File name:

microsoft office 2007 service pack 2.exe.zip

Full analysis: https://app.any.run/tasks/ef5e4e53-8367-4bb3-a02c-b458d935c4f0
Verdict: Malicious activity
Analysis date: March 02, 2024, 16:48:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

EBE8B633D231BBFEE9543D744A2AB59D

SHA1:

9D3395D94C6BBBA52ABF0E6AFCBF4CA312597C21

SHA256:

4842C6E6A522207C69870B6BE3B04F3FD00BB5225C8A4C9E921991E477908ED5

SSDEEP:

3072:VzvXGeqnbr/OPvmT4ZLTLetuRcmr9rujM3fK2eiPr4ch15A/G:VrHmOLpCQamhruQF/Zz5A/G

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • WinRAR.exe (PID: 3668)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • csc.exe (PID: 2100)
      • csc.exe (PID: 1340)
      • csc.exe (PID: 2320)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Starts Visual C# compiler

      • sdiagnhost.exe (PID: 2432)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Executable content was dropped or overwritten

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • csc.exe (PID: 2100)
      • csc.exe (PID: 2320)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
      • csc.exe (PID: 1340)
    • The process creates files with name similar to system file names

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Reads settings of System Certificates

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • msdt.exe (PID: 3068)
      • northstar.exe (PID: 3496)
    • Reads security settings of Internet Explorer

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • northstar.exe (PID: 3496)
    • Checks Windows Trust Settings

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • northstar.exe (PID: 3496)
    • Probably uses Microsoft diagnostics tool to execute malicious payload

      • pcwrun.exe (PID: 1560)
    • Process drops legitimate windows executable

      • msdt.exe (PID: 3068)
    • Reads the Internet Settings

      • sdiagnhost.exe (PID: 2432)
    • Uses .NET C# to load dll

      • sdiagnhost.exe (PID: 2432)
  • INFO

    • Manual execution by a user

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 3772)
      • microsoft office 2007 service pack 2.exe (PID: 2692)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • pcwrun.exe (PID: 1560)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 3668)
    • Reads Environment values

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • northstar.exe (PID: 3496)
    • Reads the software policy settings

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • msdt.exe (PID: 3068)
      • northstar.exe (PID: 3496)
    • Reads the machine GUID from the registry

      • northstar.exe (PID: 4060)
      • northstar.exe (PID: 2756)
      • csc.exe (PID: 2100)
      • cvtres.exe (PID: 1368)
      • csc.exe (PID: 1340)
      • cvtres.exe (PID: 2888)
      • cvtres.exe (PID: 2260)
      • csc.exe (PID: 2320)
      • northstar.exe (PID: 3496)
    • Checks supported languages

      • northstar.exe (PID: 4060)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • northstar.exe (PID: 2756)
      • csc.exe (PID: 2100)
      • cvtres.exe (PID: 1368)
      • csc.exe (PID: 1340)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
      • cvtres.exe (PID: 2260)
      • csc.exe (PID: 2320)
      • cvtres.exe (PID: 2888)
      • northstar.exe (PID: 3496)
    • Reads the computer name

      • northstar.exe (PID: 4060)
      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • northstar.exe (PID: 2756)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
      • northstar.exe (PID: 3496)
    • Create files in a temporary directory

      • microsoft office 2007 service pack 2.exe (PID: 2636)
      • microsoft office 2007 service pack 2.exe (PID: 2420)
      • pcwrun.exe (PID: 1560)
      • msdt.exe (PID: 3068)
      • sdiagnhost.exe (PID: 2432)
      • csc.exe (PID: 2100)
      • cvtres.exe (PID: 1368)
      • csc.exe (PID: 1340)
      • cvtres.exe (PID: 2888)
      • cvtres.exe (PID: 2260)
      • csc.exe (PID: 2320)
      • microsoft office 2007 service pack 2.exe (PID: 3224)
    • Drops the executable file immediately after the start

      • msdt.exe (PID: 3068)
    • Reads security settings of Internet Explorer

      • msdt.exe (PID: 3068)
      • sdiagnhost.exe (PID: 2432)
    • Creates files or folders in the user directory

      • msdt.exe (PID: 3068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 819
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2012:12:27 15:15:52
ZipCRC: 0x00000000
ZipCompressedSize: 139448
ZipUncompressedSize: 178920
ZipFileName: microsoft office 2007 service pack 2.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
62
Monitored processes
18
Malicious processes
8
Suspicious processes
1

Behavior graph

Click at the process to see the details
start winrar.exe microsoft office 2007 service pack 2.exe no specs microsoft office 2007 service pack 2.exe northstar.exe no specs microsoft office 2007 service pack 2.exe no specs microsoft office 2007 service pack 2.exe northstar.exe no specs pcwrun.exe no specs msdt.exe no specs sdiagnhost.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs microsoft office 2007 service pack 2.exe northstar.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1340"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\s9c6impk.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1368C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES6ADB.tmp" "c:\Users\admin\AppData\Local\Temp\CSC6ADA.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
1560C:\Windows\system32\pcwrun.exe "C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe"C:\Windows\System32\pcwrun.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Program Compatibility Troubleshooter Invoker
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\pcwrun.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2100"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\feg-snok.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2260C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES6B49.tmp" "c:\Users\admin\AppData\Local\Temp\CSC6B48.tmp"C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
8.00.50727.5003 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cryptsp.dll
2320"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\fs52dff7.cmdline"C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe
sdiagnhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
8.0.50727.5483 (Win7SP1GDR.050727-5400)
Modules
Images
c:\windows\microsoft.net\framework\v2.0.50727\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.4940_none_d08cc06a442b34fc\msvcr80.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2420"C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe" C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
microsoft-office-2007-service-pack-2
Exit code:
0
Version:
2.2.49.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
2432C:\Windows\System32\sdiagnhost.exe -EmbeddingC:\Windows\System32\sdiagnhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Scripted Diagnostics Native Host
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sdiagnhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
2636"C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe" C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
microsoft-office-2007-service-pack-2
Exit code:
0
Version:
2.2.49.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
2692"C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe" C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
microsoft-office-2007-service-pack-2
Exit code:
3221226540
Version:
2.2.49.0
Modules
Images
c:\users\admin\appdata\local\temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exe
c:\windows\system32\ntdll.dll
Total events
27 459
Read events
27 375
Write events
81
Delete events
3

Modification events

(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(3668) WinRAR.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\phacker.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\Win7-KB3191566-x86.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe.zip
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(3668) WinRAR.exeKey:HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
Executable files
12
Suspicious files
16
Text files
23
Unknown types
1

Dropped files

PID
Process
Filename
Type
2636microsoft office 2007 service pack 2.exeC:\Users\admin\AppData\Local\Temp\nsm4572.tmp\System.dllexecutable
MD5:5EBC73650256E9C8DDBCDA231DB829A1
SHA256:1EAA543842DF7795404184E8892A1654B0773DBC9BD8B54C7FDB9E68F4355493
3668WinRAR.exeC:\Users\admin\AppData\Local\Temp\microsoft office 2007 service pack 2.exe\microsoft office 2007 service pack 2.exeexecutable
MD5:223977BFE475775F06A35F006AA81711
SHA256:0D8F1EFD9E5617DB2D6C9534B571818E7BCD58A1CCF0E365A9C0628DEE63DCDE
2420microsoft office 2007 service pack 2.exeC:\Users\admin\AppData\Local\Temp\nsz4B2F.tmp\northstar.exeexecutable
MD5:A1E2472DB630C7043C2FB486A17300BC
SHA256:0E990E290A6C3B4B3A3AC7495BFC197B698799AE840A06586EB5D5CBE74A1BD7
2636microsoft office 2007 service pack 2.exeC:\Users\admin\AppData\Local\Temp\nsm4572.tmp\northstar.exeexecutable
MD5:A1E2472DB630C7043C2FB486A17300BC
SHA256:0E990E290A6C3B4B3A3AC7495BFC197B698799AE840A06586EB5D5CBE74A1BD7
2432sdiagnhost.exeC:\Users\admin\AppData\Local\Temp\feg-snok.cmdlinetext
MD5:95FF96BB32F3F98229E10F792ED15338
SHA256:599A1E07859570928B4CCC06705CDD7579FBD002EAA6B64D417BA7AEA5644E8D
3068msdt.exeC:\Users\admin\AppData\Local\Temp\SDIAG_3fdce756-dbb7-4a6b-ad41-819a3c5f11ac\en-US\DiagPackage.dll.muiexecutable
MD5:C31BD28AB34E75BC65A5458AC8D37539
SHA256:5FB9E280013D58043C5689478F9DCFAD3212F4681534627EB33998DDD6F63308
2100csc.exeC:\Users\admin\AppData\Local\Temp\CSC6ADA.tmpbinary
MD5:968481526B91FC84D841C554EEECD92A
SHA256:EB7B541751E54F9982A0B0E5025C69118E285C5B17423637C27E805120E74863
2432sdiagnhost.exeC:\Users\admin\AppData\Local\Temp\feg-snok.0.cstext
MD5:B0DC59B099CA7C12FB8AD72D3C50C82C
SHA256:E75EAAA3D7908FB05000C0A957048D20091A0D2575E87D091D11CDB3A5B562E5
3068msdt.exeC:\Users\admin\AppData\Local\Temp\SDIAG_3fdce756-dbb7-4a6b-ad41-819a3c5f11ac\result\results.xslxml
MD5:310E1DA2344BA6CA96666FB639840EA9
SHA256:67401342192BABC27E62D4C1E0940409CC3F2BD28F77399E71D245EAE8D3F63C
2100csc.exeC:\Users\admin\AppData\Local\Temp\feg-snok.pdbbinary
MD5:F4CA55103DABAD74E11B110B81A8A1E6
SHA256:79C2AE2F6E5CD0248930736CD9B5CA57EFC2D9B76FAD13BE5E9E954799D97085
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
api.downloadmr.com
unknown

Threats

No threats detected
Process
Message
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144