Windows
Analysis Report
NezbdhNgwG.exe
Overview
General Information
Detection
Score: | 100 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- NezbdhNgwG.exe (PID: 6952 cmdline:
C:\Users\u ser\Deskto p\NezbdhNg wG.exe MD5: A650FFE73F9994AD3844FEDD49BA10F3) - netsh.exe (PID: 6584 cmdline:
netsh fire wall add a llowedprog ram "C:\Us ers\user\D esktop\Nez bdhNgwG.ex e" "Nezbdh NgwG.exe" ENABLE MD5: 4E89A1A088BE715D6C946E55AB07C7DF) - conhost.exe (PID: 7068 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- NezbdhNgwG.exe (PID: 6232 cmdline:
"C:\Users\ user\Deskt op\NezbdhN gwG.exe" . . MD5: A650FFE73F9994AD3844FEDD49BA10F3)
- NezbdhNgwG.exe (PID: 5228 cmdline:
"C:\Users\ user\Deskt op\NezbdhN gwG.exe" . . MD5: A650FFE73F9994AD3844FEDD49BA10F3)
- NezbdhNgwG.exe (PID: 3748 cmdline:
"C:\Users\ user\Deskt op\NezbdhN gwG.exe" . . MD5: A650FFE73F9994AD3844FEDD49BA10F3)
- cleanup
Name | Description | Attribution | Blogpost URLs | Link |
---|---|---|---|---|
NjRAT | RedPacket Security describes NJRat as "a remote access trojan (RAT) has capabilities to log keystrokes, access the victim's camera, steal credentials stored in browsers, open a reverse shell, upload/download files, view the victim's desktop, perform process, file, and registry manipulations, and capabilities to let the attacker update, uninstall, restart, close, disconnect the RAT and rename its campaign ID. Through the Command & Control (CnC) server software, the attacker has capabilities to create and configure the malware to spread through USB drives."It is supposedly popular with actors in the Middle East. Similar to other RATs, many leaked builders may be backdoored. |
{"Host": "System.Security.Permissions.IUnrestrictedPermission", "Port": "11531", "Version": "im523", "Campaign ID": "HacKed", "Install Name": "server.exe", "Install Dir": "TEMP"}
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
JoeSecurity_Njrat | Yara detected Njrat | Joe Security |
Source | Rule | Description | Author | Strings |
---|---|---|---|---|
JoeSecurity_Njrat | Yara detected Njrat | Joe Security | ||
Windows_Trojan_Njrat_30f3c220 | unknown | unknown |
| |
njrat1 | Identify njRat | Brian Wallace @botnet_hunter |
| |
MALWARE_Win_NjRAT | Detects NjRAT / Bladabindi | ditekSHen |
|
Timestamp: | 192.168.2.43.126.37.1849736115312814856 11/26/23-15:17:14.013168 |
SID: | 2814856 |
Source Port: | 49736 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649738115312825564 11/26/23-15:19:41.517209 |
SID: | 2825564 |
Source Port: | 49738 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649729115312033132 11/26/23-15:16:09.891923 |
SID: | 2033132 |
Source Port: | 49729 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649738115312033132 11/26/23-15:19:21.604980 |
SID: | 2033132 |
Source Port: | 49738 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649729115312825564 11/26/23-15:17:09.256355 |
SID: | 2825564 |
Source Port: | 49729 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649738115312825563 11/26/23-15:19:21.784381 |
SID: | 2825563 |
Source Port: | 49738 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.156.13.20949737115312814856 11/26/23-15:18:17.782445 |
SID: | 2814856 |
Source Port: | 49737 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.126.37.1849736115312814860 11/26/23-15:18:09.757619 |
SID: | 2814860 |
Source Port: | 49736 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649729115312814860 11/26/23-15:17:09.256355 |
SID: | 2814860 |
Source Port: | 49729 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649738115312814856 11/26/23-15:19:21.784381 |
SID: | 2814856 |
Source Port: | 49738 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.156.13.20949737115312033132 11/26/23-15:18:17.603963 |
SID: | 2033132 |
Source Port: | 49737 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.156.13.20949737115312814860 11/26/23-15:18:42.758182 |
SID: | 2814860 |
Source Port: | 49737 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649729115312814856 11/26/23-15:16:10.074575 |
SID: | 2814856 |
Source Port: | 49729 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649738115312814860 11/26/23-15:19:41.517209 |
SID: | 2814860 |
Source Port: | 49738 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.126.37.1849736115312033132 11/26/23-15:17:13.832319 |
SID: | 2033132 |
Source Port: | 49736 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.43.126.37.1849736115312825564 11/26/23-15:18:09.757619 |
SID: | 2825564 |
Source Port: | 49736 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.156.13.20949737115312825563 11/26/23-15:18:17.782445 |
SID: | 2825563 |
Source Port: | 49737 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.192.93.8649729115312825563 11/26/23-15:16:10.074575 |
SID: | 2825563 |
Source Port: | 49729 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Timestamp: | 192.168.2.418.156.13.20949737115312825564 11/26/23-15:18:42.758182 |
SID: | 2825564 |
Source Port: | 49737 |
Destination Port: | 11531 |
Protocol: | TCP |
Classtype: | A Network Trojan was detected |
Click to jump to signature section
AV Detection |
---|
Source: | Malware Configuration Extractor: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Source: | Avira: |
Source: | Virustotal: | Perma Link |
Source: | Avira: |
Source: | ReversingLabs: | |||
Source: | Virustotal: | Perma Link |
Source: | Joe Sandbox ML: |
Source: | Joe Sandbox ML: |
Source: | Static PE information: |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Networking |
---|
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: | ||
Source: | Snort IDS: |
Source: | URLs: |
Source: | ASN Name: | ||
Source: | ASN Name: |
Source: | IP Address: | ||
Source: | IP Address: | ||
Source: | IP Address: |
Source: | TCP traffic: | ||
Source: | TCP traffic: | ||
Source: | TCP traffic: |
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: | ||
Source: | UDP traffic detected without corresponding DNS query: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | DNS traffic detected: |
Key, Mouse, Clipboard, Microphone and Screen Capturing |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
E-Banking Fraud |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Operating System Destruction |
---|
Source: | Process information set: | Jump to behavior |
System Summary |
---|
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Static PE information: |
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: | ||
Source: | Matched rule: |
Source: | Code function: | 0_2_00A3170F |
Source: | Code function: | 0_2_0060BBEA | |
Source: | Code function: | 0_2_0060BECA | |
Source: | Code function: | 0_2_0060BBC8 | |
Source: | Code function: | 0_2_0060BE8F |
Source: | Process Stats: |
Source: | Binary or memory string: |
Source: | ReversingLabs: | ||
Source: | Virustotal: |
Source: | File read: | Jump to behavior |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | |||
Source: | Process created: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 0_2_0060B89A | |
Source: | Code function: | 0_2_0060B863 |
Source: | File created: | Jump to behavior |
Source: | Classification label: |
Source: | Static file information: | |||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Mutant created: | ||
Source: | Mutant created: | ||
Source: | Mutant created: |
Source: | File opened: | Jump to behavior |
Source: | File opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Data Obfuscation |
---|
Source: | .Net Code: | ||
Source: | .Net Code: |
Source: | File created: | Jump to dropped file |
Boot Survival |
---|
Source: | File created: | Jump to dropped file |
Source: | Registry value created or modified: | Jump to behavior |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | File created: | Jump to behavior |
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior | ||
Source: | Registry value created or modified: | Jump to behavior |
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior | ||
Source: | Process information set: | Jump to behavior |
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior | ||
Source: | Thread sleep time: | Jump to behavior |
Source: | Last function: |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior | ||
Source: | Window / User API: | Jump to behavior |
Source: | Process information queried: | Jump to behavior |
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior | ||
Source: | Thread delayed: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Process token adjusted: | Jump to behavior |
Source: | Memory allocated: | Jump to behavior |
HIPS / PFW / Operating System Protection Evasion |
---|
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: | ||
Source: | Reference to suspicious API methods: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior | ||
Source: | Queries volume information: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Lowering of HIPS / PFW / Operating System Security Settings |
---|
Source: | Process created: |
Source: | Process created: |
Stealing of Sensitive Information |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Remote Access Functionality |
---|
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: | ||
Source: | File source: |
Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Exfiltration | Command and Control | Network Effects | Remote Service Effects | Impact | Resource Development | Reconnaissance |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 Replication Through Removable Media | 1 Native API | 221 Registry Run Keys / Startup Folder | 1 Access Token Manipulation | 1 Masquerading | 1 Input Capture | 11 Security Software Discovery | 1 Replication Through Removable Media | 1 Input Capture | Exfiltration Over Other Network Medium | 1 Encrypted Channel | Exploit SS7 to Redirect Phone Calls/SMS | Remotely Wipe Data Without Authorization | Abuse Accessibility Features | Acquire Infrastructure | Gather Victim Identity Information |
Default Accounts | Scheduled Task/Job | Boot or Logon Initialization Scripts | 2 Process Injection | 21 Disable or Modify Tools | LSASS Memory | 2 Process Discovery | Remote Desktop Protocol | 1 Archive Collected Data | Exfiltration Over Bluetooth | 1 Non-Standard Port | SIM Card Swap | Obtain Device Cloud Backups | Network Denial of Service | Domains | Credentials |
Domain Accounts | At | Logon Script (Windows) | 221 Registry Run Keys / Startup Folder | 21 Virtualization/Sandbox Evasion | Security Account Manager | 21 Virtualization/Sandbox Evasion | SMB/Windows Admin Shares | Data from Network Shared Drive | Automated Exfiltration | 1 Non-Application Layer Protocol | Data Encrypted for Impact | DNS Server | Email Addresses | ||
Local Accounts | Cron | Login Hook | Login Hook | 1 Access Token Manipulation | NTDS | 1 Application Window Discovery | Distributed Component Object Model | Input Capture | Traffic Duplication | 11 Application Layer Protocol | Data Destruction | Virtual Private Server | Employee Names | ||
Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Process Injection | LSA Secrets | 1 Peripheral Device Discovery | SSH | Keylogging | Scheduled Transfer | Fallback Channels | Data Encrypted for Impact | Server | Gather Victim Network Information | ||
Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 Software Packing | Cached Domain Credentials | 12 System Information Discovery | VNC | GUI Input Capture | Data Transfer Size Limits | Multiband Communication | Service Stop | Botnet | Domain Properties |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
86% | ReversingLabs | ByteCode-MSIL.Trojan.NjRAT | ||
83% | Virustotal | Browse | ||
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/ATRAPS.Gen | ||
100% | Joe Sandbox ML | |||
86% | ReversingLabs | ByteCode-MSIL.Trojan.NjRAT | ||
83% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
16% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
2.tcp.eu.ngrok.io | 18.192.93.86 | true | true |
| unknown |
Name | Malicious | Antivirus Detection | Reputation |
---|---|---|---|
true |
| unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false | high | |||
false |
| low |
- No. of IPs < 25%
- 25% < No. of IPs < 50%
- 50% < No. of IPs < 75%
- 75% < No. of IPs
IP | Domain | Country | Flag | ASN | ASN Name | Malicious |
---|---|---|---|---|---|---|
18.192.93.86 | 2.tcp.eu.ngrok.io | United States | 16509 | AMAZON-02US | true | |
3.126.37.18 | unknown | United States | 16509 | AMAZON-02US | true | |
18.156.13.209 | unknown | United States | 16509 | AMAZON-02US | true |
Joe Sandbox Version: | 38.0.0 Ammolite |
Analysis ID: | 1347939 |
Start date and time: | 2023-11-26 15:15:11 +01:00 |
Joe Sandbox Product: | CloudBasic |
Overall analysis duration: | 0h 6m 53s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 11 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample file name: | NezbdhNgwG.exerenamed because original name is a hash value |
Original Sample Name: | a650ffe73f9994ad3844fedd49ba10f3.exe |
Detection: | MAL |
Classification: | mal100.troj.adwa.spyw.evad.winEXE@7/4@4/3 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, dllhost.exe, WMIADAP.exe, SIHClient.exe, conhost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing behavior information.
- Report size getting too big, too many NtAllocateVirtualMemory calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
Time | Type | Description |
---|---|---|
14:16:05 | Autostart | |
14:16:14 | Autostart | |
14:16:22 | Autostart | |
14:16:30 | Autostart | |
15:16:40 | API Interceptor |
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
18.192.93.86 | Get hash | malicious | RedLine | Browse |
| |
Get hash | malicious | RedLine | Browse |
| ||
3.126.37.18 | Get hash | malicious | Njrat | Browse | ||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Metasploit | Browse | |||
Get hash | malicious | Unknown | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
Get hash | malicious | Njrat | Browse | |||
18.156.13.209 | Get hash | malicious | RedLine | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
2.tcp.eu.ngrok.io | Get hash | malicious | Njrat | Browse |
| |
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
| ||
Get hash | malicious | Njrat | Browse |
|
Match | Associated Sample Name / URL | SHA 256 | Detection | Threat Name | Link | Context |
---|---|---|---|---|---|---|
AMAZON-02US | Get hash | malicious | DBatLoader, FormBook | Browse |
| |
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Clipboard Hijacker | Browse |
| ||
Get hash | malicious | Clipboard Hijacker | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
AMAZON-02US | Get hash | malicious | DBatLoader, FormBook | Browse |
| |
Get hash | malicious | DBatLoader, FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Remcos | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Unknown | Browse |
| ||
Get hash | malicious | Clipboard Hijacker | Browse |
| ||
Get hash | malicious | Clipboard Hijacker | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai, Moobot | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | Mirai | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | FormBook | Browse |
| ||
Get hash | malicious | Unknown | Browse |
|
Process: | C:\Users\user\Desktop\NezbdhNgwG.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 525 |
Entropy (8bit): | 5.259753436570609 |
Encrypted: | false |
SSDEEP: | 12:Q3LaJU2C9XAn10Ug+9pfu9t0U29xtUz1B0U2uk71K6xhk7v:MLF2CpI3zffup29Iz52Ve |
MD5: | 260E01CC001F9C4643CA7A62F395D747 |
SHA1: | 492AD0ACE3A9C8736909866EEA168962D418BE5A |
SHA-256: | 4BC52CCF866F489772A6919A0CC2C55B1432729D6BDF29E17E5853ABDFAB6030 |
SHA-512: | 01AF7D75257E3DBD460E328F5C057D0367B83D3D9397E89CA3AE54AB9B2842D62352D8CCB4BE98ACE0C5667846759D32C199DE39ECCD0CF9CD6A83267D27E7C4 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8c3a19ded61c2fe03bf66a3900261406.exe
Download File
Process: | C:\Users\user\Desktop\NezbdhNgwG.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 36864 |
Entropy (8bit): | 5.525477592058185 |
Encrypted: | false |
SSDEEP: | 384:OOtvEiTbTvpWNcZ0y8fvCv3v3cLkacpjrAF+rMRTyN/0L+EcoinblneHQM3epzX6:7t7TZ38fvCv3E1c1rM+rMRa8Numzt |
MD5: | A650FFE73F9994AD3844FEDD49BA10F3 |
SHA1: | 958E2C74BDF856EEB7CA4DBBF9AB746D1C85E712 |
SHA-256: | 1064502587B0806BA7B4C026520F1774E8B9446C68E511CF3EDF1850132AE699 |
SHA-512: | A303032B3E83C43D0FDCC043C2E804061CEB04F60068E19367E27F903455028740A034FDC336A2FA52165022997FF60795CAA71555A41577C89834B9EE4B3F97 |
Malicious: | true |
Yara Hits: |
|
Antivirus: |
|
Reputation: | low |
Preview: |
C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\8c3a19ded61c2fe03bf66a3900261406.exe:Zone.Identifier
Download File
Process: | C:\Users\user\Desktop\NezbdhNgwG.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 26 |
Entropy (8bit): | 3.95006375643621 |
Encrypted: | false |
SSDEEP: | 3:ggPYV:rPYV |
MD5: | 187F488E27DB4AF347237FE461A079AD |
SHA1: | 6693BA299EC1881249D59262276A0D2CB21F8E64 |
SHA-256: | 255A65D30841AB4082BD9D0EEA79D49C5EE88F56136157D8D6156AEF11C12309 |
SHA-512: | 89879F237C0C051EBE784D0690657A6827A312A82735DA42DAD5F744D734FC545BEC9642C19D14C05B2F01FF53BC731530C92F7327BB7DC9CDE1B60FB21CD64E |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
Process: | C:\Windows\SysWOW64\netsh.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 313 |
Entropy (8bit): | 4.971939296804078 |
Encrypted: | false |
SSDEEP: | 6:/ojfKsUTGN8Ypox42k9L+DbGMKeQE+vigqAZs2E+AYeDPO+Yswyha:wjPIGNrkHk9iaeIM6ADDPOHyha |
MD5: | 689E2126A85BF55121488295EE068FA1 |
SHA1: | 09BAAA253A49D80C18326DFBCA106551EBF22DD6 |
SHA-256: | D968A966EF474068E41256321F77807A042F1965744633D37A203A705662EC25 |
SHA-512: | C3736A8FC7E6573FA1B26FE6A901C05EE85C55A4A276F8F569D9EADC9A58BEC507D1BB90DBF9EA62AE79A6783178C69304187D6B90441D82E46F5F56172B5C5C |
Malicious: | false |
Reputation: | high, very likely benign file |
Preview: |
File type: | |
Entropy (8bit): | 5.525477592058185 |
TrID: |
|
File name: | NezbdhNgwG.exe |
File size: | 36'864 bytes |
MD5: | a650ffe73f9994ad3844fedd49ba10f3 |
SHA1: | 958e2c74bdf856eeb7ca4dbbf9ab746d1c85e712 |
SHA256: | 1064502587b0806ba7b4c026520f1774e8b9446c68e511cf3edf1850132ae699 |
SHA512: | a303032b3e83c43d0fdcc043c2e804061ceb04f60068e19367e27f903455028740a034fdc336a2fa52165022997ff60795caa71555a41577c89834b9ee4b3f97 |
SSDEEP: | 384:OOtvEiTbTvpWNcZ0y8fvCv3v3cLkacpjrAF+rMRTyN/0L+EcoinblneHQM3epzX6:7t7TZ38fvCv3E1c1rM+rMRa8Numzt |
TLSH: | C8F22A4D7BE08168D9FD067B05B2E4130776E04B5E23DD0D8EF2A4EA37636D18B54EA2 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..L....G[e................................. ........@.. ....................................@................................ |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x40abbe |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, 32BIT_MACHINE |
DLL Characteristics: | DYNAMIC_BASE, NX_COMPAT, NO_SEH, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x655B47B0 [Mon Nov 20 11:49:04 2023 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | f34d5f2d4577ed6d9ceec516c1f5a744 |
Instruction |
---|
jmp dword ptr [00402000h] |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
add byte ptr [eax], al |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0xab6c | 0x4f | .text |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0xc000 | 0xc | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2000 | 0x8 | .text |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x2008 | 0x48 | .text |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|
.text | 0x2000 | 0x8bc4 | 0x8c00 | False | 0.4636997767857143 | data | 5.608731270610776 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.reloc | 0xc000 | 0xc | 0x200 | False | 0.044921875 | data | 0.08153941234324169 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
DLL | Import |
---|---|
mscoree.dll | _CorExeMain |
Timestamp | Protocol | SID | Message | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|---|---|---|
192.168.2.43.126.37.1849736115312814856 11/26/23-15:17:14.013168 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
192.168.2.418.192.93.8649738115312825564 11/26/23-15:19:41.517209 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649729115312033132 11/26/23-15:16:09.891923 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649738115312033132 11/26/23-15:19:21.604980 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649729115312825564 11/26/23-15:17:09.256355 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649738115312825563 11/26/23-15:19:21.784381 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.156.13.20949737115312814856 11/26/23-15:18:17.782445 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
192.168.2.43.126.37.1849736115312814860 11/26/23-15:18:09.757619 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
192.168.2.418.192.93.8649729115312814860 11/26/23-15:17:09.256355 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649738115312814856 11/26/23-15:19:21.784381 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.156.13.20949737115312033132 11/26/23-15:18:17.603963 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
192.168.2.418.156.13.20949737115312814860 11/26/23-15:18:42.758182 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
192.168.2.418.192.93.8649729115312814856 11/26/23-15:16:10.074575 | TCP | 2814856 | ETPRO TROJAN njrat ver 0.7d Malware CnC Callback (inf) | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.192.93.8649738115312814860 11/26/23-15:19:41.517209 | TCP | 2814860 | ETPRO TROJAN njRAT/Bladabindi CnC Callback (act) | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.43.126.37.1849736115312033132 11/26/23-15:17:13.832319 | TCP | 2033132 | ET TROJAN Generic njRAT/Bladabindi CnC Activity (ll) | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
192.168.2.43.126.37.1849736115312825564 11/26/23-15:18:09.757619 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
192.168.2.418.156.13.20949737115312825563 11/26/23-15:18:17.782445 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
192.168.2.418.192.93.8649729115312825563 11/26/23-15:16:10.074575 | TCP | 2825563 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (inf) | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
192.168.2.418.156.13.20949737115312825564 11/26/23-15:18:42.758182 | TCP | 2825564 | ETPRO TROJAN Generic njRAT/Bladabindi CnC Activity (act) | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 26, 2023 15:16:09.431395054 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:09.613898039 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:09.614084959 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:09.891922951 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:10.074409962 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:10.074574947 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:10.256975889 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:15.083389044 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:15.265846968 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:23.741148949 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:23.923768997 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:39.092544079 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:39.092727900 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:41.709747076 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:16:41.892309904 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:57.016311884 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:16:57.016413927 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:17:07.959525108 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:17:08.141911030 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:17:09.256355047 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:17:09.438638926 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:17:11.288283110 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:17:11.288377047 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:17:13.511118889 CET | 49729 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:17:13.646476984 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:13.693680048 CET | 11531 | 49729 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:17:13.827280045 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:13.827383041 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:13.832319021 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:14.013078928 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:14.013168097 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:14.193963051 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:14.912760973 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:15.093735933 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:15.093784094 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:15.274584055 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:16.178138018 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:16.360241890 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:16.360415936 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:16.541205883 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:16.541291952 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:16.731105089 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:16.731301069 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:16.912110090 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:16.912249088 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:17.093115091 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:17.093211889 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:17.274190903 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:17.274279118 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:17.456373930 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:17.456563950 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:17.637754917 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:17.637888908 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:17.818708897 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:17.818789959 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:17.999633074 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:17.999723911 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:18.180509090 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:18.180625916 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:18.361455917 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:18.361572981 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:18.542367935 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:18.542448044 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:18.723185062 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:18.723284960 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:18.905602932 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:18.905719995 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:19.086555004 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:19.086636066 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:19.267574072 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:19.267708063 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:19.448591948 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:19.448720932 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:19.631359100 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:19.631494999 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:19.812367916 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:19.812484026 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:19.993233919 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:19.993338108 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:20.176121950 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:20.176201105 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:20.357003927 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:20.357183933 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:20.541517973 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:20.541636944 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:20.722486019 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:20.722621918 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:20.903361082 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:20.903435946 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:21.084799051 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:21.084894896 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:21.265791893 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:21.265886068 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:21.446891069 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:21.446953058 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:21.627641916 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:21.627721071 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:21.809509993 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:21.809664965 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:21.990515947 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:21.990611076 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:22.171487093 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:22.171616077 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:22.352520943 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:22.352648973 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:22.533507109 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:22.533708096 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:22.714728117 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:22.714838982 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:22.895659924 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:22.895736933 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:23.076895952 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:23.077022076 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:23.258374929 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:23.258526087 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:23.439542055 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:23.439721107 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:23.620600939 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:23.620687008 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:23.801623106 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:23.801693916 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:23.982521057 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:23.982631922 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:24.163747072 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:24.163856030 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:24.344638109 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:24.344705105 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:24.527699947 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:24.527820110 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:24.708728075 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:24.708949089 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:24.889877081 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:24.889972925 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:25.070867062 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:25.070955992 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:25.251899004 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:25.252110958 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:25.433146954 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:25.433233023 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:25.614097118 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:25.614195108 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:25.795162916 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:25.795258045 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:25.976160049 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:25.976272106 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:26.157118082 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:26.157301903 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:26.338130951 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:26.338224888 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:26.519217968 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:26.519280910 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:26.700170994 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:26.700249910 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:26.881000996 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:26.881072998 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:27.061888933 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:27.061961889 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:27.243763924 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:27.243838072 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:27.428391933 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:27.428487062 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:27.609548092 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:27.609725952 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:27.790766954 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:29.684566975 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:29.865417957 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:29.865689039 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:30.049297094 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:30.049613953 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:30.230443001 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:30.230523109 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:30.411613941 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:30.411756039 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:30.592603922 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:30.592812061 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:30.774288893 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:30.774349928 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:30.956262112 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:30.956358910 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:31.139028072 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:31.139128923 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:31.319935083 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:31.320152044 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:31.501025915 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:31.501205921 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:31.681994915 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:31.682178974 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:31.862992048 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:31.863246918 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:32.044050932 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:32.044274092 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:32.228190899 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:32.228288889 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:32.409133911 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:32.409328938 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:32.590173960 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:32.590257883 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:32.771114111 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:32.771321058 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:32.952178001 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:32.952258110 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:33.136365891 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:33.136475086 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:33.317339897 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:33.317464113 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:33.498316050 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:33.498522043 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:17:33.679425001 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:48.745446920 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:17:48.745522976 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:18:03.929421902 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:18:03.932360888 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:18:09.757618904 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:18:09.938425064 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:18:15.286236048 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:18:15.286333084 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:18:17.287522078 CET | 49736 | 11531 | 192.168.2.4 | 3.126.37.18 |
Nov 26, 2023 15:18:17.423034906 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:18:17.468398094 CET | 11531 | 49736 | 3.126.37.18 | 192.168.2.4 |
Nov 26, 2023 15:18:17.601541996 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:18:17.601739883 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:18:17.603962898 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:18:17.782394886 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:18:17.782444954 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:18:17.960891962 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:18:20.521955967 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:18:20.700448036 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:18:34.616025925 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:18:34.794645071 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:18:42.758182049 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:18:42.936748981 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:18:58.072940111 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:18:58.073147058 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:19:13.253568888 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:19:13.253739119 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:19:19.284349918 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:19:19.284482956 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:19:21.287312031 CET | 49737 | 11531 | 192.168.2.4 | 18.156.13.209 |
Nov 26, 2023 15:19:21.423450947 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:21.466115952 CET | 11531 | 49737 | 18.156.13.209 | 192.168.2.4 |
Nov 26, 2023 15:19:21.602653980 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:21.602735043 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:21.604979992 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:21.784280062 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:21.784380913 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:21.963493109 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:24.662637949 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:24.841862917 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:32.054653883 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:32.233968019 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:33.476535082 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:33.655824900 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:39.420361996 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:39.599628925 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:39.617821932 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:39.798747063 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:40.799016953 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:40.978250027 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:40.978458881 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:41.158391953 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:41.158543110 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:41.337805033 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:41.337951899 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:41.517117023 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:41.517209053 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Nov 26, 2023 15:19:41.696475029 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:56.724064112 CET | 11531 | 49738 | 18.192.93.86 | 192.168.2.4 |
Nov 26, 2023 15:19:56.724136114 CET | 49738 | 11531 | 192.168.2.4 | 18.192.93.86 |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
Nov 26, 2023 15:16:09.294425011 CET | 54386 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 26, 2023 15:16:09.428083897 CET | 53 | 54386 | 1.1.1.1 | 192.168.2.4 |
Nov 26, 2023 15:17:13.512598038 CET | 56512 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 26, 2023 15:17:13.645319939 CET | 53 | 56512 | 1.1.1.1 | 192.168.2.4 |
Nov 26, 2023 15:18:17.289370060 CET | 56393 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 26, 2023 15:18:17.421515942 CET | 53 | 56393 | 1.1.1.1 | 192.168.2.4 |
Nov 26, 2023 15:19:21.288693905 CET | 51800 | 53 | 192.168.2.4 | 1.1.1.1 |
Nov 26, 2023 15:19:21.422415972 CET | 53 | 51800 | 1.1.1.1 | 192.168.2.4 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
Nov 26, 2023 15:16:09.294425011 CET | 192.168.2.4 | 1.1.1.1 | 0x1413 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 26, 2023 15:17:13.512598038 CET | 192.168.2.4 | 1.1.1.1 | 0x77c0 | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 26, 2023 15:18:17.289370060 CET | 192.168.2.4 | 1.1.1.1 | 0xe20d | Standard query (0) | A (IP address) | IN (0x0001) | false | |
Nov 26, 2023 15:19:21.288693905 CET | 192.168.2.4 | 1.1.1.1 | 0x8067 | Standard query (0) | A (IP address) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
Nov 26, 2023 15:16:09.428083897 CET | 1.1.1.1 | 192.168.2.4 | 0x1413 | No error (0) | 18.192.93.86 | A (IP address) | IN (0x0001) | false | ||
Nov 26, 2023 15:17:13.645319939 CET | 1.1.1.1 | 192.168.2.4 | 0x77c0 | No error (0) | 3.126.37.18 | A (IP address) | IN (0x0001) | false | ||
Nov 26, 2023 15:18:17.421515942 CET | 1.1.1.1 | 192.168.2.4 | 0xe20d | No error (0) | 18.156.13.209 | A (IP address) | IN (0x0001) | false | ||
Nov 26, 2023 15:19:21.422415972 CET | 1.1.1.1 | 192.168.2.4 | 0x8067 | No error (0) | 18.192.93.86 | A (IP address) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Click to jump to process
Target ID: | 0 |
Start time: | 15:15:59 |
Start date: | 26/11/2023 |
Path: | C:\Users\user\Desktop\NezbdhNgwG.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x20000 |
File size: | 36'864 bytes |
MD5 hash: | A650FFE73F9994AD3844FEDD49BA10F3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | .Net C# or VB.NET |
Yara matches: |
|
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 15:16:05 |
Start date: | 26/11/2023 |
Path: | C:\Windows\SysWOW64\netsh.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1560000 |
File size: | 82'432 bytes |
MD5 hash: | 4E89A1A088BE715D6C946E55AB07C7DF |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | moderate |
Has exited: | true |
Target ID: | 2 |
Start time: | 15:16:05 |
Start date: | 26/11/2023 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7699e0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | true |
Target ID: | 4 |
Start time: | 15:16:14 |
Start date: | 26/11/2023 |
Path: | C:\Users\user\Desktop\NezbdhNgwG.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x330000 |
File size: | 36'864 bytes |
MD5 hash: | A650FFE73F9994AD3844FEDD49BA10F3 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | .Net C# or VB.NET |
Reputation: | low |
Has exited: | true |
Target ID: | 6 |
Start time: | 15:16:22 |
Start date: | 26/11/2023 |
Path: | C:\Users\user\Desktop\NezbdhNgwG.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x9f0000 |
File size: | 36'864 bytes |
MD5 hash: | A650FFE73F9994AD3844FEDD49BA10F3 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | .Net C# or VB.NET |
Reputation: | low |
Has exited: | true |
Target ID: | 9 |
Start time: | 15:16:30 |
Start date: | 26/11/2023 |
Path: | C:\Users\user\Desktop\NezbdhNgwG.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x1c0000 |
File size: | 36'864 bytes |
MD5 hash: | A650FFE73F9994AD3844FEDD49BA10F3 |
Has elevated privileges: | false |
Has administrator privileges: | false |
Programmed in: | .Net C# or VB.NET |
Reputation: | low |
Has exited: | true |
Execution Graph
Execution Coverage: | 17.9% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 13.1% |
Total number of Nodes: | 175 |
Total number of Limit Nodes: | 7 |
Graph
Function 0060B863 Relevance: 1.6, APIs: 1, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BE8F Relevance: 1.6, APIs: 1, Instructions: 64nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060B89A Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BBC8 Relevance: 1.6, APIs: 1, Instructions: 50nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BBEA Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BECA Relevance: 1.5, APIs: 1, Instructions: 38nativeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A3170F Relevance: .7, Instructions: 684COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A30F90 Relevance: 1.6, APIs: 1, Instructions: 115COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00A30F80 Relevance: 1.6, APIs: 1, Instructions: 112COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1C32 Relevance: 1.6, APIs: 1, Instructions: 108COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC19A4 Relevance: 1.6, APIs: 1, Instructions: 93COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1290 Relevance: 1.6, APIs: 1, Instructions: 89COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060ADAD Relevance: 1.6, APIs: 1, Instructions: 86fileCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BAD0 Relevance: 1.6, APIs: 1, Instructions: 85COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC189C Relevance: 1.6, APIs: 1, Instructions: 85timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC2F88 Relevance: 1.6, APIs: 1, Instructions: 85COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC19C6 Relevance: 1.6, APIs: 1, Instructions: 84COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC2EB9 Relevance: 1.6, APIs: 1, Instructions: 80COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060AEA8 Relevance: 1.6, APIs: 1, Instructions: 79COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC0E6A Relevance: 1.6, APIs: 1, Instructions: 77networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1446 Relevance: 1.6, APIs: 1, Instructions: 77fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A078 Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060ADD2 Relevance: 1.6, APIs: 1, Instructions: 76fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC12B6 Relevance: 1.6, APIs: 1, Instructions: 76COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC3087 Relevance: 1.6, APIs: 1, Instructions: 73COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC16DD Relevance: 1.6, APIs: 1, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A140 Relevance: 1.6, APIs: 1, Instructions: 71networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060B64C Relevance: 1.6, APIs: 1, Instructions: 71COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC0C02 Relevance: 1.6, APIs: 1, Instructions: 70fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC2DF3 Relevance: 1.6, APIs: 1, Instructions: 69COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060AB4D Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060B930 Relevance: 1.6, APIs: 1, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC0E8A Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1B76 Relevance: 1.6, APIs: 1, Instructions: 67networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1466 Relevance: 1.6, APIs: 1, Instructions: 67fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1F32 Relevance: 1.6, APIs: 1, Instructions: 66libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060ACE8 Relevance: 1.6, APIs: 1, Instructions: 64fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A710 Relevance: 1.6, APIs: 1, Instructions: 64COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC18DA Relevance: 1.6, APIs: 1, Instructions: 64timeCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC30AA Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC2FC6 Relevance: 1.6, APIs: 1, Instructions: 62COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BB0E Relevance: 1.6, APIs: 1, Instructions: 61COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BDE4 Relevance: 1.6, APIs: 1, Instructions: 60COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC0C22 Relevance: 1.6, APIs: 1, Instructions: 60fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC2E16 Relevance: 1.6, APIs: 1, Instructions: 58COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A9B5 Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC170A Relevance: 1.6, APIs: 1, Instructions: 57COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A2D2 Relevance: 1.6, APIs: 1, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC0170 Relevance: 1.6, APIs: 1, Instructions: 56COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1F52 Relevance: 1.6, APIs: 1, Instructions: 56libraryCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC2EF2 Relevance: 1.6, APIs: 1, Instructions: 55COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060B67E Relevance: 1.6, APIs: 1, Instructions: 53COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060AD0A Relevance: 1.6, APIs: 1, Instructions: 53fileCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060AEEA Relevance: 1.6, APIs: 1, Instructions: 52COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A918 Relevance: 1.6, APIs: 1, Instructions: 51COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060BE06 Relevance: 1.5, APIs: 1, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1BA6 Relevance: 1.5, APIs: 1, Instructions: 49networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060AB8E Relevance: 1.5, APIs: 1, Instructions: 48COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A0BE Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC1CC6 Relevance: 1.5, APIs: 1, Instructions: 47COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BC0192 Relevance: 1.5, APIs: 1, Instructions: 45COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060B96A Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A186 Relevance: 1.5, APIs: 1, Instructions: 42networkCOMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A93A Relevance: 1.5, APIs: 1, Instructions: 40COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A9E2 Relevance: 1.5, APIs: 1, Instructions: 39COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0060A2FE Relevance: 1.5, APIs: 1, Instructions: 35COMMON
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD109C Relevance: .1, Instructions: 75COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD1070 Relevance: .1, Instructions: 69COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 051126C0 Relevance: .1, Instructions: 60COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD0934 Relevance: .1, Instructions: 59COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD08FC Relevance: .1, Instructions: 54COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0081B858 Relevance: .1, Instructions: 52COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD10F6 Relevance: .0, Instructions: 48COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD05E0 Relevance: .0, Instructions: 47COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD09F0 Relevance: .0, Instructions: 31COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00BD0606 Relevance: .0, Instructions: 27COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0511272B Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 05111FD7 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 0081B8A7 Relevance: .0, Instructions: 26COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006023F4 Relevance: .0, Instructions: 15COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 006023BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 8.7% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 12 |
Total number of Limit Nodes: | 0 |
Graph
Callgraph
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00DE0310 Relevance: .2, Instructions: 192COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00DE0369 Relevance: .2, Instructions: 158COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00DE03BD Relevance: .1, Instructions: 135COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00DE0088 Relevance: .1, Instructions: 126COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C605E0 Relevance: .0, Instructions: 45COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C60606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C923F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00C923BC Relevance: .0, Instructions: 14COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00DE006C Relevance: .0, Instructions: 5COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 12.2% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 015B0310 Relevance: 3.9, Strings: 3, Instructions: 190COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015B03BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 012EA710 Relevance: 1.6, APIs: 1, Instructions: 66COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 012EA74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015B0080 Relevance: .1, Instructions: 131COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 015B0006 Relevance: .1, Instructions: 51COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 014C05DF Relevance: .0, Instructions: 46COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 014C0606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 012E23F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 012E23BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Execution Graph
Execution Coverage: | 11.6% |
Dynamic/Decrypted Code Coverage: | 100% |
Signature Coverage: | 0% |
Total number of Nodes: | 19 |
Total number of Limit Nodes: | 1 |
Graph
Callgraph
Function 04980310 Relevance: 3.9, Strings: 3, Instructions: 191COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 049803BD Relevance: 3.9, Strings: 3, Instructions: 135COMMON
Control-flow Graph
Strings |
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AAA710 Relevance: 1.6, APIs: 1, Instructions: 66COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AAA74E Relevance: 1.5, APIs: 1, Instructions: 43COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04980080 Relevance: .1, Instructions: 129COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00CF05E0 Relevance: .0, Instructions: 47COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 04980006 Relevance: .0, Instructions: 45COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00CF0606 Relevance: .0, Instructions: 27COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AA23F4 Relevance: .0, Instructions: 15COMMON
Control-flow Graph
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |
Function 00AA23BC Relevance: .0, Instructions: 14COMMON
Memory Dump Source |
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Uniqueness |
Uniqueness Score: -1.00% |