Windows
Analysis Report
OneDriveUpdater.exe
Overview
General Information
Detection
Score: | 0 |
Range: | 0 - 100 |
Whitelisted: | true |
Confidence: | 100% |
Signatures
Classification
- System is w10x64
- OneDriveUpdater.exe (PID: 7252 cmdline:
"C:\Users\ user\Deskt op\OneDriv eUpdater.e xe" MD5: 792E95B64B9CF45AC8BC10D4D0F077C2)
- cleanup
Click to jump to signature section
There are no malicious signatures, click here to show all signatures.
Source: | Code function: | 0_2_00007FF7C4110E98 | |
Source: | Code function: | 0_2_00007FF7C4120034 | |
Source: | Code function: | 0_2_00007FF7C4113C64 | |
Source: | Code function: | 0_2_00007FF7C40B8874 | |
Source: | Code function: | 0_2_00007FF7C42D0F3C | |
Source: | Code function: | 0_2_00007FF7C42D0C78 | |
Source: | Code function: | 0_2_00007FF7C42D0CD4 | |
Source: | Code function: | 0_2_00007FF7C42D11CC | |
Source: | Code function: | 0_2_00007FF7C42D1338 | |
Source: | Code function: | 0_2_00007FF7C42D14A4 | |
Source: | Code function: | 0_2_00007FF7C4092050 | |
Source: | Code function: | 0_2_00007FF7C40920B4 | |
Source: | Code function: | 0_2_00007FF7C40921A4 | |
Source: | Code function: | 0_2_00007FF7C40921F0 | |
Source: | Code function: | 0_2_00007FF7C4092220 | |
Source: | Code function: | 0_2_00007FF7C409224C |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Code function: | 0_2_00007FF7C4030EC4 | |
Source: | Code function: | 0_2_00007FF7C406521C | |
Source: | Code function: | 0_2_00007FF7C403125C | |
Source: | Code function: | 0_2_00007FF7C407ACC0 | |
Source: | Code function: | 0_2_00007FF7C40A91B4 | |
Source: | Code function: | 0_2_00007FF7C410DFF8 | |
Source: | Code function: | 0_2_00007FF7C4122020 | |
Source: | Code function: | 0_2_00007FF7C4122080 | |
Source: | Code function: | 0_2_00007FF7C4051A80 | |
Source: | Code function: | 0_2_00007FF7C414E934 | |
Source: | Code function: | 0_2_00007FF7C412F9D0 |
Source: | Code function: | 0_2_00007FF7C4122A30 |
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: | ||
Source: | String found in binary or memory: |
Source: | Code function: | 0_2_00007FF7C4120034 |
Source: | Code function: | 0_2_00007FF7C407B214 |
Source: | Code function: | 0_2_00007FF7C4121F10 |
Source: | Code function: | 0_2_00007FF7C4121CA0 |
Source: | Code function: | 0_2_00007FF7C4014748 | |
Source: | Code function: | 0_2_00007FF7C41107BC | |
Source: | Code function: | 0_2_00007FF7C40642AC | |
Source: | Code function: | 0_2_00007FF7C414C3FC | |
Source: | Code function: | 0_2_00007FF7C4010490 | |
Source: | Code function: | 0_2_00007FF7C40E04A4 | |
Source: | Code function: | 0_2_00007FF7C401D018 | |
Source: | Code function: | 0_2_00007FF7C42CD084 | |
Source: | Code function: | 0_2_00007FF7C40E091C | |
Source: | Code function: | 0_2_00007FF7C4111748 | |
Source: | Code function: | 0_2_00007FF7C41317B8 | |
Source: | Code function: | 0_2_00007FF7C40A97C0 | |
Source: | Code function: | 0_2_00007FF7C406521C | |
Source: | Code function: | 0_2_00007FF7C4165224 | |
Source: | Code function: | 0_2_00007FF7C4025280 | |
Source: | Code function: | 0_2_00007FF7C4061D0C | |
Source: | Code function: | 0_2_00007FF7C412A8E0 | |
Source: | Code function: | 0_2_00007FF7C41129C0 | |
Source: | Code function: | 0_2_00007FF7C4026C30 | |
Source: | Code function: | 0_2_00007FF7C4103E90 | |
Source: | Code function: | 0_2_00007FF7C411BE6C | |
Source: | Code function: | 0_2_00007FF7C4120034 | |
Source: | Code function: | 0_2_00007FF7C416C520 | |
Source: | Code function: | 0_2_00007FF7C4158570 | |
Source: | Code function: | 0_2_00007FF7C42B4600 | |
Source: | Code function: | 0_2_00007FF7C40F45F8 | |
Source: | Code function: | 0_2_00007FF7C4094620 | |
Source: | Code function: | 0_2_00007FF7C4048690 | |
Source: | Code function: | 0_2_00007FF7C40C4698 | |
Source: | Code function: | 0_2_00007FF7C4114714 | |
Source: | Code function: | 0_2_00007FF7C41AC7A0 | |
Source: | Code function: | 0_2_00007FF7C413C7E0 | |
Source: | Code function: | 0_2_00007FF7C42B8850 | |
Source: | Code function: | 0_2_00007FF7C40B8874 | |
Source: | Code function: | 0_2_00007FF7C415C8E0 | |
Source: | Code function: | 0_2_00007FF7C4190154 | |
Source: | Code function: | 0_2_00007FF7C42B8130 | |
Source: | Code function: | 0_2_00007FF7C4174120 | |
Source: | Code function: | 0_2_00007FF7C404C1AC | |
Source: | Code function: | 0_2_00007FF7C41241D0 | |
Source: | Code function: | 0_2_00007FF7C42B81B0 | |
Source: | Code function: | 0_2_00007FF7C40C41FC | |
Source: | Code function: | 0_2_00007FF7C40C8310 | |
Source: | Code function: | 0_2_00007FF7C4020390 | |
Source: | Code function: | 0_2_00007FF7C40BC414 | |
Source: | Code function: | 0_2_00007FF7C40C0420 | |
Source: | Code function: | 0_2_00007FF7C411C430 | |
Source: | Code function: | 0_2_00007FF7C40F045C | |
Source: | Code function: | 0_2_00007FF7C407C4D0 | |
Source: | Code function: | 0_2_00007FF7C40B0DD0 | |
Source: | Code function: | 0_2_00007FF7C4084DD8 | |
Source: | Code function: | 0_2_00007FF7C404CE48 | |
Source: | Code function: | 0_2_00007FF7C411CE84 | |
Source: | Code function: | 0_2_00007FF7C4168E80 | |
Source: | Code function: | 0_2_00007FF7C40C0E5C | |
Source: | Code function: | 0_2_00007FF7C42D0F3C | |
Source: | Code function: | 0_2_00007FF7C413CF90 | |
Source: | Code function: | 0_2_00007FF7C4084F78 | |
Source: | Code function: | 0_2_00007FF7C4118F70 | |
Source: | Code function: | 0_2_00007FF7C40A0FE0 | |
Source: | Code function: | 0_2_00007FF7C41809F0 | |
Source: | Code function: | 0_2_00007FF7C4090A24 | |
Source: | Code function: | 0_2_00007FF7C4168A58 | |
Source: | Code function: | 0_2_00007FF7C40B8AE0 | |
Source: | Code function: | 0_2_00007FF7C4154ADC | |
Source: | Code function: | 0_2_00007FF7C4004B60 | |
Source: | Code function: | 0_2_00007FF7C40C8B60 | |
Source: | Code function: | 0_2_00007FF7C4098BDC | |
Source: | Code function: | 0_2_00007FF7C416CC70 | |
Source: | Code function: | 0_2_00007FF7C412CCC8 | |
Source: | Code function: | 0_2_00007FF7C42BCCE0 | |
Source: | Code function: | 0_2_00007FF7C4199554 | |
Source: | Code function: | 0_2_00007FF7C4031560 | |
Source: | Code function: | 0_2_00007FF7C40E1558 | |
Source: | Code function: | 0_2_00007FF7C415D560 | |
Source: | Code function: | 0_2_00007FF7C41410B0 | |
Source: | Code function: | 0_2_00007FF7C4055670 | |
Source: | Code function: | 0_2_00007FF7C419D710 | |
Source: | Code function: | 0_2_00007FF7C42C5790 | |
Source: | Code function: | 0_2_00007FF7C41497A4 | |
Source: | Code function: | 0_2_00007FF7C40D9810 | |
Source: | Code function: | 0_2_00007FF7C405982A | |
Source: | Code function: | 0_2_00007FF7C40D9860 | |
Source: | Code function: | 0_2_00007FF7C4129860 | |
Source: | Code function: | 0_2_00007FF7C42C58B0 | |
Source: | Code function: | 0_2_00007FF7C40A1904 | |
Source: | Code function: | 0_2_00007FF7C405911C | |
Source: | Code function: | 0_2_00007FF7C419912C | |
Source: | Code function: | 0_2_00007FF7C404D1CC | |
Source: | Code function: | 0_2_00007FF7C41AD280 | |
Source: | Code function: | 0_2_00007FF7C41612C0 | |
Source: | Code function: | 0_2_00007FF7C42C12B8 | |
Source: | Code function: | 0_2_00007FF7C411CE84 | |
Source: | Code function: | 0_2_00007FF7C4179448 | |
Source: | Code function: | 0_2_00007FF7C41E1DFC | |
Source: | Code function: | 0_2_00007FF7C4139E04 | |
Source: | Code function: | 0_2_00007FF7C4055DE0 | |
Source: | Code function: | 0_2_00007FF7C4161F40 | |
Source: | Code function: | 0_2_00007FF7C4141F1C | |
Source: | Code function: | 0_2_00007FF7C4021F44 | |
Source: | Code function: | 0_2_00007FF7C4159FAC | |
Source: | Code function: | 0_2_00007FF7C419997C | |
Source: | Code function: | 0_2_00007FF7C41410B0 | |
Source: | Code function: | 0_2_00007FF7C4005A00 | |
Source: | Code function: | 0_2_00007FF7C40BDA30 | |
Source: | Code function: | 0_2_00007FF7C4051A80 | |
Source: | Code function: | 0_2_00007FF7C40BDAA0 | |
Source: | Code function: | 0_2_00007FF7C40B1AA0 | |
Source: | Code function: | 0_2_00007FF7C4031B60 | |
Source: | Code function: | 0_2_00007FF7C4099CD4 | |
Source: | Code function: | 0_2_00007FF7C4111CF0 | |
Source: | Code function: | 0_2_00007FF7C415252C | |
Source: | Code function: | 0_2_00007FF7C415E560 | |
Source: | Code function: | 0_2_00007FF7C40B2660 | |
Source: | Code function: | 0_2_00007FF7C40DA65C | |
Source: | Code function: | 0_2_00007FF7C4096720 | |
Source: | Code function: | 0_2_00007FF7C402A780 | |
Source: | Code function: | 0_2_00007FF7C4166830 | |
Source: | Code function: | 0_2_00007FF7C414A830 | |
Source: | Code function: | 0_2_00007FF7C41A285C | |
Source: | Code function: | 0_2_00007FF7C418A144 | |
Source: | Code function: | 0_2_00007FF7C41EA11C | |
Source: | Code function: | 0_2_00007FF7C40B6140 | |
Source: | Code function: | 0_2_00007FF7C41EA21C | |
Source: | Code function: | 0_2_00007FF7C41BA2DC | |
Source: | Code function: | 0_2_00007FF7C4016354 | |
Source: | Code function: | 0_2_00007FF7C405E35C | |
Source: | Code function: | 0_2_00007FF7C411E410 | |
Source: | Code function: | 0_2_00007FF7C415A3DC | |
Source: | Code function: | 0_2_00007FF7C40C6480 | |
Source: | Code function: | 0_2_00007FF7C406ED48 | |
Source: | Code function: | 0_2_00007FF7C404ADB4 | |
Source: | Code function: | 0_2_00007FF7C4016E90 | |
Source: | Code function: | 0_2_00007FF7C405EF21 | |
Source: | Code function: | 0_2_00007FF7C40AEF60 | |
Source: | Code function: | 0_2_00007FF7C405EFAB | |
Source: | Code function: | 0_2_00007FF7C404AF9C | |
Source: | Code function: | 0_2_00007FF7C4156FD0 | |
Source: | Code function: | 0_2_00007FF7C406F050 | |
Source: | Code function: | 0_2_00007FF7C416F06C | |
Source: | Code function: | 0_2_00007FF7C415B0C4 | |
Source: | Code function: | 0_2_00007FF7C42C3108 | |
Source: | Code function: | 0_2_00007FF7C40E3110 | |
Source: | Code function: | 0_2_00007FF7C40B6958 | |
Source: | Code function: | 0_2_00007FF7C405A9E8 | |
Source: | Code function: | 0_2_00007FF7C40DA65C | |
Source: | Code function: | 0_2_00007FF7C404A9E0 | |
Source: | Code function: | 0_2_00007FF7C405EA30 | |
Source: | Code function: | 0_2_00007FF7C4156A80 | |
Source: | Code function: | 0_2_00007FF7C4006A80 | |
Source: | Code function: | 0_2_00007FF7C4072B3C | |
Source: | Code function: | 0_2_00007FF7C404ABC8 | |
Source: | Code function: | 0_2_00007FF7C403EC48 | |
Source: | Code function: | 0_2_00007FF7C405B538 | |
Source: | Code function: | 0_2_00007FF7C410F56C | |
Source: | Code function: | 0_2_00007FF7C42C3600 | |
Source: | Code function: | 0_2_00007FF7C4137610 | |
Source: | Code function: | 0_2_00007FF7C41135EC | |
Source: | Code function: | 0_2_00007FF7C40476CC | |
Source: | Code function: | 0_2_00007FF7C40DB6DC | |
Source: | Code function: | 0_2_00007FF7C4133734 | |
Source: | Code function: | 0_2_00007FF7C406F7AC | |
Source: | Code function: | 0_2_00007FF7C41A77FC | |
Source: | Code function: | 0_2_00007FF7C416B7F0 | |
Source: | Code function: | 0_2_00007FF7C40AF824 | |
Source: | Code function: | 0_2_00007FF7C4167850 | |
Source: | Code function: | 0_2_00007FF7C42B78D0 | |
Source: | Code function: | 0_2_00007FF7C414B8C8 | |
Source: | Code function: | 0_2_00007FF7C404B188 | |
Source: | Code function: | 0_2_00007FF7C40971C0 | |
Source: | Code function: | 0_2_00007FF7C40BB1C4 | |
Source: | Code function: | 0_2_00007FF7C401F1E8 | |
Source: | Code function: | 0_2_00007FF7C40FB254 | |
Source: | Code function: | 0_2_00007FF7C405B2BC | |
Source: | Code function: | 0_2_00007FF7C411B2F4 | |
Source: | Code function: | 0_2_00007FF7C404B370 | |
Source: | Code function: | 0_2_00007FF7C4117400 | |
Source: | Code function: | 0_2_00007FF7C42BB474 | |
Source: | Code function: | 0_2_00007FF7C40A7D2D | |
Source: | Code function: | 0_2_00007FF7C418FD2C | |
Source: | Code function: | 0_2_00007FF7C41E3DD0 | |
Source: | Code function: | 0_2_00007FF7C4117E78 | |
Source: | Code function: | 0_2_00007FF7C4133EC0 | |
Source: | Code function: | 0_2_00007FF7C40FBEF4 | |
Source: | Code function: | 0_2_00007FF7C414FF28 | |
Source: | Code function: | 0_2_00007FF7C415BF88 | |
Source: | Code function: | 0_2_00007FF7C4057930 | |
Source: | Code function: | 0_2_00007FF7C419F920 | |
Source: | Code function: | 0_2_00007FF7C41539C4 | |
Source: | Code function: | 0_2_00007FF7C408F9C8 | |
Source: | Code function: | 0_2_00007FF7C42CF9A4 | |
Source: | Code function: | 0_2_00007FF7C4197A68 |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Classification label: |
Source: | Code function: | 0_2_00007FF7C4121670 | |
Source: | Code function: | 0_2_00007FF7C4117230 | |
Source: | Code function: | 0_2_00007FF7C40C74A0 |
Source: | Code function: | 0_2_00007FF7C41221B0 |
Source: | Code function: | 0_2_00007FF7C4121DA0 |
Source: | Code function: | 0_2_00007FF7C4139C30 |
Source: | Code function: | 0_2_00007FF7C4105810 |
Source: | Code function: | 0_2_00007FF7C4121910 |
Source: | File created: | Jump to behavior |
Source: | Mutant created: |
Source: | File created: | Jump to behavior |
Source: | Static PE information: |
Source: | File read: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: | ||
Source: | Binary or memory string: |
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior | ||
Source: | Section loaded: | Jump to behavior |
Source: | Key value queried: | Jump to behavior |
Source: | File written: | Jump to behavior |
Source: | Key opened: | Jump to behavior |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static file information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Static PE information: |
Source: | Binary string: | ||
Source: | Binary string: |
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF7C41241D0 |
Source: | Static PE information: | ||
Source: | Static PE information: |
Source: | Code function: | 0_2_00007FF7C412E483 |
Source: | Code function: | 0_2_00007FF7C414F332 |
Source: | Process information set: | Jump to behavior |
Source: | Code function: | 0_2_00007FF7C4030EC4 | |
Source: | Code function: | 0_2_00007FF7C406521C | |
Source: | Code function: | 0_2_00007FF7C403125C | |
Source: | Code function: | 0_2_00007FF7C407ACC0 | |
Source: | Code function: | 0_2_00007FF7C40A91B4 | |
Source: | Code function: | 0_2_00007FF7C410DFF8 | |
Source: | Code function: | 0_2_00007FF7C4122020 | |
Source: | Code function: | 0_2_00007FF7C4122080 | |
Source: | Code function: | 0_2_00007FF7C4051A80 | |
Source: | Code function: | 0_2_00007FF7C414E934 | |
Source: | Code function: | 0_2_00007FF7C412F9D0 |
Source: | Process information queried: | Jump to behavior |
Source: | Code function: | 0_2_00007FF7C4038BBC |
Source: | Code function: | 0_2_00007FF7C41241D0 |
Source: | Code function: | 0_2_00007FF7C419580C |
Source: | Code function: | 0_2_00007FF7C4038DA0 | |
Source: | Code function: | 0_2_00007FF7C4038FC4 | |
Source: | Code function: | 0_2_00007FF7C4038BBC | |
Source: | Code function: | 0_2_00007FF7C40465BC |
Source: | Code function: | 0_2_00007FF7C41216B0 |
Source: | Code function: | 0_2_00007FF7C4063FF0 |
Source: | Code function: | 0_2_00007FF7C414F1B8 | |
Source: | Code function: | 0_2_00007FF7C40585E0 | |
Source: | Code function: | 0_2_00007FF7C4058738 | |
Source: | Code function: | 0_2_00007FF7C40587E8 | |
Source: | Code function: | 0_2_00007FF7C4058914 | |
Source: | Code function: | 0_2_00007FF7C4058228 | |
Source: | Code function: | 0_2_00007FF7C40582F8 | |
Source: | Code function: | 0_2_00007FF7C4058390 | |
Source: | Code function: | 0_2_00007FF7C40533C4 | |
Source: | Code function: | 0_2_00007FF7C4057ED8 | |
Source: | Code function: | 0_2_00007FF7C4053960 |
Source: | Code function: | 0_2_00007FF7C40648E8 |
Source: | Code function: | 0_2_00007FF7C4120880 |
Source: | Code function: | 0_2_00007FF7C41930C8 |
Source: | Code function: | 0_2_00007FF7C411B8FC |
Source: | Key value queried: | Jump to behavior |
Source: | Code function: | 0_2_00007FF7C410D754 | |
Source: | Code function: | 0_2_00007FF7C4082CD0 | |
Source: | Code function: | 0_2_00007FF7C41235C0 | |
Source: | Code function: | 0_2_00007FF7C41235D0 | |
Source: | Code function: | 0_2_00007FF7C41235B0 | |
Source: | Code function: | 0_2_00007FF7C4123620 | |
Source: | Code function: | 0_2_00007FF7C4123670 | |
Source: | Code function: | 0_2_00007FF7C4123710 |
Reconnaissance | Resource Development | Initial Access | Execution | Persistence | Privilege Escalation | Defense Evasion | Credential Access | Discovery | Lateral Movement | Collection | Command and Control | Exfiltration | Impact |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Gather Victim Identity Information | Acquire Infrastructure | 1 Valid Accounts | 11 Service Execution | 1 Valid Accounts | 1 Valid Accounts | 1 Masquerading | OS Credential Dumping | 2 System Time Discovery | Remote Services | 11 Archive Collected Data | 2 Encrypted Channel | Exfiltration Over Other Network Medium | 1 Data Encrypted for Impact |
Credentials | Domains | Default Accounts | 1 Native API | 12 Windows Service | 11 Access Token Manipulation | 1 Valid Accounts | LSASS Memory | 2 Security Software Discovery | Remote Desktop Protocol | Data from Removable Media | Junk Data | Exfiltration Over Bluetooth | Network Denial of Service |
Email Addresses | DNS Server | Domain Accounts | At | 1 DLL Side-Loading | 12 Windows Service | 11 Access Token Manipulation | Security Account Manager | 2 Process Discovery | SMB/Windows Admin Shares | Data from Network Shared Drive | Steganography | Automated Exfiltration | Data Encrypted for Impact |
Employee Names | Virtual Private Server | Local Accounts | Cron | Login Hook | 1 DLL Side-Loading | 1 Deobfuscate/Decode Files or Information | NTDS | 1 Account Discovery | Distributed Component Object Model | Input Capture | Protocol Impersonation | Traffic Duplication | Data Destruction |
Gather Victim Network Information | Server | Cloud Accounts | Launchd | Network Logon Script | Network Logon Script | 2 Obfuscated Files or Information | LSA Secrets | 1 System Owner/User Discovery | SSH | Keylogging | Fallback Channels | Scheduled Transfer | Data Encrypted for Impact |
Domain Properties | Botnet | Replication Through Removable Media | Scheduled Task | RC Scripts | RC Scripts | 1 DLL Side-Loading | Cached Domain Credentials | 1 System Network Connections Discovery | VNC | GUI Input Capture | Multiband Communication | Data Transfer Size Limits | Service Stop |
DNS | Web Services | External Remote Services | Systemd Timers | Startup Items | Startup Items | Compile After Delivery | DCSync | 3 File and Directory Discovery | Windows Remote Management | Web Portal Capture | Commonly Used Port | Exfiltration Over C2 Channel | Inhibit System Recovery |
Network Trust Dependencies | Serverless | Drive-by Compromise | Container Orchestration Job | Scheduled Task/Job | Scheduled Task/Job | Indicator Removal from Tools | Proc Filesystem | 36 System Information Discovery | Cloud Services | Credential API Hooking | Application Layer Protocol | Exfiltration Over Alternative Protocol | Defacement |
This section contains all screenshots as thumbnails, including those not shown in the slideshow.
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | ReversingLabs |
Source | Detection | Scanner | Label | Link |
---|---|---|---|---|
0% | URL Reputation | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe | ||
0% | Avira URL Cloud | safe |
Name | Source | Malicious | Antivirus Detection | Reputation |
---|---|---|---|---|
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown | ||
false |
| unknown |
Joe Sandbox version: | 40.0.0 Tourmaline |
Analysis ID: | 1467919 |
Start date and time: | 2024-07-05 01:39:47 +02:00 |
Joe Sandbox product: | CloudBasic |
Overall analysis duration: | 0h 5m 38s |
Hypervisor based Inspection enabled: | false |
Report type: | full |
Cookbook file name: | default.jbs |
Analysis system description: | Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01 |
Number of analysed new started processes analysed: | 7 |
Number of new started drivers analysed: | 0 |
Number of existing processes analysed: | 0 |
Number of existing drivers analysed: | 0 |
Number of injected processes analysed: | 0 |
Technologies: |
|
Analysis Mode: | default |
Analysis stop reason: | Timeout |
Sample name: | OneDriveUpdater.exe |
Detection: | CLEAN |
Classification: | clean6.winEXE@1/6@0/0 |
EGA Information: |
|
HCA Information: |
|
Cookbook Comments: |
|
- Exclude process from analysis (whitelisted): MpCmdRun.exe, WMIADAP.exe, SIHClient.exe, conhost.exe, svchost.exe
- Excluded domains from analysis (whitelisted): oneclient.sfx.ms, g.live.com, ocsp.digicert.com, slscr.update.microsoft.com, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
- Not all processes where analyzed, report is missing behavior information
- Report size exceeded maximum capacity and may have missing disassembly code.
- VT rate limit hit for: OneDriveUpdater.exe
C:\Users\user\AppData\Local\Microsoft\OneDrive\StandaloneUpdater\PreSignInSettingsConfig.json
Download File
Process: | C:\Users\user\Desktop\OneDriveUpdater.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 64854 |
Entropy (8bit): | 5.39444677062414 |
Encrypted: | false |
SSDEEP: | 384:poaSLGTSy3S0XuMU9mCzHS7vpvpJGV6Hu/i49Pji7iJI5TZCP56vS1xDR+dBUFvT:WryF7U9mCzHS7vu/xV2iP56vcDR+P0T |
MD5: | E516A60BC980095E8D156B1A99AB5EEE |
SHA1: | 238E243FFC12D4E012FD020C9822703109B987F6 |
SHA-256: | 543796A1B343B4EBC0285D89CB8EB70667AC7B513DA37495E38003704E9D88D7 |
SHA-512: | 9B51E99BA20E9DA56D1ACC24A1CF9F9C9DBDEB742BEC034E0FF2BC179A60F4AFF249F40344F9DDD43229DCDEFA1041940F65AFB336D46C175FFEFF725C638D58 |
Malicious: | false |
Reputation: | moderate, very likely benign file |
Preview: |
Process: | C:\Users\user\Desktop\OneDriveUpdater.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 899 |
Entropy (8bit): | 5.650905767540785 |
Encrypted: | false |
SSDEEP: | 24:JdbC/3ZGhufHCSnnSO8fSSnedSSEfmC6MSnASo:3sMOBR2xeamFPS |
MD5: | E14BDA011C0CF74E3AA14DB6FA10D3F2 |
SHA1: | 8B198AEC3F814CCEBD84A684E8F3EC9D06382AA8 |
SHA-256: | 8068D76A11CB451E82352AE2FE92DF07216040461B8830408FE181B71AF7F1C5 |
SHA-512: | 5780023CD4E4AF2AE8C8EF6B219DE7B1250162E91C50A9105DD0035C8ED96B10A1C45110E80973E44CF3C4AB4396D432F2FDF04799BF818224F5409ED8C35542 |
Malicious: | false |
Reputation: | low |
Preview: |
Process: | C:\Users\user\Desktop\OneDriveUpdater.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 2619 |
Entropy (8bit): | 5.650376775847054 |
Encrypted: | false |
SSDEEP: | 48:3jOBR2xeamFP7OzoPZY2cboc0GicDSM6ydS1uyc2g55g5T:zC7TqvCcGM0uRl5E |
MD5: | 5156D44272713C25BAB73568881D6231 |
SHA1: | A7BEAC91AC601654AC45818566F650D27C0DD86A |
SHA-256: | D3D5D10E19439834BB702265A4A33F226FAE10584A3936B05B169FF876E299D8 |
SHA-512: | 5B67B413C8881CA3FB6CA13E18231651D06F0DB1DCCD5F54BA90E75445CA0555880E5BE3D90C1757E12D93C9AF12BF6E79242DE8B8668FDB4AFE5BF2A67E555B |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\OneDrive\logs\Common\DeviceHealthSummaryConfiguration.ini
Download File
Process: | C:\Users\user\Desktop\OneDriveUpdater.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 77 |
Entropy (8bit): | 4.779728184019344 |
Encrypted: | false |
SSDEEP: | 3:RsRo7JKIAY9PGvpZjTOjKfrQQUqNs:qVI99uvp5aYFUqNs |
MD5: | F619535A518729085EA69D79C0746C2D |
SHA1: | 335545C6C0B044F296746936C84F5BF25AE3A9EF |
SHA-256: | 562D161B3F384285970422BC6F407FE4982FAF9C20AC7A030595AAB3D5BABE37 |
SHA-512: | C9790EF2B11BD3D620EDAABA3BBA4BEF0F201A6709DDD3E7FBA607D23F5DCE1135FDC26CC680951C9493C28C86B992E70260BA56178802BAA8E2EA732EE0E542 |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\OneDrive\logs\Common\StandaloneUpdater-2024-07-04.2340.7252.1.aodl
Download File
Process: | C:\Users\user\Desktop\OneDriveUpdater.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 5.056512452939649 |
Encrypted: | false |
SSDEEP: | 768:FwpdE6kFc1bkFc1Q6bxFqNcL3KBEX1nFNm:FQEd1kbx |
MD5: | 54FEE4BADA5FDB439E1C49156A43CC6A |
SHA1: | 9BC59140F3B10FA1ADD45C6BD574BA979B771D8D |
SHA-256: | 87532FD65C754A17A6D87854C5FD94B1F47208B21C9109B795ECACEB35020EA3 |
SHA-512: | AD579CD62B9B420DF9A2A0B4C219C540A443506FF0B3A77A1E14AFB081819BF731E162217A8CE2F9A70EADB294AE81CCEE433ADBEE5B3B6AB0F5E14FA24919DA |
Malicious: | false |
Reputation: | low |
Preview: |
C:\Users\user\AppData\Local\Microsoft\OneDrive\setup\logs\StandaloneUpdate_2024-07-04_234035_7252-7256.log
Download File
Process: | C:\Users\user\Desktop\OneDriveUpdater.exe |
File Type: | |
Category: | dropped |
Size (bytes): | 65536 |
Entropy (8bit): | 0.910466497696784 |
Encrypted: | false |
SSDEEP: | 192:XA7Au+F8FgFJoFwfFIF3F/FmF7FeF+F8FcFJUFhEFeF:w7AuqEQJowtIVNCBKqEkJMh8K |
MD5: | AF858438BF320D1B45EF6E6037FB1976 |
SHA1: | 3D3A5315E7B8EBC78615D1A0AD2D7361643946BF |
SHA-256: | 2E3A473D2D4F64848DA1B672B02731F2D49EFE677579D03E591727146E7C143D |
SHA-512: | BC8C62240BEB770DA3493BCF5E2452E778EE7093CB1463876BE2E211BD72A4EA771853BC4BF9CB2E35320F0398F12267FF37B636AB60C9CE7543AEAEC1EB3266 |
Malicious: | false |
Reputation: | low |
Preview: |
File type: | |
Entropy (8bit): | 6.255702585045085 |
TrID: |
|
File name: | OneDriveUpdater.exe |
File size: | 4'200'864 bytes |
MD5: | 792e95b64b9cf45ac8bc10d4d0f077c2 |
SHA1: | e50af7ee7e0a323d8aa60b6d9b3d39ab33b004f5 |
SHA256: | 60e64dd2c6d2ac6fe9b498fadac81bc34a725de5d893e7df8b2728d8dc5b192d |
SHA512: | 5064c1a64fa0bd5a31b205d8b34cb85cc3da7091dd2412421f6394d42b9a596430b67ea4d05129912ad942458198280a3a69409388d2413072c53d928de70e86 |
SSDEEP: | 49152:3EenBpKLBz+dV0LWUEur5XVmy1rVaou58gZbkT3FjNVcXrkj6B+/T+k54Q1Wb:6VlH0MAQj8k5d18 |
TLSH: | 3E165A4BA2B901E4D0BBD23D8A679617FAB1785587359BDF0690435A0F33BE09E3E710 |
File Content Preview: | MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......6x.Sr.b.r.b.r.b..kg...b..pf.{.b..pg.I.b..lk.~.b. lf.a.b. la.z.b. lg...b..ka.|.b..kf.m.b..kd.p.b..kc._.b.r.c...b..lg...b..lb.s.b |
Icon Hash: | 90cececece8e8eb0 |
Entrypoint: | 0x140038ba0 |
Entrypoint Section: | .text |
Digitally signed: | true |
Imagebase: | 0x140000000 |
Subsystem: | windows gui |
Image File Characteristics: | EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE |
DLL Characteristics: | HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE |
Time Stamp: | 0x24CF8552 [Thu Jul 27 21:57:38 1989 UTC] |
TLS Callbacks: | 0x40167610, 0x1, 0x40167690, 0x1 |
CLR (.Net) Version: | |
OS Version Major: | 6 |
OS Version Minor: | 0 |
File Version Major: | 6 |
File Version Minor: | 0 |
Subsystem Version Major: | 6 |
Subsystem Version Minor: | 0 |
Import Hash: | 998485b035498bd8f4259c68101e6cc3 |
Signature Valid: | true |
Signature Issuer: | CN=Microsoft Code Signing PCA 2010, O=Microsoft Corporation, L=Redmond, S=Washington, C=US |
Signature Validation Error: | The operation completed successfully |
Error Number: | 0 |
Not Before, Not After |
|
Subject Chain |
|
Version: | 3 |
Thumbprint MD5: | CCB19DD724F52810AD930629C1825FA3 |
Thumbprint SHA-1: | 9251BD18AC5C69FDC0CB16B51D5133A84FE6BC2F |
Thumbprint SHA-256: | E93FB5ABE1EF7797849E0B6B487C954EBDDABCB53DD16E4EF952524D51C30F9D |
Serial: | 330000042535216F36087CEB06000000000425 |
Instruction |
---|
dec eax |
sub esp, 28h |
call 00007FDC80803C94h |
dec eax |
add esp, 28h |
jmp 00007FDC8080344Fh |
int3 |
int3 |
and dword ptr [003A4991h], 00000000h |
ret |
dec eax |
mov dword ptr [esp+08h], ebx |
push ebp |
dec eax |
lea ebp, dword ptr [esp-000004C0h] |
dec eax |
sub esp, 000005C0h |
mov ebx, ecx |
mov ecx, 00000017h |
call dword ptr [002B096Ah] |
test eax, eax |
je 00007FDC808035D6h |
mov ecx, ebx |
int 29h |
mov ecx, 00000003h |
call 00007FDC80803599h |
xor edx, edx |
dec eax |
lea ecx, dword ptr [ebp-10h] |
inc ecx |
mov eax, 000004D0h |
call 00007FDC80804C04h |
dec eax |
lea ecx, dword ptr [ebp-10h] |
call dword ptr [002B123Dh] |
dec eax |
mov ebx, dword ptr [ebp+000000E8h] |
dec eax |
lea edx, dword ptr [ebp+000004D8h] |
dec eax |
mov ecx, ebx |
inc ebp |
xor eax, eax |
call dword ptr [002B122Bh] |
dec eax |
test eax, eax |
je 00007FDC8080360Eh |
dec eax |
and dword ptr [esp+38h], 00000000h |
dec eax |
lea ecx, dword ptr [ebp+000004E0h] |
dec eax |
mov edx, dword ptr [ebp+000004D8h] |
dec esp |
mov ecx, eax |
dec eax |
mov dword ptr [esp+30h], ecx |
dec esp |
mov eax, ebx |
dec eax |
lea ecx, dword ptr [ebp+000004E8h] |
dec eax |
mov dword ptr [esp+28h], ecx |
dec eax |
lea ecx, dword ptr [ebp-10h] |
dec eax |
mov dword ptr [esp+20h], ecx |
xor ecx, ecx |
call dword ptr [002B11F2h] |
dec eax |
Name | Virtual Address | Virtual Size | Is in Section |
---|---|---|---|
IMAGE_DIRECTORY_ENTRY_EXPORT | 0x3b43e0 | 0x72cc | .rdata |
IMAGE_DIRECTORY_ENTRY_IMPORT | 0x3bb6ac | 0x1cc | .rdata |
IMAGE_DIRECTORY_ENTRY_RESOURCE | 0x402000 | 0xb60 | .rsrc |
IMAGE_DIRECTORY_ENTRY_EXCEPTION | 0x3e3000 | 0x1ce6c | .pdata |
IMAGE_DIRECTORY_ENTRY_SECURITY | 0x3ff400 | 0x25a0 | |
IMAGE_DIRECTORY_ENTRY_BASERELOC | 0x403000 | 0x528c | .reloc |
IMAGE_DIRECTORY_ENTRY_DEBUG | 0x362040 | 0x70 | .rdata |
IMAGE_DIRECTORY_ENTRY_COPYRIGHT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_GLOBALPTR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_TLS | 0x362100 | 0x28 | .rdata |
IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG | 0x35af90 | 0x138 | .rdata |
IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_IAT | 0x2e9000 | 0xef8 | .rdata |
IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT | 0x3b4250 | 0x60 | .rdata |
IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR | 0x0 | 0x0 | |
IMAGE_DIRECTORY_ENTRY_RESERVED | 0x0 | 0x0 |
Name | Virtual Address | Virtual Size | Raw Size | MD5 | Xored PE | ZLIB Complexity | File Type | Entropy | Characteristics |
---|---|---|---|---|---|---|---|---|---|
.text | 0x1000 | 0x2e791c | 0x2e7a00 | a23d1340ce6770bd3e96322ec9b8471e | unknown | unknown | unknown | unknown | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ |
.rdata | 0x2e9000 | 0xd5a44 | 0xd5c00 | 3aa3851f60487a2dcdffab0194e0ef4f | False | 0.31893046418128657 | data | 4.962151045168778 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.data | 0x3bf000 | 0x23214 | 0x1e600 | ba3d3cf5404aba214171beb85f132b1d | False | 0.1951437114197531 | data | 4.8715384935366615 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
.pdata | 0x3e3000 | 0x1ce6c | 0x1d000 | e4f42dd872058c005b33a5ecac3104d7 | False | 0.5015069369612069 | data | 6.283611176742107 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.didat | 0x400000 | 0x48 | 0x200 | bab7359b53959913b7a4cb69225e1e2e | False | 0.076171875 | data | 0.5703483918359332 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE |
_RDATA | 0x401000 | 0xfc | 0x200 | 88f14c29479baa4dadcc14245a4175ba | False | 0.318359375 | data | 2.458301158770647 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.rsrc | 0x402000 | 0xb60 | 0xc00 | 1e19c28ffefb2ba22f1cb67e37d3548c | False | 0.3821614583333333 | data | 4.648152733517116 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ |
.reloc | 0x403000 | 0x528c | 0x5400 | 2fe0dbcb762c4ef1986df34a76320f1a | False | 0.2546968005952381 | data | 5.441211306199959 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ |
Name | RVA | Size | Type | Language | Country | ZLIB Complexity |
---|---|---|---|---|---|---|
EDPENLIGHTENEDAPPINFOID | 0x402b50 | 0x2 | data | English | United States | 5.0 |
EDPPERMISSIVEAPPINFOID | 0x402b58 | 0x2 | data | English | United States | 5.0 |
RT_VERSION | 0x402210 | 0x408 | data | English | United States | 0.42151162790697677 |
RT_MANIFEST | 0x402618 | 0x533 | XML 1.0 document, ASCII text, with CRLF line terminators | English | United States | 0.4320060105184072 |
DLL | Import |
---|---|
KERNEL32.dll | RtlPcToFileHeader, InterlockedPushEntrySList, SetLastError, EncodePointer, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, ExitProcess, GetModuleFileNameW, GetStdHandle, WriteFile, GetCurrentThread, FindFirstFileExW, IsValidCodePage, GetACP, GetOEMCP, GetCPInfo, GetCommandLineA, MultiByteToWideChar, WideCharToMultiByte, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetEnvironmentVariableW, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, GetDateFormatW, GetTimeFormatW, CompareStringW, LCMapStringW, GetLocaleInfoW, IsValidLocale, GetUserDefaultLCID, EnumSystemLocalesW, GetFileType, SetStdHandle, GetStringTypeW, GetTimeZoneInformation, FlushFileBuffers, GetConsoleOutputCP, GetConsoleMode, GetFileSizeEx, SetFilePointerEx, ReadFile, RtlUnwindEx, WriteConsoleW, CompareFileTime, FindClose, FindNextFileW, FindFirstFileW, Process32NextW, OpenProcess, Process32FirstW, CreateToolhelp32Snapshot, CreateProcessW, GetProductInfo, VerifyVersionInfoW, VerSetConditionMask, LoadLibraryExW, MoveFileExW, IsWow64Process, ExpandEnvironmentStringsW, UnmapViewOfFile, MapViewOfFileEx, CreateFileMappingW, GetFileSize, CreateFileW, LocalFree, LocalAlloc, OpenMutexW, FileTimeToSystemTime, FileTimeToLocalFileTime, GetTickCount64, GetVolumePathNameW, Sleep, GetCommandLineW, GetModuleHandleExW, FreeLibrary, GetEnvironmentVariableW, InitializeSListHead, GetSystemTimeAsFileTime, GetCurrentThreadId, GetCurrentProcessId, QueryPerformanceCounter, TerminateProcess, GetCurrentProcess, IsProcessorFeaturePresent, GetStartupInfoW, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetProcAddress, GetModuleHandleW, CreateEventW, WaitForSingleObjectEx, ResetEvent, SetEvent, InitializeCriticalSectionAndSpinCount, CloseHandle, LeaveCriticalSection, EnterCriticalSection, OutputDebugStringW, IsDebuggerPresent, DeleteCriticalSection, InitializeCriticalSectionEx, GetProcessHeap, HeapSize, HeapFree, HeapReAlloc, HeapAlloc, HeapDestroy, GetLastError, SystemTimeToTzSpecificLocalTime, PeekNamedPipe, GetDriveTypeW, FreeLibraryAndExitThread, ExitThread, CreateThread, RtlUnwind, LoadLibraryExA, VirtualQuery, VirtualProtect, InitializeCriticalSection, HeapCreate, GetDiskFreeSpaceW, LockFile, GetFullPathNameA, HeapValidate, GetTempPathA, FormatMessageW, GetDiskFreeSpaceA, GetFileAttributesA, FlushViewOfFile, CreateFileA, LoadLibraryA, DeleteFileA, GetSystemInfo, HeapCompact, UnlockFile, MapViewOfFile, GetSystemPowerStatus, GetModuleFileNameA, OutputDebugStringA, CompareStringEx, LCMapStringEx, DecodePointer, InitOnceExecuteOnce, GetLocaleInfoEx, CreateHardLinkW, AreFileApisANSI, SetEndOfFile, GetCurrentDirectoryW, AcquireSRWLockShared, ReleaseSRWLockShared, SleepConditionVariableSRW, SleepConditionVariableCS, WakeAllConditionVariable, RaiseException, ReadConsoleW, DeleteFileW, GetSystemTime, CreateDirectoryW, GetFullPathNameW, GetTempFileNameW, RemoveDirectoryW, SetFileTime, GetTempPathW, CopyFileW, SystemTimeToFileTime, LockFileEx, UnlockFileEx, DeviceIoControl, LoadLibraryW, WerRegisterFile, WerUnregisterFile, GetTickCount, K32GetModuleFileNameExW, WaitForSingleObject, WaitForMultipleObjects, QueueUserWorkItem, CreateMutexW, GetVersionExW, MoveFileW, GetUserDefaultLocaleName, GetComputerNameW, FindFirstVolumeW, FindNextVolumeW, FindVolumeClose, GetDiskFreeSpaceExW, GetFileAttributesW, GetFileAttributesExW, GetFileInformationByHandle, GetFinalPathNameByHandleW, GetLongPathNameW, SetFileAttributesW, SetFileInformationByHandle, SetFilePointer, GetCompressedFileSizeW, FindFirstFileNameW, CreateIoCompletionPort, GetQueuedCompletionStatus, PostQueuedCompletionStatus, ReleaseMutex, GetProcessTimes, GetExitCodeProcess, GetSystemTimes, SetDllDirectoryW, ReplaceFileW, ReadDirectoryChangesW, RegisterApplicationRestart, GetFileInformationByHandleEx, OpenFileById, CreateSymbolicLinkW, CompareStringOrdinal, GetUserGeoID, GlobalFree, ReadProcessMemory, QueryPerformanceFrequency, FormatMessageA, InitializeSRWLock, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, TryEnterCriticalSection, SwitchToThread, GetExitCodeThread, GetNativeSystemInfo, InitializeConditionVariable, WakeConditionVariable |
USER32.dll | PostThreadMessageW, SendMessageTimeoutW, ShowWindow, DestroyWindow, CreateWindowExW, RegisterClassW, DispatchMessageW, GetMessageW, SystemParametersInfoW, GetWindowThreadProcessId, GetClassNameW, EnumWindows, PostMessageW, PostQuitMessage, TranslateMessage |
OLEAUT32.dll | VariantChangeType, VarBstrCmp, VariantClear, SysStringByteLen, LoadTypeLib, LoadRegTypeLib, SysFreeString, SysStringLen, SetErrorInfo, GetErrorInfo, GetRecordInfoFromTypeInfo, SysAllocStringLen, VariantInit, SysAllocString, SysAllocStringByteLen |
ntdll.dll | RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind |
SHLWAPI.dll | StrStrIW, SHRegGetBoolUSValueW, SHRegGetValueW, PathStripToRootW, PathStripPathW, PathIsDirectoryW, PathRemoveFileSpecW, PathFileExistsW, SHSetValueW, SHCreateStreamOnFileEx, PathIsRelativeW, PathFindFileNameW, SHDeleteKeyW, SHDeleteValueW, SHGetValueW, PathIsPrefixW, SHCreateStreamOnFileW |
VERSION.dll | VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW |
USERENV.dll | GetDefaultUserProfileDirectoryW, CreateEnvironmentBlock, GetProfileType |
ADVAPI32.dll | RegGetValueA, EventUnregister, CryptAcquireContextW, CryptReleaseContext, CryptGetHashParam, CryptCreateHash, EventWriteTransfer, GetUserNameW, RegOpenKeyExW, OpenProcessToken, GetTokenInformation, MapGenericMask, IsValidAcl, DuplicateToken, AccessCheck, OpenThreadToken, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetNamedSecurityInfoW, StartServiceW, StartServiceCtrlDispatcherW, SetServiceStatus, RegisterServiceCtrlHandlerW, QueryServiceStatusEx, QueryServiceStatus, QueryServiceConfigW, DeleteService, CreateServiceW, ControlService, ChangeServiceConfig2W, CryptHashData, CryptDestroyHash, AdjustTokenPrivileges, AllocateAndInitializeSid, FreeSid, LookupPrivilegeValueW, SetEntriesInAclW, SetNamedSecurityInfoW, ImpersonateLoggedOnUser, RevertToSelf, CopySid, GetLengthSid, IsValidSid, RegDeleteValueW, RegEnumKeyExW, RegEnumValueW, RegQueryInfoKeyW, RegSetKeyValueW, RegGetValueW, LookupAccountNameW, CryptDestroyKey, CryptSetHashParam, CryptImportKey, CreateProcessAsUserW, CreateWellKnownSid, DuplicateTokenEx, GetAclInformation, SetFileSecurityW, RegCreateKeyTransactedW, RegDeleteKeyExW, RegEnumKeyW, RegLoadKeyW, RegUnLoadKeyW, RegDeleteTreeW, ChangeServiceConfigW, OpenSCManagerW, ConvertSidToStringSidW, RegSetValueExW, RegCreateKeyExW, RegCloseKey, RegQueryValueExW, CloseServiceHandle, OpenServiceW, EventRegister |
SHELL32.dll | SHLoadNonloadedIconOverlayIdentifiers, SHChangeNotify, SHParseDisplayName, SHCreateItemFromParsingName, SHGetFolderPathAndSubDirW, SHSetKnownFolderPath, CommandLineToArgvW, SHGetSpecialFolderPathW, SHCreateDirectoryExW, SHGetFolderPathW, ShellExecuteExW, SHGetKnownFolderPath, SHFileOperationW |
ole32.dll | CoSetProxyBlanket, CoInitialize, CreateBindCtx, StringFromCLSID, CoTaskMemAlloc, StringFromGUID2, CoCreateInstance, CoTaskMemFree, GetRunningObjectTable, CreateItemMoniker, CoCreateGuid, CoUninitialize, CoInitializeEx, CLSIDFromString, CoCreateFreeThreadedMarshaler |
WINHTTP.dll | WinHttpGetProxyForUrl, WinHttpSetCredentials, WinHttpSetOption, WinHttpCloseHandle, WinHttpOpen, WinHttpGetIEProxyConfigForCurrentUser |
RstrtMgr.DLL | RmGetList, RmRegisterResources, RmEndSession, RmStartSession |
WINTRUST.dll | WTHelperGetProvSignerFromChain, WTHelperProvDataFromStateData, WinVerifyTrustEx |
WTSAPI32.dll | WTSFreeMemory, WTSQuerySessionInformationW, WTSEnumerateSessionsW, WTSQueryUserToken |
bcrypt.dll | BCryptEncrypt, BCryptGenerateSymmetricKey, BCryptCloseAlgorithmProvider, BCryptDestroyKey, BCryptOpenAlgorithmProvider, BCryptGenRandom, BCryptSetProperty |
CRYPT32.dll | CertVerifyCertificateChainPolicy, CertFreeCertificateChain, CryptBinaryToStringW, CryptStringToBinaryW |
RPCRT4.dll | UuidToStringW, RpcBindingFree, RpcBindingFromStringBindingW, RpcBindingVectorFree, RpcBindingSetAuthInfoExW, RpcEpRegisterW, RpcEpUnregister, RpcServerInqCallAttributesW, RpcStringFreeW, RpcStringBindingComposeW, RpcServerInqBindings, RpcServerRegisterIfEx, RpcServerUnregisterIf, RpcServerUseProtseqW, RpcExceptionFilter |
Secur32.dll | GetUserNameExW |
urlmon.dll | URLOpenStreamW |
WININET.dll | InternetCheckConnectionW, InternetCrackUrlA, InternetOpenW, InternetConnectA, InternetReadFile, InternetQueryOptionW, InternetSetStatusCallbackW, HttpOpenRequestA, InternetCloseHandle, HttpSendRequestW, HttpQueryInfoA, HttpAddRequestHeadersA |
WS2_32.dll | bind, closesocket, htonl, accept, listen, send, setsockopt, socket, WSAStartup, WSAGetLastError, htons |
IPHLPAPI.DLL | GetAdaptersInfo |
Name | Ordinal | Address |
---|---|---|
?$TSS0@?1??stateLock@DebugEventSource@Events@Applications@Microsoft@@KAAEAVrecursive_mutex@std@@XZ@4HA | 1 | 0x1403e1660 |
??0DebugEventDispatcher@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 2 | 0x14016a1c0 |
??0DebugEventDispatcher@Events@Applications@Microsoft@@QEAA@XZ | 3 | 0x14016a1c0 |
??0DebugEventListener@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 4 | 0x14016a1d0 |
??0DebugEventListener@Events@Applications@Microsoft@@QEAA@XZ | 5 | 0x14016a1d0 |
??0DebugEventSource@Events@Applications@Microsoft@@QEAA@$$QEAV0123@@Z | 6 | 0x14016a1e0 |
??0DebugEventSource@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 7 | 0x14016a2a0 |
??0DebugEventSource@Events@Applications@Microsoft@@QEAA@XZ | 8 | 0x1400a69f0 |
??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 9 | 0x140171af0 |
??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 10 | 0x140171b40 |
??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@5@@Z | 11 | 0x140171b70 |
??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@E@Z | 12 | 0x140171bc0 |
??0EventProperties@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$initializer_list@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@5@@Z | 13 | 0x140171cc0 |
??0EventProperties@Events@Applications@Microsoft@@QEAA@XZ | 14 | 0x140171d20 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@$$QEAU0123@@Z | 15 | 0x140176d70 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@NV?$allocator@N@std@@@std@@W4PiiKind@123@W4DataCategory@123@@Z | 16 | 0x140176dc0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@UGUID_t@Events@Applications@Microsoft@@V?$allocator@UGUID_t@Events@Applications@Microsoft@@@std@@@std@@W4PiiKind@123@W4DataCategory@123@@Z | 17 | 0x140176e30 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@std@@W4PiiKind@123@W4DataCategory@123@@Z | 18 | 0x140176ea0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@AEAV?$vector@_JV?$allocator@_J@std@@@std@@W4PiiKind@123@W4DataCategory@123@@Z | 19 | 0x140176f10 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@AEBU0123@@Z | 20 | 0x140176d70 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@123@W4DataCategory@123@@Z | 21 | 0x140176f80 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@CW4PiiKind@123@W4DataCategory@123@@Z | 22 | 0x140177000 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@EW4PiiKind@123@W4DataCategory@123@@Z | 23 | 0x140177030 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@FW4PiiKind@123@W4DataCategory@123@@Z | 24 | 0x140177060 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@GW4PiiKind@123@W4DataCategory@123@@Z | 25 | 0x140177090 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@HW4PiiKind@123@W4DataCategory@123@@Z | 26 | 0x1401770c0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@IW4PiiKind@123@W4DataCategory@123@@Z | 27 | 0x1401770f0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@JW4PiiKind@123@W4DataCategory@123@@Z | 28 | 0x1401770c0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@NW4PiiKind@123@W4DataCategory@123@@Z | 29 | 0x140177120 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@PEBDW4PiiKind@123@W4DataCategory@123@@Z | 30 | 0x140177150 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@UGUID_t@123@W4PiiKind@123@W4DataCategory@123@@Z | 31 | 0x1401771e0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@Utime_ticks_t@123@W4PiiKind@123@W4DataCategory@123@@Z | 32 | 0x140177220 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@XZ | 33 | 0x140177250 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@_JW4PiiKind@123@W4DataCategory@123@@Z | 34 | 0x1401772c0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@_KW4PiiKind@123@W4DataCategory@123@@Z | 35 | 0x1401772c0 |
??0EventProperty@Events@Applications@Microsoft@@QEAA@_NW4PiiKind@123@W4DataCategory@123@@Z | 36 | 0x1401772f0 |
??0GUID_t@Events@Applications@Microsoft@@QEAA@AEBU0123@@Z | 37 | 0x140177310 |
??0GUID_t@Events@Applications@Microsoft@@QEAA@HHHAEBV?$initializer_list@E@std@@@Z | 38 | 0x140177350 |
??0GUID_t@Events@Applications@Microsoft@@QEAA@PEBD@Z | 39 | 0x140177390 |
??0GUID_t@Events@Applications@Microsoft@@QEAA@QEBE_N@Z | 40 | 0x140177470 |
??0GUID_t@Events@Applications@Microsoft@@QEAA@U_GUID@@@Z | 41 | 0x140177550 |
??0GUID_t@Events@Applications@Microsoft@@QEAA@XZ | 42 | 0x1401775c0 |
??0IAuthTokensController@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 43 | 0x14016a310 |
??0IAuthTokensController@Events@Applications@Microsoft@@QEAA@XZ | 44 | 0x14016a310 |
??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@$$QEAV0123@@Z | 45 | 0x14016a320 |
??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 46 | 0x14016a3c0 |
??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@AEBV?$initializer_list@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VVariant@Events@Applications@Microsoft@@@std@@@std@@@Z | 47 | 0x1401748c0 |
??0ILogConfiguration@Events@Applications@Microsoft@@QEAA@XZ | 48 | 0x1400a6a80 |
??0ILogController@Events@Applications@Microsoft@@QEAA@$$QEAV0123@@Z | 49 | 0x14016a410 |
??0ILogController@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 50 | 0x14016a410 |
??0ILogController@Events@Applications@Microsoft@@QEAA@XZ | 51 | 0x14016a410 |
??0ILogManager@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 52 | 0x14016a420 |
??0ILogManager@Events@Applications@Microsoft@@QEAA@XZ | 53 | 0x14016a420 |
??0ILogger@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 54 | 0x14016a450 |
??0ILogger@Events@Applications@Microsoft@@QEAA@XZ | 55 | 0x14016a450 |
??0IModule@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 56 | 0x14016a460 |
??0IModule@Events@Applications@Microsoft@@QEAA@XZ | 57 | 0x14016a460 |
??0ISemanticContext@Events@Applications@Microsoft@@QEAA@AEBV0123@@Z | 58 | 0x14016a470 |
??0ISemanticContext@Events@Applications@Microsoft@@QEAA@XZ | 59 | 0x14016a470 |
??0LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@$$QEAU0123@@Z | 60 | 0x14016a480 |
??0LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@AEBU0123@@Z | 61 | 0x14016a580 |
??0LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@XZ | 62 | 0x14016a640 |
??0time_ticks_t@Events@Applications@Microsoft@@QEAA@AEBU0123@@Z | 63 | 0x14016b060 |
??0time_ticks_t@Events@Applications@Microsoft@@QEAA@PEB_J@Z | 64 | 0x1401775d0 |
??0time_ticks_t@Events@Applications@Microsoft@@QEAA@XZ | 65 | 0x1401775f0 |
??0time_ticks_t@Events@Applications@Microsoft@@QEAA@_K@Z | 66 | 0x140177600 |
??1DebugEventDispatcher@Events@Applications@Microsoft@@UEAA@XZ | 67 | 0x1400299a0 |
??1DebugEventListener@Events@Applications@Microsoft@@UEAA@XZ | 68 | 0x1400299a0 |
??1DebugEventSource@Events@Applications@Microsoft@@UEAA@XZ | 69 | 0x1400a7770 |
??1EventProperties@Events@Applications@Microsoft@@UEAA@XZ | 70 | 0x140171fe0 |
??1EventProperty@Events@Applications@Microsoft@@UEAA@XZ | 71 | 0x140177640 |
??1IAuthTokensController@Events@Applications@Microsoft@@UEAA@XZ | 72 | 0x14016a9e0 |
??1ILogConfiguration@Events@Applications@Microsoft@@QEAA@XZ | 73 | 0x1400b7ba0 |
??1ILogManager@Events@Applications@Microsoft@@UEAA@XZ | 74 | 0x14016a9f0 |
??1ILogger@Events@Applications@Microsoft@@UEAA@XZ | 75 | 0x14016aa20 |
??1IModule@Events@Applications@Microsoft@@UEAA@XZ | 76 | 0x1400299a0 |
??1ISemanticContext@Events@Applications@Microsoft@@UEAA@XZ | 77 | 0x14016aa30 |
??1LogConfiguration@Telemetry@Applications@Microsoft@@QEAA@XZ | 78 | 0x14016aa40 |
??4DebugEventDispatcher@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 79 | 0x140019ae0 |
??4DebugEventListener@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 80 | 0x140019ae0 |
??4DebugEventSource@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z | 81 | 0x14016acf0 |
??4DebugEventSource@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 82 | 0x14016ada0 |
??4EventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 83 | 0x140172110 |
??4EventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@std@@@Z | 84 | 0x140172130 |
??4EventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@V?$initializer_list@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@std@@@Z | 85 | 0x140172170 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z | 86 | 0x140177650 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 87 | 0x140177690 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@NV?$allocator@N@std@@@std@@@Z | 88 | 0x140177710 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@UGUID_t@Events@Applications@Microsoft@@V?$allocator@UGUID_t@Events@Applications@Microsoft@@@std@@@std@@@Z | 89 | 0x140177770 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@std@@@Z | 90 | 0x1401777d0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@AEBV?$vector@_JV?$allocator@_J@std@@@std@@@Z | 91 | 0x140177830 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@C@Z | 92 | 0x140177890 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@E@Z | 93 | 0x1401778a0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@F@Z | 94 | 0x1401778b0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@G@Z | 95 | 0x1401778c0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@H@Z | 96 | 0x1401778d0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@I@Z | 97 | 0x1401778e0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@J@Z | 98 | 0x1401778d0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@N@Z | 99 | 0x1401778f0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@PEBD@Z | 100 | 0x140177920 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@UGUID_t@123@@Z | 101 | 0x140177980 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@Utime_ticks_t@123@@Z | 102 | 0x1401779c0 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@_J@Z | 103 | 0x140177a00 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@_K@Z | 104 | 0x140177a30 |
??4EventProperty@Events@Applications@Microsoft@@QEAAAEAU0123@_N@Z | 105 | 0x140177a40 |
??4GUID_t@Events@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z | 106 | 0x14016ae30 |
??4IAuthTokensController@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 107 | 0x140019ae0 |
??4ILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z | 108 | 0x14016ae40 |
??4ILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 109 | 0x14016aed0 |
??4ILogController@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z | 110 | 0x140019ae0 |
??4ILogController@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 111 | 0x140019ae0 |
??4ILogManager@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 112 | 0x140019ae0 |
??4ILogger@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 113 | 0x140019ae0 |
??4IModule@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 114 | 0x140019ae0 |
??4ISemanticContext@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 115 | 0x140019ae0 |
??4LogConfiguration@Telemetry@Applications@Microsoft@@QEAAAEAU0123@$$QEAU0123@@Z | 116 | 0x14016af40 |
??4LogConfiguration@Telemetry@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z | 117 | 0x14016afd0 |
??4LogManagerProvider@Events@Applications@Microsoft@@QEAAAEAV0123@$$QEAV0123@@Z | 118 | 0x140019ae0 |
??4LogManagerProvider@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV0123@@Z | 119 | 0x140019ae0 |
??4time_ticks_t@Events@Applications@Microsoft@@QEAAAEAU0123@AEBU0123@@Z | 120 | 0x14016b060 |
??8EventProperty@Events@Applications@Microsoft@@QEBA_NAEBU0123@@Z | 121 | 0x140177a70 |
??8GUID_t@Events@Applications@Microsoft@@QEBA_NAEBU0123@@Z | 122 | 0x140177f90 |
??AILogConfiguration@Events@Applications@Microsoft@@QEAAAEAVVariant@123@PEBD@Z | 123 | 0x140174970 |
??DILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VVariant@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@VVariant@Events@Applications@Microsoft@@@std@@@2@@std@@XZ | 124 | 0x140019ae0 |
??MGUID_t@Events@Applications@Microsoft@@QEBA_NAEBU0123@@Z | 125 | 0x140177fe0 |
??YEventProperties@Events@Applications@Microsoft@@QEAAAEAV0123@AEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@std@@@Z | 126 | 0x140172350 |
??_7DebugEventDispatcher@Events@Applications@Microsoft@@6B@ | 127 | 0x1402fea30 |
??_7DebugEventListener@Events@Applications@Microsoft@@6B@ | 128 | 0x140300898 |
??_7DebugEventSource@Events@Applications@Microsoft@@6B@ | 129 | 0x1402fea48 |
??_7EventProperties@Events@Applications@Microsoft@@6B@ | 130 | 0x14032eb28 |
??_7EventProperty@Events@Applications@Microsoft@@6B@ | 131 | 0x14032f220 |
??_7IAuthTokensController@Events@Applications@Microsoft@@6B@ | 132 | 0x14032e280 |
??_7ILogController@Events@Applications@Microsoft@@6B@ | 133 | 0x14032e2c8 |
??_7ILogManager@Events@Applications@Microsoft@@6BDebugEventDispatcher@123@@ | 134 | 0x14032e4a8 |
??_7ILogManager@Events@Applications@Microsoft@@6BIContextProvider@123@@ | 135 | 0x14032e490 |
??_7ILogManager@Events@Applications@Microsoft@@6BILogController@123@@ | 136 | 0x14032e330 |
??_7ILogger@Events@Applications@Microsoft@@6B@ | 137 | 0x14032e128 |
??_7IModule@Events@Applications@Microsoft@@6B@ | 138 | 0x14032ddd8 |
??_7ISemanticContext@Events@Applications@Microsoft@@6B@ | 139 | 0x14032de08 |
?AddEventListener@DebugEventSource@Events@Applications@Microsoft@@UEAAXW4DebugEventType@234@AEAVDebugEventListener@234@@Z | 140 | 0x1401707d0 |
?AddModule@ILogConfiguration@Events@Applications@Microsoft@@QEAAXPEBDAEBV?$shared_ptr@VIModule@Events@Applications@Microsoft@@@std@@@Z | 141 | 0x140174a20 |
?AttachEventSource@DebugEventSource@Events@Applications@Microsoft@@UEAA_NAEAV1234@@Z | 142 | 0x140170880 |
?ClearExperimentIds@ISemanticContext@Events@Applications@Microsoft@@UEAAXXZ | 143 | 0x1400299a0 |
?CreateLogManager@LogManagerProvider@Events@Applications@Microsoft@@SAPEAVILogManager@234@AEAVILogConfiguration@234@AEAW4status_t@234@@Z | 144 | 0x14016b6b0 |
?CreateLogManager@LogManagerProvider@Events@Applications@Microsoft@@SAPEAVILogManager@234@PEBDAEAW4status_t@234@_K@Z | 145 | 0x14016b6c0 |
?CreateLogManager@LogManagerProvider@Events@Applications@Microsoft@@SAPEAVILogManager@234@PEBD_NAEAVILogConfiguration@234@AEAW4status_t@234@_K@Z | 146 | 0x14016b6d0 |
?DestroyLogManager@LogManagerProvider@Events@Applications@Microsoft@@SA?AW4status_t@234@PEBD@Z | 147 | 0x14016b7e0 |
?DetachEventSource@DebugEventSource@Events@Applications@Microsoft@@UEAA_NAEAV1234@@Z | 148 | 0x140170920 |
?DispatchEvent@DebugEventSource@Events@Applications@Microsoft@@UEAA_NVDebugEvent@234@@Z | 149 | 0x1401709a0 |
?DispatchEventBroadcast@ILogManager@Events@Applications@Microsoft@@SA_NVDebugEvent@234@@Z | 150 | 0x14018c9f0 |
?FromJSON@Events@Applications@Microsoft@@YA?AVILogConfiguration@123@PEBD@Z | 151 | 0x140183cb0 |
?FromLogConfiguration@Events@Applications@Microsoft@@YA?AVILogConfiguration@123@AEAULogConfiguration@Telemetry@23@@Z | 152 | 0x140183e70 |
?Get@LogManagerProvider@Events@Applications@Microsoft@@CAPEAVILogManager@234@AEAVILogConfiguration@234@AEAW4status_t@234@@Z | 153 | 0x1401750c0 |
?Get@LogManagerProvider@Events@Applications@Microsoft@@CAPEAVILogManager@234@PEBDAEAW4status_t@234@@Z | 154 | 0x140175100 |
?GetDefaultConfiguration@Events@Applications@Microsoft@@YAAEBVILogConfiguration@123@XZ | 155 | 0x140184260 |
?GetLatency@EventProperties@Events@Applications@Microsoft@@QEBA?AW4EventLatency@234@XZ | 156 | 0x140172530 |
?GetLogObfuscationKeyManger@@YAJPEAPEAVILogObfuscationKeyManager@@@Z | 157 | 0x1400bb050 |
?GetLogObfuscatorAes@@YAJPEAPEAVILogObfuscatorAes@@@Z | 158 | 0x1400b8a30 |
?GetModule@ILogConfiguration@Events@Applications@Microsoft@@QEAA?AV?$shared_ptr@VIModule@Events@Applications@Microsoft@@@std@@PEBD@Z | 159 | 0x140174af0 |
?GetModules@ILogConfiguration@Events@Applications@Microsoft@@QEAAAEAV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$shared_ptr@VIModule@Events@Applications@Microsoft@@@2@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$shared_ptr@VIModule@Events@Applications@Microsoft@@@2@@std@@@2@@std@@XZ | 160 | 0x140174d40 |
?GetName@EventProperties@Events@Applications@Microsoft@@QEBAAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ | 161 | 0x1400855e0 |
?GetPersistence@EventProperties@Events@Applications@Microsoft@@QEBA?AW4EventPersistence@234@XZ | 162 | 0x140172540 |
?GetPiiProperties@EventProperties@Events@Applications@Microsoft@@QEBA?BV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$pair@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@Events@Applications@Microsoft@@@2@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@U?$pair@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@Events@Application | 163 | 0x140172550 |
?GetPolicyBitFlags@EventProperties@Events@Applications@Microsoft@@QEBA_KXZ | 164 | 0x1401727c0 |
?GetPopSample@EventProperties@Events@Applications@Microsoft@@QEBANXZ | 165 | 0x1401727d0 |
?GetPriority@EventProperties@Events@Applications@Microsoft@@QEBA?AW4EventPriority@234@XZ | 166 | 0x140172530 |
?GetProperties@EventProperties@Events@Applications@Microsoft@@QEBAAEBV?$map@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@U?$less@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@V?$allocator@U?$pair@$$CBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@Events@Applications@Microsoft@@@std@@@2@@std@@W4DataCategory@234@@Z | 167 | 0x1401727e0 |
?GetTimestamp@EventProperties@Events@Applications@Microsoft@@QEBA_JXZ | 168 | 0x140172800 |
?GetType@EventProperties@Events@Applications@Microsoft@@QEBAAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ | 169 | 0x140172810 |
?HasConfig@ILogConfiguration@Events@Applications@Microsoft@@QEAA_NPEBD@Z | 170 | 0x140174d50 |
?Hash@GUID_t@Events@Applications@Microsoft@@QEBA_KXZ | 171 | 0x1401781c0 |
?Initialize@IModule@Events@Applications@Microsoft@@UEAAXPEAVILogManager@234@@Z | 172 | 0x1400299a0 |
?Release@LogManagerProvider@Events@Applications@Microsoft@@SA?AW4status_t@234@AEAVILogConfiguration@234@@Z | 173 | 0x1401751c0 |
?Release@LogManagerProvider@Events@Applications@Microsoft@@SA?AW4status_t@234@PEBD@Z | 174 | 0x1401751f0 |
?RemoveEventListener@DebugEventSource@Events@Applications@Microsoft@@UEAAXW4DebugEventType@234@AEAVDebugEventListener@234@@Z | 175 | 0x140170b60 |
?SetAppEnv@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 176 | 0x14016b7f0 |
?SetAppExperimentETag@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 177 | 0x14016b8e0 |
?SetAppExperimentIds@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 178 | 0x14016b9e0 |
?SetAppExperimentImpressionId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 179 | 0x14016bad0 |
?SetAppId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 180 | 0x14016bbc0 |
?SetAppLanguage@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 181 | 0x14016bcb0 |
?SetAppName@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 182 | 0x14016bda0 |
?SetAppVersion@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 183 | 0x14016be90 |
?SetCommercialId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 184 | 0x14016bf80 |
?SetCommonField@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEBUEventProperty@234@@Z | 185 | 0x1400299a0 |
?SetCustomField@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEBUEventProperty@234@@Z | 186 | 0x1400299a0 |
?SetDeviceClass@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 187 | 0x14016c070 |
?SetDeviceId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 188 | 0x14016c160 |
?SetDeviceMake@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 189 | 0x14016c250 |
?SetDeviceModel@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 190 | 0x14016c340 |
?SetDeviceOrgId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 191 | 0x14016c430 |
?SetEventExperimentIds@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0@Z | 192 | 0x1400299a0 |
?SetLatency@EventProperties@Events@Applications@Microsoft@@QEAAXW4EventLatency@234@@Z | 193 | 0x140172820 |
?SetLevel@EventProperties@Events@Applications@Microsoft@@QEAAXE@Z | 194 | 0x14016c520 |
?SetName@EventProperties@Events@Applications@Microsoft@@QEAA_NAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 195 | 0x140172830 |
?SetNetworkCost@ISemanticContext@Events@Applications@Microsoft@@UEAAXW4NetworkCost@234@@Z | 196 | 0x14016c5e0 |
?SetNetworkProvider@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 197 | 0x14016c710 |
?SetNetworkType@ISemanticContext@Events@Applications@Microsoft@@UEAAXW4NetworkType@234@@Z | 198 | 0x14016c800 |
?SetOsBuild@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 199 | 0x14016c930 |
?SetOsName@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 200 | 0x14016ca20 |
?SetOsVersion@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 201 | 0x14016cb10 |
?SetPersistence@EventProperties@Events@Applications@Microsoft@@QEAAXW4EventPersistence@234@@Z | 202 | 0x140172970 |
?SetPolicyBitFlags@EventProperties@Events@Applications@Microsoft@@QEAAX_K@Z | 203 | 0x140172980 |
?SetPopsample@EventProperties@Events@Applications@Microsoft@@QEAAXN@Z | 204 | 0x140172990 |
?SetPriority@EventProperties@Events@Applications@Microsoft@@QEAAXW4EventPriority@234@@Z | 205 | 0x1401729a0 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@0W4PiiKind@234@W4DataCategory@234@@Z | 206 | 0x1401729e0 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@NV?$allocator@N@std@@@6@W4PiiKind@234@W4DataCategory@234@@Z | 207 | 0x140172a30 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@UGUID_t@Events@Applications@Microsoft@@V?$allocator@UGUID_t@Events@Applications@Microsoft@@@std@@@6@W4PiiKind@234@W4DataCategory@234@@Z | 208 | 0x140172a80 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@V?$allocator@V?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@2@@6@W4PiiKind@234@W4DataCategory@234@@Z | 209 | 0x140172ad0 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AEAV?$vector@_JV?$allocator@_J@std@@@6@W4PiiKind@234@W4DataCategory@234@@Z | 210 | 0x140172b20 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@CW4PiiKind@234@W4DataCategory@234@@Z | 211 | 0x14016cc00 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@EW4PiiKind@234@W4DataCategory@234@@Z | 212 | 0x14016cc10 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@FW4PiiKind@234@W4DataCategory@234@@Z | 213 | 0x14016cc20 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@GW4PiiKind@234@W4DataCategory@234@@Z | 214 | 0x14016cc30 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@HW4PiiKind@234@W4DataCategory@234@@Z | 215 | 0x14016cc40 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@IW4PiiKind@234@W4DataCategory@234@@Z | 216 | 0x14016cc50 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@NW4PiiKind@234@W4DataCategory@234@@Z | 217 | 0x140172b70 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@PEBDW4PiiKind@234@W4DataCategory@234@@Z | 218 | 0x140172bc0 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UEventProperty@234@@Z | 219 | 0x140172c10 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@UGUID_t@234@W4PiiKind@234@W4DataCategory@234@@Z | 220 | 0x140172d10 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@Utime_ticks_t@234@W4PiiKind@234@W4DataCategory@234@@Z | 221 | 0x140172d60 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_JW4PiiKind@234@W4DataCategory@234@@Z | 222 | 0x140172dc0 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_KW4PiiKind@234@W4DataCategory@234@@Z | 223 | 0x14016cc60 |
?SetProperty@EventProperties@Events@Applications@Microsoft@@QEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@_NW4PiiKind@234@W4DataCategory@234@@Z | 224 | 0x140172e10 |
?SetTicket@ISemanticContext@Events@Applications@Microsoft@@UEAAXW4TicketType@234@AEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 225 | 0x1400299a0 |
?SetTimestamp@EventProperties@Events@Applications@Microsoft@@QEAAX_J@Z | 226 | 0x140172e60 |
?SetType@EventProperties@Events@Applications@Microsoft@@QEAA_NAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 227 | 0x140172e70 |
?SetUserANID@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 228 | 0x14016cc70 |
?SetUserAdvertisingId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 229 | 0x14016cd60 |
?SetUserId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4PiiKind@234@@Z | 230 | 0x14016ce50 |
?SetUserLanguage@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 231 | 0x14016cf30 |
?SetUserMsaId@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 232 | 0x14016d020 |
?SetUserTimeZone@ISemanticContext@Events@Applications@Microsoft@@UEAAXAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@@Z | 233 | 0x14016d110 |
?Teardown@IModule@Events@Applications@Microsoft@@UEAAXXZ | 234 | 0x1400299a0 |
?TryGetLevel@EventProperties@Events@Applications@Microsoft@@QEBA?AV?$tuple@_NE@std@@XZ | 235 | 0x140173010 |
?clear@EventProperty@Events@Applications@Microsoft@@QEAAXXZ | 236 | 0x140178380 |
?convertUintVectorToGUID@GUID_t@Events@Applications@Microsoft@@SA?AU_GUID@@AEBV?$vector@EV?$allocator@E@std@@@std@@@Z | 237 | 0x140178430 |
?copydata@EventProperty@Events@Applications@Microsoft@@AEAAXPEBU1234@@Z | 238 | 0x140178490 |
?empty@EventProperty@Events@Applications@Microsoft@@QEAA_NXZ | 239 | 0x140178620 |
?erase@EventProperties@Events@Applications@Microsoft@@QEAA_KAEBV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@W4DataCategory@234@@Z | 240 | 0x1401733f0 |
?lock@?1??stateLock@DebugEventSource@Events@Applications@Microsoft@@KAAEAVrecursive_mutex@std@@XZ@4V67@A | 241 | 0x1403e1610 |
?pack@EventProperties@Events@Applications@Microsoft@@QEAAPEAUevt_prop@@XZ | 242 | 0x140173410 |
?stateLock@DebugEventSource@Events@Applications@Microsoft@@KAAEAVrecursive_mutex@std@@XZ | 243 | 0x14016fbc0 |
?to_bytes@GUID_t@Events@Applications@Microsoft@@QEBAXAEAY0BA@E@Z | 244 | 0x140178650 |
?to_string@EventProperty@Events@Applications@Microsoft@@UEBA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ | 245 | 0x1401786a0 |
?to_string@GUID_t@Events@Applications@Microsoft@@QEBA?AV?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@XZ | 246 | 0x140178f50 |
?type_name@EventProperty@Events@Applications@Microsoft@@SAPEBDI@Z | 247 | 0x140178f70 |
?unpack@EventProperties@Events@Applications@Microsoft@@QEAA_NPEAUevt_prop@@_K@Z | 248 | 0x1401736e0 |
evt_api_call_default | 249 | 0x140167850 |
Language of compilation system | Country where language is spoken | Map |
---|---|---|
English | United States |
Click to jump to process
Click to jump to process
back
Click to dive into process behavior distribution
Target ID: | 0 |
Start time: | 19:40:35 |
Start date: | 04/07/2024 |
Path: | C:\Users\user\Desktop\OneDriveUpdater.exe |
Wow64 process (32bit): | false |
Commandline: | |
Imagebase: | 0x7ff7c4000000 |
File size: | 4'200'864 bytes |
MD5 hash: | 792E95B64B9CF45AC8BC10D4D0F077C2 |
Has elevated privileges: | true |
Has administrator privileges: | true |
Programmed in: | C, C++ or other language |
Reputation: | low |
Has exited: | false |
Execution Graph
Execution Coverage: | 7.5% |
Dynamic/Decrypted Code Coverage: | 0% |
Signature Coverage: | 14.4% |
Total number of Nodes: | 2000 |
Total number of Limit Nodes: | 55 |
Graph
Function 00007FF7C40A97C0 Relevance: 156.9, APIs: 23, Strings: 65, Instructions: 2922COMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C412A8E0 Relevance: 143.7, APIs: 41, Strings: 40, Instructions: 1907registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4010490 Relevance: 78.5, APIs: 22, Strings: 22, Instructions: 1535COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41317B8 Relevance: 73.3, APIs: 1, Strings: 40, Instructions: 1520COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4026C30 Relevance: 51.6, APIs: 6, Strings: 23, Instructions: 868COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4103E90 Relevance: 46.3, APIs: 9, Strings: 17, Instructions: 808COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4014748 Relevance: 36.0, APIs: 7, Strings: 13, Instructions: 960COMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41129C0 Relevance: 32.0, APIs: 5, Strings: 13, Instructions: 529COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E1558 Relevance: 32.0, APIs: 2, Strings: 16, Instructions: 480synchronizationCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C406521C Relevance: 30.1, APIs: 8, Strings: 9, Instructions: 349filetimeCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4120034 Relevance: 27.2, APIs: 18, Instructions: 233encryptionCOMMON
Control-flow Graph
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C411BE6C Relevance: 26.6, APIs: 9, Strings: 6, Instructions: 348COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4025280 Relevance: 25.0, APIs: 1, Strings: 13, Instructions: 493COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4110E98 Relevance: 17.6, APIs: 9, Strings: 1, Instructions: 118encryptionCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E091C Relevance: 16.0, APIs: 4, Strings: 5, Instructions: 278filesynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4030EC4 Relevance: 16.0, APIs: 5, Strings: 4, Instructions: 227fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41107BC Relevance: 14.4, APIs: 4, Strings: 4, Instructions: 387registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C403125C Relevance: 14.2, APIs: 5, Strings: 3, Instructions: 178fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4061D0C Relevance: 10.8, APIs: 7, Instructions: 286COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4113C64 Relevance: 10.6, APIs: 7, Instructions: 143encryptionCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4111748 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 159COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4139C30 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 108processCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40648E8 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 80timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40642AC Relevance: 6.1, APIs: 2, Strings: 2, Instructions: 102COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4105810 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 53comCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4013820 Relevance: 33.9, APIs: 3, Strings: 16, Instructions: 621COMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4105CF0 Relevance: 26.4, APIs: 7, Strings: 8, Instructions: 168synchronizationCOMMON
Control-flow Graph
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40A0584 Relevance: 25.0, APIs: 8, Strings: 6, Instructions: 482COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C401BD50 Relevance: 21.3, APIs: 5, Strings: 7, Instructions: 315COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4105208 Relevance: 19.6, APIs: 4, Strings: 7, Instructions: 351synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4012200 Relevance: 19.5, APIs: 2, Strings: 9, Instructions: 234COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4105FC0 Relevance: 19.5, APIs: 5, Strings: 6, Instructions: 215synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4028450 Relevance: 17.7, APIs: 3, Strings: 7, Instructions: 180COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4106D60 Relevance: 17.7, APIs: 6, Strings: 4, Instructions: 159filesynchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C401602C Relevance: 17.6, APIs: 6, Strings: 4, Instructions: 122COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41050CC Relevance: 17.6, APIs: 4, Strings: 6, Instructions: 79synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4106FC8 Relevance: 16.0, APIs: 6, Strings: 3, Instructions: 288COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4124258 Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 164registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4015C14 Relevance: 15.9, APIs: 5, Strings: 4, Instructions: 139sleepCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C401E994 Relevance: 14.2, APIs: 3, Strings: 5, Instructions: 234COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4116324 Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 137COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C410359C Relevance: 14.1, APIs: 6, Strings: 2, Instructions: 118memoryfileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41080D0 Relevance: 14.1, APIs: 4, Strings: 4, Instructions: 99synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4107DF0 Relevance: 14.1, APIs: 2, Strings: 6, Instructions: 60COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C410DD5C Relevance: 12.4, APIs: 3, Strings: 4, Instructions: 160COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41063D8 Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 154synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4064D10 Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 122COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4053440 Relevance: 12.4, APIs: 5, Strings: 2, Instructions: 117COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4104D88 Relevance: 12.3, APIs: 5, Strings: 2, Instructions: 91registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40F78C8 Relevance: 10.8, APIs: 2, Strings: 4, Instructions: 274COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C410FE2C Relevance: 10.7, APIs: 4, Strings: 2, Instructions: 187COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4110600 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 106COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4107A3C Relevance: 10.6, APIs: 3, Strings: 3, Instructions: 103COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4012E00 Relevance: 10.6, APIs: 2, Strings: 4, Instructions: 94synchronizationCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4106684 Relevance: 10.6, APIs: 4, Strings: 2, Instructions: 90COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4028218 Relevance: 10.6, APIs: 1, Strings: 5, Instructions: 71COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4028334 Relevance: 10.6, APIs: 1, Strings: 5, Instructions: 71COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4080440 Relevance: 9.2, APIs: 2, Strings: 3, Instructions: 488COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40267E0 Relevance: 9.0, APIs: 2, Strings: 3, Instructions: 282COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E82C8 Relevance: 9.0, APIs: 2, Strings: 3, Instructions: 249COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C401C5CC Relevance: 9.0, APIs: 2, Strings: 3, Instructions: 210COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C408B578 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 183COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40F9730 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 169COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41246E0 Relevance: 8.9, APIs: 4, Strings: 1, Instructions: 162COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40F94D0 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 159COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4111978 Relevance: 8.9, APIs: 1, Strings: 4, Instructions: 119COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C408B484 Relevance: 8.8, APIs: 2, Strings: 3, Instructions: 65COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4105AB4 Relevance: 8.8, APIs: 3, Strings: 2, Instructions: 45COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C410EE14 Relevance: 7.8, APIs: 1, Strings: 4, Instructions: 310COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E62F4 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 201COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4088E50 Relevance: 7.2, APIs: 1, Strings: 3, Instructions: 187COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4065DD0 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 131COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4085BE8 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 128COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E6630 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 128COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40A03E4 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 117COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40954F0 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 111COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4124240 Relevance: 7.1, APIs: 2, Strings: 2, Instructions: 64libraryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4016228 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 63COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C410E590 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 60registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C411AF40 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 57registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E2720 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 55COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4116AA8 Relevance: 7.0, APIs: 1, Strings: 3, Instructions: 48COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4134FFC Relevance: 6.0, APIs: 1, Strings: 3, Instructions: 40COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41350A8 Relevance: 6.0, APIs: 1, Strings: 3, Instructions: 40COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E8E90 Relevance: 5.5, APIs: 1, Strings: 2, Instructions: 203COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4080EEC Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 152fileCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4135C10 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 139COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40E01A0 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 101COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4076D98 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 91COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C411F868 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 88COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4113F98 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 65COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41244F4 Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 61COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C411FC24 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 59COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41059E4 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 48registryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41123C0 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 44COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C401C900 Relevance: 5.3, APIs: 1, Strings: 2, Instructions: 30COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C410EA74 Relevance: 4.6, APIs: 3, Instructions: 129registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C410EC54 Relevance: 4.6, APIs: 3, Instructions: 119registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4038858 Relevance: 4.5, APIs: 3, Instructions: 29COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4024BCC Relevance: 3.8, APIs: 1, Strings: 1, Instructions: 288COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4139968 Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 182COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C414591C Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 163COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4077024 Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 158COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C412FE98 Relevance: 3.7, APIs: 1, Strings: 1, Instructions: 151COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40A5C78 Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 130COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C408676C Relevance: 3.6, APIs: 1, Strings: 1, Instructions: 112COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4125438 Relevance: 3.5, APIs: 1, Strings: 1, Instructions: 38COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4071CA0 Relevance: 3.1, APIs: 2, Instructions: 121registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C401A488 Relevance: 3.1, APIs: 2, Instructions: 118COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4052E8C Relevance: 3.0, APIs: 2, Instructions: 46COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C401B82C Relevance: 3.0, APIs: 2, Instructions: 33COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4050F00 Relevance: 3.0, APIs: 2, Instructions: 19threadCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C42CDA0C Relevance: 1.6, APIs: 1, Instructions: 105COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4061BF0 Relevance: 1.6, APIs: 1, Instructions: 74COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4019AF8 Relevance: 1.6, APIs: 1, Instructions: 72COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4048D64 Relevance: 1.5, APIs: 1, Instructions: 41COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4051870 Relevance: 1.5, APIs: 1, Instructions: 36memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4054E88 Relevance: 1.5, APIs: 1, Instructions: 29memoryCOMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41241D0 Relevance: 44.3, APIs: 13, Strings: 12, Instructions: 572libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C416C520 Relevance: 37.2, APIs: 7, Strings: 14, Instructions: 473COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41AC7A0 Relevance: 23.5, APIs: 5, Strings: 8, Instructions: 704COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4114714 Relevance: 23.3, APIs: 7, Strings: 6, Instructions: 562COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4158570 Relevance: 13.7, APIs: 5, Strings: 2, Instructions: 1497COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4058914 Relevance: 10.7, APIs: 7, Instructions: 171COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40B8874 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 156COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C413C7E0 Relevance: 7.9, APIs: 5, Instructions: 359registryCOMMON
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4058228 Relevance: 1.6, APIs: 1, Instructions: 61COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40582F8 Relevance: 1.5, APIs: 1, Instructions: 41COMMONLIBRARYCODE
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C42B4600 Relevance: .7, Instructions: 668COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4190154 Relevance: .3, Instructions: 306COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4174120 Relevance: .3, Instructions: 306COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C42B8130 Relevance: .2, Instructions: 249COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C42B81B0 Relevance: .2, Instructions: 199COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C42B8850 Relevance: .0, Instructions: 40COMMON
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C419C344 Relevance: 40.7, APIs: 13, Strings: 10, Instructions: 415COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4194144 Relevance: 24.8, APIs: 12, Strings: 2, Instructions: 301libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4038250 Relevance: 21.1, APIs: 8, Strings: 4, Instructions: 61libraryloaderCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4034560 Relevance: 15.9, APIs: 3, Strings: 6, Instructions: 143timeCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
APIs |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40B02E0 Relevance: 14.2, APIs: 3, Strings: 5, Instructions: 185COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40FC834 Relevance: 12.6, APIs: 3, Strings: 4, Instructions: 354COMMON
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41B45C0 Relevance: 12.4, APIs: 4, Strings: 3, Instructions: 180COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40C07AC Relevance: 10.7, APIs: 5, Strings: 1, Instructions: 187memoryCOMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C419C154 Relevance: 10.6, APIs: 1, Strings: 5, Instructions: 112COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4138644 Relevance: 9.0, APIs: 2, Strings: 3, Instructions: 201COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40F4224 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 157COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41B4850 Relevance: 8.9, APIs: 2, Strings: 3, Instructions: 126COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C403C6E0 Relevance: 7.2, APIs: 2, Strings: 2, Instructions: 191COMMONLIBRARYCODE
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4018830 Relevance: 7.2, APIs: 1, Strings: 3, Instructions: 176COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C40C0594 Relevance: 7.1, APIs: 1, Strings: 3, Instructions: 147COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4184854 Relevance: 7.1, APIs: 3, Strings: 1, Instructions: 116COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41982F8 Relevance: 5.5, APIs: 2, Strings: 1, Instructions: 235COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C41B4220 Relevance: 5.4, APIs: 2, Strings: 1, Instructions: 163COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C4018630 Relevance: 5.4, APIs: 1, Strings: 2, Instructions: 124COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|
Function 00007FF7C405C1AC Relevance: 5.3, APIs: 2, Strings: 1, Instructions: 58COMMON
APIs |
|
Strings |
|
Memory Dump Source |
|
|
Joe Sandbox IDA Plugin |
|
Similarity |
|