Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
Boku no Hero Academia 6th Season - Episode 13.exe

Overview

General Information

Sample Name:Boku no Hero Academia 6th Season - Episode 13.exe
Analysis ID:776910
MD5:71eabe2172181c2e4517c30c22cb6d12
SHA1:caaa052ae05d6032d8361e61fa22a686c6b5a392
SHA256:147e1b5a750fbfd8863449d523e3d6d110defceb74ad9cdb7c939ab75ffa2180
Infos:

Detection

Score:26
Range:0 - 100
Whitelisted:false
Confidence:0%

Compliance

Score:36
Range:0 - 100

Signatures

Uses cmd line tools excessively to alter registry or file data
Obfuscated command line found
Uses schtasks.exe or at.exe to add and modify task schedules
Uses 32bit PE files
Queries the volume information (name, serial number etc) of a device
Drops PE files to the application program directory (C:\ProgramData)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Very long cmdline option found, this is very uncommon (may be encrypted or packed)
Deletes files inside the Windows folder
Uses code obfuscation techniques (call, push, ret)
Creates files inside the system directory
PE file contains sections with non-standard names
Detected potential crypto function
Contains functionality to query CPU information (cpuid)
Found potential string decryption / allocating functions
Sample execution stops while process was sleeping (likely an evasion)
Creates processes with suspicious names
Found dropped PE file which has not been started or loaded
Uses the system / local time for branch decision (may execute only at specific dates)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
PE file contains executable resources (Code or Archives)
Is looking for software installed on the system
PE file does not import any functions
DLL planting / hijacking vulnerabilities found
Sample file is different than original file name gathered from version info
Drops PE files
Tries to load missing DLLs
Contains functionality to read the PEB
Drops PE files to the windows directory (C:\Windows)
Found evasive API chain checking for process token information
Binary contains a suspicious time stamp
Uses reg.exe to modify the Windows registry
Checks for available system drives (often done to infect USB drives)
Uses Microsoft's Enhanced Cryptographic Provider
Creates a process in suspended mode (likely to inject code)

Classification

Analysis Advice

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox
Sample is looking for USB drives. Launch the sample with the USB Fake Disk cookbook
Sample tries to load a library which is not present or installed on the analysis machine, adding the library might reveal more behavior
Sample may offer command line options, please run it with the 'Execute binary with arguments' cookbook (it's possible that the command line switches require additional characters like: "-", "/", "--")
Sample searches for specific file, try point organization specific fake files to the analysis machine
  • System is w10x64
  • Boku no Hero Academia 6th Season - Episode 13.exe (PID: 5216 cmdline: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe MD5: 71EABE2172181C2E4517C30C22CB6D12)
    • Boku no Hero Academia 6th Season - Episode 13.tmp (PID: 5512 cmdline: "C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$30408,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" MD5: F16A37D7AF3DB8C75F19AF9B3453D9C8)
      • Boku no Hero Academia 6th Season - Episode 13.exe (PID: 5204 cmdline: "C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENT MD5: 71EABE2172181C2E4517C30C22CB6D12)
        • Boku no Hero Academia 6th Season - Episode 13.tmp (PID: 2632 cmdline: "C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$2040C,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENT MD5: F16A37D7AF3DB8C75F19AF9B3453D9C8)
          • VC_redist.x64.exe (PID: 1972 cmdline: "C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe" /install /quiet MD5: 703BD677778F2A1BA1EB4338BAC3B868)
            • VC_redist.x64.exe (PID: 5372 cmdline: "C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exe" -burn.clean.room="C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=628 /install /quiet MD5: 848DA6B57CB8ACC151A8D64D15BA383D)
              • VC_redist.x64.exe (PID: 5468 cmdline: "C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{E9871BE9-995B-4EFF-BA27-126D1FC36700} {ED4F63C9-39F6-4A7D-A76D-4B8F059F42ED} 5372 MD5: 848DA6B57CB8ACC151A8D64D15BA383D)
                • VC_redist.x64.exe (PID: 5280 cmdline: "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468 MD5: CAA6E1DCAE648CE17BC57A5B7D383CC8)
                  • VC_redist.x64.exe (PID: 2140 cmdline: "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=540 -burn.filehandle.self=564 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468 MD5: CAA6E1DCAE648CE17BC57A5B7D383CC8)
                    • VC_redist.x64.exe (PID: 4548 cmdline: "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{DC57C196-DCD2-4148-818F-F83AAF0E5C46} {63FE371D-956D-4D2B-988F-00929D1EE668} 2140 MD5: CAA6E1DCAE648CE17BC57A5B7D383CC8)
          • InstallExtension.exe (PID: 1580 cmdline: "C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe" install MD5: 6B435C6EA00DA06603EA9927D489AB6A)
            • cmd.exe (PID: 5816 cmdline: C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" " MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
              • conhost.exe (PID: 5844 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
              • schtasks.exe (PID: 5912 cmdline: schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate MD5: 838D346D1D28F00783B7A6C6BD03A0DA)
          • cmd.exe (PID: 5928 cmdline: C:\Windows\system32\cmd.exe" /C ""C:\Users\user\AppData\Local\WindowsApp\reg.bat" install MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
            • conhost.exe (PID: 5872 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
            • schtasks.exe (PID: 6036 cmdline: schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate MD5: 838D346D1D28F00783B7A6C6BD03A0DA)
  • msiexec.exe (PID: 1092 cmdline: C:\Windows\system32\msiexec.exe /V MD5: 4767B71A318E201188A0D0A420C8B608)
  • VC_redist.x64.exe (PID: 1272 cmdline: "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" /burn.runonce MD5: 848DA6B57CB8ACC151A8D64D15BA383D)
    • VC_redist.x64.exe (PID: 4668 cmdline: "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" /quiet /burn.log.append "C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20230102153454.log" /install MD5: 848DA6B57CB8ACC151A8D64D15BA383D)
      • VC_redist.x64.exe (PID: 3732 cmdline: "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=564 /quiet /burn.log.append "C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20230102153454.log" /install MD5: 848DA6B57CB8ACC151A8D64D15BA383D)
        • VC_redist.x64.exe (PID: 1324 cmdline: "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{9F679354-B01C-4132-8C3B-9D0B8BAD9686} {7ADE5D70-631D-453D-B602-70E5C1B36EAF} 3732 MD5: 848DA6B57CB8ACC151A8D64D15BA383D)
          • VC_redist.x64.exe (PID: 4544 cmdline: "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324 MD5: CAA6E1DCAE648CE17BC57A5B7D383CC8)
            • VC_redist.x64.exe (PID: 4008 cmdline: "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=576 -burn.filehandle.self=572 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324 MD5: CAA6E1DCAE648CE17BC57A5B7D383CC8)
  • InstallExtension.exe (PID: 5852 cmdline: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe MD5: 6B435C6EA00DA06603EA9927D489AB6A)
    • cmd.exe (PID: 6092 cmdline: C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" " MD5: 4E2ACF4F8A396486AB4268C94A6A245F)
      • conhost.exe (PID: 6096 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: EA777DEEA782E8B4D7C7C33BBF8A4496)
      • reg.exe (PID: 5392 cmdline: REG DELETE HKLM\SOFTWARE\Policies\Google\Chrome /f MD5: E3DACF0B31841FA02064B4457D44B357)
      • reg.exe (PID: 4396 cmdline: REG DELETE HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f MD5: E3DACF0B31841FA02064B4457D44B357)
      • reg.exe (PID: 5428 cmdline: REG DELETE HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f MD5: E3DACF0B31841FA02064B4457D44B357)
      • reg.exe (PID: 5416 cmdline: REG ADD "HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallAllowlist" /v "1" /t REG_SZ /d dbffglanhdhedkjkijpkplhpcdndpchj /f MD5: E3DACF0B31841FA02064B4457D44B357)
      • reg.exe (PID: 2040 cmdline: REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "path" /t REG_SZ /d "C:\Users\user\AppData\Local\WindowsApp\apps-helper\apps.crx" /f MD5: E3DACF0B31841FA02064B4457D44B357)
      • reg.exe (PID: 4528 cmdline: REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "version" /t REG_SZ /d 1.0 /f MD5: E3DACF0B31841FA02064B4457D44B357)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
No Snort rule has matched

Click to jump to signature section

Show All Signature Results
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00029EB7 DecryptFileW,4_2_00029EB7
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004F961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,4_2_0004F961
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00029C99 DecryptFileW,DecryptFileW,4_2_00029C99
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000C9EB7 DecryptFileW,5_2_000C9EB7
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000EF961 CryptAcquireContextW,GetLastError,CryptCreateHash,GetLastError,CryptHashData,ReadFile,GetLastError,CryptDestroyHash,CryptReleaseContext,GetLastError,CryptGetHashParam,GetLastError,SetFilePointerEx,GetLastError,5_2_000EF961
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000C9C99 DecryptFileW,DecryptFileW,5_2_000C9C99
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: edputil.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: PROPSYS.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: SspiCli.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: MSVCP140.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: iertutil.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: VCRUNTIME140_1.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: urlmon.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: CRYPTBASE.DLL
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: CLDAPI.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: VCRUNTIME140.dll

Compliance

barindex
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: edputil.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: PROPSYS.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: SspiCli.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: MSVCP140.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: iertutil.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: VCRUNTIME140_1.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: urlmon.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: CRYPTBASE.DLL
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: CLDAPI.dll
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeDLL: VCRUNTIME140.dll
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore SRInitDoneJump to behavior
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\SystemRestore SRInitDone
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1028\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1029\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1031\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1036\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1040\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1041\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1042\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1045\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1046\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1049\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1055\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\2052\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\3082\license.rtfJump to behavior
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1028\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1029\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1031\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1036\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1040\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1041\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1042\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1045\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1046\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1049\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1055\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\2052\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\3082\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1028\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1029\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1031\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1036\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1040\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1041\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1042\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1045\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1046\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1049\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1055\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\2052\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\3082\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1028\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1029\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1031\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1036\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1040\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1041\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1042\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1045\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1046\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1049\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1055\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\2052\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\3082\license.rtf
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CF4C347D-954E-4543-88D2-EC17F07F466F}
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpDirectory created: C:\Program Files\InstallerJump to behavior
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic PE information: certificate valid
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: VC_redist.x64.exe, 00000004.00000002.377084608.000000000005B000.00000002.00000001.01000000.00000008.sdmp, VC_redist.x64.exe, 00000004.00000000.270201080.000000000005B000.00000002.00000001.01000000.00000008.sdmp, VC_redist.x64.exe, 00000005.00000000.271727251.00000000000FB000.00000002.00000001.01000000.0000000A.sdmp, VC_redist.x64.exe, 00000005.00000002.374381326.00000000000FB000.00000002.00000001.01000000.0000000A.sdmp, VC_redist.x64.exe, 00000007.00000000.285438279.0000000000EBB000.00000002.00000001.01000000.0000000D.sdmp, VC_redist.x64.exe, 00000007.00000002.368408492.0000000000EBB000.00000002.00000001.01000000.0000000D.sdmp, VC_redist.x64.exe, 00000010.00000002.324092324.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000010.00000000.318798304.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000011.00000002.375653352.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000011.00000000.322751737.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000012.00000002.373692696.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000012.00000000.324242625.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000013.00000002.366393157.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 00000014.00000002.363516573.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 00000019.00000002.371119144.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000019.00000000.348409137.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 0000001B.00000002.368331825.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 0000001C.00000002.366244549.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 0000001D.00000002.356595702.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe.5.dr, VC_redist.x64.exe.7.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: msvcp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFCM140U.amd64.pdb source: mfcm140u.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdbGCTL source: msvcp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcamp140.amd64.pdb source: vcamp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFC140DEU.amd64.pdb source: mfc140deu.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFC140ENU.amd64.pdb source: mfc140enu.dll.15.dr
Source: Binary string: C:\Users\dsaxc\Desktop\InstallExtension\x64\Release\InstallExtension.pdb source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.392947585.0000000004EA0000.00000004.00001000.00020000.00000000.sdmp, InstallExtension.exe, 0000001E.00000000.378319985.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 0000001E.00000002.382242447.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000000.382129606.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000002.387277253.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, is-NDGJF.tmp.3.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\concrt140.amd64.pdb source: concrt140.dll.15.dr
Source: Binary string: C:\Users\dsaxc\Desktop\InstallExtension\x64\Release\InstallExtension.pdb%% source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.392947585.0000000004EA0000.00000004.00001000.00020000.00000000.sdmp, InstallExtension.exe, 0000001E.00000000.378319985.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 0000001E.00000002.382242447.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000000.382129606.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000002.387277253.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, is-NDGJF.tmp.3.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_atomic_wait.amd64.pdbGCTL source: msvcp140_atomic_wait.dll.15.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixStdBA.pdb source: wixstdba.dll.5.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_atomic_wait.amd64.pdb source: msvcp140_atomic_wait.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdb source: msvcp140_2.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFC140JPN.amd64.pdb source: mfc140jpn.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcamp140.amd64.pdbGCTL source: vcamp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdbGCTL source: msvcp140_2.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\concrt140.amd64.pdbGCTL source: concrt140.dll.15.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixDepCA.pdb source: vcRuntimeAdditional_x64.5.dr, 3cd711.msi.15.dr
Source: C:\Windows\System32\msiexec.exeFile opened: z:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: x:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: v:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: t:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: r:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: p:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: n:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: l:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: j:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: h:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: f:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: b:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: y:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: w:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: u:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: s:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: q:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: o:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: m:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: k:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: i:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: g:Jump to behavior
Source: C:\Windows\System32\msiexec.exeFile opened: e:Jump to behavior
Source: C:\Windows\System32\cmd.exeFile opened: c:
Source: C:\Windows\System32\msiexec.exeFile opened: a:Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00013BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,4_2_00013BC3
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00054315 FindFirstFileW,FindClose,4_2_00054315
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0002993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,4_2_0002993E
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00047A87 FindFirstFileExW,4_2_00047A87
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000F4315 FindFirstFileW,FindClose,5_2_000F4315
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000C993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,5_2_000C993E
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000B3BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,5_2_000B3BC3
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E7A87 FindFirstFileExW,5_2_000E7A87
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\cab1.cabJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\NULLJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\NULLJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64Jump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packagesJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\NULLJump to behavior
Source: VC_redist.x64.exeString found in binary or memory: http://appsyndication.org/2006/appsyn
Source: VC_redist.x64.exe, 00000004.00000002.377084608.000000000005B000.00000002.00000001.01000000.00000008.sdmp, VC_redist.x64.exe, 00000004.00000000.270201080.000000000005B000.00000002.00000001.01000000.00000008.sdmp, VC_redist.x64.exe, 00000005.00000000.271727251.00000000000FB000.00000002.00000001.01000000.0000000A.sdmp, VC_redist.x64.exe, 00000005.00000002.374381326.00000000000FB000.00000002.00000001.01000000.0000000A.sdmp, VC_redist.x64.exe, 00000007.00000000.285438279.0000000000EBB000.00000002.00000001.01000000.0000000D.sdmp, VC_redist.x64.exe, 00000007.00000002.368408492.0000000000EBB000.00000002.00000001.01000000.0000000D.sdmp, VC_redist.x64.exe, 00000010.00000002.324092324.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000010.00000000.318798304.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000011.00000002.375653352.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000011.00000000.322751737.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000012.00000002.373692696.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000012.00000000.324242625.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000013.00000002.366393157.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 00000014.00000002.363516573.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 00000019.00000002.371119144.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000019.00000000.348409137.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 0000001B.00000002.368331825.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 0000001C.00000002.366244549.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 0000001D.00000002.356595702.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe.5.dr, VC_redist.x64.exe.7.drString found in binary or memory: http://appsyndication.org/2006/appsynapplicationapuputil.cppupgradeexclusivetrueenclosuredigestalgor
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://cert.ssl.com/SSLcom-SubCA-EV-CodeSigning-RSA-4096-R3.cer0_
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://crls.ssl.com/SSLcom-RootCA-EV-RSA-4096-R2.crl0
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://crls.ssl.com/SSLcom-SubCA-EV-CodeSigning-RSA-4096-R3.crl0
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://ocsp.digicert.com0A
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://ocsp.digicert.com0C
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://ocsp.digicert.com0X
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://ocsps.ssl.com0
Source: VC_redist.x64.exe, 0000001C.00000003.364850644.00000000037AB000.00000004.00000800.00020000.00000000.sdmp, VC_redist.x64.exe, 0000001C.00000003.365160612.0000000003390000.00000004.00000020.00020000.00000000.sdmp, thm.xml.20.dr, thm.xml.18.drString found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010
Source: VC_redist.x64.exe, 00000012.00000002.374125705.0000000003100000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010d=
Source: VC_redist.x64.exe, 00000012.00000002.374125705.0000000003100000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://wixtoolset.org/schemas/thmutil/2010le
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: http://www.ssl.com/repository/SSLcom-RootCA-EV-RSA-4096-R2.crt0
Source: Boku no Hero Academia 6th Season - Episode 13.exeString found in binary or memory: https://jrsoftware.org/ishelp/index.php?topic=setupcmdlineSetupU
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000001.00000003.250432231.0000000003500000.00000004.00001000.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.exe, 00000002.00000003.410317140.0000000002304000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smash.com
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000001.00000003.253560445.00000000025E4000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smash.com1R
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.407483126.00000000024F4000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smash.com1RO
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000001.00000003.253560445.00000000025E4000.00000004.00001000.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.407483126.00000000024F4000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smash.com2
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000001.00000003.253560445.00000000025E4000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smash.comiR
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.407483126.00000000024F4000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smash.comiRO
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.407001467.00000000024E6000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.408105135.0000000000A81000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.php
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.408105135.0000000000A81000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.php(
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409480442.0000000000AEA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.php2
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409374574.0000000000AC7000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404893356.0000000000AC7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.php8
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409434366.0000000000ADC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.php:
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.408105135.0000000000A81000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.php=
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.407404878.00000000024ED000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpA
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409693542.0000000003920000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpC:
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409480442.0000000000AEA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpJ6
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409480442.0000000000AEA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpR
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409391670.0000000000ACD000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404893356.0000000000AC7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpVH
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409434366.0000000000ADC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpb
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409434366.0000000000ADC000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpeewi
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.408105135.0000000000A81000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpl
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409480442.0000000000AEA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phplW7
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409410186.0000000000AD5000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404893356.0000000000AC7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpoft
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409480442.0000000000AEA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpv7
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409410186.0000000000AD5000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404893356.0000000000AC7000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.phpwEI
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409480442.0000000000AEA000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com/welcome2.php~6s
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409029766.0000000000A48000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://smashbrowser.com;4
Source: Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000003.244618238.0000000002520000.00000004.00001000.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000003.245016813.000000007FBD0000.00000004.00001000.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000001.00000000.248083178.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp.2.drString found in binary or memory: https://www.innosetup.com/
Source: Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000003.244618238.0000000002520000.00000004.00001000.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000003.245016813.000000007FBD0000.00000004.00001000.00020000.00000000.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp, 00000001.00000000.248083178.0000000000401000.00000020.00000001.01000000.00000004.sdmp, Boku no Hero Academia 6th Season - Episode 13.tmp.2.drString found in binary or memory: https://www.remobjects.com/ps
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.408510272.000000000018D000.00000004.00000010.00020000.00000000.sdmp, is-NDGJF.tmp.3.drString found in binary or memory: https://www.ssl.com/repository0
Source: unknownDNS traffic detected: queries for: accounts.google.com
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, BYTES_REVERSED_LO, 32BIT_MACHINE, BYTES_REVERSED_HI
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeFile deleted: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\Installer\3cd703.msiJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003C0FA4_2_0003C0FA
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_000161844_2_00016184
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004022D4_2_0004022D
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004A3B04_2_0004A3B0
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_000406624_2_00040662
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0001A7EF4_2_0001A7EF
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004A85E4_2_0004A85E
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003F9194_2_0003F919
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_000269CC4_2_000269CC
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00040A974_2_00040A97
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00042B214_2_00042B21
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004ED4C4_2_0004ED4C
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00042D504_2_00042D50
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003FE154_2_0003FE15
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000C69CC5_2_000C69CC
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000DC0FA5_2_000DC0FA
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000B61845_2_000B6184
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E022D5_2_000E022D
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000EA3B05_2_000EA3B0
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E06625_2_000E0662
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000BA7EF5_2_000BA7EF
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000EA85E5_2_000EA85E
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000DF9195_2_000DF919
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E0A975_2_000E0A97
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E2B215_2_000E2B21
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000EED4C5_2_000EED4C
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E2D505_2_000E2D50
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000DFE155_2_000DFE15
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: String function: 0005061A appears 34 times
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: String function: 00011F20 appears 54 times
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: String function: 000531C7 appears 83 times
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: String function: 000137D3 appears 496 times
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: String function: 0005012F appears 677 times
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: String function: 000F012F appears 678 times
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: String function: 000F061A appears 34 times
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: String function: 000B1F20 appears 54 times
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: String function: 000F31C7 appears 83 times
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: String function: 000B37D3 appears 496 times
Source: Boku no Hero Academia 6th Season - Episode 13.tmp.0.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: Boku no Hero Academia 6th Season - Episode 13.tmp.2.drStatic PE information: Resource name: RT_RCDATA type: PE32+ executable (console) x86-64, for MS Windows
Source: mfc140deu.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140rus.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140cht.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140jpn.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140kor.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140fra.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140chs.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140esn.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140ita.dll.15.drStatic PE information: No import functions for PE file found
Source: mfc140enu.dll.15.drStatic PE information: No import functions for PE file found
Source: Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000003.255058911.00000000022E8000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenamekernel32j% vs Boku no Hero Academia 6th Season - Episode 13.exe
Source: Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000000.243931389.00000000004C6000.00000002.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFileName vs Boku no Hero Academia 6th Season - Episode 13.exe
Source: Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000003.244618238.0000000002520000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFileName vs Boku no Hero Academia 6th Season - Episode 13.exe
Source: Boku no Hero Academia 6th Season - Episode 13.exe, 00000000.00000003.245016813.000000007FBD0000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFileName vs Boku no Hero Academia 6th Season - Episode 13.exe
Source: Boku no Hero Academia 6th Season - Episode 13.exe, 00000002.00000003.410259634.00000000022D8000.00000004.00001000.00020000.00000000.sdmpBinary or memory string: OriginalFilenamekernel32j% vs Boku no Hero Academia 6th Season - Episode 13.exe
Source: Boku no Hero Academia 6th Season - Episode 13.exeBinary or memory string: OriginalFileName vs Boku no Hero Academia 6th Season - Episode 13.exe
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeSection loaded: tsappcmp.dllJump to behavior
Source: C:\Windows\System32\msiexec.exeSection loaded: tsappcmp.dll
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\Policies\Google\Chrome /f
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile read: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$30408,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe"
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe "C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENT
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$2040C,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENT
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe "C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe" /install /quiet
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeProcess created: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exe "C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exe" -burn.clean.room="C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=628 /install /quiet
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeProcess created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exe "C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{E9871BE9-995B-4EFF-BA27-126D1FC36700} {ED4F63C9-39F6-4A7D-A76D-4B8F059F42ED} 5372
Source: unknownProcess created: C:\Windows\System32\msiexec.exe C:\Windows\system32\msiexec.exe /V
Source: unknownProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" /burn.runonce
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" /quiet /burn.log.append "C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20230102153454.log" /install
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=564 /quiet /burn.log.append "C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20230102153454.log" /install
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=540 -burn.filehandle.self=564 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{9F679354-B01C-4132-8C3B-9D0B8BAD9686} {7ADE5D70-631D-453D-B602-70E5C1B36EAF} 3732
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=576 -burn.filehandle.self=572 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{DC57C196-DCD2-4148-818F-F83AAF0E5C46} {63FE371D-956D-4D2B-988F-00929D1EE668} 2140
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe "C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe" install
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" "
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate
Source: unknownProcess created: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe" /C ""C:\Users\user\AppData\Local\WindowsApp\reg.bat" install
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" "
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\Policies\Google\Chrome /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallAllowlist" /v "1" /t REG_SZ /d dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "path" /t REG_SZ /d "C:\Users\user\AppData\Local\WindowsApp\apps-helper\apps.crx" /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "version" /t REG_SZ /d 1.0 /f
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$30408,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe "C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENTJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$2040C,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENTJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe "C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe" /install /quietJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe "C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe" installJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe" /C ""C:\Users\user\AppData\Local\WindowsApp\reg.bat" installJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeProcess created: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exe "C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exe" -burn.clean.room="C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=628 /install /quietJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeProcess created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exe "C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{E9871BE9-995B-4EFF-BA27-126D1FC36700} {ED4F63C9-39F6-4A7D-A76D-4B8F059F42ED} 5372Jump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468Jump to behavior
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" /quiet /burn.log.append "C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20230102153454.log" /install
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=564 /quiet /burn.log.append "C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20230102153454.log" /install
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=540 -burn.filehandle.self=564 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{DC57C196-DCD2-4148-818F-F83AAF0E5C46} {63FE371D-956D-4D2B-988F-00929D1EE668} 2140
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=576 -burn.filehandle.self=572 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" "
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" "
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\Policies\Google\Chrome /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallAllowlist" /v "1" /t REG_SZ /d dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "path" /t REG_SZ /d "C:\Users\user\AppData\Local\WindowsApp\apps-helper\apps.crx" /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "version" /t REG_SZ /d 1.0 /f
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{1f486a52-3cb1-48fd-8f50-b8dc300d9f9d}\InProcServer32Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_000144E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,4_2_000144E9
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000B44E9 GetCurrentProcess,OpenProcessToken,GetLastError,LookupPrivilegeValueW,GetLastError,AdjustTokenPrivileges,GetLastError,Sleep,InitiateSystemShutdownExW,GetLastError,CloseHandle,5_2_000B44E9
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Users\user\AppData\Local\ProgramsJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile created: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmpJump to behavior
Source: classification engineClassification label: sus26.winEXE@73/269@12/0
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00052F23 GetModuleHandleA,GetLastError,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CoCreateInstance,ExitProcess,4_2_00052F23
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
Source: vcRuntimeAdditional_x64.5.dr, 3cd711.msi.15.drBinary or memory string: SELECT `WixDependencyProvider`.`WixDependencyProvider`, `WixDependencyProvider`.`Component_`, `WixDependencyProvider`.`ProviderKey`, `WixDependencyProvider`.`Attributes` FROM `WixDependencyProvider`SELECT `WixDependency`.`WixDependency`, `WixDependencyProvider`.`Component_`, `WixDependency`.`ProviderKey`, `WixDependency`.`MinVersion`, `WixDependency`.`MaxVersion`, `WixDependency`.`Attributes` FROM `WixDependencyProvider`, `WixDependency`, `WixDependencyRef` WHERE `WixDependency`.`WixDependency` = `WixDependencyRef`.`WixDependency_` AND `WixDependencyProvider`.`WixDependencyProvider` = `WixDependencyRef`.`WixDependencyProvider_`WixDependencyRequireFailed to initialize.Failed to initialize the registry functions.ALLUSERSFailed to ensure required dependencies for (re)installing components.WixDependencyCheckFailed to ensure absent dependents for uninstalling components.WixDependencySkipping the dependency check since no dependencies are authored.Failed to check if the WixDependency table exists.Failed to initialize the unique dependency string list.Failed to open the query view for dependencies.Failed to get WixDependency.WixDependency.Failed to get WixDependencyProvider.Component_.Skipping dependency check for %ls because the component %ls is not being (re)installed.Failed to get WixDependency.ProviderKey.Failed to get WixDependency.MinVersion.Failed to get WixDependency.MaxVersion.Failed to get WixDependency.Attributes.Failed dependency check for %ls.Failed to enumerate all of the rows in the dependency query view.Failed to create the dependency record for message %d.Unexpected message response %d from user or bootstrapper application.Failed to get the ignored dependents.ALLFailed to check if "ALL" was set in IGNOREDEPENDENCIES.Skipping the dependencies check since IGNOREDEPENDENCIES contains "ALL".WixDependencyProviderSkipping the dependents check since no dependency providers are authored.Failed to check if the WixDependencyProvider table exists.Failed to open the query view for dependency providers.Failed to get WixDependencyProvider.WixDependencyProvider.Failed to get WixDependencyProvider.Component.Skipping dependents check for %ls because the component %ls is not being uninstalled.Failed to get WixDependencyProvider.ProviderKey.Failed to get WixDependencyProvider.Attributes.Failed dependents check for %ls.Failed to enumerate all of the rows in the dependency provider query view.;IGNOREDEPENDENCIESFailed to get the string value of the IGNOREDEPENDENCIES property.Failed to create the string dictionary.Failed to ignored dependency "%ls" to the string dictionary.wixdepca.cppNot enough memory to create the message record.Failed to set the message identifier into the message record.Failed to set the number of dependencies into the message record.The dependency "%ls" is missing or is not the required version.Found dependent "%ls", name: "%ls".Failed to set the dependency key "%ls" into the message record.Failed to set the dependency name "%ls" into
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004FD20 FormatMessageW,GetLastError,LocalFree,4_2_0004FD20
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00036945 ChangeServiceConfigW,GetLastError,4_2_00036945
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:6096:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5844:120:WilError_01
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:5872:120:WilError_01
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Program Files\InstallerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: cabinet.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: msi.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: version.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: wininet.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: comres.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: clbcatq.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: msasn1.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: crypt32.dll4_2_00011070
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCommand line argument: feclient.dll4_2_00011070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: cabinet.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: msi.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: version.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: wininet.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: comres.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: clbcatq.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: msasn1.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: crypt32.dll5_2_000B1070
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCommand line argument: feclient.dll5_2_000B1070
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" "
Source: VC_redist.x64.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: VC_redist.x64.exeString found in binary or memory: Failed to re-launch bundle process after RunOnce: %ls
Source: Boku no Hero Academia 6th Season - Episode 13.exeString found in binary or memory: /LOADINF="filename"
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOrganizationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion RegisteredOwnerJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpWindow found: window name: TMainFormJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpAutomated click: Next >
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeWindow detected: Number of UI elements: 23
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeWindow detected: Number of UI elements: 23
Source: C:\Windows\System32\msiexec.exeRegistry value created: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{CF4C347D-954E-4543-88D2-EC17F07F466F}
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic file information: File size 25461096 > 1048576
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpDirectory created: C:\Program Files\InstallerJump to behavior
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic PE information: certificate valid
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\burn.pdb source: VC_redist.x64.exe, 00000004.00000002.377084608.000000000005B000.00000002.00000001.01000000.00000008.sdmp, VC_redist.x64.exe, 00000004.00000000.270201080.000000000005B000.00000002.00000001.01000000.00000008.sdmp, VC_redist.x64.exe, 00000005.00000000.271727251.00000000000FB000.00000002.00000001.01000000.0000000A.sdmp, VC_redist.x64.exe, 00000005.00000002.374381326.00000000000FB000.00000002.00000001.01000000.0000000A.sdmp, VC_redist.x64.exe, 00000007.00000000.285438279.0000000000EBB000.00000002.00000001.01000000.0000000D.sdmp, VC_redist.x64.exe, 00000007.00000002.368408492.0000000000EBB000.00000002.00000001.01000000.0000000D.sdmp, VC_redist.x64.exe, 00000010.00000002.324092324.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000010.00000000.318798304.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000011.00000002.375653352.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000011.00000000.322751737.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000012.00000002.373692696.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000012.00000000.324242625.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000013.00000002.366393157.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 00000014.00000002.363516573.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 00000019.00000002.371119144.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 00000019.00000000.348409137.0000000000C6B000.00000002.00000001.01000000.00000010.sdmp, VC_redist.x64.exe, 0000001B.00000002.368331825.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 0000001C.00000002.366244549.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe, 0000001D.00000002.356595702.000000000005B000.00000002.00000001.01000000.00000013.sdmp, VC_redist.x64.exe.5.dr, VC_redist.x64.exe.7.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdb source: msvcp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFCM140U.amd64.pdb source: mfcm140u.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140.amd64.pdbGCTL source: msvcp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcamp140.amd64.pdb source: vcamp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFC140DEU.amd64.pdb source: mfc140deu.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFC140ENU.amd64.pdb source: mfc140enu.dll.15.dr
Source: Binary string: C:\Users\dsaxc\Desktop\InstallExtension\x64\Release\InstallExtension.pdb source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.392947585.0000000004EA0000.00000004.00001000.00020000.00000000.sdmp, InstallExtension.exe, 0000001E.00000000.378319985.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 0000001E.00000002.382242447.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000000.382129606.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000002.387277253.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, is-NDGJF.tmp.3.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\concrt140.amd64.pdb source: concrt140.dll.15.dr
Source: Binary string: C:\Users\dsaxc\Desktop\InstallExtension\x64\Release\InstallExtension.pdb%% source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.392947585.0000000004EA0000.00000004.00001000.00020000.00000000.sdmp, InstallExtension.exe, 0000001E.00000000.378319985.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 0000001E.00000002.382242447.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000000.382129606.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, InstallExtension.exe, 00000022.00000002.387277253.00007FF6C2DF7000.00000002.00000001.01000000.00000015.sdmp, is-NDGJF.tmp.3.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_atomic_wait.amd64.pdbGCTL source: msvcp140_atomic_wait.dll.15.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixStdBA.pdb source: wixstdba.dll.5.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_atomic_wait.amd64.pdb source: msvcp140_atomic_wait.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdb source: msvcp140_2.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\MFC140JPN.amd64.pdb source: mfc140jpn.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcamp140.amd64.pdbGCTL source: vcamp140.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\msvcp140_2.amd64.pdbGCTL source: msvcp140_2.dll.15.dr
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\concrt140.amd64.pdbGCTL source: concrt140.dll.15.dr
Source: Binary string: C:\agent\_work\8\s\build\ship\x86\WixDepCA.pdb source: vcRuntimeAdditional_x64.5.dr, 3cd711.msi.15.dr

Data Obfuscation

barindex
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$30408,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe"
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$2040C,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENT
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$30408,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" Jump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess created: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp "C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmp" /SL5="$2040C,24635135,780800,C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENTJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003E876 push ecx; ret 4_2_0003E889
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000DE876 push ecx; ret 5_2_000DE889
Source: Boku no Hero Academia 6th Season - Episode 13.exeStatic PE information: section name: .didata
Source: Boku no Hero Academia 6th Season - Episode 13.tmp.0.drStatic PE information: section name: .didata
Source: Boku no Hero Academia 6th Season - Episode 13.tmp.2.drStatic PE information: section name: .didata
Source: is-DLQHQ.tmp.3.drStatic PE information: section name: .wixburn
Source: VC_redist.x64.exe.4.drStatic PE information: section name: .wixburn
Source: VC_redist.x64.exe.5.drStatic PE information: section name: .wixburn
Source: VC_redist.x64.exe.7.drStatic PE information: section name: .wixburn
Source: mfc140.dll.15.drStatic PE information: section name: .didat
Source: mfc140u.dll.15.drStatic PE information: section name: .didat
Source: mfcm140.dll.15.drStatic PE information: section name: .nep
Source: mfcm140u.dll.15.drStatic PE information: section name: .nep
Source: vcomp140.dll.15.drStatic PE information: section name: _RDATA
Source: vcruntime140.dll.15.drStatic PE information: section name: _RDATA
Source: mfc140.dll.15.drStatic PE information: 0xFBD5982D [Wed Nov 21 09:09:01 2103 UTC]

Persistence and Installation Behavior

barindex
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\System32\cmd.exeProcess created: reg.exe
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeJump to dropped file
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile created: \boku no hero academia 6th season - episode 13.exe
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmp
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile created: \boku no hero academia 6th season - episode 13.exe
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmp
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmp
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmp
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile created: \boku no hero academia 6th season - episode 13.exeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmpJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile created: \boku no hero academia 6th season - episode 13.exeJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmpJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: \boku no hero academia 6th season - episode 13.tmpJump to behavior
Source: C:\Windows\System32\msiexec.exeFile created: 3cd71e.rbf (copy)Jump to dropped file
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140jpn.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140ita.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140esn.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd70e.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140deu.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd71b.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd708.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd718.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140chs.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfcm140u.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd722.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140enu.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Users\user\AppData\Local\WindowsApp\is-NDGJF.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\concrt140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140fra.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd70b.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vccorlib140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd707.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd71c.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcruntime140_1.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_atomic_wait.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcomp140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd71d.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd70d.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140cht.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140rus.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfcm140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140kor.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exe (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_2.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140u.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Users\user\AppData\Local\Temp\is-QUMRA.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd724.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd71f.rbf (copy)Jump to dropped file
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile created: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd70a.rbf (copy)Jump to dropped file
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeFile created: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd71a.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd70f.rbf (copy)Jump to dropped file
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeFile created: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd717.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_codecvt_ids.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd723.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcamp140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd710.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcruntime140.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\is-DLQHQ.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd720.rbf (copy)Jump to dropped file
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeJump to dropped file
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_1.dllJump to dropped file
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd721.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd709.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: 3cd719.rbf (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpFile created: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe (copy)Jump to dropped file
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140kor.dllJump to dropped file
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140jpn.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_2.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140ita.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140esn.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140deu.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140u.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140chs.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfcm140u.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140enu.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\concrt140.dllJump to dropped file
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140fra.dllJump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeFile created: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_codecvt_ids.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vccorlib140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcamp140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcruntime140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcruntime140_1.dllJump to dropped file
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_atomic_wait.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\vcomp140.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\msvcp140_1.dllJump to dropped file
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\wixstdba.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140cht.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfc140rus.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeFile created: C:\Windows\System32\mfcm140.dllJump to dropped file
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1028\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1029\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1031\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1036\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1040\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1041\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1042\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1045\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1046\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1049\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\1055\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\2052\license.rtfJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeFile created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\3082\license.rtfJump to behavior
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1028\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1029\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1031\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1036\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1040\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1041\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1042\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1045\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1046\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1049\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\1055\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\2052\license.rtf
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeFile created: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\3082\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1028\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1029\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1031\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1036\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1040\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1041\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1042\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1045\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1046\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1049\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\1055\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\2052\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\3082\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1028\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1029\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1031\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1036\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1040\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1041\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1042\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1045\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1046\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1049\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\1055\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\2052\license.rtf
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeFile created: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\3082\license.rtf

Boot Survival

barindex
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exeProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information set: FAILCRITICALERRORS | NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\msiexec.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\cmd.exeProcess information set: NOOPENFILEERRORBOX
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\conhost.exeLast function: Thread delayed
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd71e.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd70e.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd71b.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd708.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd718.rbf (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd722.rbf (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\is-QUMRA.tmp\_isetup\_setup64.tmpJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd724.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd71f.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd70a.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd71a.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd70f.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd70b.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd717.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\System32\msvcp140_codecvt_ids.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd723.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd707.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd710.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd71c.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd720.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: C:\Windows\System32\msvcp140_atomic_wait.dllJump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd71d.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd70d.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd721.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd709.rbf (copy)Jump to dropped file
Source: C:\Windows\System32\msiexec.exeDropped PE file which has not been started: 3cd719.rbf (copy)Jump to dropped file
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 0004FE5Dh4_2_0004FDC2
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004FDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 0004FE56h4_2_0004FDC2
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000EFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 05h and CTI: je 000EFE5Dh5_2_000EFDC2
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000EFDC2 GetLocalTime followed by cmp: cmp dword ptr [ebp+08h], 01h and CTI: je 000EFE56h5_2_000EFDC2
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeRegistry key enumerated: More than 302 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeRegistry key enumerated: More than 452 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeRegistry key enumerated: More than 150 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeRegistry key enumerated: More than 151 enums for key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCheck user administrative privileges: GetTokenInformation,DecisionNodes
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess information queried: ProcessInformationJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0005962D VirtualQuery,GetSystemInfo,4_2_0005962D
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00013BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,4_2_00013BC3
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00054315 FindFirstFileW,FindClose,4_2_00054315
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0002993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,4_2_0002993E
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00047A87 FindFirstFileExW,4_2_00047A87
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000F4315 FindFirstFileW,FindClose,5_2_000F4315
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000C993E FindFirstFileW,lstrlenW,FindNextFileW,FindClose,5_2_000C993E
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000B3BC3 GetFileAttributesW,GetLastError,GetLastError,SetFileAttributesW,GetLastError,GetTempPathW,GetLastError,FindFirstFileW,GetLastError,SetFileAttributesW,DeleteFileW,GetTempFileNameW,MoveFileExW,MoveFileExW,MoveFileExW,FindNextFileW,GetLastError,GetLastError,GetLastError,GetLastError,RemoveDirectoryW,GetLastError,MoveFileExW,GetLastError,FindClose,5_2_000B3BC3
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E7A87 FindFirstFileExW,5_2_000E7A87
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeAPI call chain: ExitProcess graph end node
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeAPI call chain: ExitProcess graph end node
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\System32\msiexec.exeFile Volume queried: C:\ FullSizeInformation
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\cab1.cabJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\NULLJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\NULLJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64Jump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packagesJump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeFile opened: C:\ProgramData\Package Cache\{12578975-C765-4BDF-8DDC-3284BC0E855F}v14.21.27702\packages\vcRuntimeAdditional_amd64\NULLJump to behavior
Source: VC_redist.x64.exe, 0000001C.00000003.364382485.0000000001568000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#000000001F400000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000026700000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\STORAGE#Volume#{e6e9dfc6-98f2-11e9-90ce-806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}
Source: VC_redist.x64.exe, 0000001C.00000003.364382485.0000000001568000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: \\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\\?\Volume{e6e9dfd8-98f2-11e9-90ce-806e6f6e6963}\
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000003.404958372.0000000000ADC000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}7
Source: Boku no Hero Academia 6th Season - Episode 13.tmp, 00000003.00000002.409480442.0000000000AEA000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: 806e6f6e6963}#0000000000100000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b}\\?\SCSI#CdRom&Ven_NECVMWar&Prod_VMware_SATA_CD00#5&280b647&0&000000#{53f5630d-b6bf-11d0-94f2-00a0c91efb8b},
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003E625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_0003E625
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_000138D4 GetProcessHeap,RtlAllocateHeap,4_2_000138D4
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00044812 mov eax, dword ptr fs:[00000030h]4_2_00044812
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E4812 mov eax, dword ptr fs:[00000030h]5_2_000E4812
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003E773 SetUnhandledExceptionFilter,4_2_0003E773
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003E188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,4_2_0003E188
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003E625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_0003E625
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00043BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,4_2_00043BB0
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000DE773 SetUnhandledExceptionFilter,5_2_000DE773
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000DE188 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,5_2_000DE188
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000DE625 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_000DE625
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeCode function: 5_2_000E3BB0 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,5_2_000E3BB0
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "c:\programdata\package cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\vc_redist.x64.exe" -burn.clean.room="c:\programdata\package cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\vc_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=564 /quiet /burn.log.append "c:\users\user\appdata\local\temp\dd_vcredist_amd64_20230102153454.log" /install
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded burnpipe.{652d427c-3fcf-4f57-9b0a-0ffbca2578fc} {cf7111b3-ff83-47bf-a56d-0e99b89a84c1} 5468
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.clean.room="c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.filehandle.attached=540 -burn.filehandle.self=564 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded burnpipe.{652d427c-3fcf-4f57-9b0a-0ffbca2578fc} {cf7111b3-ff83-47bf-a56d-0e99b89a84c1} 5468
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded burnpipe.{8ade75be-8c64-4d11-b05a-a6c78aecd63f} {6ee058d7-d097-43e8-87f0-a357d97d5238} 1324
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.clean.room="c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.filehandle.attached=576 -burn.filehandle.self=572 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded burnpipe.{8ade75be-8c64-4d11-b05a-a6c78aecd63f} {6ee058d7-d097-43e8-87f0-a357d97d5238} 1324
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded burnpipe.{652d427c-3fcf-4f57-9b0a-0ffbca2578fc} {cf7111b3-ff83-47bf-a56d-0e99b89a84c1} 5468Jump to behavior
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "c:\programdata\package cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\vc_redist.x64.exe" -burn.clean.room="c:\programdata\package cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\vc_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=564 /quiet /burn.log.append "c:\users\user\appdata\local\temp\dd_vcredist_amd64_20230102153454.log" /install
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.clean.room="c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.filehandle.attached=540 -burn.filehandle.self=564 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded burnpipe.{652d427c-3fcf-4f57-9b0a-0ffbca2578fc} {cf7111b3-ff83-47bf-a56d-0e99b89a84c1} 5468
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded burnpipe.{8ade75be-8c64-4d11-b05a-a6c78aecd63f} {6ee058d7-d097-43e8-87f0-a357d97d5238} 1324
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.clean.room="c:\programdata\package cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\vc_redist.x64.exe" -burn.filehandle.attached=576 -burn.filehandle.self=572 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded burnpipe.{8ade75be-8c64-4d11-b05a-a6c78aecd63f} {6ee058d7-d097-43e8-87f0-a357d97d5238} 1324
Source: C:\Users\user\AppData\Local\Temp\is-4VP2B.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe "C:\Users\user\Desktop\Boku no Hero Academia 6th Season - Episode 13.exe" /SILENTJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-4N7PP.tmp\Boku no Hero Academia 6th Season - Episode 13.tmpProcess created: unknown unknownJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeProcess created: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exe "C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exe" -burn.clean.room="C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=628 /install /quietJump to behavior
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeProcess created: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exe "C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{E9871BE9-995B-4EFF-BA27-126D1FC36700} {ED4F63C9-39F6-4A7D-A76D-4B8F059F42ED} 5372Jump to behavior
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468Jump to behavior
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exe" -burn.filehandle.attached=588 -burn.filehandle.self=564 /quiet /burn.log.append "C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20230102153454.log" /install
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=540 -burn.filehandle.self=564 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=1008 -burn.embedded BurnPipe.{652D427C-3FCF-4F57-9B0A-0FFBCA2578FC} {CF7111B3-FF83-47BF-A56D-0E99B89A84C1} 5468
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{DC57C196-DCD2-4148-818F-F83AAF0E5C46} {63FE371D-956D-4D2B-988F-00929D1EE668} 2140
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeProcess created: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe "C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.clean.room="C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exe" -burn.filehandle.attached=576 -burn.filehandle.self=572 -uninstall -quiet -burn.related.upgrade -burn.ancestors={d4cecf3b-b68f-4995-8840-52ea0fab646e} -burn.filehandle.self=900 -burn.embedded BurnPipe.{8ADE75BE-8C64-4D11-B05A-A6C78AECD63F} {6EE058D7-D097-43E8-87F0-A357D97D5238} 1324
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" "
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate
Source: C:\Users\user\AppData\Local\WindowsApp\InstallExtension.exeProcess created: C:\Windows\System32\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\WindowsApp\chrome.bat" "
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\schtasks.exe schtasks.exe /Create /XML "C:\Users\user\AppData\Local\WindowsApp\reg.xml" /tn GoogleUpdate
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\Policies\Google\Chrome /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG DELETE HKLM\SOFTWARE\WOW6432Node\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Policies\Google\Chrome\ExtensionInstallAllowlist" /v "1" /t REG_SZ /d dbffglanhdhedkjkijpkplhpcdndpchj /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "path" /t REG_SZ /d "C:\Users\user\AppData\Local\WindowsApp\apps-helper\apps.crx" /f
Source: C:\Windows\System32\cmd.exeProcess created: C:\Windows\System32\reg.exe REG ADD "HKLM\SOFTWARE\Google\Chrome\Extensions\dbffglanhdhedkjkijpkplhpcdndpchj" /v "version" /t REG_SZ /d 1.0 /f
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Windows\System32\cmd.exeProcess created: unknown unknown
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_000515CB InitializeSecurityDescriptor,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,CreateWellKnownSid,GetLastError,CreateWellKnownSid,SetEntriesInAclA,SetSecurityDescriptorOwner,GetLastError,SetSecurityDescriptorGroup,GetLastError,SetSecurityDescriptorDacl,GetLastError,CoInitializeSecurity,LocalFree,4_2_000515CB
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0005393B AllocateAndInitializeSid,CheckTokenMembership,4_2_0005393B
Source: C:\Windows\Temp\{22FC44A3-9D0C-4078-AD49-1FDAE23A881A}\.cr\VC_redist.x64.exeQueries volume information: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.ba\logo.png VolumeInformationJump to behavior
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\Windows\System32\vcruntime140.dll VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\Windows\System32\msvcp140.dll VolumeInformation
Source: C:\Windows\System32\msiexec.exeQueries volume information: C:\ VolumeInformation
Source: C:\ProgramData\Package Cache\{d4cecf3b-b68f-4995-8840-52ea0fab646e}\VC_redist.x64.exeQueries volume information: C:\Users\user\AppData\Local\Temp\{9B8C7EDA-2539-42FC-9E66-AE939366FE45}\.ba\logo.png VolumeInformation
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeQueries volume information: C:\Windows\Temp\{36CC976F-BDDA-47B0-BB5A-7568B395BA2A}\.ba\logo.png VolumeInformation
Source: C:\ProgramData\Package Cache\{f4220b74-9edd-4ded-bc8b-0342c1e164d8}\VC_redist.x64.exeQueries volume information: C:\Windows\Temp\{7B1AA818-8405-4B0F-ACAF-0273ABC8852E}\.ba\logo.png VolumeInformation
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0003E9A7 cpuid 4_2_0003E9A7
Source: C:\Windows\Temp\{52175C1E-180F-452E-83F2-4EF07DAE0BCF}\.be\VC_redist.x64.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00024CE8 ConvertStringSecurityDescriptorToSecurityDescriptorW,GetLastError,CreateNamedPipeW,GetLastError,CreateNamedPipeW,GetLastError,CloseHandle,LocalFree,4_2_00024CE8
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0004FDC2 EnterCriticalSection,GetCurrentProcessId,GetCurrentThreadId,GetLocalTime,LeaveCriticalSection,4_2_0004FDC2
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_00058733 GetTimeZoneInformation,SystemTimeToTzSpecificLocalTime,4_2_00058733
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_0001508D GetModuleHandleW,CoInitializeEx,GetVersionExW,GetLastError,CoUninitialize,4_2_0001508D
Source: C:\Users\user\AppData\Local\Temp\is-8STSI.tmp\VC_redist.x64.exeCode function: 4_2_000160BA GetUserNameW,GetLastError,4_2_000160BA
Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionExfiltrationCommand and ControlNetwork EffectsRemote Service EffectsImpact
1
Replication Through Removable Media
1
Scripting
1
DLL Side-Loading
1
DLL Side-Loading
11
Deobfuscate/Decode Files or Information
OS Credential Dumping12
System Time Discovery
1
Replication Through Removable Media
1
Archive Collected Data
Exfiltration Over Other Network Medium2
Encrypted Channel
Eavesdrop on Insecure Network CommunicationRemotely Track Device Without AuthorizationModify System Partition
Default Accounts1
Native API
1
DLL Search Order Hijacking
1
DLL Search Order Hijacking
1
Scripting
LSASS Memory11
Peripheral Device Discovery
Remote Desktop ProtocolData from Removable MediaExfiltration Over Bluetooth1
Non-Application Layer Protocol
Exploit SS7 to Redirect Phone Calls/SMSRemotely Wipe Data Without AuthorizationDevice Lockout
Domain Accounts213
Command and Scripting Interpreter
2
Windows Service
1
Access Token Manipulation
2
Obfuscated Files or Information
Security Account Manager1
Account Discovery
SMB/Windows Admin SharesData from Network Shared DriveAutomated Exfiltration1
Application Layer Protocol
Exploit SS7 to Track Device LocationObtain Device Cloud BackupsDelete Device Data
Local Accounts1
Scheduled Task/Job
1
Scheduled Task/Job
2
Windows Service
1
Timestomp
NTDS3
File and Directory Discovery
Distributed Component Object ModelInput CaptureScheduled TransferProtocol ImpersonationSIM Card SwapCarrier Billing Fraud
Cloud Accounts1
Service Execution
Network Logon Script12
Process Injection
1
DLL Side-Loading
LSA Secrets36
System Information Discovery
SSHKeyloggingData Transfer Size LimitsFallback ChannelsManipulate Device CommunicationManipulate App Store Rankings or Ratings
Replication Through Removable MediaLaunchdRc.common1
Scheduled Task/Job
1
DLL Search Order Hijacking
Cached Domain Credentials21
Security Software Discovery
VNCGUI Input CaptureExfiltration Over C2 ChannelMultiband CommunicationJamming or Denial of ServiceAbuse Accessibility Features
External Remote ServicesScheduled TaskStartup ItemsStartup Items1
File Deletion
DCSync11
Process Discovery
Windows Remote ManagementWeb Portal CaptureExfiltration Over Alternative ProtocolCommonly Used PortRogue Wi-Fi Access PointsData Encrypted for Impact
Drive-by CompromiseCommand and Scripting InterpreterScheduled Task/JobScheduled Task/Job23
Masquerading
Proc Filesystem3
System Owner/User Discovery
Shared WebrootCredential API HookingExfiltration Over Symmetric Encrypted Non-C2 ProtocolApplication Layer ProtocolDowngrade to Insecure ProtocolsGenerate Fraudulent Advertising Revenue
Exploit Public-Facing ApplicationPowerShellAt (Linux)At (Linux)1
Modify Registry
/etc/passwd and /etc/shadowSystem Network Connections DiscoverySoftware Deployment ToolsData StagedExfiltration Over Asymmetric Encrypted Non-C2 ProtocolWeb ProtocolsRogue Cellular Base StationData Destruction
Supply Chain CompromiseAppleScriptAt (Windows)At (Windows)1
Access Token Manipulation
Network SniffingProcess DiscoveryTaint Shared ContentLocal Data StagingExfiltration Over Unencrypted/Obfuscated Non-C2 ProtocolFile Transfer ProtocolsData Encrypted for Impact
Compromise Software Dependencies and Development ToolsWindows Command ShellCronCron12
Process Injection
Input CapturePermission Groups DiscoveryReplication Through Removable MediaRemote Data StagingExfiltration Over Physical MediumMail ProtocolsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 776910 Sample: Boku no Hero Academia 6th S... Startdate: 02/01/2023 Architecture: WINDOWS Score: 26 125 www3.l.google.com 2->125 127 www.google.com 2->127 129 13 other IPs or domains 2->129 135 Obfuscated command line found 2->135 15 Boku no Hero Academia 6th Season - Episode 13.exe 2 2->15         started        19 msiexec.exe 122 2->19         started        21 InstallExtension.exe 2->21         started        23 VC_redist.x64.exe 2->23         started        signatures3 process4 file5 107 Boku no Hero Acade...on - Episode 13.tmp, PE32 15->107 dropped 131 Obfuscated command line found 15->131 25 Boku no Hero Academia 6th Season - Episode 13.tmp 3 13 15->25         started        109 C:\Windows\System32\vcruntime140_1.dll, PE32+ 19->109 dropped 111 C:\Windows\System32\vcruntime140.dll, PE32+ 19->111 dropped 113 C:\Windows\System32\vcomp140.dll, PE32+ 19->113 dropped 115 45 other files (none is malicious) 19->115 dropped 28 cmd.exe 21->28         started        31 VC_redist.x64.exe 23->31         started        signatures6 process7 file8 103 C:\Users\user\AppData\Local\...\_setup64.tmp, PE32+ 25->103 dropped 33 Boku no Hero Academia 6th Season - Episode 13.exe 2 25->33         started        137 Uses cmd line tools excessively to alter registry or file data 28->137 37 conhost.exe 28->37         started        39 reg.exe 28->39         started        41 reg.exe 28->41         started        45 4 other processes 28->45 43 VC_redist.x64.exe 31->43         started        signatures9 process10 file11 93 Boku no Hero Acade...on - Episode 13.tmp, PE32 33->93 dropped 133 Obfuscated command line found 33->133 47 Boku no Hero Academia 6th Season - Episode 13.tmp 5 33 33->47         started        95 C:\Users\user\AppData\Local\...\wixstdba.dll, PE32 43->95 dropped 50 VC_redist.x64.exe 43->50         started        signatures12 process13 file14 117 C:\Users\user\AppData\Local\...\is-NDGJF.tmp, PE32+ 47->117 dropped 119 C:\Users\user\...\InstallExtension.exe (copy), PE32+ 47->119 dropped 121 C:\Users\user\AppData\Local\...\is-DLQHQ.tmp, PE32 47->121 dropped 123 2 other files (none is malicious) 47->123 dropped 52 InstallExtension.exe 47->52         started        55 VC_redist.x64.exe 3 47->55         started        57 cmd.exe 47->57         started        59 VC_redist.x64.exe 50->59         started        process15 file16 99 C:\Users\user\AppData\Local\...\reg.xml, XML 52->99 dropped 61 cmd.exe 52->61         started        101 C:\Windows\Temp\...\VC_redist.x64.exe, PE32 55->101 dropped 64 VC_redist.x64.exe 71 55->64         started        67 conhost.exe 57->67         started        69 schtasks.exe 57->69         started        71 VC_redist.x64.exe 59->71         started        process17 file18 139 Uses cmd line tools excessively to alter registry or file data 61->139 141 Uses schtasks.exe or at.exe to add and modify task schedules 61->141 73 conhost.exe 61->73         started        75 schtasks.exe 61->75         started        87 C:\Windows\Temp\...\VC_redist.x64.exe, PE32 64->87 dropped 89 C:\Windows\Temp\...\wixstdba.dll, PE32 64->89 dropped 77 VC_redist.x64.exe 30 18 64->77         started        91 C:\Windows\Temp\...\wixstdba.dll, PE32 71->91 dropped signatures19 process20 file21 105 C:\ProgramData\...\VC_redist.x64.exe, PE32 77->105 dropped 80 VC_redist.x64.exe 77->80         started        process22 process23 82 VC_redist.x64.exe 80->82         started        file24 97 C:\Windows\Temp\...\wixstdba.dll, PE32 82->97 dropped 85 VC_redist.x64.exe 82->85         started        process25

This section contains all screenshots as thumbnails, including those not shown in the slideshow.