E6F75F9BD7C76BC72C5C379D1A41050979D22E5BA56D420FDD71066BBA4397A
                                                            SHA-512:81FCC7359F3CB584E4DEDA58906E5E8C9C1E99F146CDF8E1BE595185FBA1B9F18D2BB93C9587A0B0D731635834E1BCE47FB1A80ECC94C54D5B3E5BE108E87981
                                                            Malicious:false
                                                            Preview:................$.......,........j.......j.......j..'....k..:....k.......k..$....k..6....l..(...Jl......sl.......m..|....m..S....n..G...rn..*....n..K....n......1o..m....o......Op.......p.......q......Rr......Ys......bs......ls......ys.......s.......s.......s.......s.......s.......s.......s.......s..g....s..P...>t.......t..F...#u......ju..1....u.......u......Uv......Rw.......w......}x....../y.......y.......z......>{.......|.......|......I}......d~..0....~.......~.......~..4....~......................&......./.......7.......C.......P.......W......._.......h.......r.......y.......................................................................................................%.......+.......@.......S.......l.......r...........................................8.......;..........&.......E...7...a..........................R......0...+.......\...(...d.....................................................................................................J...........S.......Y.......b...-...
                                                            File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                                            Entropy (8bit):7.994312498291434
                                                            TrID:
                                                            • Win32 Executable (generic) a (10002005/4) 99.96%
                                                            • Generic Win/DOS Executable (2004/3) 0.02%
                                                            • DOS Executable Generic (2002/1) 0.02%
                                                            • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                                            File name:WsiysHggF9.exe
                                                            File size:21526435
                                                            MD5:350ea577229a9518d3b9dcd76d109e14
                                                            SHA1:b9431df0ca98d1fa3abeefc92d1bd25e4c8b4e22
                                                            SHA256:2c8960c00dfc803bb8175a6833904173b6ff044c7128c24c8de2379b47274c77
                                                            SHA512:b0c50dfeb8889935ebf97982f358ad0b7b4c2969b676904aab325e18f9f7c2db25ffb811df33cbd42f068454d8597a4dbbba88983178dff5006dc2e050059746
                                                            SSDEEP:393216:M1TPcOFw/xVaHL8LTsemEsDVwodwzpl8z8vjw3lbbl3AxMT/fiUUE8qH+T8s:6TEOFeVaHIU1DVwy5m4lbbBAxMDiUeWc
                                                            TLSH:E8273311B39161B4F335B07407AAD33070353D419B9B1CDFA7F93AAAAD70185EE35AA2
                                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......b`..&...&...&.....h.+.....j.......k.>.....^.$...._..0...._..5...._....../y..,.../y..#...&...,...._......._..'...._f.'...._..'..
                                                            Icon Hash:68d6b0686868f010
                                                            Entrypoint:0x41ea80
                                                            Entrypoint Section:.text
                                                            Digitally signed:false
                                                            Imagebase:0x400000
                                                            Subsystem:windows gui
                                                            Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                                            DLL Characteristics:DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                                                            Time Stamp:0x5EF47EA0 [Thu Jun 25 10:38:24 2020 UTC]
                                                            TLS Callbacks:
                                                            CLR (.Net) Version:
                                                            OS Version Major:5
                                                            OS Version Minor:1
                                                            File Version Major:5
                                                            File Version Minor:1
                                                            Subsystem Version Major:5
                                                            Subsystem Version Minor:1
                                                            Import Hash:fcf1390e9ce472c7270447fc5c61a0c1
                                                            Instruction
                                                            call 00007F385CAD8039h
                                                            jmp 00007F385CAD7A3Dh
                                                            cmp ecx, dword ptr [0043D668h]
                                                            jne 00007F385CAD7BB5h
                                                            ret
                                                            jmp 00007F385CAD81BEh
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            push ebp
                                                            mov ebp, esp
                                                            push esi
                                                            push dword ptr [ebp+08h]
                                                            mov esi, ecx
                                                            call 00007F385CACAA67h
                                                            mov dword ptr [esi], 00434560h
                                                            mov eax, esi
                                                            pop esi
                                                            pop ebp
                                                            retn 0004h
                                                            and dword ptr [ecx+04h], 00000000h
                                                            mov eax, ecx
                                                            and dword ptr [ecx+08h], 00000000h
                                                            mov dword ptr [ecx+04h], 00434568h
                                                            mov dword ptr [ecx], 00434560h
                                                            ret
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            int3
                                                            push ebp
                                                            mov ebp, esp
                                                            push esi
                                                            mov esi, ecx
                                                            lea eax, dword ptr [esi+04h]
                                                            mov dword ptr [esi], 00434548h
                                                            push eax
                                                            call 00007F385CADAD57h
                                                            test byte ptr [ebp+08h], 00000001h
                                                            pop ecx
                                                            je 00007F385CAD7BBCh
                                                            push 0000000Ch
                                                            push esi
                                                            call 00007F385CAD7184h
                                                            pop ecx
                                                            pop ecx
                                                            mov eax, esi
                                                            pop esi
                                                            pop ebp
                                                            retn 0004h
                                                            push ebp
                                                            mov ebp, esp
                                                            sub esp, 0Ch
                                                            lea ecx, dword ptr [ebp-0Ch]
                                                            call 00007F385CACA9E2h
                                                            push 0043A6A4h
                                                            lea eax, dword ptr [ebp-0Ch]
                                                            push eax
                                                            call 00007F385CADA456h
                                                            int3
                                                            push ebp
                                                            mov ebp, esp
                                                            sub esp, 0Ch
                                                            lea ecx, dword ptr [ebp-0Ch]
                                                            call 00007F385CAD7B38h
                                                            push 0043A8FCh
                                                            lea eax, dword ptr [ebp-0Ch]
                                                            push eax
                                                            call 00007F385CADA439h
                                                            int3
                                                            Programming Language:
                                                            • [ C ] VS2008 SP1 build 30729
                                                            • [IMP] VS2008 SP1 build 30729
                                                            • [C++] VS2015 UPD3.1 build 24215
                                                            • [EXP] VS2015 UPD3.1 build 24215
                                                            • [RES] VS2015 UPD3 build 24213
                                                            • [LNK] VS2015 UPD3.1 build 24215
                                                            NameVirtual AddressVirtual Size Is in Section
                                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x3b8000x34.rdata
                                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x3b8340x3c.rdata
                                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x620000x39580.rsrc
                                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x9c0000x2264.reloc
                                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x39aa00x54.rdata
                                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x344e80x40.rdata
                                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                            IMAGE_DIRECTORY_ENTRY_IAT0x320000x260.rdata
                                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x3ada40x120.rdata
                                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                            NameVirtual AddressVirtual SizeRaw SizeXored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                            .text0x10000x30f2a0x31000False0.5837751116071429data6.704420140465974IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                            .rdata0x320000xa5f20xa600False0.457996046686747data5.259297003766902IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                            .data0x3d0000x237200x1000False0.367431640625data3.705679035284865IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                            .didat0x610000x1880x200False0.443359375data3.299508867679483IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                            .rsrc0x620000x395800x39600False0.3759914556100218data5.246982386311533IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                            .reloc0x9c0000x22640x2400False0.7727864583333334data6.556746947659253IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                            NameRVASizeTypeLanguageCountry
                                                            PNG0x6265c0xb45PNG image data, 93 x 302, 8-bit/color RGB, non-interlacedEnglishUnited States
                                                            PNG0x631a40x15a9PNG image data, 186 x 604, 8-bit/color RGB, non-interlacedEnglishUnited States
                                                            RT_BITMAP0x647500x14a7aDevice independent bitmap graphic, 93 x 302 x 24, image size 84562, resolution 3778 x 3778 px/m
                                                            RT_ICON0x791cc0x7b3cPNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced
                                                            RT_ICON0x80d080x10828Device independent bitmap graphic, 128 x 256 x 32, image size 65536
                                                            RT_ICON0x915300x4228Device independent bitmap graphic, 64 x 128 x 32, image size 16384
                                                            RT_ICON0x957580x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 9216
                                                            RT_ICON0x97d000x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 4096
                                                            RT_ICON0x98da80x468Device independent bitmap graphic, 16 x 32 x 32, image size 1024
                                                            RT_DIALOG0x992100x286dataEnglishUnited States
                                                            RT_DIALOG0x994980x13adataEnglishUnited States
                                                            RT_DIALOG0x995d40xecdataEnglishUnited States
                                                            RT_DIALOG0x996c00x12edataEnglishUnited States
                                                            RT_DIALOG0x997f00x338dataEnglishUnited States
                                                            RT_DIALOG0x99b280x252dataEnglishUnited States
                                                            RT_STRING0x99d7c0x1e2dataEnglishUnited States
                                                            RT_STRING0x99f600x1ccdataEnglishUnited States
                                                            RT_STRING0x9a12c0x1b8dataEnglishUnited States
                                                            RT_STRING0x9a2e40x146dataEnglishUnited States
                                                            RT_STRING0x9a42c0x446dataEnglishUnited States
                                                            RT_STRING0x9a8740x166dataEnglishUnited States
                                                            RT_STRING0x9a9dc0x152dataEnglishUnited States
                                                            RT_STRING0x9ab300x10adataEnglishUnited States
                                                            RT_STRING0x9ac3c0xbcdataEnglishUnited States
                                                            RT_STRING0x9acf80xd6dataEnglishUnited States
                                                            RT_GROUP_ICON0x9add00x5adata
                                                            RT_MANIFEST0x9ae2c0x753XML 1.0 document, ASCII text, with CRLF line terminatorsEnglishUnited States
                                                            DLLImport
                                                            KERNEL32.dllGetLastError, SetLastError, FormatMessageW, GetCurrentProcess, DeviceIoControl, SetFileTime, CloseHandle, CreateDirectoryW, RemoveDirectoryW, CreateFileW, DeleteFileW, CreateHardLinkW, GetShortPathNameW, GetLongPathNameW, MoveFileW, GetFileType, GetStdHandle, WriteFile, ReadFile, FlushFileBuffers, SetEndOfFile, SetFilePointer, SetFileAttributesW, GetFileAttributesW, FindClose, FindFirstFileW, FindNextFileW, GetVersionExW, GetCurrentDirectoryW, GetFullPathNameW, FoldStringW, GetModuleFileNameW, GetModuleHandleW, FindResourceW, FreeLibrary, GetProcAddress, GetCurrentProcessId, ExitProcess, SetThreadExecutionState, Sleep, LoadLibraryW, GetSystemDirectoryW, CompareStringW, AllocConsole, FreeConsole, AttachConsole, WriteConsoleW, GetProcessAffinityMask, CreateThread, SetThreadPriority, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, SetEvent, ResetEvent, ReleaseSemaphore, WaitForSingleObject, CreateEventW, CreateSemaphoreW, GetSystemTime, SystemTimeToTzSpecificLocalTime, TzSpecificLocalTimeToSystemTime, SystemTimeToFileTime, FileTimeToLocalFileTime, LocalFileTimeToFileTime, FileTimeToSystemTime, GetCPInfo, IsDBCSLeadByte, MultiByteToWideChar, WideCharToMultiByte, GlobalAlloc, LockResource, GlobalLock, GlobalUnlock, GlobalFree, LoadResource, SizeofResource, SetCurrentDirectoryW, GetExitCodeProcess, GetLocalTime, GetTickCount, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, OpenFileMappingW, GetCommandLineW, SetEnvironmentVariableW, ExpandEnvironmentStringsW, GetTempPathW, MoveFileExW, GetLocaleInfoW, GetTimeFormatW, GetDateFormatW, GetNumberFormatW, SetFilePointerEx, GetConsoleMode, GetConsoleCP, HeapSize, SetStdHandle, GetProcessHeap, RaiseException, GetSystemInfo, VirtualProtect, VirtualQuery, LoadLibraryExA, IsProcessorFeaturePresent, IsDebuggerPresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetStartupInfoW, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, TerminateProcess, RtlUnwind, EncodePointer, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, LoadLibraryExW, QueryPerformanceFrequency, GetModuleHandleExW, GetModuleFileNameA, GetACP, HeapFree, HeapAlloc, HeapReAlloc, GetStringTypeW, LCMapStringW, FindFirstFileExA, FindNextFileA, IsValidCodePage, GetOEMCP, GetCommandLineA, GetEnvironmentStringsW, FreeEnvironmentStringsW, DecodePointer
                                                            gdiplus.dllGdiplusShutdown, GdiplusStartup, GdipCreateHBITMAPFromBitmap, GdipCreateBitmapFromStreamICM, GdipCreateBitmapFromStream, GdipDisposeImage, GdipCloneImage, GdipFree, GdipAlloc
                                                            Language of compilation systemCountry where language is spokenMap
                                                            EnglishUnited States
                                                            TimestampProtocolSIDMessageSource PortDest PortSource IPDest IP
                                                            188.34.179.139192.168.2.610561496932850353 10/03/22-17:32:43.853269TCP2850353ETPRO MALWARE Redline Stealer TCP CnC - Id1Response1056149693188.34.179.139192.168.2.6
                                                            192.168.2.6188.34.179.13949693105612850027 10/03/22-17:32:43.736332TCP2850027ETPRO TROJAN RedLine Stealer TCP CnC net.tcp Init4969310561192.168.2.6188.34.179.139
                                                            192.168.2.6188.34.179.13949693105612850286 10/03/22-17:32:54.635526TCP2850286ETPRO TROJAN Redline Stealer TCP CnC Activity4969310561192.168.2.6188.34.179.139
                                                            TimestampSource PortDest PortSource IPDest IP
                                                            Oct 3, 2022 17:32:56.459109068 CEST5373153192.168.2.68.8.8.8
                                                            Oct 3, 2022 17:32:56.482225895 CEST53537318.8.8.8192.168.2.6
                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                            Oct 3, 2022 17:32:56.459109068 CEST192.168.2.68.8.8.80x15a7Standard query (0)updates.audacityteam.orgA (IP address)IN (0x0001)false
                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                            Oct 3, 2022 17:32:56.482225895 CEST8.8.8.8192.168.2.60x15a7No error (0)updates.audacityteam.org172.67.74.133A (IP address)IN (0x0001)false
                                                            Oct 3, 2022 17:32:56.482225895 CEST8.8.8.8192.168.2.60x15a7No error (0)updates.audacityteam.org104.26.0.108A (IP address)IN (0x0001)false
                                                            Oct 3, 2022 17:32:56.482225895 CEST8.8.8.8192.168.2.60x15a7No error (0)updates.audacityteam.org104.26.1.108A (IP address)IN (0x0001)false

                                                            Click to jump to process

                                                            Target ID:0
                                                            Start time:17:30:39
                                                            Start date:03/10/2022
                                                            Path:C:\Users\user\Desktop\WsiysHggF9.exe
                                                            Wow64 process (32bit):true
                                                            Commandline:C:\Users\user\Desktop\WsiysHggF9.exe
                                                            Imagebase:0x240000
                                                            File size:21526435 bytes
                                                            MD5 hash:350EA577229A9518D3B9DCD76D109E14
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:low

                                                            Target ID:1
                                                            Start time:17:30:48
                                                            Start date:03/10/2022
                                                            Path:C:\ProgramData\Installation_controller.exe
                                                            Wow64 process (32bit):true
                                                            Commandline:"C:\ProgramData\Installation_controller.exe"
                                                            Imagebase:0x400000
                                                            File size:7705088 bytes
                                                            MD5 hash:46A16F35F193D36DB5B03B6E692658B3
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:low

                                                            Target ID:10
                                                            Start time:17:31:03
                                                            Start date:03/10/2022
                                                            Path:C:\ProgramData\audacity-win-3.2.0-64bit.exe
                                                            Wow64 process (32bit):true
                                                            Commandline:"C:\ProgramData\audacity-win-3.2.0-64bit.exe"
                                                            Imagebase:0x400000
                                                            File size:14290656 bytes
                                                            MD5 hash:553B47079E2FD4820EF2F9841297EF97
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:Borland Delphi
                                                            Reputation:low

                                                            Target ID:11
                                                            Start time:17:31:23
                                                            Start date:03/10/2022
                                                            Path:C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp
                                                            Wow64 process (32bit):true
                                                            Commandline:"C:\Users\user\AppData\Local\Temp\is-BVVE5.tmp\audacity-win-3.2.0-64bit.tmp" /SL5="$5040E,13178964,955904,C:\ProgramData\audacity-win-3.2.0-64bit.exe"
                                                            Imagebase:0x400000
                                                            File size:3301352 bytes
                                                            MD5 hash:220722BABC7320F6FF80BB591C9DA719
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:Borland Delphi
                                                            Reputation:low

                                                            Target ID:12
                                                            Start time:17:32:00
                                                            Start date:03/10/2022
                                                            Path:C:\Users\user\AppData\Local\Temp\is-GK43T.tmp\_isetup\_setup64.tmp
                                                            Wow64 process (32bit):false
                                                            Commandline:helper 105 0x420
                                                            Imagebase:0x140000000
                                                            File size:6144 bytes
                                                            MD5 hash:E4211D6D009757C078A9FAC7FF4F03D4
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:moderate

                                                            Target ID:13
                                                            Start time:17:32:00
                                                            Start date:03/10/2022
                                                            Path:C:\Windows\System32\conhost.exe
                                                            Wow64 process (32bit):false
                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                            Imagebase:0x7ff6da640000
                                                            File size:625664 bytes
                                                            MD5 hash:EA777DEEA782E8B4D7C7C33BBF8A4496
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:high

                                                            Target ID:16
                                                            Start time:17:32:34
                                                            Start date:03/10/2022
                                                            Path:C:\Program Files\Audacity\Audacity.exe
                                                            Wow64 process (32bit):
                                                            Commandline:C:\Program Files\Audacity\audacity.exe
                                                            Imagebase:
                                                            File size:18346984 bytes
                                                            MD5 hash:686920484890800433A208E111666FE1
                                                            Has elevated privileges:true
                                                            Has administrator privileges:true
                                                            Programmed in:C, C++ or other language
                                                            Reputation:low

                                                            No disassembly