Windows
Analysis Report
sj-updater-app.exe
Overview
General Information
Detection
Score: | 2 |
Range: | 0 - 100 |
Whitelisted: | false |
Confidence: | 40% |
Signatures
Classification
- System is w10x64
sj-updater-app.exe (PID: 3716 cmdline:
"C:\Users\ user\Deskt op\sj-upda ter-app.ex e" MD5: 457DD6E4DC5E7866F2B10B065379F3E3) conhost.exe (PID: 1864 cmdline:
C:\Windows \system32\ conhost.ex e 0xffffff ff -ForceV 1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Code function: | 0_2_00007FF63CC07210 |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_00007FF63CC51620 | |
Source: | Code function: | 0_2_00007FF63CC355E0 | |
Source: | Code function: | 0_2_00007FF63CC45EF0 | |
Source: | Code function: | 0_2_00007FF63CC47EA0 | |
Source: | Code function: | 0_2_00007FF63CC40650 | |
Source: | Code function: | 0_2_00007FF63CC09660 | |
Source: | Code function: | 0_2_00007FF63CC48030 | |
Source: | Code function: | 0_2_00007FF63CC12FC0 | |
Source: | Code function: | 0_2_00007FF63CC557E0 | |
Source: | Code function: | 0_2_00007FF63CC32FA0 | |
Source: | Code function: | 0_2_00007FF63CCF7740 | |
Source: | Code function: | 0_2_00007FF63CC02F50 | |
Source: | Code function: | 0_2_00007FF63CBFCF60 | |
Source: | Code function: | 0_2_00007FF63CC3F760 | |
Source: | Code function: | 0_2_00007FF63CC58F60 | |
Source: | Code function: | 0_2_00007FF63CC27100 | |
Source: | Code function: | 0_2_00007FF63CBEE0C0 | |
Source: | Code function: | 0_2_00007FF63CC0A0C0 | |
Source: | Code function: | 0_2_00007FF63CBF0080 | |
Source: | Code function: | 0_2_00007FF63CC408B0 | |
Source: | Code function: | 0_2_00007FF63CBF2840 | |
Source: | Code function: | 0_2_00007FF63CBEA060 | |
Source: | Code function: | 0_2_00007FF63CC07210 | |
Source: | Code function: | 0_2_00007FF63CC32230 | |
Source: | Code function: | 0_2_00007FF63CC25A20 | |
Source: | Code function: | 0_2_00007FF63CC479A0 | |
Source: | Code function: | 0_2_00007FF63CD06970 | |
Source: | Code function: | 0_2_00007FF63CC2DB10 | |
Source: | Code function: | 0_2_00007FF63CC2D330 | |
Source: | Code function: | 0_2_00007FF63CC40AD0 | |
Source: | Code function: | 0_2_00007FF63CC2B290 | |
Source: | Code function: | 0_2_00007FF63CC29A90 | |
Source: | Code function: | 0_2_00007FF63CBE12B0 | |
Source: | Code function: | 0_2_00007FF63CBF5B80 | |
Source: | Code function: | 0_2_00007FF63CBEFBB0 | |
Source: | Code function: | 0_2_00007FF63CBE6BB0 | |
Source: | Code function: | 0_2_00007FF63CC4E340 | |
Source: | Code function: | 0_2_00007FF63CC01370 | |
Source: | Code function: | 0_2_00007FF63CC47CF0 | |
Source: | Code function: | 0_2_00007FF63CC3E4A0 | |
Source: | Code function: | 0_2_00007FF63CC52440 |
Source: | Code function: |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | Code function: | 0_2_00007FF63CD446DC |
Source: | Code function: | 0_2_00007FF63CC28A90 |
Source: | Code function: | 0_2_00007FF63CC28A90 |
Source: | Mutant created: |
Source: | Static PE information: |
Source: | Key opened: | Jump to behavior |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Process created: | ||
Source: | Process created: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF63CC28A90 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Last function: |
Source: | Code function: | 0_2_00007FF63CC27100 |
Source: | Thread injection, dropped files, key value created, disk infection and DNS query: |
Source: | Code function: | 0_2_00007FF63CD458EC |
Source: | Code function: | 0_2_00007FF63CC27100 |
Source: | Code function: | 0_2_00007FF63CD43C4C |
Source: | Code function: | 0_2_00007FF63CD45DFC |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | Valid Accounts | 2 Command and Scripting Interpreter | 3 Windows Service | 3 Windows Service | 1 Process Injection | OS Credential Dumping | 1 System Time Discovery | Remote Services | 1 Archive Collected Data | 1 Encrypted Channel | Exfiltration Over Other Network Medium | Abuse Accessibility Features |
Credentials | Domains | Default Accounts | 2 Service Execution | 1 DLL Side-Loading | 1 Process Injection | 1 Deobfuscate/Decode Files or Information | LSASS Memory | 1 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | 1 Ingress Tool Transfer | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | Logon Script (Windows) | 1 DLL Side-Loading | 1 DLL Side-Loading | Security Account Manager | 13 System Information Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | Login Hook | 1 Obfuscated Files or Information | NTDS | System Network Configuration Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs | |||
0% | Virustotal | Browse |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse | ||
0% | Virustotal | Browse |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1448097 |
Start date and time: | 2024-05-27 19:40:31 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 4m 16s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 6 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | sj-updater-app.exe |
Detection: | CLEAN |
Classification: | clean2.winEXE@2/0@0/0 |
EGA Information: | Failed |
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): dllhost.exe, WMIADAP.exe, SIHClient.exe, svchost.exe
- Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Execution Graph export aborted for target sj-updater-app.exe, PID 3716 because there are no executed function
- Not all processes where analyzed, report is missing behavior information
File type: | |
Entropy (8bit): | 6.4431538128735575 |
TrID: |
|
File name: | sj-updater-app.exe |
File size: | 2'156'920 bytes |
MD5: | 457dd6e4dc5e7866f2b10b065379f3e3 |
SHA1: | 7a2b3bd51b34f6e8361a41dc428917234edf76d9 |
SHA256: | a3281a97f2bdbeba81f22630ba5dd9543e28debcdda17188357ecdf4c7c7ff8a |
SHA512: | c47b24fdf59f21bddd870b853883b759879082de8ef34e33f596271aeb738a04333bb9e10a3d410ecba9a5d0ea761cc6fbf849f42a6e868d8728a9fbc080fd6b |
SSDEEP: | 49152:vqb2/b89m6CtyrQUeKHyeIDXSjw6iuTkP9XqYRYXDJHL+bkanXCe:xtukdBX5 |
TLSH: | 1AA56B2AA17801F9C1F9D2BCCA079A0BE7713C4A872497DB01D492562F77BE85A7F311 |
File Content Preview: | MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$........nlQ.............w.......w.......................................w.......w..................u.................................. |
Icon Hash: | 3361d8cee6c47117 |
Entrypoint: | 0x140165450 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x140000000 |
Subsystem: | windows cui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x6645EC1D [Thu May 16 11:21:01 2024 UTC] |
TLS Callbacks: | 0x40165044, 0x1, 0x40165a70, 0x1 |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 3480307717bc1f63a8a2166d772abab1 |
Signature Valid: | true |
Signature Issuer: | CN=DigiCert Trusted G4 Code Signing RSA4096 SHA384 2021 CA1, O="DigiCert, Inc.", C=US |
Signature Validation Error: | The operation completed successfully |
Error Number: | 0 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | 9770BF7BD57D482BF98AAFDE48DAA71D |
Thumbprint SHA-1: | 1F1716DE492ABB315EE61EDBE7DC7A8DD9949FCB |
Thumbprint SHA-256: | 0C31F784621C4477A1312EA315023B841670D1D9BE4A52BA9AFE73DB0029ED14 |
Serial: | 036FCEF1A90FDA45B3B90FDAFA68B3A6 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007F30CCBA8EA8h |
dec eax |
add esp, 28h |
jmp 00007F30CCBA8377h |
int3 |
int3 |
dec eax |
mov eax, esp |
dec eax |
mov dword ptr [eax+18h], ebx |
dec eax |
mov dword ptr [eax+20h], esi |
dec eax |
mov dword ptr [eax+10h], edx |
dec eax |
mov dword ptr [eax+08h], ecx |
push edi |
inc ecx |
push esi |
inc ecx |
push edi |
dec eax |
sub esp, 30h |
dec ebp |
mov edi, ecx |
dec ebp |
mov esi, eax |
dec eax |
mov esi, edx |
dec eax |
mov edi, ecx |
xor ebx, ebx |
dec eax |
mov dword ptr [eax-20h], ebx |
mov byte ptr [eax-28h], bl |
dec ecx |
cmp ebx, esi |
je 00007F30CCBA8523h |
dec eax |
mov ecx, edi |
dec ecx |
mov eax, edi |
dec eax |
mov edx, dword ptr [00017FF1h] |
call edx |
dec eax |
add edi, esi |
dec eax |
mov dword ptr [esp+50h], edi |
dec eax |
inc ebx |
dec eax |
mov dword ptr [esp+28h], ebx |
jmp 00007F30CCBA84DCh |
mov byte ptr [esp+20h], 00000001h |
dec eax |
mov ebx, dword ptr [esp+60h] |
dec eax |
mov esi, dword ptr [esp+68h] |
dec eax |
add esp, 30h |
inc ecx |
pop edi |
inc ecx |
pop esi |
pop edi |
ret |
dec eax |
mov eax, esp |
dec esp |
mov dword ptr [eax+20h], ecx |
dec esp |
mov dword ptr [eax+18h], eax |
dec eax |
mov dword ptr [eax+10h], edx |
push ebx |
push esi |
push edi |
inc ecx |
push esi |
dec eax |
sub esp, 38h |
dec ebp |
mov esi, ecx |
dec ecx |
mov ebx, eax |
dec eax |
mov esi, edx |
mov byte ptr [eax-38h], 00000000h |
dec eax |
mov edi, edx |
dec ecx |
imul edi, eax |
dec eax |
add edi, ecx |
dec eax |
mov dword ptr [eax+08h], edi |
dec eax |
mov eax, ebx |
dec eax |
dec ebx |
dec eax |
mov dword ptr [esp+70h], ebx |
dec eax |
test eax, eax |
je 00007F30CCBA851Bh |
Programming Language: |
|
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x1cc190 | 0x58 | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x1cc1e8 | 0x2bc | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x20d000 | 0x47e0 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x1fc000 | 0x10fd4 | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x20c000 | 0x2978 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x212000 | 0x1c14 | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x196260 | 0x54 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x196300 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x196120 | 0x140 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x17c000 | 0x1488 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x17a0ae | 0x17a200 | d6fd822a2b043007c1925e64c54a1947 | False | 0.3910550103305785 | data | 6.266377553091015 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x17c000 | 0x57144 | 0x57200 | 455e724f786a990c2711476aad0f46ea | False | 0.36740607065997133 | data | 5.649743654870318 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x1d4000 | 0x27f28 | 0x23200 | 7365931882848f6761bd954b11edfc37 | False | 0.05800989768683274 | data | 4.774395582119203 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x1fc000 | 0x10fd4 | 0x11000 | d6369e387f5303316fe8925b184e47f1 | False | 0.5015940946691176 | data | 6.185500891038529 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x20d000 | 0x47e0 | 0x4800 | 6b0dfffa6550b5b414375f2d31c24123 | False | 0.22119140625 | data | 3.5607877279033175 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x212000 | 0x1c14 | 0x1e00 | d8541aa71c824377a4d4845a2e976f30 | False | 0.36692708333333335 | data | 5.308603692560612 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
RT_ICON | 0x20d418 | 0x4228 | Device independent bitmap graphic, 64 x 128 x 32, image size 16384 | English | United States | 0.19768540387340577 |
RT_GROUP_ICON | 0x211640 | 0x14 | data | English | United States | 1.1 |
RT_VERSION | 0x20d150 | 0x2c8 | data | English | United States | 0.48174157303370785 |
RT_MANIFEST | 0x211658 | 0x188 | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.5892857142857143 |
DLL | Import |
---|---|
boost_iostreams-vc143-mt-x64-1_83.dll | ?process@gzip_footer@detail@iostreams@boost@@QEAAXD@Z, ?reset@gzip_footer@detail@iostreams@boost@@QEAAXXZ, ?default_compression@zlib@iostreams@boost@@3HB, ?deflated@zlib@iostreams@boost@@3HB, ??1gzip_header@detail@iostreams@boost@@QEAA@XZ, ?reset@gzip_header@detail@iostreams@boost@@QEAAXXZ, ?process@gzip_header@detail@iostreams@boost@@QEAAXD@Z, ??0gzip_header@detail@iostreams@boost@@QEAA@XZ, ?do_init@zlib_base@detail@iostreams@boost@@AEAAXAEBUzlib_params@34@_NP6APEAXPEAXII@ZP6AX22@Z2@Z, ?default_strategy@zlib@iostreams@boost@@3HB, ?okay@zlib@iostreams@boost@@3HB, ?reset@zlib_base@detail@iostreams@boost@@IEAAX_N0@Z, ?stream_end@zlib@iostreams@boost@@3HB, ?xinflate@zlib_base@detail@iostreams@boost@@IEAAHH@Z, ?after@zlib_base@detail@iostreams@boost@@IEAAXAEAPEBDAEAPEAD_N@Z, ?sync_flush@zlib@iostreams@boost@@3HB, ?xdeflate@zlib_base@detail@iostreams@boost@@IEAAHH@Z, ??0gzip_header@detail@iostreams@boost@@QEAA@AEBV0123@@Z, ?best_speed@zlib@iostreams@boost@@3HB, ?check@zlib_error@iostreams@boost@@SAXH@Z, ?before@zlib_base@detail@iostreams@boost@@IEAAXAEAPEBDPEBDAEAPEADPEAD@Z, ??1zlib_base@detail@iostreams@boost@@IEAA@XZ, ??0zlib_base@detail@iostreams@boost@@IEAA@XZ, ?best_compression@zlib@iostreams@boost@@3HB, ?finish@zlib@iostreams@boost@@3HB, ?no_flush@zlib@iostreams@boost@@3HB |
libssl-3-x64.dll | SSL_CTX_set_default_passwd_cb_userdata, SSL_CTX_set_verify, SSL_CTX_get_verify_callback, SSL_CTX_get_cert_store, SSL_CTX_free, SSL_CTX_new, SSL_CTX_set_options, SSL_get_ex_data_X509_STORE_CTX_idx, SSL_get_shutdown, SSL_CTX_ctrl, TLS_client_method, SSL_CTX_set_ex_data, SSL_CTX_get_ex_data, SSL_set_alpn_protos, SSL_get0_alpn_selected, SSL_free, SSL_shutdown, SSL_set_ex_data, SSL_get_ex_data, SSL_set_bio, SSL_get_verify_mode, SSL_set_verify, SSL_new, SSL_accept, SSL_connect, SSL_read, SSL_write, SSL_ctrl, SSL_CTX_get_default_passwd_cb_userdata, SSL_get_verify_callback, SSL_CTX_set_security_level, SSL_get_error |
libcrypto-3-x64.dll | ERR_clear_error, BIO_new_bio_pair, ERR_get_error, BIO_ctrl, BIO_write, BIO_read, X509_STORE_CTX_get_current_cert, X509_STORE_CTX_get0_chain, X509_free, BIO_new_mem_buf, X509_STORE_add_cert, OPENSSL_sk_value, X509_STORE_CTX_get_error_depth, OPENSSL_sk_num, X509_STORE_CTX_get_ex_data, PEM_read_bio_X509, BIO_ctrl_pending, BIO_new, BIO_s_mem, ASN1_STRING_length, ASN1_STRING_get0_data, OBJ_obj2txt, EVP_sha1, X509_digest, X509_cmp_current_time, X509_getm_notBefore, X509_getm_notAfter, X509_NAME_entry_count, X509_NAME_get_entry, X509_NAME_ENTRY_get_object, X509_NAME_ENTRY_get_data, PEM_write_bio_X509, ERR_error_string, X509_check_host, X509_check_ip_asc, X509_up_ref, X509_get_subject_name, EVP_get_digestbyname, i2d_X509_bio, X509_new, BIO_free, ERR_lib_error_string, ERR_reason_error_string, EVP_MD_CTX_new, EVP_MD_CTX_free, EVP_DigestInit_ex, EVP_DigestUpdate, EVP_DigestFinal_ex, d2i_X509 |
spdlog.dll | ?sink_it_@logger@spdlog@@MEAAXAEBUlog_msg@details@2@@Z, ??0log_msg@details@spdlog@@QEAA@Usource_loc@2@V?$basic_string_view@D@v10@fmt@@W4level_enum@level@2@1@Z, ?enabled@backtracer@details@spdlog@@QEBA_NXZ, ?should_log@logger@spdlog@@QEBA_NW4level_enum@level@2@@Z, ?log_it_@logger@spdlog@@IEAAXAEBUlog_msg@details@2@_N1@Z, ?err_handler_@logger@spdlog@@IEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z, ?default_logger_raw@spdlog@@YAPEAVlogger@1@XZ, ?log@logger@spdlog@@QEAAXUsource_loc@2@W4level_enum@level@2@V?$basic_string_view@D@v10@fmt@@@Z, ?from_str@level@spdlog@@YA?AW4level_enum@12@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z, ??1periodic_worker@details@spdlog@@QEAA@XZ, ?flush_all@registry@details@spdlog@@QEAAXXZ, ?instance@registry@details@spdlog@@SAAEAV123@XZ, ??0logger@spdlog@@QEAA@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z, ??1logger@spdlog@@UEAA@XZ, ?sinks@logger@spdlog@@QEAAAEAV?$vector@V?$shared_ptr@Vsink@sinks@spdlog@@@std@@V?$allocator@V?$shared_ptr@Vsink@sinks@spdlog@@@std@@@2@@std@@XZ, ?set_level@spdlog@@YAXW4level_enum@level@1@@Z, ?default_logger@spdlog@@YA?AV?$shared_ptr@Vlogger@spdlog@@@std@@XZ, ?set_default_logger@spdlog@@YAXV?$shared_ptr@Vlogger@spdlog@@@std@@@Z, ?set_level@sink@sinks@spdlog@@QEAAXW4level_enum@level@3@@Z, ??0?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@QEAA@XZ, ??1?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@UEAA@XZ, ??1file_helper@details@spdlog@@QEAA@XZ, ??0?$wincolor_stdout_sink@Uconsole_mutex@details@spdlog@@@sinks@spdlog@@QEAA@W4color_mode@2@@Z, ??0?$stdout_sink@Uconsole_mutex@details@spdlog@@@sinks@spdlog@@QEAA@XZ, ??1?$base_sink@Vmutex@std@@@sinks@spdlog@@UEAA@XZ, ??0?$basic_file_sink@Vmutex@std@@@sinks@spdlog@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_NAEBUfile_event_handlers@2@@Z, ?log@?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@UEAAXAEBUlog_msg@details@3@@Z, ?flush@?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@UEAAXXZ, ?set_pattern@?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z, ?set_formatter@?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@UEAAXV?$unique_ptr@Vformatter@spdlog@@U?$default_delete@Vformatter@spdlog@@@std@@@std@@@Z, ?set_pattern_@?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@MEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z, ?set_formatter_@?$base_sink@Unull_mutex@details@spdlog@@@sinks@spdlog@@MEAAXV?$unique_ptr@Vformatter@spdlog@@U?$default_delete@Vformatter@spdlog@@@std@@@std@@@Z, ?clone@logger@spdlog@@UEAA?AV?$shared_ptr@Vlogger@spdlog@@@std@@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@4@@Z, ?flush_@logger@spdlog@@MEAAXXZ |
fmt.dll | ?is_printable@detail@v10@fmt@@YA_NI@Z, ?throw_format_error@detail@v10@fmt@@YAXPEBD@Z, ??$vformat_to@D@detail@v10@fmt@@YAXAEAV?$buffer@D@012@V?$basic_string_view@D@12@V?$basic_format_args@V?$basic_format_context@Vappender@v10@fmt@@D@v10@fmt@@@12@Vlocale_ref@012@@Z, ?vformat@v10@fmt@@YA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$basic_string_view@D@12@V?$basic_format_args@V?$basic_format_context@Vappender@v10@fmt@@D@v10@fmt@@@12@@Z, ??$get@Vlocale@std@@@locale_ref@detail@v10@fmt@@QEBA?AVlocale@std@@XZ |
brotlienc.dll | BrotliEncoderHasMoreOutput, BrotliEncoderCompressStream, BrotliEncoderDestroyInstance, BrotliEncoderCreateInstance, BrotliEncoderSetParameter |
brotlidec.dll | BrotliDecoderDecompressStream, BrotliDecoderDestroyInstance, BrotliDecoderGetErrorCode, BrotliDecoderCreateInstance |
sentry.dll | sentry_options_set_handler_path, sentry_options_set_database_path, sentry_options_set_environment, sentry_options_set_release, sentry_options_set_dsn, sentry_options_free, sentry_options_new, sentry_value_new_message_event, sentry_set_tag, sentry_init, sentry_close, sentry_capture_event, sentry_options_add_attachment |
KERNEL32.dll | AreFileApisANSI, SetFileInformationByHandle, GetFinalPathNameByHandleW, GetFileAttributesExW, FindNextFileW, FindFirstFileExW, FindFirstFileW, FindClose, CreateFileW, CreateDirectoryW, GetLocaleInfoEx, MoveFileExW, GetFileInformationByHandleEx, ReleaseSRWLockExclusive, ReleaseSRWLockShared, GetDiskFreeSpaceExW, AcquireSRWLockExclusive, GetCurrentThreadId, QueryPerformanceCounter, IsDebuggerPresent, IsProcessorFeaturePresent, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RtlVirtualUnwind, RtlLookupFunctionEntry, RtlCaptureContext, SleepConditionVariableSRW, WakeAllConditionVariable, InitOnceComplete, InitOnceBeginInitialize, CreateProcessW, GetSystemTimeAsFileTime, GetConsoleWindow, MultiByteToWideChar, GetProcAddress, GetModuleHandleW, GetModuleHandleA, GetModuleFileNameW, GetCurrentProcessId, GetEnvironmentVariableW, GetTempPathW, CreateMutexW, ReleaseMutex, GetCurrentProcess, GetProcessHeap, HeapFree, HeapAlloc, Sleep, CreateEventW, SleepEx, ResetEvent, InitializeCriticalSectionAndSpinCount, GetLastError, WideCharToMultiByte, FormatMessageW, FormatMessageA, LocalFree, TerminateThread, QueueUserAPC, WaitForMultipleObjects, WaitForSingleObject, SetEvent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, CloseHandle, InitializeSListHead, AcquireSRWLockShared |
SHELL32.dll | SHGetKnownFolderPath |
ole32.dll | CoInitializeEx, CoInitializeSecurity, CoSetProxyBlanket, CoCreateInstance, CoTaskMemFree, CoUninitialize |
OLEAUT32.dll | SysFreeString, VariantInit, VariantClear, SysAllocString, VariantChangeType |
ADVAPI32.dll | DuplicateTokenEx, RegGetValueW, RegDeleteKeyValueW, RegSetValueExW, RegQueryValueExW, RegQueryInfoKeyW, RegOpenKeyExW, RegEnumValueW, RegEnumKeyExW, RegDeleteKeyW, RegCreateKeyExW, RegCloseKey, CreateProcessAsUserW, StartServiceCtrlDispatcherA, SetServiceStatus, RegisterServiceCtrlHandlerExA, GetTokenInformation, FreeSid, EqualSid, AllocateAndInitializeSid, OpenProcessToken |
MSVCP140.dll | ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ, ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ, ??7ios_base@std@@QEBA_NXZ, ??Bios_base@std@@QEBA_NXZ, ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z, ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z, ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z, ?always_noconv@codecvt_base@std@@QEBA_NXZ, ??1?$basic_iostream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??0?$basic_iostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@H@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z, ?_Random_device@std@@YAIXZ, ?setf@ios_base@std@@QEAAHHH@Z, _Thrd_id, _Thrd_join, ?id@?$collate@D@std@@2V0locale@2@A, ?id@?$ctype@D@std@@2V0locale@2@A, ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ, ?_Incref@facet@locale@std@@UEAAXXZ, ?_Xregex_error@std@@YAXW4error_type@regex_constants@1@@Z, ?_Getcat@?$ctype@D@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ?tolower@?$ctype@D@std@@QEBAPEBDPEADPEBD@Z, ?tolower@?$ctype@D@std@@QEBADD@Z, ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z, ??1facet@locale@std@@MEAA@XZ, ??0facet@locale@std@@IEAA@_K@Z, ?_Getcoll@_Locinfo@std@@QEBA?AU_Collvec@@XZ, ??1_Locinfo@std@@QEAA@XZ, ??0_Locinfo@std@@QEAA@PEBD@Z, _Strxfrm, _Strcoll, _Cnd_do_broadcast_at_thread_exit, _Cnd_timedwait, _Mtx_current_owns, ?_Xinvalid_argument@std@@YAXPEBD@Z, ?_Gnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ, ?id@?$ctype@_W@std@@2V0locale@2@A, ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@XZ, ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QEAAXXZ, ?fill@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBA_WXZ, ?rdbuf@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBAPEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@2@XZ, ?tie@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEBAPEAV?$basic_ostream@_WU?$char_traits@_W@std@@@2@XZ, ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z, ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAA_JPEB_W_J@Z, ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEAAG_W@Z, ?pbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z, ?_Getcat@?$ctype@_W@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ?widen@?$ctype@_W@std@@QEBA_WD@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@I@Z, ?_Xbad_function_call@std@@YAXXZ, ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@N@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_K@Z, ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ, ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ, ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z, ?setp@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD0@Z, ?epptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?setg@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAD00@Z, ?gbump@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXH@Z, ?egptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?pptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?pbase@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?gptr@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, ?eback@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBAPEADXZ, _Cnd_unregister_at_thread_exit, _Cnd_register_at_thread_exit, _Cnd_broadcast, _Cnd_wait, _Cnd_destroy_in_situ, _Cnd_init_in_situ, ?__ExceptionPtrToBool@@YA_NPEBX@Z, _Query_perf_frequency, ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A, ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ, ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ, ?pbackfail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHH@Z, ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ, ?underflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ, ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ, ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z, ?seekoff@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA?AV?$fpos@U_Mbstatet@@@2@_JHH@Z, ?seekpos@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA?AV?$fpos@U_Mbstatet@@@2@V32@H@Z, ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAPEAV12@PEAD_J@Z, ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAHXZ, ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAAXAEBVlocale@2@@Z, ??_D?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ, ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z, ?_Getcat@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ?put@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@QEBA?AV?$ostreambuf_iterator@DU?$char_traits@D@std@@@2@V32@AEAVios_base@2@DPEBUtm@@DD@Z, ?imbue@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z, ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ, ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ, ?_Getcat@?$codecvt@_WDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z, ?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z, ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ, ?classic@locale@std@@SAAEBV12@XZ, ??Bid@locale@std@@QEAA_KXZ, ?c_str@?$_Yarn@D@std@@QEBAPEBDXZ, ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z, ?__ExceptionPtrRethrow@@YAXPEBX@Z, ?__ExceptionPtrCurrentException@@YAXPEAX@Z, ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z, ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z, ?__ExceptionPtrDestroy@@YAXPEAX@Z, ?__ExceptionPtrCreate@@YAXPEAX@Z, ??1_Lockit@std@@QEAA@XZ, ??0_Lockit@std@@QEAA@H@Z, ?_Winerror_map@std@@YAHH@Z, ?_Syserror_map@std@@YAPEBDH@Z, ?_Throw_Cpp_error@std@@YAXH@Z, _Mtx_unlock, _Mtx_lock, ?_Xout_of_range@std@@YAXPEBD@Z, ?cerr@std@@3V?$basic_ostream@DU?$char_traits@D@std@@@1@A, ?_Pnavail@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEBA_JXZ, ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ, ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXPEAPEAD0PEAH001@Z, ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAADD@Z, ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z, ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV01@_J@Z, ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z, ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ, ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z, ?gcount@?$basic_istream@DU?$char_traits@D@std@@@std@@QEBA_JXZ, ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z, ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A, ?eof@ios_base@std@@QEBA_NXZ, ?exceptions@ios_base@std@@QEBAHXZ, ?exceptions@ios_base@std@@QEAAXH@Z, ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ, ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ, ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z, ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z, ?tellp@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ, ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z, ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ, ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z, ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z, ?_ReportUnobservedException@details@Concurrency@@YAXXZ, ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ, ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z, ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ, ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ, ?ReportUnhandledError@_ExceptionHolder@details@Concurrency@@AEAAXXZ, ??0task_continuation_context@Concurrency@@AEAA@XZ, ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z, ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ, ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ, ?_Gninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ, ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@XZ, ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAXXZ, ?fill@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADXZ, ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@XZ, ?tie@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBAPEAV?$basic_ostream@DU?$char_traits@D@std@@@2@XZ, ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z, ?sputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEBD_J@Z, ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHD@Z, ?width@ios_base@std@@QEAA_J_J@Z, _Query_perf_counter, _Xtime_get_ticks, ?_Xlength_error@std@@YAXPEBD@Z, ?_Xbad_alloc@std@@YAXXZ, ?uncaught_exceptions@std@@YAHXZ, ?width@ios_base@std@@QEBA_JXZ, ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ, ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ, ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ, ?pubimbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA?AVlocale@2@AEBV32@@Z, ?pubsync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ, ?sgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAA_JPEAD_J@Z, ?rdbuf@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAPEAV?$basic_streambuf@DU?$char_traits@D@std@@@2@PEAV32@@Z, ?fail@ios_base@std@@QEBA_NXZ, ?seekp@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@V?$fpos@U_Mbstatet@@@2@@Z, ?swap@?$basic_iostream@DU?$char_traits@D@std@@@std@@IEAAXAEAV12@@Z, _Thrd_sleep, _Mtx_init_in_situ, _Mtx_destroy_in_situ, ?getloc@ios_base@std@@QEBA?AVlocale@2@XZ, ?good@ios_base@std@@QEBA_NXZ, ?wclog@std@@3V?$basic_ostream@_WU?$char_traits@_W@std@@@1@A, ?id@?$time_put@DV?$ostreambuf_iterator@DU?$char_traits@D@std@@@std@@@std@@2V0locale@2@A, ?flags@ios_base@std@@QEBAHXZ |
MSVCP140_ATOMIC_WAIT.dll | __std_atomic_wait_get_remaining_timeout, __std_atomic_wait_get_deadline, __std_atomic_notify_one_direct, __std_atomic_wait_direct |
WS2_32.dll | getservbyname, WSACleanup, __WSAFDIsSet, accept, bind, closesocket, connect, ioctlsocket, getsockname, htonl, listen, select, setsockopt, WSAGetLastError, WSARecv, WSASend, WSASocketW, htons, gethostbyname, WSASetLastError, WSAStringToAddressW, getsockopt, getpeername, ntohl, shutdown, WSAAddressToStringW, WSAStartup |
WINTRUST.dll | WinVerifyTrust |
WTSAPI32.dll | WTSFreeMemory, WTSEnumerateSessionsW, WTSQueryUserToken |
POWRPROF.dll | GetPwrCapabilities |
VERSION.dll | GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW |
RstrtMgr.DLL | RmRegisterResources, RmGetList, RmShutdown, RmStartSession, RmEndSession |
CRYPT32.dll | CertOpenStore, CertEnumCertificatesInStore, CertFindCertificateInStore, CertFreeCertificateContext, CertAddCertificateContextToStore, CertDeleteCertificateFromStore, CertVerifyRevocation, CryptQueryObject, CertCloseStore |
USERENV.dll | CreateEnvironmentBlock, DestroyEnvironmentBlock |
VCRUNTIME140.dll | memchr, memset, strchr, memcpy, strstr, __std_type_info_compare, _CxxThrowException, __std_exception_destroy, __std_exception_copy, __std_terminate, _purecall, memcmp, __C_specific_handler_noexcept, __C_specific_handler, __RTDynamicCast, __current_exception, __current_exception_context, memmove |
VCRUNTIME140_1.dll | __CxxFrameHandler4 |
api-ms-win-crt-runtime-l1-1-0.dll | _get_initial_narrow_environment, _initterm, _set_app_type, _seh_filter_exe, _initterm_e, terminate, exit, _exit, __p___argc, __p___argv, _c_exit, _beginthreadex, abort, strerror, _errno, signal, _invalid_parameter_noinfo_noreturn, _crt_atexit, _cexit, _initialize_onexit_table, _register_onexit_function, _register_thread_local_exe_atexit_callback, _initialize_narrow_environment, _configure_narrow_argv |
api-ms-win-crt-stdio-l1-1-0.dll | fseek, ftell, __stdio_common_vfprintf, _close, _lseek, _read, _setmode, _write, _sopen_dispatch, _fileno, fgets, ferror, __acrt_iob_func, clearerr, fopen, __p__commode, __stdio_common_vsprintf, _get_stream_buffer_pointers, fclose, fflush, fgetc, fgetpos, fputc, fread, fsetpos, _fseeki64, _set_fmode, fwrite, setvbuf, ungetc, feof |
api-ms-win-crt-string-l1-1-0.dll | strcpy_s, strncpy, strcmp, isspace, isdigit, tolower, strnlen |
api-ms-win-crt-heap-l1-1-0.dll | realloc, free, malloc, _set_new_mode, _callnewh |
api-ms-win-crt-convert-l1-1-0.dll | strtol, strtoll, strtod, atoi, strtoull |
api-ms-win-crt-math-l1-1-0.dll | ceil, floor, _dclass, _dsign, ceilf, __setusermatherr |
api-ms-win-crt-time-l1-1-0.dll | _get_dstbias, _get_timezone, _time64, strftime, _gmtime64, _localtime64_s, _localtime64, asctime, _tzset |
api-ms-win-crt-locale-l1-1-0.dll | ___lc_codepage_func, _configthreadlocale, localeconv |
api-ms-win-crt-filesystem-l1-1-0.dll | _lock_file, _unlock_file |
Name | Ordinal | Address |
---|---|---|
OPENSSL_Applink | 1 | 0x140147c90 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Timestamp | Source Port | Dest Port | Source IP | Dest IP |
---|---|---|---|---|
May 27, 2024 19:41:38.767080069 CEST | 53 | 51883 | 1.1.1.1 | 192.168.2.5 |
Click to jump to process
Click to jump to process
Click to jump to process
Target ID: | 0 |
Start time: | 13:41:15 |
Start date: | 27/05/2024 |
Path: | C:\Users\user\Desktop\sj-updater-app.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff63cbe0000 |
File size: | 2'156'920 bytes |
MD5 hash: | 457DD6E4DC5E7866F2B10B065379F3E3 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Target ID: | 1 |
Start time: | 13:41:16 |
Start date: | 27/05/2024 |
Path: | C:\Windows\System32\conhost.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff6d64d0000 |
File size: | 862'208 bytes |
MD5 hash: | 0D698AF330FD17BEE3BF90011D49251D |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | high |
Has exited: | false |
Function 00007FF63CC3E4A0 Relevance: 56.7, APIs: 30, Strings: 2, Instructions: 682COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF0080 Relevance: 56.7, APIs: 15, Strings: 17, Instructions: 664COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC4E340 Relevance: 54.6, APIs: 24, Strings: 7, Instructions: 308COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC27100 Relevance: 47.5, APIs: 24, Strings: 3, Instructions: 265memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC0A0C0 Relevance: 35.6, APIs: 5, Strings: 15, Instructions: 616COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC25A20 Relevance: 33.8, APIs: 16, Strings: 3, Instructions: 500COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC01370 Relevance: 32.0, APIs: 1, Strings: 17, Instructions: 514COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2DB10 Relevance: 28.5, APIs: 9, Strings: 7, Instructions: 452COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC29A90 Relevance: 28.4, APIs: 9, Strings: 7, Instructions: 385COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFCF60 Relevance: 28.3, APIs: 11, Strings: 5, Instructions: 307COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC3F760 Relevance: 28.3, APIs: 8, Strings: 8, Instructions: 279COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC557E0 Relevance: 26.7, APIs: 14, Strings: 1, Instructions: 466COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBEA060 Relevance: 26.5, APIs: 2, Strings: 13, Instructions: 252COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC45EF0 Relevance: 24.8, APIs: 6, Strings: 8, Instructions: 288COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC32FA0 Relevance: 24.8, APIs: 6, Strings: 8, Instructions: 273COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF7740 Relevance: 24.7, APIs: 10, Strings: 4, Instructions: 206COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC32230 Relevance: 23.1, APIs: 2, Strings: 11, Instructions: 325COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2D330 Relevance: 19.9, APIs: 5, Strings: 8, Instructions: 364COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC12FC0 Relevance: 19.6, APIs: 8, Strings: 3, Instructions: 353COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBEE0C0 Relevance: 17.8, APIs: 7, Strings: 3, Instructions: 259COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE6BB0 Relevance: 16.1, APIs: 7, Strings: 2, Instructions: 374COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC408B0 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 134COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC40AD0 Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 115COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC28A90 Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 65COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC40650 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 150COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC09660 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 211COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CD45DFC Relevance: 6.0, APIs: 4, Instructions: 39timethreadCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC07210 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 197networkCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CD43C4C Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 41windowCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CD06970 Relevance: .4, Instructions: 414COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC48030 Relevance: .1, Instructions: 142COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC47CF0 Relevance: .1, Instructions: 120COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC47EA0 Relevance: .1, Instructions: 112COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC136F0 Relevance: 51.1, APIs: 18, Strings: 11, Instructions: 390COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE2000 Relevance: 49.8, APIs: 9, Strings: 24, Instructions: 345COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF5210 Relevance: 35.2, APIs: 18, Strings: 2, Instructions: 203COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC19FF0 Relevance: 33.6, APIs: 15, Strings: 4, Instructions: 378COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF80D0 Relevance: 33.5, APIs: 11, Strings: 8, Instructions: 255COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF8650 Relevance: 33.5, APIs: 18, Strings: 1, Instructions: 223COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC34030 Relevance: 31.8, APIs: 10, Strings: 8, Instructions: 325COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF3060 Relevance: 30.2, APIs: 13, Strings: 4, Instructions: 429COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC02200 Relevance: 30.1, APIs: 5, Strings: 12, Instructions: 355COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC09930 Relevance: 30.0, APIs: 10, Strings: 7, Instructions: 205synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFA070 Relevance: 26.6, APIs: 14, Strings: 1, Instructions: 308COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC0BF10 Relevance: 24.9, APIs: 10, Strings: 4, Instructions: 363COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC98D90 Relevance: 22.9, APIs: 11, Strings: 2, Instructions: 193COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBECDB0 Relevance: 22.9, APIs: 7, Strings: 6, Instructions: 135stringCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFB630 Relevance: 19.4, APIs: 10, Strings: 1, Instructions: 121COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC3FCD0 Relevance: 17.8, APIs: 9, Strings: 1, Instructions: 300COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC25530 Relevance: 17.7, APIs: 5, Strings: 5, Instructions: 233COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFE760 Relevance: 17.6, APIs: 5, Strings: 5, Instructions: 139COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC56310 Relevance: 16.0, APIs: 6, Strings: 3, Instructions: 237COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF3850 Relevance: 16.0, APIs: 7, Strings: 2, Instructions: 236COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF8370 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 167COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF74D0 Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 162COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE80B0 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 159COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF7D30 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 158COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF6CB0 Relevance: 15.9, APIs: 7, Strings: 2, Instructions: 155COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC0AD00 Relevance: 15.9, APIs: 2, Strings: 7, Instructions: 143COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC33440 Relevance: 15.9, APIs: 2, Strings: 7, Instructions: 142COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC445D0 Relevance: 15.8, APIs: 5, Strings: 4, Instructions: 98libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC27AE0 Relevance: 15.8, APIs: 2, Strings: 7, Instructions: 98COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC24B90 Relevance: 15.8, APIs: 1, Strings: 8, Instructions: 71COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCDF250 Relevance: 14.2, APIs: 4, Strings: 4, Instructions: 181COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF79D0 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 173COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF7660 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 172COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE83C0 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 166COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC01E00 Relevance: 14.2, APIs: 4, Strings: 4, Instructions: 164COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE7A80 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 161COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE7DA0 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 160COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC263D0 Relevance: 14.2, APIs: 7, Strings: 1, Instructions: 155COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC32D50 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 141COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC05350 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 128COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2A1B0 Relevance: 12.6, APIs: 5, Strings: 2, Instructions: 307COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC157F0 Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 172COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CD13C20 Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 170COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC1EBE0 Relevance: 12.4, APIs: 1, Strings: 6, Instructions: 145COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF8BF0 Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 134COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC004E0 Relevance: 12.4, APIs: 1, Strings: 6, Instructions: 120COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE5790 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 54COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC00190 Relevance: 12.3, APIs: 1, Strings: 6, Instructions: 53COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2C310 Relevance: 10.9, APIs: 1, Strings: 5, Instructions: 384COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE7480 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 203COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF4F10 Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 199COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBED070 Relevance: 10.7, APIs: 2, Strings: 5, Instructions: 161COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFC300 Relevance: 10.7, APIs: 3, Strings: 3, Instructions: 153COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC53F80 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 139COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE3820 Relevance: 10.6, APIs: 5, Strings: 1, Instructions: 129COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFEAF0 Relevance: 10.6, APIs: 1, Strings: 5, Instructions: 109COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC04500 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 109COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE58A0 Relevance: 10.6, APIs: 1, Strings: 5, Instructions: 107COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC46BF0 Relevance: 10.6, APIs: 1, Strings: 5, Instructions: 103COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC26D50 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 94COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC44AD0 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 185COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC24E90 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 169COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC00EF0 Relevance: 8.9, APIs: 3, Strings: 2, Instructions: 168COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF6D40 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 155COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFB930 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 142COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBEDEC0 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 136COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC111C0 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 136COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBEDCC0 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 136COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBEE490 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 136COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CD0E9E0 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 131COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC46520 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 126COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC27C70 Relevance: 8.9, APIs: 1, Strings: 4, Instructions: 120COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC46180 Relevance: 8.9, APIs: 1, Strings: 4, Instructions: 104COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC258D0 Relevance: 8.8, APIs: 1, Strings: 4, Instructions: 76COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFC930 Relevance: 8.8, APIs: 1, Strings: 4, Instructions: 67COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2EC50 Relevance: 7.7, APIs: 1, Strings: 4, Instructions: 219COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBEF540 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 131COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC11070 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 99COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF1885 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 94COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC42270 Relevance: 7.6, APIs: 2, Strings: 3, Instructions: 51COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC058D0 Relevance: 7.5, APIs: 5, Instructions: 43synchronizationthreadinjectionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC27090 Relevance: 7.5, APIs: 2, Strings: 3, Instructions: 23memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2A6B0 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 214COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF7190 Relevance: 7.2, APIs: 1, Strings: 3, Instructions: 176COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2BD40 Relevance: 7.2, APIs: 3, Strings: 1, Instructions: 169COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBE9D7A Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 132COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC01A30 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 131COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF5EE0 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 98COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF5B50 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 98COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC50AB0 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 84COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC42340 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 82COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC2EB40 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 78COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC294B0 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 78synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC059D0 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 66COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC40550 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 65COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC05AD0 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 65COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF6416 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 18COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF6430 Relevance: 7.0, APIs: 2, Strings: 2, Instructions: 15COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFBB50 Relevance: 6.2, APIs: 2, Strings: 2, Instructions: 186COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CD18CF0 Relevance: 5.5, APIs: 1, Strings: 2, Instructions: 208COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC0CDA0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 171COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF2DD0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 165COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBED2F0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 128COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC541A0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 118COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC191A0 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 111COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF8C50 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 108COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBFA560 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 77COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CCF6140 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 51COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC44420 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 43COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CBF9069 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 38COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC478F0 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 36COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF63CC09FC0 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 26COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|