Windows
Analysis Report
signed.exe
Overview
General Information
Detection
Score: | 72 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
signed.exe (PID: 5872 cmdline:
"C:\Users\ user\Deskt op\signed. exe" MD5: ADAC67FA4E7FBD2C7DE600768C40AD69)
- cleanup
Click to jump to signature section
AV Detection |
---|
Source: | Avira: |
Source: | Avira: |
Source: | ReversingLabs: |
Source: | ReversingLabs: |
Source: | Static PE information: |
Source: | Code function: | 0_2_0042A31A |
Source: | DNS traffic detected: |
Source: | UDP traffic detected without corresponding DNS query: |
Source: | DNS traffic detected: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_0041DB44 |
Source: | Code function: | 0_2_0041DB44 |
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00420400 | |
Source: | Code function: | 0_2_0042E502 | |
Source: | Code function: | 0_2_00423591 | |
Source: | Code function: | 0_2_00433975 | |
Source: | Code function: | 0_2_0041C9DD | |
Source: | Code function: | 0_2_0041DB44 | |
Source: | Code function: | 0_2_0040EC34 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Static PE information: |
Source: | Classification label: |
Source: | Code function: | 0_2_004278A6 |
Source: | Code function: | 0_2_00405D5A |
Source: | Code function: | 0_2_00409099 |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | ReversingLabs: |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | File read: | Jump to behavior |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | LNK file: | ||
Source: | LNK file: |
Source: | File opened: | Jump to behavior |
Source: | Window detected: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00433794 |
Source: | Code function: | 0_2_0042BE2E | |
Source: | Code function: | 0_2_00429E36 |
Source: | File created: | Jump to dropped file |
Source: | File created: | Jump to dropped file |
Source: | Code function: | 0_2_004017EE |
Source: | File created: | Jump to behavior | ||
Source: | File created: | Jump to behavior |
Source: | Code function: | 0_2_00405155 |
Source: | Dropped PE file which has not been started: | Jump to dropped file |
Source: | Code function: | 0_2_0042A31A |
Source: | Binary or memory string: |
Source: | API call chain: | graph_0-21390 |
Source: | Code function: | 0_2_00433794 |
Source: | Code function: | 0_2_00431CEA | |
Source: | Code function: | 0_2_00431CFC |
Source: | Queries volume information: | Jump to behavior |
Source: | Code function: | 0_2_0042BB27 |
Source: | Code function: | 0_2_00430499 |
Source: | Code function: | 0_2_0042A6BB |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 1 Registry Run Keys / Startup Folder | 1 Registry Run Keys / Startup Folder | 21 Masquerading | OS Credential Dumping | 2 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 1 Native API | 1 DLL Side-Loading | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 11 Security Software Discovery | Remote Desktop Protocol | 2 Clipboard Data | 1 Non-Application Layer Protocol | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | Logon Script (Windows) | 2 Obfuscated Files or Information | Security Account Manager | 1 Application Window Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | 1 Application Layer Protocol | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 DLL Side-Loading | NTDS | 2 File and Directory Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | Software Packing | LSA Secrets | 13 System Information Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
87% | ReversingLabs | Win32.Trojan.Ymacco | ||
100% | Avira | TR/Agent.396616 |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
100% | Avira | TR/Agent.396616 | ||
62% | ReversingLabs | Win32.Trojan.Scar |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | IP | Active | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|---|
206.23.85.13.in-addr.arpa | unknown | unknown | false | unknown |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1445853 |
Start date and time: | 2024-05-22 17:14:34 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 6s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 9 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | signed.exe |
Detection: | MAL |
Classification: | mal72.winEXE@1/3@1/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Report size getting too big, too many NtOpenKeyEx calls found.
- Report size getting too big, too many NtQueryValueKey calls found.
- VT rate limit hit for: signed.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RealLegal E-Transcript Viewer\RealLegal E-Transcript Viewer.lnk
Download File
Process: | C:\Users\user\Desktop\signed.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 897 |
Entropy (8bit): | 4.629970644384975 |
Encrypted: | false |
SSDEEP: | 24:8tzhEpwA/APglh8Z+IYA82+J2bTGPqygm:8hhzPgAxdMETRyg |
MD5: | 156293BF19D4183D208CC6AFECC124CE |
SHA1: | 4BD8CACA39E1EB5CD569611513F81406FDF702AE |
SHA-256: | 2E883DB7578228D8256EC350F8BC9ECD75D620759DEC3929242873E342267AC4 |
SHA-512: | 013955A1A05C2B5129800971B09A2F9293A485371C33CC4323FDB16353F4B33F2B2012966B31907A65275815A15AA5D238E00A2BCDB2303086EADCABBB5318F6 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\signed.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 879 |
Entropy (8bit): | 4.649885728909304 |
Encrypted: | false |
SSDEEP: | 24:8tzhEpwA/APglh8Mv+IYA82+J2bTGPqygm:8hhzPgAM3dMETRyg |
MD5: | E76367F2F85A37FA1DBDA6970844E916 |
SHA1: | C71E648A86B6E3EFE0D9B25CFC18C9ECED551376 |
SHA-256: | 6D05301D63937AD01E1798FCE3B79EA46736151667BE7C8AC098966889465853 |
SHA-512: | 67570F6F2D306065C5181E084BEF3693FC1E5C3202F272C73DD4DC3E9D04F6EFB000F6319A643AAC06E40225467A7D636211D3831D14DA3E1CB1F6A12B840F61 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\signed.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 380928 |
Entropy (8bit): | 6.1734613399593 |
Encrypted: | false |
SSDEEP: | 6144:AKHQypT6oiKpsoQEX6npbWdhlG8dj61M65PZDeC2TqI6/qygKjJVLesH7uCicrPW:PHQypT6oiKpsoQEX6npbWdhlG8dj6h56 |
MD5: | F70D964D36EA0D4BFE8F1106BCD6D9BE |
SHA1: | 6B98EF8904948AF07757688EEAE3036A10C03A98 |
SHA-256: | 6953A607F4219659C440D016C4C4CD2AEF5A9945085A4ABF7537A868D1219C62 |
SHA-512: | EF8A2725D3113BA68774A026E65A49A21B1E2CAB3437ADF6B649B2B013C8DE578976BAE3C5982BA532ECBEA457631E1D57D6FAC7D9CFB0F8A6293732C6DE4CE1 |
Malicious: | true |
Antivirus: |
|
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.2783295761255555 |
TrID: |
|
File name: | signed.exe |
File size: | 396'616 bytes |
MD5: | adac67fa4e7fbd2c7de600768c40ad69 |
SHA1: | c79c40e5272ac11180cf90715156e0538336fdbf |
SHA256: | 3904b06e1150e4e9e167eb1b63a877ed00c08320c637396f12b98e9f14d71010 |
SHA512: | ea4cda9dc74b67e1a73915184be4e3161000b64de3d77af37735875b0764677a6e5938c1b8138a016c99cad582873380bc9ab05f4a2f4548db59c4b1cad19b33 |
SSDEEP: | 12288:PHQypT6oiKpsoQEX6npbWdhlG8dj6h5PZDeCcq/qybjJVLesH7uCicrPYyr2ac85:PHQypT6oiKpsoQEX6npbWdhlG8dj6rci |
TLSH: | A184AF127BE08823E4F386311E656B75FB79FA162E78C68B53C46A5EFC31542CE25305 |
File Content Preview: | MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......O.....w...w...w.p.{...w.V.|...w.V.}.s.w...y...w.T.}...w...|...w.].d...w...w...w.i.d...w...v.H.w.T.|.4.w...q...w.Rich..w........ |
Icon Hash: | 2d4e5e70faca82b8 |
Entrypoint: | 0x42a6bb |
Entrypoint Section: | .text |
Digitally signed: | false |
Imagebase: | 0x400000 |
Subsystem: | windows gui |
Image File Characteristics: | RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE |
DLL Characteristics: | |
Time Stamp: | 0x3DFB76EC [Sat Dec 14 18:22:36 2002 UTC] |
TLS Callbacks: | |
CLR (.Net) Version: | |
OS Version Major: | 4 |
OS Version Minor: | 0 |
File Version Major: | 4 |
File Version Minor: | 0 |
Subsystem Version Major: | 4 |
Subsystem Version Minor: | 0 |
Import Hash: | b6aeefc612e58a3beaa47c456a910042 |
Instruction |
---|
push ebp |
mov ebp, esp |
push FFFFFFFFh |
push 00438238h |
push 0042FF90h |
mov eax, dword ptr fs:[00000000h] |
push eax |
mov dword ptr fs:[00000000h], esp |
sub esp, 58h |
push ebx |
push esi |
push edi |
mov dword ptr [ebp-18h], esp |
call dword ptr [00437214h] |
xor edx, edx |
mov dl, ah |
mov dword ptr [00446F00h], edx |
mov ecx, eax |
and ecx, 000000FFh |
mov dword ptr [00446EFCh], ecx |
shl ecx, 08h |
add ecx, edx |
mov dword ptr [00446EF8h], ecx |
shr eax, 10h |
mov dword ptr [00446EF4h], eax |
xor esi, esi |
push esi |
call 00007F275081125Fh |
pop ecx |
test eax, eax |
jne 00007F275080DD2Ah |
push 0000001Ch |
call 00007F275080DDD5h |
pop ecx |
mov dword ptr [ebp-04h], esi |
call 00007F27508133D2h |
call dword ptr [00437218h] |
mov dword ptr [00448740h], eax |
call 00007F2750813290h |
mov dword ptr [00446EA4h], eax |
call 00007F2750813039h |
call 00007F2750812F7Bh |
call 00007F2750810F4Eh |
mov dword ptr [ebp-30h], esi |
lea eax, dword ptr [ebp-5Ch] |
push eax |
call dword ptr [0043721Ch] |
call 00007F2750812F0Ch |
mov dword ptr [ebp-64h], eax |
test byte ptr [ebp-30h], 00000001h |
je 00007F275080DD28h |
movzx eax, word ptr [ebp-2Ch] |
jmp 00007F275080DD25h |
push 0000000Ah |
pop eax |
push eax |
push dword ptr [ebp-64h] |
push esi |
push esi |
call dword ptr [00437220h] |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x39d2c | 0xf0 | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x49000 | 0x17428 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x37000 | 0x520 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x39b50 | 0x40 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x354f5 | 0x36000 | 6a5a5fae276ae0a2c23cd1235b3ec3fb | False | 0.5645164207175926 | data | 6.5194046239212335 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x37000 | 0x4836 | 0x5000 | 38460c6c358985e4dd49abf01f00a90d | False | 0.355126953125 | data | 5.086068831149444 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x3c000 | 0xc744 | 0x9000 | 9ddf77fe13cf57aeb2ab4654f7f8670a | False | 0.4037543402777778 | data | 4.893839902601005 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.rsrc | 0x49000 | 0x17428 | 0x18000 | e3eae7483518ebcb4c553808f1b31ad4 | False | 0.43975830078125 | data | 5.123736066627297 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
BININC | 0x49c70 | 0x9cf | ASCII text, with CRLF line terminators | English | United States | 0.3819195539625647 |
BININC | 0x4a640 | 0x9d71 | MS Windows 3.1 help, Thu Dec 5 18:59:46 2002, 40305 bytes | English | United States | 0.6649299094405161 |
RT_CURSOR | 0x5ed88 | 0x134 | data | English | United States | 0.37337662337662336 |
RT_CURSOR | 0x5eed8 | 0x134 | data | English | United States | 0.2922077922077922 |
RT_BITMAP | 0x5b020 | 0x568 | Device independent bitmap graphic, 160 x 16 x 4, image size 1280 | English | United States | 0.4147398843930636 |
RT_BITMAP | 0x5ae90 | 0xc8 | Device independent bitmap graphic, 12 x 12 x 4, image size 96 | English | United States | 0.495 |
RT_BITMAP | 0x5af58 | 0xc8 | Device independent bitmap graphic, 12 x 12 x 4, image size 96 | English | United States | 0.385 |
RT_BITMAP | 0x5b7e0 | 0x288 | Device independent bitmap graphic, 32 x 34 x 4, image size 544 | English | United States | 0.25462962962962965 |
RT_BITMAP | 0x56580 | 0x4848 | Device independent bitmap graphic, 400 x 299 x 8, 1 compression, image size 17440 | English | United States | 0.25810635538262 |
RT_BITMAP | 0x5adc8 | 0xc8 | Device independent bitmap graphic, 12 x 12 x 4, image size 96 | English | United States | 0.385 |
RT_BITMAP | 0x564b8 | 0xc8 | Device independent bitmap graphic, 12 x 12 x 4, image size 96 | English | United States | 0.45 |
RT_BITMAP | 0x5b588 | 0xc8 | Device independent bitmap graphic, 12 x 12 x 4, image size 96 | English | United States | 0.34 |
RT_BITMAP | 0x5b650 | 0xc8 | Device independent bitmap graphic, 12 x 12 x 4, image size 96 | English | United States | 0.415 |
RT_BITMAP | 0x5b718 | 0xc8 | Device independent bitmap graphic, 12 x 12 x 4, image size 96 | English | United States | 0.465 |
RT_BITMAP | 0x5e9d8 | 0x3b0 | Device independent bitmap graphic, 112 x 15 x 4, image size 840 | English | United States | 0.2521186440677966 |
RT_ICON | 0x561b8 | 0x2e8 | Device independent bitmap graphic, 32 x 64 x 4, image size 640 | English | United States | 0.21236559139784947 |
RT_MENU | 0x543b8 | 0x5ec | data | English | United States | 0.3449868073878628 |
RT_DIALOG | 0x54a28 | 0xd6 | data | English | United States | 0.6728971962616822 |
RT_DIALOG | 0x55a08 | 0x28a | data | English | United States | 0.48307692307692307 |
RT_DIALOG | 0x54b00 | 0x3f6 | data | English | United States | 0.4408284023668639 |
RT_DIALOG | 0x55108 | 0x406 | data | English | United States | 0.4553398058252427 |
RT_DIALOG | 0x54ef8 | 0x20a | data | English | United States | 0.5440613026819924 |
RT_DIALOG | 0x55548 | 0x4bc | data | English | United States | 0.4249174917491749 |
RT_DIALOG | 0x55510 | 0x36 | data | English | United States | 0.7962962962962963 |
RT_DIALOG | 0x55c98 | 0x36c | data | English | United States | 0.4554794520547945 |
RT_DIALOG | 0x56008 | 0x1b0 | data | English | United States | 0.5879629629629629 |
RT_DIALOG | 0x5bce0 | 0x1b6 | data | English | United States | 0.5662100456621004 |
RT_DIALOG | 0x5e3f0 | 0x5e6 | data | English | United States | 0.4112582781456954 |
RT_DIALOG | 0x5be98 | 0x538 | data | English | United States | 0.46107784431137727 |
RT_DIALOG | 0x5e0b0 | 0x33e | data | English | United States | 0.46265060240963857 |
RT_DIALOG | 0x5c6b8 | 0x6e | data | English | United States | 0.8 |
RT_DIALOG | 0x5c3d0 | 0x2e2 | data | English | United States | 0.5094850948509485 |
RT_DIALOG | 0x5d4a0 | 0xd6 | data | English | United States | 0.6822429906542056 |
RT_DIALOG | 0x5d578 | 0x4fc | data | English | United States | 0.45141065830721006 |
RT_DIALOG | 0x5da78 | 0x2dc | data | English | United States | 0.48633879781420764 |
RT_DIALOG | 0x5ba68 | 0x272 | data | English | United States | 0.5223642172523961 |
RT_DIALOG | 0x5c728 | 0x556 | data | English | United States | 0.44875549048316254 |
RT_DIALOG | 0x5dd58 | 0x352 | data | English | United States | 0.4682352941176471 |
RT_DIALOG | 0x5cc80 | 0x40a | data | English | United States | 0.49806576402321084 |
RT_DIALOG | 0x5d090 | 0x40a | data | English | United States | 0.4874274661508704 |
RT_STRING | 0x5fbf0 | 0x37a | data | English | United States | 0.3382022471910112 |
RT_STRING | 0x5ff70 | 0xa0 | data | English | United States | 0.64375 |
RT_STRING | 0x5f878 | 0x1ee | Matlab v4 mat-file (little endian) h, numeric, rows 0, columns 0 | English | United States | 0.4493927125506073 |
RT_STRING | 0x5f840 | 0x32 | data | English | United States | 0.56 |
RT_STRING | 0x5f800 | 0x3c | data | English | United States | 0.7 |
RT_STRING | 0x5f3c8 | 0x436 | Matlab v4 mat-file (little endian) F, numeric, rows 0, columns 0 | English | United States | 0.2884972170686456 |
RT_STRING | 0x5f318 | 0xac | data | English | United States | 0.5465116279069767 |
RT_STRING | 0x5faa8 | 0xd2 | data | English | United States | 0.6142857142857143 |
RT_STRING | 0x5fa68 | 0x3a | data | English | United States | 0.6379310344827587 |
RT_STRING | 0x5fb80 | 0x6c | data | English | United States | 0.7037037037037037 |
RT_STRING | 0x60010 | 0x48 | data | English | United States | 0.6944444444444444 |
RT_STRING | 0x603b0 | 0x78 | data | English | United States | 0.6833333333333333 |
RT_STRING | 0x60058 | 0xa6 | data | English | United States | 0.572289156626506 |
RT_STRING | 0x60100 | 0xb6 | data | English | United States | 0.6538461538461539 |
RT_STRING | 0x601b8 | 0x1f8 | data | English | United States | 0.4503968253968254 |
RT_ACCELERATOR | 0x549a8 | 0x80 | data | English | United States | 0.7265625 |
RT_GROUP_CURSOR | 0x5f010 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.3 |
RT_GROUP_CURSOR | 0x5eec0 | 0x14 | Lotus unknown worksheet or configuration, revision 0x1 | English | United States | 1.25 |
RT_GROUP_ICON | 0x564a0 | 0x14 | data | English | United States | 1.2 |
RT_VERSION | 0x5f028 | 0x2ec | data | English | United States | 0.4679144385026738 |
DLL | Import |
---|---|
KERNEL32.dll | FreeLibrary, lstrlenA, GetTempPathA, GetTempFileNameA, lstrcpyA, GetPrivateProfileStringA, GetModuleFileNameA, LoadLibraryA, WaitForSingleObject, SetEvent, ResetEvent, CreateEventA, FormatMessageA, LocalFree, GetLastError, GetProfileStringA, GetVersionExA, lstrcpynA, GetTickCount, CopyFileA, GlobalReAlloc, WritePrivateProfileStringA, GetPrivateProfileIntA, CreateFileA, ReadFile, CloseHandle, _llseek, GlobalAlloc, GlobalLock, _hread, GlobalHandle, GlobalUnlock, GlobalFree, MultiByteToWideChar, FindResourceA, SizeofResource, LoadResource, LockResource, _hwrite, FreeResource, SystemTimeToFileTime, FileTimeToLocalFileTime, FileTimeToSystemTime, GetTimeZoneInformation, GetWindowsDirectoryA, _lopen, _lcreat, _lread, _lwrite, _lclose, lstrcatA, lstrcmpiA, GetEnvironmentStringsW, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, LCMapStringW, LCMapStringA, IsBadWritePtr, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, GetEnvironmentVariableA, HeapSize, GetCurrentProcess, TerminateProcess, WriteFile, GetLocalTime, GetSystemTime, HeapValidate, HeapReAlloc, ExitProcess, GetVersion, GetCommandLineA, GetStartupInfoA, GetModuleHandleA, CreateDirectoryA, RemoveDirectoryA, FindClose, FindFirstFileA, HeapAlloc, HeapFree, RtlUnwind, DeleteFileA, GetFileAttributesA, SetFileAttributesA, WideCharToMultiByte, RaiseException, InterlockedExchange, LocalAlloc, GetEnvironmentStrings, GetProcAddress, SetHandleCount, GetStdHandle, GetFileType, WinExec, CompareStringA, SetFilePointer, SetUnhandledExceptionFilter, SetStdHandle, FlushFileBuffers, IsBadReadPtr, IsBadCodePtr, GetCPInfo, SetEndOfFile, CompareStringW, GetACP, GetOEMCP, SetEnvironmentVariableA, GetStringTypeA, GetStringTypeW |
USER32.dll | LoadAcceleratorsA, SetWindowsHookA, OffsetRect, GetSystemMetrics, GetMessageA, RegisterClassA, TranslateAcceleratorA, TranslateMessage, DispatchMessageA, UnhookWindowsHook, LoadStringA, ShowWindow, GetWindowRect, MoveWindow, SendDlgItemMessageA, SetWindowTextA, GetWindow, GetDlgItemTextA, CharLowerA, SetDlgItemTextA, GetDlgItemInt, PostQuitMessage, IsZoomed, GetWindowPlacement, PtInRect, CheckDlgButton, SetDlgItemInt, InvalidateRect, LoadIconA, GetDlgItem, EndDialog, CopyRect, SetWindowPos, CreateWindowExA, SetWindowLongA, GetParent, GetWindowLongA, SetRect, DrawTextA, BeginPaint, GetPropA, RemovePropA, SetPropA, GetClassNameA, GetKeyState, IsDialogMessageA, GetFocus, IsWindowEnabled, EmptyClipboard, SetClipboardData, EndPaint, GetMenu, GetSubMenu, EnableWindow, UpdateWindow, DialogBoxParamA, MessageBoxA, SendMessageA, SetRectEmpty, DefWindowProcA, IsIconic, IsDlgButtonChecked, CheckRadioButton, LoadBitmapA, CloseClipboard, SetTimer, KillTimer, GetScrollRange, CharUpperBuffA, GetScrollInfo, LoadCursorA, SetCursor, GetCapture, GetClientRect, IsWindowVisible, WinHelpA, InvertRect, EnableScrollBar, SetActiveWindow, ReleaseCapture, SetCapture, ClientToScreen, GetDesktopWindow, PeekMessageA, CreateDialogParamA, GetScrollPos, ScrollWindow, SetScrollPos, GetDC, ReleaseDC, InflateRect, DrawTextExA, GetCursor, DestroyWindow, IsRectEmpty, SetScrollRange, DestroyCursor, GetWindowTextA, IsCharAlphaA, CharUpperA, IsCharAlphaNumericA, IsCharLowerA, IsCharUpperA, CallWindowProcA, GetCursorPos, ScreenToClient, GetSysColor, GetWindowTextLengthA, FillRect, wsprintfA, GetActiveWindow, PostMessageA, CallNextHookEx, CheckMenuItem, GetMenuItemCount, GetMenuItemInfoA, EnableMenuItem, MessageBeep, SetFocus, IsWindow, OpenClipboard, DrawMenuBar, SetMenu, wsprintfW |
GDI32.dll | SetBkMode, BitBlt, SelectObject, CreateCompatibleDC, GetStockObject, DeleteObject, GetObjectA, TextOutA, SetBkColor, SetTextColor, SetTextAlign, CreatePalette, CreateFontIndirectA, SetWindowOrgEx, CreateSolidBrush, SetRectRgn, ExtTextOutA, SelectClipRgn, CreateRectRgn, GetTextExtentPointA, GetTextMetricsA, PatBlt, CreatePatternBrush, CreateBitmap, SetViewportOrgEx, GetWindowOrgEx, LPtoDP, SetViewportExtEx, GetWindowExtEx, SetMapMode, GetDeviceCaps, EnumFontFamiliesA, CreatePen, RealizePalette, SelectPalette, LineTo, MoveToEx, CreateFontA, GetCharWidthA, CreateICA, EndPage, StartPage, StartDocA, EndDoc, AbortDoc, DeleteDC, CreateDCA, GetTextAlign |
WINSPOOL.DRV | OpenPrinterA, DeviceCapabilitiesA, GetPrinterA, ClosePrinter, DocumentPropertiesA |
comdlg32.dll | GetOpenFileNameA, GetSaveFileNameA, CommDlgExtendedError, PrintDlgA |
ADVAPI32.dll | RegCloseKey, RegQueryValueExA, RegOpenKeyExA, RegQueryValueA, RegSetValueExA, RegCreateKeyExA, RegDeleteKeyA |
SHELL32.dll | SHGetMalloc, SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHChangeNotify, ShellExecuteA |
ole32.dll | CoCreateInstance, CoInitialize, OleSetMenuDescriptor, StgCreateDocfile, CoUninitialize |
RPCRT4.dll | UuidToStringA, RpcStringFreeA |
COMCTL32.dll | InitCommonControlsEx, CreateToolbarEx |
VERSION.dll | VerQueryValueA, GetFileVersionInfoA, GetFileVersionInfoSizeA |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 22, 2024 17:15:54.234720945 CEST | 53 | 61696 | 162.159.36.2 | 192.168.2.6 |
May 22, 2024 17:15:54.782475948 CEST | 58276 | 53 | 192.168.2.6 | 1.1.1.1 |
May 22, 2024 17:15:54.820730925 CEST | 53 | 58276 | 1.1.1.1 | 192.168.2.6 |
Timestamp | Source IP | Dest IP | Trans ID | OP Code | Name | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|
May 22, 2024 17:15:54.782475948 CEST | 192.168.2.6 | 1.1.1.1 | 0x7cfb | Standard query (0) | PTR (Pointer record) | IN (0x0001) | false |
Timestamp | Source IP | Dest IP | Trans ID | Reply Code | Name | CName | Address | Type | Class | DNS over HTTPS |
---|---|---|---|---|---|---|---|---|---|---|
May 22, 2024 17:15:54.820730925 CEST | 1.1.1.1 | 192.168.2.6 | 0x7cfb | Name error (3) | none | none | PTR (Pointer record) | IN (0x0001) | false |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 11:15:16 |
Start date: | 22/05/2024 |
Path: | C:\Users\user\Desktop\signed.exe |
Wow64 process (32bit): | true |
Commandline: | |
Imagebase: | 0x400000 |
File size: | 396'616 bytes |
MD5 hash: | ADAC67FA4E7FBD2C7DE600768C40AD69 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 10.3% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 6.8% |
Total number of Nodes: | 1497 |
Total number of Limit Nodes: | 122 |
Graph
Function 00405D5A Relevance: 44.0, APIs: 21, Strings: 4, Instructions: 226stringcomwindowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405155 Relevance: 23.0, APIs: 12, Strings: 1, Instructions: 204windowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00430499 Relevance: 10.7, APIs: 3, Strings: 3, Instructions: 196timeCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042A31A Relevance: 3.1, APIs: 2, Instructions: 62fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406252 Relevance: 66.7, APIs: 30, Strings: 8, Instructions: 223registrystringwindowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004022EE Relevance: 65.0, APIs: 35, Strings: 2, Instructions: 265windowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004172E4 Relevance: 46.7, APIs: 31, Instructions: 249COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404056 Relevance: 36.9, APIs: 17, Strings: 4, Instructions: 191registrylibrarywindowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004064C3 Relevance: 33.4, APIs: 11, Strings: 8, Instructions: 151windowstringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E06C Relevance: 31.6, APIs: 16, Strings: 2, Instructions: 137stringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403447 Relevance: 28.2, APIs: 15, Strings: 1, Instructions: 158windowstringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408027 Relevance: 26.6, APIs: 13, Strings: 2, Instructions: 301windowCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040459A Relevance: 24.7, APIs: 12, Strings: 2, Instructions: 237stringCOMMON
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405BDA Relevance: 21.1, APIs: 11, Strings: 1, Instructions: 106stringCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00432D3B Relevance: 19.5, APIs: 9, Strings: 2, Instructions: 221COMMONLIBRARYCODE
Control-flow Graph
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403A45 Relevance: 19.5, APIs: 10, Strings: 1, Instructions: 207stringwindowCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E538 Relevance: 15.9, APIs: 8, Strings: 1, Instructions: 174stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042286E Relevance: 15.1, APIs: 10, Instructions: 129COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405FDE Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 76registrystringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B308 Relevance: 13.7, APIs: 9, Instructions: 209COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405B55 Relevance: 12.3, APIs: 6, Strings: 1, Instructions: 41stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E753 Relevance: 12.1, APIs: 8, Instructions: 128COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B6FC Relevance: 10.6, APIs: 7, Instructions: 80COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00408570 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 59windowstringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410E4D Relevance: 9.0, APIs: 6, Instructions: 33memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403F44 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 89stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004229C8 Relevance: 7.6, APIs: 5, Instructions: 114stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004086D5 Relevance: 7.6, APIs: 5, Instructions: 77windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004044C4 Relevance: 7.6, APIs: 5, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B689 Relevance: 7.5, APIs: 5, Instructions: 42COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004147A5 Relevance: 6.2, APIs: 4, Instructions: 193COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040EA3E Relevance: 6.0, APIs: 4, Instructions: 38COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040EA96 Relevance: 6.0, APIs: 4, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040176B Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 37stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004175C1 Relevance: 4.5, APIs: 3, Instructions: 26COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041BB0A Relevance: 4.5, APIs: 3, Instructions: 26COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404D6D Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 86windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410C0A Relevance: 3.0, APIs: 2, Instructions: 41COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004146CC Relevance: 3.0, APIs: 2, Instructions: 34COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042DC54 Relevance: 3.0, APIs: 2, Instructions: 30memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414B66 Relevance: 3.0, APIs: 2, Instructions: 26COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00405AEC Relevance: 3.0, APIs: 2, Instructions: 21COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00429FC1 Relevance: 3.0, APIs: 2, Instructions: 19COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042A491 Relevance: 3.0, APIs: 2, Instructions: 17COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00429610 Relevance: 3.0, APIs: 2, Instructions: 16fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041AFAA Relevance: 3.0, APIs: 2, Instructions: 16windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040679C Relevance: 1.6, APIs: 1, Instructions: 110COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040C2C4 Relevance: 1.6, APIs: 1, Instructions: 79COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042A043 Relevance: 1.5, APIs: 1, Instructions: 46memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404442 Relevance: 1.5, APIs: 1, Instructions: 41COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00421FDA Relevance: 1.5, APIs: 1, Instructions: 36COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416F2A Relevance: 1.5, APIs: 1, Instructions: 26COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040C116 Relevance: 1.5, APIs: 1, Instructions: 20COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040E4EF Relevance: 1.5, APIs: 1, Instructions: 11COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040ABD8 Relevance: 1.5, APIs: 1, Instructions: 11COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414480 Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040AD6C Relevance: 1.3, APIs: 1, Instructions: 69stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004017EE Relevance: 79.1, APIs: 21, Strings: 24, Instructions: 372registrywindowstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041DB44 Relevance: 46.0, APIs: 22, Strings: 4, Instructions: 512stringmemoryclipboardCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00433975 Relevance: 26.7, Strings: 21, Instructions: 417COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00420400 Relevance: 21.6, APIs: 7, Strings: 5, Instructions: 562stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00433794 Relevance: 14.0, APIs: 4, Strings: 4, Instructions: 50libraryloaderCOMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00423591 Relevance: 9.2, APIs: 2, Strings: 3, Instructions: 459windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042A6BB Relevance: 6.1, APIs: 4, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040EC34 Relevance: 5.3, Strings: 2, Instructions: 2798COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C9DD Relevance: 4.6, APIs: 3, Instructions: 131COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042BB27 Relevance: 4.6, APIs: 3, Instructions: 75timeCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004278A6 Relevance: 4.5, APIs: 3, Instructions: 45windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00431CEA Relevance: 1.5, APIs: 1, Instructions: 4COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00431CFC Relevance: 1.5, APIs: 1, Instructions: 3COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042E502 Relevance: .3, Instructions: 259COMMONLIBRARYCODE
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402C8E Relevance: 172.0, APIs: 75, Strings: 23, Instructions: 471stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004136AC Relevance: 96.7, APIs: 49, Strings: 6, Instructions: 427windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413BE0 Relevance: 87.7, APIs: 49, Strings: 1, Instructions: 230windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041BD31 Relevance: 68.5, APIs: 38, Strings: 1, Instructions: 288windowstringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402686 Relevance: 66.8, APIs: 35, Strings: 3, Instructions: 332windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004185BE Relevance: 65.1, APIs: 35, Strings: 2, Instructions: 337windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411737 Relevance: 65.0, APIs: 33, Strings: 4, Instructions: 282stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C1C1 Relevance: 63.3, APIs: 29, Strings: 7, Instructions: 319stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00420AD1 Relevance: 58.0, APIs: 28, Strings: 5, Instructions: 259stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004048CF Relevance: 56.2, APIs: 25, Strings: 7, Instructions: 234stringwindowprocessCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00434D1B Relevance: 54.5, APIs: 7, Strings: 24, Instructions: 299stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040B70B Relevance: 54.5, APIs: 2, Strings: 29, Instructions: 217stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041588C Relevance: 52.8, APIs: 35, Instructions: 250COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004354BF Relevance: 51.0, APIs: 17, Strings: 12, Instructions: 229stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041F111 Relevance: 46.9, APIs: 31, Instructions: 407COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414C2F Relevance: 44.0, APIs: 11, Strings: 14, Instructions: 225windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004169F8 Relevance: 38.6, APIs: 21, Strings: 1, Instructions: 121stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00425FD7 Relevance: 36.1, APIs: 24, Instructions: 143COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00404BBD Relevance: 35.2, APIs: 17, Strings: 3, Instructions: 159stringtimeCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415193 Relevance: 33.5, APIs: 15, Strings: 4, Instructions: 220windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040DCE6 Relevance: 33.4, APIs: 18, Strings: 1, Instructions: 181stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041BB6F Relevance: 33.4, APIs: 18, Strings: 1, Instructions: 134stringwindowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004032B8 Relevance: 29.9, APIs: 12, Strings: 5, Instructions: 125stringwindowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00435772 Relevance: 28.2, APIs: 10, Strings: 6, Instructions: 174stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00403628 Relevance: 28.1, APIs: 15, Strings: 1, Instructions: 131stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413345 Relevance: 26.4, APIs: 10, Strings: 5, Instructions: 198windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004351E2 Relevance: 26.4, APIs: 8, Strings: 7, Instructions: 180stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00411CA5 Relevance: 26.4, APIs: 13, Strings: 2, Instructions: 148stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00427D34 Relevance: 26.4, APIs: 6, Strings: 9, Instructions: 138synchronizationCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041312F Relevance: 24.6, APIs: 10, Strings: 4, Instructions: 141windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004057D7 Relevance: 24.6, APIs: 11, Strings: 3, Instructions: 70stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415BFE Relevance: 24.2, APIs: 16, Instructions: 152COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402AD3 Relevance: 24.1, APIs: 16, Instructions: 130COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004251B1 Relevance: 22.6, APIs: 15, Instructions: 99COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00412F5B Relevance: 21.2, APIs: 7, Strings: 5, Instructions: 159filewindowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004135CD Relevance: 21.1, APIs: 9, Strings: 3, Instructions: 68windowstringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00424346 Relevance: 19.6, APIs: 13, Instructions: 124COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00423C60 Relevance: 19.6, APIs: 13, Instructions: 96COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004167D4 Relevance: 19.6, APIs: 13, Instructions: 90COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004256AA Relevance: 19.4, APIs: 9, Strings: 2, Instructions: 128stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00428F60 Relevance: 19.3, APIs: 8, Strings: 3, Instructions: 84windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00426B88 Relevance: 19.3, APIs: 10, Strings: 1, Instructions: 69windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040939C Relevance: 19.3, APIs: 9, Strings: 2, Instructions: 67stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00424207 Relevance: 19.3, APIs: 4, Strings: 7, Instructions: 54stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00428926 Relevance: 17.7, APIs: 9, Strings: 1, Instructions: 187librarymemoryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042F5A4 Relevance: 17.7, APIs: 9, Strings: 1, Instructions: 177COMMONLIBRARYCODE
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040947B Relevance: 17.6, APIs: 8, Strings: 2, Instructions: 93stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414A1C Relevance: 17.6, APIs: 7, Strings: 3, Instructions: 93stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041D21F Relevance: 16.7, APIs: 11, Instructions: 186COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042451C Relevance: 16.6, APIs: 11, Instructions: 95COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041E0E8 Relevance: 16.2, APIs: 7, Strings: 2, Instructions: 447stringwindowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004222E8 Relevance: 16.0, APIs: 8, Strings: 1, Instructions: 243windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00423D97 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 110stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00409890 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 105stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416E49 Relevance: 15.8, APIs: 8, Strings: 1, Instructions: 93stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004230D8 Relevance: 15.8, APIs: 6, Strings: 3, Instructions: 88stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041EBAF Relevance: 15.2, APIs: 10, Instructions: 192COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00423221 Relevance: 15.2, APIs: 10, Instructions: 163COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00424703 Relevance: 15.1, APIs: 10, Instructions: 93COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042460F Relevance: 15.1, APIs: 10, Instructions: 92COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00402608 Relevance: 15.1, APIs: 10, Instructions: 51COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004300A1 Relevance: 14.1, APIs: 3, Strings: 5, Instructions: 100fileCOMMONLIBRARYCODE
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00421A0F Relevance: 13.8, APIs: 9, Instructions: 329COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042189F Relevance: 13.6, APIs: 9, Instructions: 145COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041C583 Relevance: 13.6, APIs: 9, Instructions: 81COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004084F1 Relevance: 13.6, APIs: 9, Instructions: 56windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004014A9 Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 151processwindowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00433609 Relevance: 12.4, APIs: 6, Strings: 1, Instructions: 117COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401528 Relevance: 12.3, APIs: 4, Strings: 3, Instructions: 96processwindowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041669F Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 61windowstringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042FCAA Relevance: 12.1, APIs: 8, Instructions: 132COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00434AF0 Relevance: 12.1, APIs: 1, Strings: 7, Instructions: 97stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00425F1E Relevance: 12.1, APIs: 8, Instructions: 62stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004262C6 Relevance: 12.0, APIs: 8, Instructions: 44COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00432110 Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 230fileCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B7D9 Relevance: 10.6, APIs: 7, Instructions: 89COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415F64 Relevance: 10.6, APIs: 7, Instructions: 84windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00425E5A Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 77stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004038F2 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 70stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00423497 Relevance: 10.6, APIs: 7, Instructions: 66COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041AD0D Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 61registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040EAE4 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 52stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041652D Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 51registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416080 Relevance: 9.2, APIs: 6, Instructions: 172windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041DA04 Relevance: 9.1, APIs: 6, Instructions: 115COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416D18 Relevance: 9.1, APIs: 6, Instructions: 84COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041BA52 Relevance: 9.1, APIs: 6, Instructions: 75COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042698F Relevance: 9.1, APIs: 6, Instructions: 63windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00410EA8 Relevance: 9.1, APIs: 6, Instructions: 55memoryCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00418381 Relevance: 9.1, APIs: 3, Strings: 3, Instructions: 54stringCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407A8D Relevance: 9.0, APIs: 6, Instructions: 41stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00428B50 Relevance: 9.0, APIs: 6, Instructions: 36memoryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416CAB Relevance: 9.0, APIs: 6, Instructions: 33COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00412D66 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 151stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042C853 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 139fileCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B0BA Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 86windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040540C Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 54windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407CD9 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 53windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00428C70 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 42windowCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00426AE6 Relevance: 8.8, APIs: 4, Strings: 1, Instructions: 32registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041EEA5 Relevance: 7.7, APIs: 5, Instructions: 184COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042FDDC Relevance: 7.6, APIs: 5, Instructions: 143COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041CDB1 Relevance: 7.6, APIs: 5, Instructions: 137COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B1C3 Relevance: 7.6, APIs: 5, Instructions: 91COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415DEC Relevance: 7.6, APIs: 5, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415E9C Relevance: 7.6, APIs: 5, Instructions: 72COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B557 Relevance: 7.6, APIs: 5, Instructions: 70COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004240F9 Relevance: 7.6, APIs: 5, Instructions: 61stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B9B3 Relevance: 7.6, APIs: 5, Instructions: 61COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041A2BD Relevance: 7.6, APIs: 5, Instructions: 54windowCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416DD6 Relevance: 7.5, APIs: 5, Instructions: 46COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416935 Relevance: 7.5, APIs: 5, Instructions: 41windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416993 Relevance: 7.5, APIs: 5, Instructions: 40COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00407F2B Relevance: 7.5, APIs: 5, Instructions: 38COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041B61D Relevance: 7.5, APIs: 5, Instructions: 35COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041CC69 Relevance: 7.5, APIs: 5, Instructions: 31COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041CC21 Relevance: 7.5, APIs: 5, Instructions: 31COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042343E Relevance: 7.5, APIs: 5, Instructions: 27COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00425DE6 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 51stringCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414B0D Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 28registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004242A6 Relevance: 7.0, APIs: 3, Strings: 1, Instructions: 26stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041677F Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 25registryCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401E94 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 19stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042D518 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 13libraryloaderCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042EB27 Relevance: 6.4, APIs: 5, Instructions: 102memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004301F4 Relevance: 6.2, APIs: 4, Instructions: 174fileCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00401000 Relevance: 6.1, APIs: 4, Instructions: 136windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041F7EC Relevance: 6.1, APIs: 4, Instructions: 112stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042505C Relevance: 6.1, APIs: 4, Instructions: 91COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00406B58 Relevance: 6.1, APIs: 4, Instructions: 90stringCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00415B1D Relevance: 6.1, APIs: 4, Instructions: 68COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041F757 Relevance: 6.1, APIs: 4, Instructions: 56stringCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0040AFAF Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 55stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414719 Relevance: 6.1, APIs: 4, Instructions: 52COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00416BA1 Relevance: 6.0, APIs: 4, Instructions: 49COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041A22E Relevance: 6.0, APIs: 4, Instructions: 43COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041727C Relevance: 6.0, APIs: 4, Instructions: 39COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041457B Relevance: 6.0, APIs: 4, Instructions: 39COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041A1BD Relevance: 6.0, APIs: 2, Strings: 2, Instructions: 38stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00428C20 Relevance: 6.0, APIs: 4, Instructions: 34COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041D695 Relevance: 6.0, APIs: 4, Instructions: 31timeCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004096EC Relevance: 6.0, APIs: 3, Strings: 1, Instructions: 30stringCOMMON
APIs |
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00428E60 Relevance: 6.0, APIs: 4, Instructions: 28COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004226CF Relevance: 6.0, APIs: 4, Instructions: 27COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004168F2 Relevance: 6.0, APIs: 4, Instructions: 25windowCOMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 004145E1 Relevance: 6.0, APIs: 4, Instructions: 21COMMON
APIs |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0041AE28 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 47COMMONLIBRARYCODE
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00413E5E Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 45windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00417605 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 28registryCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00414BCB Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 21windowCOMMON
APIs |
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00423AEE Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 10windowCOMMON
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Strings |
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 0042E356 Relevance: 5.1, APIs: 4, Instructions: 53memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|