| File name: | ashampoo_driver_updater_1.5.2.exe |
| Full analysis: | https://app.any.run/tasks/b15a2c5d-12c5-4206-8e9f-936a87b064d7 |
| Verdict: | Malicious activity |
| Analysis date: | March 06, 2024, 01:57:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 78DB1DF96F6A9AEE0858D3370B670F2C |
| SHA1: | 026625D8A9337A5374888C080F2F4160D07DE54B |
| SHA256: | CA386489CF1D48120C89D9DFCB69D1D79CB33436F23DDB845F8E39D4D801BD0C |
| SSDEEP: | 98304:O0ihJuC63L6AOGD3sLZrWDp0ZR1U8bYJEunnihCkXDNpu+3y0jLM3RUczep94Dwi:V8NAW+vtO0UutTs4QWT5gDK7iQl |
| .exe | | | Win32 Executable Delphi generic (57.2) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (18.2) |
| .exe | | | Win16/32 Executable Delphi generic (8.3) |
| .exe | | | Generic Win/DOS Executable (8) |
| .exe | | | DOS Executable Generic (8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:14 13:27:46+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 346112 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1181c |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.5.2.0 |
| ProductVersionNumber: | 1.5.2.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Ashampoo GmbH & Co. KG |
| FileDescription: | Ashampoo Driver Updater Setup |
| FileVersion: | 1.5.2 |
| LegalCopyright: | Ashampoo GmbH & Co. KG |
| ProductName: | Ashampoo Driver Updater |
| ProductVersion: | 1.5.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1040 | "C:\Windows\System32\taskkill.exe" /f /im "ashpdu.exe" | C:\Windows\System32\taskkill.exe | — | ashampoo_driver_updater_1.5.2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2244 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESA302.tmp" "c:\Users\admin\AppData\Local\Temp\CSCA301.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.5003 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 2572 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2592 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\t08-jzqr.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | ashpdu.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 2908 | "C:\Program Files\Ashampoo\Ashampoo Driver Updater\ashpdu.exe" firstshow | C:\Program Files\Ashampoo\Ashampoo Driver Updater\ashpdu.exe | ashampoo_driver_updater_1.5.2.tmp | ||||||||||||
User: admin Company: Ashampoo Integrity Level: HIGH Description: Ashampoo Driver Updater Exit code: 0 Version: 1.5.2.0 Modules
| |||||||||||||||
| 3464 | "C:\Users\admin\AppData\Local\Temp\is-UMJFV.tmp\ashampoo_driver_updater_1.5.2.tmp" /SL5="$100130,10561423,413696,C:\Users\admin\AppData\Local\Temp\ashampoo_driver_updater_1.5.2.exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-UMJFV.tmp\ashampoo_driver_updater_1.5.2.tmp | ashampoo_driver_updater_1.5.2.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3536 | "C:\Users\admin\AppData\Local\Temp\is-VCQ7B.tmp\ashampoo_driver_updater_1.5.2.tmp" /SL5="$E0170,10561423,413696,C:\Users\admin\AppData\Local\Temp\ashampoo_driver_updater_1.5.2.exe" | C:\Users\admin\AppData\Local\Temp\is-VCQ7B.tmp\ashampoo_driver_updater_1.5.2.tmp | — | ashampoo_driver_updater_1.5.2.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3656 | "C:\Users\admin\AppData\Local\Temp\ashampoo_driver_updater_1.5.2.exe" | C:\Users\admin\AppData\Local\Temp\ashampoo_driver_updater_1.5.2.exe | explorer.exe | ||||||||||||
User: admin Company: Ashampoo GmbH & Co. KG Integrity Level: MEDIUM Description: Ashampoo Driver Updater Setup Exit code: 0 Version: 1.5.2 Modules
| |||||||||||||||
| 3948 | "C:\Users\admin\AppData\Local\Temp\ashampoo_driver_updater_1.5.2.exe" /SPAWNWND=$16013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\ashampoo_driver_updater_1.5.2.exe | ashampoo_driver_updater_1.5.2.tmp | ||||||||||||
User: admin Company: Ashampoo GmbH & Co. KG Integrity Level: HIGH Description: Ashampoo Driver Updater Setup Exit code: 0 Version: 1.5.2 Modules
| |||||||||||||||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates |
| Operation: | delete value | Name: | 9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6 |
Value: | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6 |
| Operation: | write | Name: | Blob |
Value: 0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3 | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6 |
| Operation: | write | Name: | Blob |
Value: 1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3 | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6 |
| Operation: | write | Name: | Blob |
Value: 190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3 | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3464) ashampoo_driver_updater_1.5.2.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | Ashampoo Driver Updater |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\setup_05.bmp | image | |
MD5:BC2833D903B17B6BF9A280CC73AA4FD4 | SHA256:A722383B8AC9C6D36CB2EAE789E6583761FCFC8B3CDDED5BD08403555C3DC503 | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\innocallback.dll | executable | |
MD5:1C55AE5EF9980E3B1028447DA6105C75 | SHA256:6AFA2D104BE6EFE3D9A2AB96DBB75DB31565DAD64DD0B791E402ECC25529809F | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\setup_licensefalse.bmp | image | |
MD5:7729E55C021A83C61B8B3851588C0702 | SHA256:1843487FEA17ED619F742440AF36BE50E8209FC4137A145B817F5CBEF12CF68D | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\setup_enterkey.bmp | image | |
MD5:A85B53538BADD319BA696D246140D649 | SHA256:8BB0ED1D52750E7FDA2CDBD1CF14C435CDE2F339431419FC7D05E5600094C5CD | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\_isetup\_iscrypt.dll | executable | |
MD5:A69559718AB506675E907FE49DEB71E9 | SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC | |||
| 3948 | ashampoo_driver_updater_1.5.2.exe | C:\Users\admin\AppData\Local\Temp\is-UMJFV.tmp\ashampoo_driver_updater_1.5.2.tmp | executable | |
MD5:7E9F63CD486BFD2971646376A00D2623 | SHA256:542C6BF0ADCBA067C28E873E9D014D26BDD233BE34C9142C9C12EF577839FC09 | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\setup_false.bmp | image | |
MD5:AEFB420644E78A84205DCEA5C05D77B1 | SHA256:546B2ED39B230C058FD15A93F077743FC2F7897A336F9455230A056543BC8B89 | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\setup_ok.bmp | image | |
MD5:A87E8A503EB9469DF9ECCA250E4D36E6 | SHA256:F7F10E8722DC9940E0E6671BB246C81DA050790D70127D14759B1C73EBAD3708 | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\setup_03_bg.bmp | image | |
MD5:6A371CB6B19923D977D72F472C3B091B | SHA256:BBF3E7244C9259CF2737A00E988A0B7BC1AB67CF6FFB90714ECEA69A56A186CF | |||
| 3464 | ashampoo_driver_updater_1.5.2.tmp | C:\Users\admin\AppData\Local\Temp\is-SGN9M.tmp\setup_01b_bg.bmp | image | |
MD5:500FC4E3DB1F28D93A9506580D71DF66 | SHA256:365DC91B696D97D46FB52BA7B6D19E1E2803E275E9331741EF73A7A2B4C877DD | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2908 | ashpdu.exe | POST | 200 | 67.219.146.138:80 | http://websvr3.ashcdn.net/v2/api/SystemInfo | unknown | binary | 65 b | unknown |
2908 | ashpdu.exe | POST | — | 67.219.146.138:80 | http://websvr3.ashcdn.net/v2/api/Drivers | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3464 | ashampoo_driver_updater_1.5.2.tmp | 52.59.70.47:443 | et.ashampoo.com | AMAZON-02 | DE | unknown |
2908 | ashpdu.exe | 67.219.146.138:80 | websvr3.ashcdn.net | MADEIT | US | unknown |
Domain | IP | Reputation |
|---|---|---|
linktarget.ashampoo.com |
| whitelisted |
et.ashampoo.com |
| unknown |
websvr3.ashcdn.net |
| unknown |
Process | Message |
|---|---|
ashpdu.exe |
*** HR originated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
|
ashpdu.exe |
*** HR propagated: -2147024774
*** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
|