Signatures
Checks available memory
Queries the keyboard layout
SetUnhandledExceptionFilter detected (possible anti-debug)
Checks adapter addresses which can be used to detect virtual network interfaces
A file with an unusual extension was attempted to be loaded as a DLL.
Possible date expiration check, exits too soon after checking local time
process: powershell.exe, PID 4996
Anomalous file deletion behavior detected (10+)
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2acbee.TMP
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_flglbmfj.co5.ps1
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_dhrdm2bq.0we.psm1
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2ad082.TMP
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_4vczcp2r.5jp.ps1
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_vi5jzsch.sji.psm1
file: C:\Users\Packager\AppData\Local\Temp\{9D2CE97D-3D64-4BE9-BE50-0CE04F2E6D65}.png
file: C:\Users\Packager\AppData\Local\Temp\{06E5347C-A0E0-456D-B915-DEF0F0AAD33C}.png
file: C:\Users\Packager\AppData\Local\Microsoft\Windows\Explorer\NotifyIcon\Microsoft.Explorer.Notification.{B0AA627D-AE34-F5C9-9971-19C8E1D372A3}.png
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2adb40.TMP
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_yfbr1t2i.klp.ps1
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_xsrtjvhg.ev5.psm1
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.pdb
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.tmp
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.cmdline
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.err
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.out
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.dll
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.dll
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.err
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.0.cs
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.cmdline
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.out
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.tmp
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.pdb
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2b0f31.TMP
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_fhlepf3t.zqu.ps1
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_tvipahfx.02g.psm1
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.out
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.err
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.cmdline
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.dll
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.pdb
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.tmp
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.pdb
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.dll
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.tmp
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.out
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.cmdline
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.0.cs
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.err
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_k1qb5hwf.0ua.ps1
file: C:\Users\Packager\AppData\Local\Temp\__PSScriptPolicyTest_jax1rebi.eug.psm1
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.cmdline
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.tmp
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.out
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.err
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.pdb
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.dll
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.err
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.out
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.0.cs
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.cmdline
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.tmp
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.pdb
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.dll
file: C:\Users\Packager\AppData\Local\Temp\RESAD94.tmp
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\CSCC325E59DF6324D5E94CEF9A2127DC5.TMP
file: C:\Users\Packager\AppData\Local\Temp\RESC4E.tmp
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\CSC3929ABE813164F8A9CE7A02E5C3604A.TMP
file: C:\Users\Packager\AppData\Local\Temp\RES18E1.tmp
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\CSCF1369EE98E045459A25853A9256DB9.TMP
file: C:\Users\Packager\AppData\Local\Temp\RES266D.tmp
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\CSC920B500EE9DB4722B11928A146C843C6.TMP
file: C:\Users\Packager\AppData\Local\Temp\RES79BE.tmp
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\CSC9E3DB80FF4D2471195BD7CF6053F921.TMP
file: C:\Users\Packager\AppData\Local\Temp\RES82C6.tmp
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\CSC8F52E0DFFD804426BDA81C753DE9E931.TMP
file: C:\Windows\Temp\{6F28593F-24E6-41AC-8997-8EE884FA5776}\.cr\TableauReader-64bit-2024-3-3.exe
Guard pages use detected - possible anti-debugging.
At least one IP Address, Domain, or File Name was found in a crypto call
ioc: https://go.microsoft.com/fwlink/
ioc: 3.1.0.0
ioc: anagement.dll
ioc: 1.0.0.0
ioc: v1.0.cdxml
ioc: ask.types.ps1xml
ioc: ask.format.ps1xml
ioc: http://schemas.microsoft.com/cmdlets-over-objects/2009/11
ioc: powershell.exe
ioc: 3.0.0.0
ioc: ecurity.dll
Resumed a thread in another process
thread_resumed: Process powershell.exe with process ID 4996 resumed a thread in another process with the process ID 4996
thread_resumed: Process powershell.exe with process ID 6128 resumed a thread in another process with the process ID 6128
thread_resumed: Process explorer.exe with process ID 640 resumed a thread in another process with the process ID 640
thread_resumed: Process powershell.exe with process ID 3532 resumed a thread in another process with the process ID 3532
thread_resumed: Process deploy-application.exe with process ID 5816 resumed a thread in another process with the process ID 5816
thread_resumed: Process powershell.exe with process ID 216 resumed a thread in another process with the process ID 216
thread_resumed: Process powershell.exe with process ID 684 resumed a thread in another process with the process ID 684
Reads data out of its own binary image
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4336, offset: 0x3030785c3030785c, length: 0x00000040
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4336, offset: 0x3030785c3030785c, length: 0x000d6178
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4336, offset: 0x3130785c3062785c, length: 0x00000008
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4336, offset: 0x3130785c3831785c, length: 0x00000018
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4336, offset: 0x3230785c3031785c, length: 0x000000a0
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4336, offset: 0x3464785c3030785c, length: 0x00000200
self_read: process: wscript.exe, pid: 3036, offset: 0x00000000, length: 0x00000040
self_read: process: wscript.exe, pid: 3036, offset: 0x3039785c3838785c, length: 0x00000010
self_read: process: wscript.exe, pid: 3036, offset: 0x3039785c3839785c, length: 0x00000002
self_read: process: wscript.exe, pid: 3036, offset: 0x30785c6138785c60, length: 0x00000018
self_read: process: wscript.exe, pid: 3036, offset: 0x30785c623032785c, length: 0x00000018
self_read: process: wscript.exe, pid: 3036, offset: 0x3130785c3030785c, length: 0x00000018
self_read: process: wscript.exe, pid: 3036, offset: 0x3130785c3866785c, length: 0x000000a0
self_read: process: wscript.exe, pid: 3036, offset: 0x6138785c3030785c, length: 0x00000018
self_read: process: wscript.exe, pid: 3036, offset: 0x6138785c3831785c, length: 0x00000008
self_read: process: wscript.exe, pid: 3036, offset: 0x6538785c3861785c, length: 0x00000010
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4208, offset: 0x3030785c3030785c, length: 0x00000040
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4208, offset: 0x3030785c3030785c, length: 0x000d6178
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4208, offset: 0x3130785c3062785c, length: 0x00000008
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4208, offset: 0x3130785c3831785c, length: 0x00000018
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4208, offset: 0x3230785c3031785c, length: 0x000000a0
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 4208, offset: 0x3464785c3030785c, length: 0x00000200
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 3368, offset: 0x3030785c3030785c, length: 0x00000040
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 3368, offset: 0x3030785c3030785c, length: 0x000d6178
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 3368, offset: 0x3130785c3062785c, length: 0x00000008
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 3368, offset: 0x3130785c3831785c, length: 0x00000018
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 3368, offset: 0x3230785c3031785c, length: 0x000000a0
self_read: process: TableauReader-64bit-2024-3-3.exe, pid: 3368, offset: 0x3464785c3030785c, length: 0x00000200
A process created a hidden window
process: svchost.exe -> \\?\C:\Windows\system32\wbem\WMIADAP.EXE
process: Deploy-Application.exe -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe
process: Deploy-Application.exe -> C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe
process: PowerShell.exe -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
process: PowerShell.exe -> C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Executed a very long command line or script command which may be indicative of chained commands or obfuscation
command: "C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
command: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
A scripting utility was executed
command: C:\Windows\system32\wscript.exe "C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/AppDeployToolkit/RunHidden.vbs
command: "C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
command: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
Uses Windows utilities for basic functionality
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.cmdline"
Tries to unhook or modify Windows functions monitored by CAPE
unhook: function_name: ObtainUserAgentString, type: removal
unhook: function_name: CoInternetSetFeatureEnabled, type: removal
unhook: function_name: URLDownloadToFileW, type: removal
unhook: function_name: IsValidURL, type: removal
unhook: function_name: URLDownloadToCacheFileW, type: removal
Compiles .NET code into an executable and executes it
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.cmdline"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RESAD94.tmp" "c:\Users\Packager\AppData\Local\Temp\keihajvj\CSCC325E59DF6324D5E94CEF9A2127DC5.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RESAD94.tmp" "c:\Users\Packager\AppData\Local\Temp\keihajvj\CSCC325E59DF6324D5E94CEF9A2127DC5.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RESC4E.tmp" "c:\Users\Packager\AppData\Local\Temp\ny53s0ai\CSC3929ABE813164F8A9CE7A02E5C3604A.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RESC4E.tmp" "c:\Users\Packager\AppData\Local\Temp\ny53s0ai\CSC3929ABE813164F8A9CE7A02E5C3604A.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES18E1.tmp" "c:\Users\Packager\AppData\Local\Temp\co4yjzy4\CSCF1369EE98E045459A25853A9256DB9.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES18E1.tmp" "c:\Users\Packager\AppData\Local\Temp\co4yjzy4\CSCF1369EE98E045459A25853A9256DB9.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES266D.tmp" "c:\Users\Packager\AppData\Local\Temp\irzrv3x1\CSC920B500EE9DB4722B11928A146C843C6.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES266D.tmp" "c:\Users\Packager\AppData\Local\Temp\irzrv3x1\CSC920B500EE9DB4722B11928A146C843C6.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES79BE.tmp" "c:\Users\Packager\AppData\Local\Temp\htzqsja5\CSC9E3DB80FF4D2471195BD7CF6053F921.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES79BE.tmp" "c:\Users\Packager\AppData\Local\Temp\htzqsja5\CSC9E3DB80FF4D2471195BD7CF6053F921.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES82C6.tmp" "c:\Users\Packager\AppData\Local\Temp\xzqdrh2p\CSC8F52E0DFFD804426BDA81C753DE9E931.TMP"
command: C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\Packager\AppData\Local\Temp\RES82C6.tmp" "c:\Users\Packager\AppData\Local\Temp\xzqdrh2p\CSC8F52E0DFFD804426BDA81C753DE9E931.TMP"
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.0.cs
file: C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/AppDeployToolkit/AppDeployToolkitMain.cs
file: C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/AppDeployToolkit/RunHidden.vbs
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.cmdline
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.cmdline
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.cmdline
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.cmdline
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.cmdline
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.cmdline
file: C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/Deploy-Application.exe
file: C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/AppDeployToolkit/SetACL.exe
file: C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/ServiceUI.exe
file: C:\Windows\Temp\{6F28593F-24E6-41AC-8997-8EE884FA5776}\.cr\TableauReader-64bit-2024-3-3.exe
file: C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/Deploy-Application.exe.config
file: C:\Users\Packager\AppData\Local\Temp\RESAD94.tmp
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\CSC3929ABE813164F8A9CE7A02E5C3604A.TMP
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\CSCF1369EE98E045459A25853A9256DB9.TMP
file: C:\Users\Packager\AppData\Local\Temp\RES18E1.tmp
file: C:\Users\Packager\AppData\Local\Temp\RES79BE.tmp
file: C:\Users\Packager\AppData\Local\Temp\RES266D.tmp
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\CSC920B500EE9DB4722B11928A146C843C6.TMP
file: C:\Users\Packager\AppData\Local\Temp\RESC4E.tmp
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\CSC9E3DB80FF4D2471195BD7CF6053F921.TMP
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\CSCC325E59DF6324D5E94CEF9A2127DC5.TMP
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\CSC8F52E0DFFD804426BDA81C753DE9E931.TMP
file: C:\Users\Packager\AppData\Local\Temp\RES82C6.tmp
Creates a hidden or system file
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2acbee.TMP
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2ad082.TMP
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2adb40.TMP
file: C:\Users\Packager\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF2b0f31.TMP
Yara detections observed in process dumps, payloads or dropped files
Hit: PID triggered the Yara rule 'INDICATOR_SUSPICIOUS_PWSH_B64Encoded_Concatenated_FileEXEC' with data '['::WriteAllBytes(', '-join', ' += ', 'System.Diagnostics.Process', 'StartInfo.UseShellExecute', 'Get-WmiObject', 'Start-Process', 'Get-Process']'
A script or command line contains a long continuous string indicative of obfuscation
command: C:\Windows\system32\wscript.exe "C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01/Package/AppDeployToolkit/RunHidden.vbs
command: "C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
command: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
Deletes executed files from disk
file: C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.cmdline
file: C:\Users\Packager\AppData\Local\Temp\keihajvj
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.cmdline
file: C:\Users\Packager\AppData\Local\Temp\irzrv3x1
file: C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.cmdline
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.cmdline
file: C:\Users\Packager\AppData\Local\Temp\htzqsja5
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.cmdline
file: C:\Users\Packager\AppData\Local\Temp\co4yjzy4
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.cmdline
file: C:\Users\Packager\AppData\Local\Temp\xzqdrh2p
file: C:\Users\Packager\AppData\Local\Temp\RESAD94.tmp
file: C:\Users\Packager\AppData\Local\Temp\RESC4E.tmp
file: C:\Users\Packager\AppData\Local\Temp\RES18E1.tmp
file: C:\Users\Packager\AppData\Local\Temp\RES266D.tmp
file: C:\Users\Packager\AppData\Local\Temp\RES79BE.tmp
file: C:\Users\Packager\AppData\Local\Temp\RES82C6.tmp
file: C:\Windows\Temp\{6F28593F-24E6-41AC-8997-8EE884FA5776}\.cr\TableauReader-64bit-2024-3-3.exe
file: C:\Windows\Temp\{6F28593F-24E6-41AC-8997-8EE884FA5776}\.cr\
file: C:\Windows\Temp\{6F28593F-24E6-41AC-8997-8EE884FA5776}\
Attempts to execute suspicious powershell command arguments
command: "C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: "C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: C:\Windows\System32\WindowsPowerShell\v1.0\PowerShell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & { & 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\Deploy-Application.ps1'; Exit $LastExitCode }
command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
command: "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
command: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
command: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Bypass -NoProfile -NoLogo -WindowStyle Hidden -Command & {
Param(
[Parameter(Mandatory = $true, Position = 0)]
[ValidateNotNullOrEmpty()]
[String]$BalloonTipText,
[Parameter(Mandatory = $false, Position = 1)]
[ValidateNotNullorEmpty()]
[String]$BalloonTipTitle,
[Parameter(Mandatory = $false, Position = 2)]
[ValidateSet('Error', 'Info', 'None', 'Warning')]
$BalloonTipIcon = 'Info',
[Parameter(Mandatory = $false, Position = 3)]
[ValidateNotNullorEmpty()]
[Int32]$BalloonTipTime,
[Parameter(Mandatory = $false, Position = 4)]
[ValidateNotNullorEmpty()]
[String]$AppDeployLogoIcon
)
Add-Type -AssemblyName 'System.Windows.Forms', 'System.Drawing' -ErrorAction 'Stop'
$BalloonTipIconText = [String]::Concat($BalloonTipTitle, ' - ', $BalloonTipText)
If ($BalloonTipIconText.Length -gt 63) {
$BalloonTipIconText = [String]::Concat($BalloonTipIconText.Substring(0, 60), '...')
}
[Windows.Forms.ToolTipIcon]$BalloonTipIcon = $BalloonTipIcon
$script:notifyIcon = New-Object -TypeName 'System.Windows.Forms.NotifyIcon' -Property @{
BalloonTipIcon = $BalloonTipIcon
BalloonTipText = $BalloonTipText
BalloonTipTitle = $BalloonTipTitle
Icon = New-Object -TypeName 'System.Drawing.Icon' -ArgumentList ($AppDeployLogoIcon)
Text = $BalloonTipIconText
Visible = $true
}
$script:notifyIcon.ShowBalloonTip($BalloonTipTime)
Start-Sleep -Milliseconds ($BalloonTipTime)
$script:notifyIcon.Dispose() } 'Installation failed.' 'Tableau Reader 2024.3.3 x64 MUI 01' 'Error' '10000' 'C:\Users\Packager\AppData\Local\Temp\Tableau_Reader_2024.3.3_x64_MUI_01\Package\AppDeployToolkit\AppDeployToolkitLogo.ico'
Collects information to fingerprint the system
regkey: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\DigitalProductId
Uses csc.exe C# compiler to build and execute code
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\keihajvj\keihajvj.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\irzrv3x1\irzrv3x1.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\ny53s0ai\ny53s0ai.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\htzqsja5\htzqsja5.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\co4yjzy4\co4yjzy4.cmdline"
command: "C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\Packager\AppData\Local\Temp\xzqdrh2p\xzqdrh2p.cmdline"
Uses suspicious command line tools or Windows utilities