analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe

Full analysis: https://app.any.run/tasks/2d456aab-1b3b-4cb9-b221-4c11d3e87f46
Verdict: Malicious activity
Analysis date: March 08, 2024, 12:44:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E87AA8DCB2F95EF40221C106579E0B5D

SHA1:

E54497D919D9245969FA4A83E27DB3C5EC931C4C

SHA256:

4D1ADF3F837C4B92D49A5892F58E6E1F6566E6A7BD648B117232FFD8341124C2

SSDEEP:

49152:WI2P/g85GkowefWaLbd6FP/+DQiFrDGP/qQqFMCqDChtRss:d/LLyWtFCP/8qDChAs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
    • Connects to the CnC server

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
    • Reads the Internet Settings

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
    • Reads security settings of Internet Explorer

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
  • INFO

    • Checks supported languages

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
      • hcs.exe (PID: 3664)
      • hcs.exe (PID: 3892)
      • hcs.exe (PID: 3732)
    • Creates files in the program directory

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
    • Reads the computer name

      • facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe (PID: 3672)
      • hcs.exe (PID: 3892)
      • hcs.exe (PID: 3664)
    • Manual execution by a user

      • notepad.exe (PID: 2564)
      • notepad.exe (PID: 1644)
      • explorer.exe (PID: 3460)
      • notepad.exe (PID: 2596)
      • notepad.exe (PID: 2384)
      • notepad.exe (PID: 2576)
      • notepad++.exe (PID: 2900)
      • notepad.exe (PID: 1404)
      • notepad.exe (PID: 2568)
      • notepad.exe (PID: 844)
      • notepad++.exe (PID: 984)
      • notepad++.exe (PID: 3444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Delphi generic (37.4)
.scr | Windows screen saver (34.5)
.exe | Win32 Executable (generic) (11.9)
.exe | Win16/32 Executable Delphi generic (5.4)
.exe | Generic Win/DOS Executable (5.2)

EXIF

EXE

Comments: No Comments
ProductVersion: 7.7
ProductName:
OriginalFileName: apc_host.exe
LegalTrademarks: -
LegalCopyright:
InternalName: -
FileVersion: 7.7.0.0
FileDescription:
CompanyName:
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 7.7.0.0
FileVersionNumber: 7.7.0.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0xcd78c
UninitializedDataSize: -
InitializedDataSize: 688128
CodeSize: 838144
LinkerVersion: 2.25
PEType: PE32
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
TimeStamp: 1992:06:19 22:22:17+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
16
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start facturacion_masmovil-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgcm9uywxkaw5obze=.exe hcs.exe no specs hcs.exe no specs hcs.exe no specs explorer.exe no specs notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad++.exe notepad.exe no specs notepad.exe no specs notepad.exe no specs notepad++.exe notepad.exe no specs notepad.exe no specs notepad++.exe

Process information

PID
CMD
Path
Indicators
Parent process
3672"C:\Users\admin\Desktop\facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe" C:\Users\admin\Desktop\facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Version:
7.7.0.0
Modules
Images
c:\users\admin\desktop\facturacion_masmovil-y3jpc2dvbjg3qgdtywlslmnvbsazodq1mjmgcm9uywxkaw5obze=.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3664"C:\ProgramData\Anyplace Control Support\hcs.exe" /effects=onC:\ProgramData\Anyplace?Control?Support\apc-settings.iniC:\ProgramData\Anyplace Control Support\hcs.exefacturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\anyplace control support\hcs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3892"C:\ProgramData\Anyplace Control Support\hcs.exe" /theme=onC:\ProgramData\Anyplace?Control?Support\apc-settings.iniC:\ProgramData\Anyplace Control Support\hcs.exefacturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\anyplace control support\hcs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3732"C:\ProgramData\Anyplace Control Support\hcs.exe" /wallpaper=onC:\ProgramData\Anyplace Control Support\hcs.exefacturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\anyplace control support\hcs.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3460"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2596"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\apc-host.logC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1644"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\apc-host.logC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2564"C:\Windows\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\apc-settings.iniC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2900"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\hostaccount.ini"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2576"C:\Windows\system32\NOTEPAD.EXE" C:\ProgramData\Anyplace Control Support\apcErrorsLog.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 445
Read events
2 395
Write events
50
Delete events
0

Modification events

(PID) Process:(3672) facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3672) facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3672) facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3672) facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2900) notepad++.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3444) notepad++.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(984) notepad++.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
3
Suspicious files
0
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\sessionID.txttext
MD5:A5EA0AD9260B1550A14CC58D2C39B03D
SHA256:F1B2F662800122BED0FF255693DF89C4487FBDCF453D3524A42D4EC20C3D9C04
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\apc-host.logtext
MD5:81051BCC2CF1BEDF378224B0A93E2877
SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\hoststate.dattext
MD5:81051BCC2CF1BEDF378224B0A93E2877
SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\apcErrorsLog.txttext
MD5:B744198D3E6317EA319F60A0753D14C1
SHA256:3198D5141D6DE297753B37F6DC51B08835225E058CA44527D1EF39BCF38E4466
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\libspeexdsp.dllexecutable
MD5:9A8608BB0B654C650743221914D87AC2
SHA256:F15B0408096EAFC700FE069B716FFA921854B4E95BED33AD08524A59CC8AD57B
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\hostaccount.initext
MD5:7918433C031AF194FC4E24B0A37C2F4E
SHA256:E1C0916FA4EA79A640470984433D41EEAFF1597FA4BEC5A397971945C2432B62
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\apc-settings.initext
MD5:CE07AB443E53CF29C39E18410C4D06BF
SHA256:849E05DF1EB0E26374B6349A00196D3F0E962E3E5B98EBC9EC342890F752A384
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\libspeex.dllexecutable
MD5:E10DB82C997A756A01B6F954E86B83E0
SHA256:65A9BBD5B3B9161C0DD61A9E185E391CFA68F31171E1A5FCFAD20BCC9EB09480
3672facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exeC:\ProgramData\Anyplace Control Support\hcs.exeexecutable
MD5:AC5933067B2C38299AE1443331A61511
SHA256:8C305BB4C07FAC5C88AD1906E6195DD8176F7B6E5014E8FB3E081A45161CF72A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
9
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
216.158.90.159:443
anyplace-gateway.work
WEBNX
US
unknown
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
216.158.90.159:80
anyplace-gateway.work
WEBNX
US
unknown

DNS requests

Domain
IP
Reputation
anyplace-gateway.work
  • 216.158.90.159
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .work TLD
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Checkin (051)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Checkin (051)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
3672
facturacion_masmovil-Y3Jpc2dvbjg3QGdtYWlsLmNvbSAzODQ1MjMgcm9uYWxkaW5obzE=.exe
Misc activity
ET INFO Anyplace Remote Access Initial Connection Attempt (005)
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\plugins\Config\nppPluginList.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe