Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
m6tly2Aqw4.exe

Overview

General Information

Sample name:m6tly2Aqw4.exe
renamed because original name is a hash value
Original sample name:0f54220218afb5d0ea00fb8033509c773e3e8b3d.exe
Analysis ID:1546803
MD5:51d4e15fa77cf644ee90f42269bced3b
SHA1:0f54220218afb5d0ea00fb8033509c773e3e8b3d
SHA256:cc05a4b105428e0c1bd13525c5cab229e67a9eb9ec77b92b158fe6fe419929f6
Tags:exeReversingLabsuser-NDA0E
Infos:

Detection

FloodFix
Score:100
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Antivirus / Scanner detection for submitted sample
Antivirus detection for dropped file
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Yara detected FloodFix
AI detected suspicious sample
Allows loading of unsigned dll using appinit_dll
Creates an undocumented autostart registry key
Hides threads from debuggers
Machine Learning detection for dropped file
Machine Learning detection for sample
PE file has nameless sections
Dropped file seen in connection with other malware
Drops PE files
Enables debug privileges
Found dropped PE file which has not been started or loaded
Found potential string decryption / allocating functions
May sleep (evasive loops) to hinder dynamic analysis
PE file contains an invalid checksum
PE file contains sections with non-standard names
Sample file is different than original file name gathered from version info
Sigma detected: Wow6432Node Windows NT CurrentVersion Autorun Keys Modification
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • m6tly2Aqw4.exe (PID: 3252 cmdline: "C:\Users\user\Desktop\m6tly2Aqw4.exe" MD5: 51D4E15FA77CF644EE90F42269BCED3B)
  • cleanup
No configs have been found
SourceRuleDescriptionAuthorStrings
C:\Program Files\Common Files\System\symsrv.dllJoeSecurity_FloodFixYara detected FloodFixJoe Security
    C:\Program Files\Common Files\System\symsrv.dllMAL_Floxif_GenericDetects Floxif MalwareFlorian Roth
      C:\Program Files\Common Files\System\symsrv.dllMALWARE_Win_FloodFixDetects FloodFixditekSHen
        SourceRuleDescriptionAuthorStrings
        0.2.m6tly2Aqw4.exe.10000000.3.unpackJoeSecurity_FloodFixYara detected FloodFixJoe Security
          0.2.m6tly2Aqw4.exe.10000000.3.unpackMAL_Floxif_GenericDetects Floxif MalwareFlorian Roth
            0.2.m6tly2Aqw4.exe.10000000.3.unpackMALWARE_Win_FloodFixDetects FloodFixditekSHen

              System Summary

              barindex
              Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\PROGRA~1\COMMON~1\System\symsrv.dll, EventID: 13, EventType: SetValue, Image: C:\Users\user\Desktop\m6tly2Aqw4.exe, ProcessId: 3252, TargetObject: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs
              No Suricata rule has matched

              Click to jump to signature section

              Show All Signature Results

              AV Detection

              barindex
              Source: m6tly2Aqw4.exeAvira: detected
              Source: C:\Program Files\Common Files\System\symsrv.dllAvira: detection malicious, Label: TR/Floxif.BB
              Source: C:\Program Files\Common Files\System\symsrv.dllReversingLabs: Detection: 100%
              Source: m6tly2Aqw4.exeReversingLabs: Detection: 92%
              Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
              Source: C:\Program Files\Common Files\System\symsrv.dllJoe Sandbox ML: detected
              Source: m6tly2Aqw4.exeJoe Sandbox ML: detected
              Source: m6tly2Aqw4.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeDirectory created: C:\Program Files\Common Files\System\symsrv.dllJump to behavior

              Spreading

              barindex
              Source: Yara matchFile source: 0.2.m6tly2Aqw4.exe.10000000.3.unpack, type: UNPACKEDPE
              Source: Yara matchFile source: C:\Program Files\Common Files\System\symsrv.dll, type: DROPPED
              Source: m6tly2Aqw4.exe, 00000000.00000003.2074705008.00000000015A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://5isohu.com/
              Source: m6tly2Aqw4.exeString found in binary or memory: http://crl.comodoca.com/COMODORSACertificationAuthority.crl0q
              Source: m6tly2Aqw4.exeString found in binary or memory: http://crl.comodoca.com/COMODORSACodeSigningCA.crl0t
              Source: m6tly2Aqw4.exeString found in binary or memory: http://ocsp.comodoca.com0
              Source: m6tly2Aqw4.exe, 00000000.00000003.2074705008.00000000015A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.aieov.com/
              Source: m6tly2Aqw4.exe, 00000000.00000003.2074705008.00000000015A4000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.aieov.com/#

              System Summary

              barindex
              Source: 0.2.m6tly2Aqw4.exe.10000000.3.unpack, type: UNPACKEDPEMatched rule: Detects Floxif Malware Author: Florian Roth
              Source: 0.2.m6tly2Aqw4.exe.10000000.3.unpack, type: UNPACKEDPEMatched rule: Detects FloodFix Author: ditekSHen
              Source: C:\Program Files\Common Files\System\symsrv.dll, type: DROPPEDMatched rule: Detects Floxif Malware Author: Florian Roth
              Source: C:\Program Files\Common Files\System\symsrv.dll, type: DROPPEDMatched rule: Detects FloodFix Author: ditekSHen
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: Joe Sandbox ViewDropped File: C:\Program Files\Common Files\System\symsrv.dll DE055A89DE246E629A8694BDE18AF2B1605E4B9B493C7E4AEF669DD67ACF5085
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: String function: 006E8EEC appears 77 times
              Source: m6tly2Aqw4.exe, 00000000.00000003.2074705008.00000000015A0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: originalfilename cintanotes.exe 6 vs m6tly2Aqw4.exe
              Source: m6tly2Aqw4.exe, 00000000.00000002.2122138799.00000000006AF000.00000080.00000001.01000000.00000003.sdmpBinary or memory string: OriginalFilenamecintanotes.exe6 vs m6tly2Aqw4.exe
              Source: m6tly2Aqw4.exe, 00000000.00000002.2124690859.000000001002F000.00000004.00000001.01000000.00000004.sdmpBinary or memory string: OriginalFilenameLanguagePack vs m6tly2Aqw4.exe
              Source: m6tly2Aqw4.exe, 00000000.00000003.2074648577.0000000003AC0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameLanguagePack vs m6tly2Aqw4.exe
              Source: m6tly2Aqw4.exeBinary or memory string: OriginalFilenamecintanotes.exe6 vs m6tly2Aqw4.exe
              Source: m6tly2Aqw4.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
              Source: 0.2.m6tly2Aqw4.exe.10000000.3.unpack, type: UNPACKEDPEMatched rule: MAL_Floxif_Generic date = 2018-05-11, author = Florian Roth, description = Detects Floxif Malware, score = de055a89de246e629a8694bde18af2b1605e4b9b493c7e4aef669dd67acf5085, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: 0.2.m6tly2Aqw4.exe.10000000.3.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_FloodFix author = ditekSHen, description = Detects FloodFix
              Source: C:\Program Files\Common Files\System\symsrv.dll, type: DROPPEDMatched rule: MAL_Floxif_Generic date = 2018-05-11, author = Florian Roth, description = Detects Floxif Malware, score = de055a89de246e629a8694bde18af2b1605e4b9b493c7e4aef669dd67acf5085, reference = Internal Research, license = https://creativecommons.org/licenses/by-nc/4.0/
              Source: C:\Program Files\Common Files\System\symsrv.dll, type: DROPPEDMatched rule: MALWARE_Win_FloodFix author = ditekSHen, description = Detects FloodFix
              Source: m6tly2Aqw4.exeStatic PE information: Section: ZLIB complexity 1.0001057103737114
              Source: m6tly2Aqw4.exeStatic PE information: Section: ZLIB complexity 0.9927026098901099
              Source: classification engineClassification label: mal100.troj.evad.winEXE@1/1@0/0
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeFile created: C:\Program Files\Common Files\System\symsrv.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeKey opened: HKEY_CURRENT_USER\Software\Borland\Delphi\LocalesJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
              Source: m6tly2Aqw4.exeReversingLabs: Detection: 92%
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeFile read: C:\Users\user\Desktop\m6tly2Aqw4.exeJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: apphelp.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: version.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: msimg32.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: winmm.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: wininet.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: dnsapi.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: wtsapi32.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: iphlpapi.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: sspicli.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: msasn1.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: ws2help.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: shfolder.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: windows.storage.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: wldp.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeSection loaded: profapi.dllJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeDirectory created: C:\Program Files\Common Files\System\symsrv.dllJump to behavior
              Source: m6tly2Aqw4.exeStatic PE information: More than 223 > 100 exports found
              Source: m6tly2Aqw4.exeStatic file information: File size 4594535 > 1048576
              Source: m6tly2Aqw4.exeStatic PE information: Raw size of is bigger than: 0x100000 < 0x1a9200
              Source: m6tly2Aqw4.exeStatic PE information: Raw size of .textTh is bigger than: 0x100000 < 0x1fca00
              Source: symsrv.dll.0.drStatic PE information: real checksum: 0x0 should be: 0x1f436
              Source: m6tly2Aqw4.exeStatic PE information: real checksum: 0x457c41 should be: 0x4658e3
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name:
              Source: m6tly2Aqw4.exeStatic PE information: section name: .textTh
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FF020 push ecx; mov dword ptr [esp], edx0_2_006FF022
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EC0AC push 006EC1C8h; ret 0_2_006EC1C0
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FE0A4 push ecx; mov dword ptr [esp], ecx0_2_006FE0A9
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006F3168 push ecx; mov dword ptr [esp], edx0_2_006F316D
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EB148 push 006EB199h; ret 0_2_006EB191
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FB1F8 push 006FB258h; ret 0_2_006FB250
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FB2AE push 006FB3C4h; ret 0_2_006FB3BC
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FC349 push esp; ret 0_2_006FC351
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EB43C push 006EB468h; ret 0_2_006EB460
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EB402 push 006EB430h; ret 0_2_006EB428
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_0070369F push 007036E3h; ret 0_2_007036DB
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_007038D4 push 00703900h; ret 0_2_007038F8
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_00703890 push 007038BCh; ret 0_2_007038B4
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_0070292C push ecx; mov dword ptr [esp], edx0_2_00702931
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FC9FA push esp; retf 006Fh0_2_006FCA09
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FCA28 push esp; retf 006Fh0_2_006FCA29
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006F3A0A push 006F3A7Bh; ret 0_2_006F3A73
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FBB60 push 006FBBADh; ret 0_2_006FBBA5
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006ECB34 pushad ; retf 0_2_006ECB35
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FCB1C push ecx; mov dword ptr [esp], edx0_2_006FCB21
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_00701B04 push ecx; mov dword ptr [esp], edx0_2_00701B06
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EBBD4 push 006EBC00h; ret 0_2_006EBBF8
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006F3B8E push 006F3BBCh; ret 0_2_006F3BB4
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_00702C56 push 00702D03h; ret 0_2_00702CFB
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EBC54 push 006EBC80h; ret 0_2_006EBC78
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EBC1A push 006EBC48h; ret 0_2_006EBC40
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FACBE push 006FAD3Dh; ret 0_2_006FAD35
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006E7CB0 push eax; ret 0_2_006E7CEC
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006EBD5D push 006EBD88h; ret 0_2_006EBD80
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_00702D08 push 00702D98h; ret 0_2_00702D90
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeCode function: 0_2_006FCD10 push ecx; mov dword ptr [esp], edx0_2_006FCD15
              Source: m6tly2Aqw4.exeStatic PE information: section name: entropy: 7.999484842813451
              Source: m6tly2Aqw4.exeStatic PE information: section name: entropy: 7.986548844569612
              Source: m6tly2Aqw4.exeStatic PE information: section name: entropy: 7.965397455300278
              Source: initial sampleStatic PE information: section name: UPX0
              Source: initial sampleStatic PE information: section name: UPX1
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeFile created: C:\Program Files\Common Files\System\symsrv.dllJump to dropped file

              Boot Survival

              barindex
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeRegistry value created: RequireSignedAppInit_DLLs 0Jump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows AppInit_DLLsJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeKey value created or modified: HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\Windows LoadAppInit_DLLsJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeDropped PE file which has not been started: C:\Program Files\Common Files\System\symsrv.dllJump to dropped file
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exe TID: 2716Thread sleep count: 289 > 30Jump to behavior
              Source: m6tly2Aqw4.exe, 00000000.00000002.2122169113.00000000006E5000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: VBoxService.exe
              Source: m6tly2Aqw4.exe, 00000000.00000002.2122169113.000000000078E000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: ~VirtualMachineTypes
              Source: m6tly2Aqw4.exe, 00000000.00000002.2122169113.000000000078E000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: ]DLL_Loader_VirtualMachine
              Source: m6tly2Aqw4.exe, 00000000.00000002.2122169113.00000000006E5000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: VMWare
              Source: m6tly2Aqw4.exe, 00000000.00000002.2122169113.000000000078E000.00000040.00000001.01000000.00000003.sdmpBinary or memory string: DLL_Loader_Marker]DLL_Loader_VirtualMachineZDLL_Loader_Reloc_Unit

              Anti Debugging

              barindex
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeThread information set: HideFromDebuggerJump to behavior
              Source: C:\Users\user\Desktop\m6tly2Aqw4.exeProcess token adjusted: DebugJump to behavior
              ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
              Gather Victim Identity InformationAcquire InfrastructureValid AccountsWindows Management Instrumentation1
              DLL Side-Loading
              1
              DLL Side-Loading
              2
              Masquerading
              OS Credential Dumping21
              Security Software Discovery
              Remote ServicesData from Local SystemData ObfuscationExfiltration Over Other Network MediumAbuse Accessibility Features
              CredentialsDomainsDefault AccountsScheduled Task/Job2
              Registry Run Keys / Startup Folder
              2
              Registry Run Keys / Startup Folder
              11
              Virtualization/Sandbox Evasion
              LSASS Memory11
              Virtualization/Sandbox Evasion
              Remote Desktop ProtocolData from Removable MediaJunk DataExfiltration Over BluetoothNetwork Denial of Service
              Email AddressesDNS ServerDomain AccountsAtLogon Script (Windows)Logon Script (Windows)21
              Software Packing
              Security Account Manager1
              System Information Discovery
              SMB/Windows Admin SharesData from Network Shared DriveSteganographyAutomated ExfiltrationData Encrypted for Impact
              Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
              Deobfuscate/Decode Files or Information
              NTDSSystem Network Configuration DiscoveryDistributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
              Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
              DLL Side-Loading
              LSA SecretsInternet Connection DiscoverySSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
              Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts31
              Obfuscated Files or Information
              Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
              Hide Legend

              Legend:

              • Process
              • Signature
              • Created File
              • DNS/IP Info
              • Is Dropped
              • Is Windows Process
              • Number of created Registry Values
              • Number of created Files
              • Visual Basic
              • Delphi
              • Java
              • .Net C# or VB.NET
              • C, C++ or other language
              • Is malicious
              • Internet

              This section contains all screenshots as thumbnails, including those not shown in the slideshow.


              windows-stand
              SourceDetectionScannerLabelLink
              m6tly2Aqw4.exe92%ReversingLabsWin32.Virus.Floxif
              m6tly2Aqw4.exe100%AviraW32/Infector.Gen4
              m6tly2Aqw4.exe100%Joe Sandbox ML
              SourceDetectionScannerLabelLink
              C:\Program Files\Common Files\System\symsrv.dll100%AviraTR/Floxif.BB
              C:\Program Files\Common Files\System\symsrv.dll100%Joe Sandbox ML
              C:\Program Files\Common Files\System\symsrv.dll100%ReversingLabsWin32.Trojan.Floxif
              No Antivirus matches
              No Antivirus matches
              No Antivirus matches
              No contacted domains info
              NameSourceMaliciousAntivirus DetectionReputation
              http://5isohu.com/m6tly2Aqw4.exe, 00000000.00000003.2074705008.00000000015A4000.00000004.00000020.00020000.00000000.sdmpfalse
                unknown
                http://www.aieov.com/#m6tly2Aqw4.exe, 00000000.00000003.2074705008.00000000015A4000.00000004.00000020.00020000.00000000.sdmpfalse
                  unknown
                  http://www.aieov.com/m6tly2Aqw4.exe, 00000000.00000003.2074705008.00000000015A4000.00000004.00000020.00020000.00000000.sdmpfalse
                    unknown
                    No contacted IP infos
                    Joe Sandbox version:41.0.0 Charoite
                    Analysis ID:1546803
                    Start date and time:2024-11-01 15:59:58 +01:00
                    Joe Sandbox product:CloudBasic
                    Overall analysis duration:0h 3m 34s
                    Hypervisor based Inspection enabled:false
                    Report type:full
                    Cookbook file name:default.jbs
                    Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                    Number of analysed new started processes analysed:2
                    Number of new started drivers analysed:0
                    Number of existing processes analysed:0
                    Number of existing drivers analysed:0
                    Number of injected processes analysed:0
                    Technologies:
                    • HCA enabled
                    • EGA enabled
                    • AMSI enabled
                    Analysis Mode:default
                    Analysis stop reason:Timeout
                    Sample name:m6tly2Aqw4.exe
                    renamed because original name is a hash value
                    Original Sample Name:0f54220218afb5d0ea00fb8033509c773e3e8b3d.exe
                    Detection:MAL
                    Classification:mal100.troj.evad.winEXE@1/1@0/0
                    EGA Information:Failed
                    HCA Information:Failed
                    Cookbook Comments:
                    • Found application associated with file extension: .exe
                    • Stop behavior analysis, all processes terminated
                    • Exclude process from analysis (whitelisted): dllhost.exe
                    • Execution Graph export aborted for target m6tly2Aqw4.exe, PID 3252 because it is empty
                    • VT rate limit hit for: m6tly2Aqw4.exe
                    No simulations
                    No context
                    No context
                    No context
                    No context
                    MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                    C:\Program Files\Common Files\System\symsrv.dll2hp5ee36OS.exeGet hashmaliciousFloodFixBrowse
                      9dePCvDX8X.exeGet hashmaliciousFloodFixBrowse
                        ZYlsAQi8bj.exeGet hashmaliciousFloodFixBrowse
                          4g33Ui2SbU.exeGet hashmaliciousFloodFixBrowse
                            4afG8b79X5.exeGet hashmaliciousFloodFixBrowse
                              c9DQdpQLKz.exeGet hashmaliciousFloodFixBrowse
                                n64NG4zCN2.exeGet hashmaliciousFloodFixBrowse
                                  0vJrK0NCd1.exeGet hashmaliciousRemcos, DBatLoader, FloodFixBrowse
                                    jpeg_12.dllGet hashmaliciousFloodFixBrowse
                                      DHL_Shipping_Docs00945_pdf.exeGet hashmaliciousFloodFixBrowse
                                        Process:C:\Users\user\Desktop\m6tly2Aqw4.exe
                                        File Type:PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, UPX compressed
                                        Category:dropped
                                        Size (bytes):69337
                                        Entropy (8bit):7.734269834755614
                                        Encrypted:false
                                        SSDEEP:1536:YjV8y93KQpFQmPLRk7G50zy/riF12jvRyo0hQk7ZL:c8y93KQjy7G55riF1cMo03V
                                        MD5:7574CF2C64F35161AB1292E2F532AABF
                                        SHA1:14BA3FA927A06224DFE587014299E834DEF4644F
                                        SHA-256:DE055A89DE246E629A8694BDE18AF2B1605E4B9B493C7E4AEF669DD67ACF5085
                                        SHA-512:4DB19F2D8D5BC1C7BBB812D3FA9C43B80FA22140B346D2760F090B73AED8A5177EDB4BDDC647A6EBD5A2DB8565BE5A1A36A602B0D759E38540D9A584BA5896AB
                                        Malicious:true
                                        Yara Hits:
                                        • Rule: JoeSecurity_FloodFix, Description: Yara detected FloodFix, Source: C:\Program Files\Common Files\System\symsrv.dll, Author: Joe Security
                                        • Rule: MAL_Floxif_Generic, Description: Detects Floxif Malware, Source: C:\Program Files\Common Files\System\symsrv.dll, Author: Florian Roth
                                        • Rule: MALWARE_Win_FloodFix, Description: Detects FloodFix, Source: C:\Program Files\Common Files\System\symsrv.dll, Author: ditekSHen
                                        Antivirus:
                                        • Antivirus: Avira, Detection: 100%
                                        • Antivirus: Joe Sandbox ML, Detection: 100%
                                        • Antivirus: ReversingLabs, Detection: 100%
                                        Joe Sandbox View:
                                        • Filename: 2hp5ee36OS.exe, Detection: malicious, Browse
                                        • Filename: 9dePCvDX8X.exe, Detection: malicious, Browse
                                        • Filename: ZYlsAQi8bj.exe, Detection: malicious, Browse
                                        • Filename: 4g33Ui2SbU.exe, Detection: malicious, Browse
                                        • Filename: 4afG8b79X5.exe, Detection: malicious, Browse
                                        • Filename: c9DQdpQLKz.exe, Detection: malicious, Browse
                                        • Filename: n64NG4zCN2.exe, Detection: malicious, Browse
                                        • Filename: 0vJrK0NCd1.exe, Detection: malicious, Browse
                                        • Filename: jpeg_12.dll, Detection: malicious, Browse
                                        • Filename: DHL_Shipping_Docs00945_pdf.exe, Detection: malicious, Browse
                                        Reputation:moderate, very likely benign file
                                        Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......V.'...I...I...I.i.E...I.$.B...I..G...I.$.C.{.I.}.B...I.p.Z...I...H..I...B...I...O...I...M...I.Rich..I.................PE..L......P...........!................................................................................................(.......L...........L...........................................................................................................UPX0....................................UPX1................................@....rsrc...............................@......................................................................................................................................................................................................................................................................................................................................................................................2.03.UPX!....
                                        File type:PE32 executable (GUI) Intel 80386, for MS Windows
                                        Entropy (8bit):7.934926885361668
                                        TrID:
                                        • Win32 Executable (generic) a (10002005/4) 99.96%
                                        • Generic Win/DOS Executable (2004/3) 0.02%
                                        • DOS Executable Generic (2002/1) 0.02%
                                        • Autodesk FLIC Image File (extensions: flc, fli, cel) (7/3) 0.00%
                                        File name:m6tly2Aqw4.exe
                                        File size:4'594'535 bytes
                                        MD5:51d4e15fa77cf644ee90f42269bced3b
                                        SHA1:0f54220218afb5d0ea00fb8033509c773e3e8b3d
                                        SHA256:cc05a4b105428e0c1bd13525c5cab229e67a9eb9ec77b92b158fe6fe419929f6
                                        SHA512:e9472cce353b50936567f0ab02dfa12566442041b87a4838ecd5ddee0debedba95057336e440c6338e9209bebb2bc298b307cbec014bf00cf50b49096b580caf
                                        SSDEEP:98304:5OkDYUJQk3X/IRjWt76alE6b3Dg/eELhyYu7ftc0URBT:XM6UalF38/eENdAbU/T
                                        TLSH:6A262345F284DF69E0648032E40DD6F256F2BC2F8599AB43B6D17E4B3C7C602AEA351D
                                        File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........N .. s.. s.. s%..s.. s...s.. s..Ms.. s...s.. s..[s.. s..!st. s...se. s...s.. s...s.. s...s.. s...s.. sRich.. s...............
                                        Icon Hash:2c160f25079f33e7
                                        Entrypoint:0x54575a
                                        Entrypoint Section:
                                        Digitally signed:true
                                        Imagebase:0x400000
                                        Subsystem:windows gui
                                        Image File Characteristics:EXECUTABLE_IMAGE, 32BIT_MACHINE
                                        DLL Characteristics:DYNAMIC_BASE, TERMINAL_SERVER_AWARE
                                        Time Stamp:0x5992E826 [Tue Aug 15 12:25:10 2017 UTC]
                                        TLS Callbacks:
                                        CLR (.Net) Version:
                                        OS Version Major:5
                                        OS Version Minor:0
                                        File Version Major:5
                                        File Version Minor:0
                                        Subsystem Version Major:5
                                        Subsystem Version Minor:0
                                        Import Hash:fdeaa73e8c8dc60422bfb11854692202
                                        Signature Valid:
                                        Signature Issuer:
                                        Signature Validation Error:
                                        Error Number:
                                        Not Before, Not After
                                          Subject Chain
                                            Version:
                                            Thumbprint MD5:
                                            Thumbprint SHA-1:
                                            Thumbprint SHA-256:
                                            Serial:
                                            Instruction
                                            jmp 00007F19D47CD49Eh
                                            jmp 00007F19D488613Eh
                                            push 0044BB60h
                                            push dword ptr fs:[00000000h]
                                            mov eax, dword ptr [esp+10h]
                                            mov dword ptr [esp+10h], ebp
                                            lea ebp, dword ptr [esp+10h]
                                            sub esp, eax
                                            push ebx
                                            push esi
                                            push edi
                                            mov eax, dword ptr [00466ECCh]
                                            xor dword ptr [ebp-04h], eax
                                            xor eax, ebp
                                            push eax
                                            mov dword ptr [ebp-18h], esp
                                            push dword ptr [ebp-08h]
                                            mov eax, dword ptr [ebp-04h]
                                            mov dword ptr [ebp-04h], FFFFFFFEh
                                            mov dword ptr [ebp-08h], eax
                                            lea eax, dword ptr [ebp-10h]
                                            mov dword ptr fs:[00000000h], eax
                                            ret
                                            mov ecx, dword ptr [ebp-10h]
                                            mov dword ptr fs:[00000000h], ecx
                                            pop ecx
                                            pop edi
                                            pop edi
                                            pop esi
                                            pop ebx
                                            mov esp, ebp
                                            pop ebp
                                            push ecx
                                            ret
                                            int3
                                            int3
                                            int3
                                            add esp, 04h
                                            jmp 00007F19D5673A21h
                                            adc al, DDh
                                            arpl word ptr [esi+6E628653h], ax
                                            jle 00007F19D48862ABh
                                            jnbe 00007F19D48862DFh
                                            mov esp, A4889840h
                                            daa
                                            or eax, 156D9686h
                                            call 00007F199EA6C74Fh
                                            pop ds
                                            and dword ptr [esi], D2248D79h
                                            or dl, cl
                                            Programming Language:
                                            • [ASM] VS2008 SP1 build 30729
                                            • [ C ] VS2005 build 50727
                                            • [ C ] VS2008 build 21022
                                            • [IMP] VS2005 build 50727
                                            • [ C ] VS2008 SP1 build 30729
                                            • [C++] VS2008 SP1 build 30729
                                            • [EXP] VS2008 SP1 build 30729
                                            • [RES] VS2008 build 21022
                                            • [LNK] VS2008 SP1 build 30729
                                            NameVirtual AddressVirtual Size Is in Section
                                            IMAGE_DIRECTORY_ENTRY_EXPORT0xd390200x1b49.textTh
                                            IMAGE_DIRECTORY_ENTRY_IMPORT0xd3ab6c0x438.textTh
                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x65f0000x35d80.rsrc
                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x00x0
                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x44be000x2ba0
                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x00x0
                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x00x0
                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_IAT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                            0x10000x4000000x1a9200dd54c32df0b7037e8a7176305bea9d2aunknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            0x4010000x13f0000x6100064850dc371d3cb479ffd93495941c05dFalse1.0001057103737114data7.999484842813451IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            0x5400000x8c0000xb6001430c0f1582d2d9550e3e847890ec300False0.9927026098901099data7.986548844569612IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            0x5cc0000x3a0000x3800fd7c40b074f72cfa8a61ccaa02cbf43bFalse0.9884207589285714data7.965397455300278IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            0x6060000x590000x0d41d8cd98f00b204e9800998ecf8427eFalse0empty0.0IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            .rsrc0x65f0000x360000x35e0056bc576258b413d7d3f115a802d248f9False0.2353311702436195data4.086740603679486IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            0x6950000x6a40000x2002a0cf4a4bf89ba6ecc21c4be8cb65707unknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            .textTh0xd390000x1fd0000x1fca0030709ae1e581438ced1821997192dc3funknownunknownunknownunknownIMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                            JPG0x5cedc00x3381dataEnglishUnited States0.9416920731707317
                                            RT_ICON0x661dc00x5a96PNG image data, 256 x 256, 8-bit/color RGBA, non-interlacedEnglishUnited States0.9898663216903838
                                            RT_ICON0x6678580x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 0EnglishUnited States0.30684647302904566
                                            RT_ICON0x669e000x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.40619136960600377
                                            RT_ICON0x66aea80x988Device independent bitmap graphic, 24 x 48 x 32, image size 0EnglishUnited States0.41024590163934427
                                            RT_ICON0x66b8300x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.6099290780141844
                                            RT_ICON0x66bc980x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.11054913294797687
                                            RT_ICON0x66c2000x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.6114864864864865
                                            RT_ICON0x66c3280x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3547297297297297
                                            RT_ICON0x66c4500x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.46170520231213874
                                            RT_ICON0x66c9b80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.05053191489361702
                                            RT_ICON0x66ce200x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3885135135135135
                                            RT_ICON0x66cf480x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.46170520231213874
                                            RT_ICON0x66d4b00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.05053191489361702
                                            RT_ICON0x66d9180x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.40202702702702703
                                            RT_ICON0x66da400x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.46170520231213874
                                            RT_ICON0x66dfa80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.05053191489361702
                                            RT_ICON0x66e4100x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3885135135135135
                                            RT_ICON0x66e5380x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4595375722543353
                                            RT_ICON0x66eaa00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.04964539007092199
                                            RT_ICON0x66ef080x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.38513513513513514
                                            RT_ICON0x66f0300x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.46170520231213874
                                            RT_ICON0x66f5980x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.05053191489361702
                                            RT_ICON0x66fa000x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3716216216216216
                                            RT_ICON0x66fb280x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.46170520231213874
                                            RT_ICON0x6700900x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.05053191489361702
                                            RT_ICON0x6704f80x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.375
                                            RT_ICON0x6706200x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.46098265895953755
                                            RT_ICON0x670b880x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.05053191489361702
                                            RT_ICON0x670ff00x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.34797297297297297
                                            RT_ICON0x6711180x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4602601156069364
                                            RT_ICON0x6716800x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.04964539007092199
                                            RT_ICON0x671ae80x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.44594594594594594
                                            RT_ICON0x671c100x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5007225433526011
                                            RT_ICON0x6721780x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.11170212765957446
                                            RT_ICON0x6725e00x128Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colorsEnglishUnited States0.3277027027027027
                                            RT_ICON0x6727080x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512, 16 important colorsEnglishUnited States0.09005376344086022
                                            RT_ICON0x6729f00x128Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colorsEnglishUnited States0.3310810810810811
                                            RT_ICON0x672b180x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512, 16 important colorsEnglishUnited States0.09005376344086022
                                            RT_ICON0x672e000x128Device independent bitmap graphic, 16 x 32 x 4, image size 128, 16 important colorsEnglishUnited States0.34797297297297297
                                            RT_ICON0x672f280x2e8Device independent bitmap graphic, 32 x 64 x 4, image size 512, 16 important colorsEnglishUnited States0.09005376344086022
                                            RT_ICON0x6732100x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.46283783783783783
                                            RT_ICON0x6733380x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5245664739884393
                                            RT_ICON0x6738a00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.15868794326241134
                                            RT_ICON0x673d080x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3783783783783784
                                            RT_ICON0x673e300x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5570809248554913
                                            RT_ICON0x6743980x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.22074468085106383
                                            RT_ICON0x6748000x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3716216216216216
                                            RT_ICON0x6749280x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4841040462427746
                                            RT_ICON0x674e900x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.09219858156028368
                                            RT_ICON0x6752f80x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3885135135135135
                                            RT_ICON0x6754200x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.48916184971098264
                                            RT_ICON0x6759880x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.10283687943262411
                                            RT_ICON0x675df00x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.47297297297297297
                                            RT_ICON0x675f180x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5498554913294798
                                            RT_ICON0x6764800x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.19680851063829788
                                            RT_ICON0x6768e80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.2695035460992908
                                            RT_ICON0x676d500x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.26063829787234044
                                            RT_ICON0x6771b80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.2632978723404255
                                            RT_ICON0x6776200x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.46621621621621623
                                            RT_ICON0x6777480x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5932080924855492
                                            RT_ICON0x677cb00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.28634751773049644
                                            RT_ICON0x6781180x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.38513513513513514
                                            RT_ICON0x6782400x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.48627167630057805
                                            RT_ICON0x6787a80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.09397163120567376
                                            RT_ICON0x678c100x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.18351063829787234
                                            RT_ICON0x6790780x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.14378612716763006
                                            RT_ICON0x6795e00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.17375886524822695
                                            RT_ICON0x679a480x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.35135135135135137
                                            RT_ICON0x679b700x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.10549132947976879
                                            RT_ICON0x67a0d80x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.13439306358381503
                                            RT_ICON0x67a6400x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.07092198581560284
                                            RT_ICON0x67aaa80x368Device independent bitmap graphic, 16 x 32 x 24, image size 0EnglishUnited States0.08371559633027523
                                            RT_ICON0x67ae100x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.0673758865248227
                                            RT_ICON0x67b2780x368Device independent bitmap graphic, 16 x 32 x 24, image size 0EnglishUnited States0.08944954128440367
                                            RT_ICON0x67b5e00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.07092198581560284
                                            RT_ICON0x67ba480x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.38513513513513514
                                            RT_ICON0x67bb700x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.49277456647398843
                                            RT_ICON0x67c0d80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.0975177304964539
                                            RT_ICON0x67c5400x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.38513513513513514
                                            RT_ICON0x67c6680x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4920520231213873
                                            RT_ICON0x67cbd00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.09840425531914894
                                            RT_ICON0x67d0380x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4624277456647399
                                            RT_ICON0x67d5a00x368Device independent bitmap graphic, 16 x 32 x 24, image size 0EnglishUnited States0.06536697247706422
                                            RT_ICON0x67d9080x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.1125886524822695
                                            RT_ICON0x67dd700x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.10372340425531915
                                            RT_ICON0x67e1d80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.09131205673758866
                                            RT_ICON0x67e6400x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.10904255319148937
                                            RT_ICON0x67eaa80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.11170212765957446
                                            RT_ICON0x67ef100x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.13829787234042554
                                            RT_ICON0x67f3780x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.06213872832369942
                                            RT_ICON0x67f8e00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.09485815602836879
                                            RT_ICON0x67fd480x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.4734042553191489
                                            RT_ICON0x6801b00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.10017730496453901
                                            RT_ICON0x6806180x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3952702702702703
                                            RT_ICON0x6807400x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.49421965317919075
                                            RT_ICON0x680ca80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.09663120567375887
                                            RT_ICON0x6811100x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.3952702702702703
                                            RT_ICON0x6812380x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4949421965317919
                                            RT_ICON0x6817a00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.09485815602836879
                                            RT_ICON0x681c080x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.0888728323699422
                                            RT_ICON0x6821700x488Device independent bitmap graphic, 8 x 16 x 8, image size 0EnglishUnited States0.0603448275862069
                                            RT_ICON0x6825f80x488Device independent bitmap graphic, 8 x 16 x 8, image size 0EnglishUnited States0.08017241379310344
                                            RT_ICON0x682a800x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.5088652482269503
                                            RT_ICON0x682ee80x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.05202312138728324
                                            RT_ICON0x6834500x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.05202312138728324
                                            RT_ICON0x6839b80x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.06864161849710983
                                            RT_ICON0x683f200x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.05635838150289017
                                            RT_ICON0x6844880x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.05563583815028902
                                            RT_ICON0x6849f00x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.0476878612716763
                                            RT_ICON0x684f580x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.17198581560283688
                                            RT_ICON0x6853c00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.16843971631205673
                                            RT_ICON0x6858280x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.12427745664739884
                                            RT_ICON0x685d900x568Device independent bitmap graphic, 16 x 32 x 8, image size 256, 256 important colorsEnglishUnited States0.6076589595375722
                                            RT_ICON0x6862f80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.5620567375886525
                                            RT_ICON0x6867600x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.19418386491557224
                                            RT_ICON0x6878080x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.274822695035461
                                            RT_ICON0x687c700x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.1870567375886525
                                            RT_ICON0x6880d80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.1950354609929078
                                            RT_ICON0x6885400x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.07092198581560284
                                            RT_ICON0x6889a80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.1976950354609929
                                            RT_ICON0x688e100x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.10332369942196531
                                            RT_ICON0x6893780x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.09896810506566604
                                            RT_ICON0x68a4200x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.2553191489361702
                                            RT_ICON0x68a8880x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.25975177304964536
                                            RT_ICON0x68acf00x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.04552023121387283
                                            RT_ICON0x68b2580x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.04552023121387283
                                            RT_ICON0x68b7c00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.225177304964539
                                            RT_ICON0x68bc280x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.13583815028901733
                                            RT_ICON0x68c1900x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 0EnglishUnited States0.04878048780487805
                                            RT_ICON0x68d2380x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.14804964539007093
                                            RT_ICON0x68d6a00x1e0Device independent bitmap graphic, 10 x 20 x 32, image size 0EnglishUnited States0.31666666666666665
                                            RT_ICON0x68d8800x1e0Device independent bitmap graphic, 10 x 20 x 32, image size 0EnglishUnited States0.37083333333333335
                                            RT_ICON0x68da600x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.46283783783783783
                                            RT_ICON0x68db880x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5382947976878613
                                            RT_ICON0x68e0f00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.16666666666666666
                                            RT_ICON0x68e5580x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.49324324324324326
                                            RT_ICON0x68e6800x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5643063583815029
                                            RT_ICON0x68ebe80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.20921985815602837
                                            RT_ICON0x68f0500x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.5878378378378378
                                            RT_ICON0x68f1780x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.5953757225433526
                                            RT_ICON0x68f6e00x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.3617021276595745
                                            RT_ICON0x68fb480x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.4527027027027027
                                            RT_ICON0x68fc700x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.49783236994219654
                                            RT_ICON0x6901d80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.1099290780141844
                                            RT_ICON0x6906400x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.4479768786127168
                                            RT_ICON0x690ba80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.0700354609929078
                                            RT_ICON0x6910100x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.43858381502890176
                                            RT_ICON0x6915780x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.06560283687943262
                                            RT_ICON0x6919e00x128Device independent bitmap graphic, 16 x 32 x 4, image size 0EnglishUnited States0.2702702702702703
                                            RT_ICON0x691b080x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.45809248554913296
                                            RT_ICON0x6920700x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.04875886524822695
                                            RT_ICON0x6924d80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.5416666666666666
                                            RT_ICON0x6929400x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.1099290780141844
                                            RT_ICON0x692da80x468Device independent bitmap graphic, 16 x 32 x 32, image size 0EnglishUnited States0.1099290780141844
                                            RT_ICON0x6932100x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.05491329479768786
                                            RT_ICON0x6937780x568Device independent bitmap graphic, 16 x 32 x 8, image size 0EnglishUnited States0.05563583815028902
                                            RT_GROUP_ICON0x693ce00x5adataEnglishUnited States0.7888888888888889
                                            RT_GROUP_ICON0x693d3c0x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x693d6c0x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x693d9c0x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x693dcc0x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x693dfc0x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x693e200x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x693e440x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x693e740x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x693e880x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x693e9c0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x693eb00x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x693ec40x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x693ed80x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x693eec0x22dataEnglishUnited States1.0588235294117647
                                            RT_GROUP_ICON0x693f100x30dataEnglishUnited States0.9375
                                            RT_GROUP_ICON0x693f400x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x693f700x30dataEnglishUnited States0.9375
                                            RT_GROUP_ICON0x693fa00x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x693fd00x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6940000x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6940300x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6940600x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6940900x30dataEnglishUnited States0.9375
                                            RT_GROUP_ICON0x6940c00x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6940f00x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6941040x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6941340x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6941640x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6941940x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6941c40x30dataEnglishUnited States0.6666666666666666
                                            RT_GROUP_ICON0x6941f40x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6942240x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x6942480x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6942780x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x69428c0x30dataEnglishUnited States0.8541666666666666
                                            RT_GROUP_ICON0x6942bc0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6942d00x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6942e40x22dataEnglishUnited States1.0588235294117647
                                            RT_GROUP_ICON0x6943080x22dataEnglishUnited States1.0588235294117647
                                            RT_GROUP_ICON0x69432c0x22dataEnglishUnited States1.0588235294117647
                                            RT_GROUP_ICON0x6943500x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x6943740x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x6943980x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6943c80x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6943f80x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x69441c0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6944300x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6944440x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6944580x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x69446c0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6944800x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6944940x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6944a80x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6944bc0x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x6944ec0x30dataEnglishUnited States0.9791666666666666
                                            RT_GROUP_ICON0x69451c0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945300x14dataEnglishUnited States1.2
                                            RT_GROUP_ICON0x6945440x14dataEnglishUnited States1.2
                                            RT_GROUP_ICON0x6945580x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x69456c0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945800x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945940x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945a80x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945bc0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945d00x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945e40x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6945f80x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x69460c0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6946200x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6946340x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6946480x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x69465c0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6946700x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6946840x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x6946a80x22dataEnglishUnited States1.0588235294117647
                                            RT_GROUP_ICON0x6946cc0x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6946e00x22dataEnglishUnited States0.8529411764705882
                                            RT_GROUP_ICON0x6947040x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x6947180x14dataEnglishUnited States1.25
                                            RT_GROUP_ICON0x69472c0x22dataEnglishUnited States1.0294117647058822
                                            RT_GROUP_ICON0x6947500x22dataEnglishUnited States1.0588235294117647
                                            RT_VERSION0x6947740x2f0SysEx File - IDPEnglishUnited States0.4574468085106383
                                            RT_MANIFEST0x694a640x31cASCII text, with very long lines (599), with CRLF line terminatorsEnglishUnited States0.49246231155778897
                                            DLLImport
                                            kernel32.dllGetModuleHandleA, GetProcAddress, ExitProcess, LoadLibraryA
                                            user32.dllMessageBoxA
                                            advapi32.dllRegCloseKey
                                            oleaut32.dllSysFreeString
                                            gdi32.dllCreateFontA
                                            shell32.dllShellExecuteA
                                            version.dllGetFileVersionInfoA
                                            COMCTL32.dll
                                            COMDLG32.dllChooseColorW
                                            MSIMG32.dllAlphaBlend
                                            WINMM.dlltimeSetEvent
                                            WS2_32.dllsetsockopt
                                            ole32.dllReleaseStgMedium
                                            PSAPI.DLLGetModuleInformation
                                            SHLWAPI.dllPathRemoveArgsW
                                            WININET.dllInternetQueryOptionW
                                            DNSAPI.dllDnsFree
                                            WTSAPI32.dllWTSUnRegisterSessionNotification
                                            NameOrdinalAddress
                                            sqlite3_activate_see10x41979c
                                            sqlite3_aggregate_context20x66a676
                                            sqlite3_aggregate_count30x65b3df
                                            sqlite3_auto_extension40x68652b
                                            sqlite3_backup_finish50x690ecb
                                            sqlite3_backup_init60x68fd82
                                            sqlite3_backup_pagecount70x65a724
                                            sqlite3_backup_remaining80x65a71c
                                            sqlite3_backup_step90x68dc41
                                            sqlite3_bind_blob100x679cec
                                            sqlite3_bind_double110x679d0a
                                            sqlite3_bind_int120x68066b
                                            sqlite3_bind_int64130x679d4d
                                            sqlite3_bind_null140x679d8f
                                            sqlite3_bind_parameter_count150x65b46e
                                            sqlite3_bind_parameter_index160x65b4f8
                                            sqlite3_bind_parameter_name170x65b47e
                                            sqlite3_bind_text180x679db4
                                            sqlite3_bind_text16190x679dd2
                                            sqlite3_bind_value200x680683
                                            sqlite3_bind_zeroblob210x679df0
                                            sqlite3_blob_bytes220x65b71a
                                            sqlite3_blob_close230x691613
                                            sqlite3_blob_open240x69bc1e
                                            sqlite3_blob_read250x691717
                                            sqlite3_blob_reopen260x691757
                                            sqlite3_blob_write270x691737
                                            sqlite3_busy_handler280x65e9dd
                                            sqlite3_busy_timeout290x65ea65
                                            sqlite3_cancel_auto_extension300x65cde4
                                            sqlite3_changes310x65e83a
                                            sqlite3_clear_bindings320x65b27c
                                            sqlite3_close330x692287
                                            sqlite3_close_v2340x692294
                                            sqlite3_collation_needed350x65ec9c
                                            sqlite3_collation_needed16360x65ecd2
                                            sqlite3_column_blob370x6799db
                                            sqlite3_column_bytes380x6799ff
                                            sqlite3_column_bytes16390x679a23
                                            sqlite3_column_count400x65b3ea
                                            sqlite3_column_database_name410x66e51b
                                            sqlite3_column_database_name16420x66e535
                                            sqlite3_column_decltype430x66e4e7
                                            sqlite3_column_decltype16440x66e501
                                            sqlite3_column_double450x679a47
                                            sqlite3_column_int460x679a71
                                            sqlite3_column_int64470x679a95
                                            sqlite3_column_name480x66e4b3
                                            sqlite3_column_name16490x66e4cd
                                            sqlite3_column_origin_name500x66e583
                                            sqlite3_column_origin_name16510x66e59d
                                            sqlite3_column_table_name520x66e54f
                                            sqlite3_column_table_name16530x66e569
                                            sqlite3_column_text540x679abf
                                            sqlite3_column_text16550x679b19
                                            sqlite3_column_type560x679b3d
                                            sqlite3_column_value570x679ae3
                                            sqlite3_commit_hook580x65eb18
                                            sqlite3_compileoption_get590x656224
                                            sqlite3_compileoption_used600x66249c
                                            sqlite3_complete610x65e4f4
                                            sqlite3_complete16620x686705
                                            sqlite3_config630x67e936
                                            sqlite3_context_db_handle640x65b3a4
                                            sqlite3_create_collation650x67f02c
                                            sqlite3_create_collation16660x67f0a9
                                            sqlite3_create_collation_v2670x67f06a
                                            sqlite3_create_function680x683c22
                                            sqlite3_create_function16690x67ed6a
                                            sqlite3_create_function_v2700x67ecd4
                                            sqlite3_create_module710x67c6ac
                                            sqlite3_create_module_v2720x67c6c7
                                            sqlite3_data_count730x65b3fa
                                            sqlite3_data_directory740x9c7dac
                                            sqlite3_db_config750x66833f
                                            sqlite3_db_filename760x65edea
                                            sqlite3_db_handle770x65b5b4
                                            sqlite3_db_mutex780x65e71a
                                            sqlite3_db_readonly790x65ee04
                                            sqlite3_db_release_memory800x65e722
                                            sqlite3_db_status810x66c32c
                                            sqlite3_declare_vtab820x6920a9
                                            sqlite3_enable_load_extension830x65cdb2
                                            sqlite3_enable_shared_cache840x65a055
                                            sqlite3_errcode850x67eea1
                                            sqlite3_errmsg860x67ee36
                                            sqlite3_errmsg16870x67738f
                                            sqlite3_errstr880x65ebec
                                            sqlite3_exec890x6917dc
                                            sqlite3_expired900x65b267
                                            sqlite3_extended_errcode910x67eed5
                                            sqlite3_extended_result_codes920x65ed11
                                            sqlite3_extension_init930x6b03ea
                                            sqlite3_file_control940x6683f1
                                            sqlite3_finalize950x691491
                                            sqlite3_free960x656aca
                                            sqlite3_free_table970x65d46d
                                            sqlite3_get_autocommit980x65ed08
                                            sqlite3_get_auxdata990x65b3ac
                                            sqlite3_get_table1000x691b8c
                                            sqlite3_global_recover1010x5296fe
                                            sqlite3_initialize1020x6854d1
                                            sqlite3_interrupt1030x65ea9f
                                            sqlite3_key1040x66eca4
                                            sqlite3_key_v21050x66dad0
                                            sqlite3_last_insert_rowid1060x65e82f
                                            sqlite3_libversion1070x65e704
                                            sqlite3_libversion_number1080x65e710
                                            sqlite3_limit1090x65ec6c
                                            sqlite3_load_extension1100x67b910
                                            sqlite3_log1110x67024e
                                            sqlite3_malloc1120x6856ee
                                            sqlite3_memory_alarm1130x656a24
                                            sqlite3_memory_highwater1140x677eeb
                                            sqlite3_memory_used1150x677ee4
                                            sqlite3_mprintf1160x6701c3
                                            sqlite3_mutex_alloc1170x6568fa
                                            sqlite3_mutex_enter1180x656933
                                            sqlite3_mutex_free1190x656925
                                            sqlite3_mutex_leave1200x656951
                                            sqlite3_mutex_try1210x656941
                                            sqlite3_next_stmt1220x65b5f6
                                            sqlite3_open1230x6a4404
                                            sqlite3_open161240x6a441e
                                            sqlite3_open_v21250x6a4419
                                            sqlite3_os_end1260x5296fe
                                            sqlite3_os_init1270x678563
                                            sqlite3_overload_function1280x67edcb
                                            sqlite3_prepare1290x65cec1
                                            sqlite3_prepare161300x6aa8f9
                                            sqlite3_prepare16_v21310x6aa917
                                            sqlite3_prepare_v21320x65cee1
                                            sqlite3_profile1330x65eae3
                                            sqlite3_progress_handler1340x65ea1a
                                            sqlite3_randomness1350x662e63
                                            sqlite3_realloc1360x662aa1
                                            sqlite3_rekey1370x690eb1
                                            sqlite3_rekey_v21380x68f2ea
                                            sqlite3_release_memory1390x5296fe
                                            sqlite3_reset1400x6914d8
                                            sqlite3_reset_auto_extension1410x6865a7
                                            sqlite3_result_blob1420x67193e
                                            sqlite3_result_double1430x65b314
                                            sqlite3_result_error1440x66e415
                                            sqlite3_result_error161450x66e439
                                            sqlite3_result_error_code1460x66e460
                                            sqlite3_result_error_nomem1470x65b378
                                            sqlite3_result_error_toobig1480x66e48d
                                            sqlite3_result_int1490x65b32c
                                            sqlite3_result_int641500x65b342
                                            sqlite3_result_null1510x65b359
                                            sqlite3_result_text1520x67195a
                                            sqlite3_result_text161530x671976
                                            sqlite3_result_text16be1540x671992
                                            sqlite3_result_text16le1550x671976
                                            sqlite3_result_value1560x66c764
                                            sqlite3_result_zeroblob1570x65b368
                                            sqlite3_rollback_hook1580x65eb82
                                            sqlite3_set_authorizer1590x65c2a7
                                            sqlite3_set_auxdata1600x66a6d7
                                            sqlite3_shutdown1610x68675c
                                            sqlite3_sleep1620x6683ca
                                            sqlite3_snprintf1630x662e49
                                            sqlite3_soft_heap_limit1640x6856d9
                                            sqlite3_soft_heap_limit641650x685664
                                            sqlite3_sourceid1660x65e70a
                                            sqlite3_sql1670x65aab7
                                            sqlite3_status1680x6777e0
                                            sqlite3_step1690x6aa935
                                            sqlite3_stmt_busy1700x65b5d8
                                            sqlite3_stmt_readonly1710x65b5c2
                                            sqlite3_stmt_status1720x65b623
                                            sqlite3_strglob1730x65cc10
                                            sqlite3_stricmp1740x656ce1
                                            sqlite3_strnicmp1750x656d24
                                            sqlite3_table_column_metadata1760x6934b7
                                            sqlite3_temp_directory1770x9c7da8
                                            sqlite3_test_control1780x686bd8
                                            sqlite3_thread_cleanup1790x41979c
                                            sqlite3_threadsafe1800x65e716
                                            sqlite3_total_changes1810x65e842
                                            sqlite3_trace1820x65eaae
                                            sqlite3_transfer_bindings1830x65b562
                                            sqlite3_unicode_collate1840x6b027d
                                            sqlite3_unicode_fold1850x6afabb
                                            sqlite3_unicode_free1860x6b040a
                                            sqlite3_unicode_init1870x6b02e8
                                            sqlite3_unicode_load1880x6b03fe
                                            sqlite3_unicode_lower1890x6afb11
                                            sqlite3_update_hook1900x65eb4d
                                            sqlite3_uri_boolean1910x668462
                                            sqlite3_uri_int641920x66848d
                                            sqlite3_uri_parameter1930x65ed41
                                            sqlite3_user_data1940x65b39a
                                            sqlite3_value_blob1950x6718f3
                                            sqlite3_value_bytes1960x66e3ce
                                            sqlite3_value_bytes161970x66e3db
                                            sqlite3_value_double1980x65b2ef
                                            sqlite3_value_int1990x65b2f8
                                            sqlite3_value_int642000x65b2f8
                                            sqlite3_value_numeric_type2010x65b69e
                                            sqlite3_value_text2020x66e3e8
                                            sqlite3_value_text162030x66e406
                                            sqlite3_value_text16be2040x66e3f7
                                            sqlite3_value_text16le2050x66e406
                                            sqlite3_value_type2060x65b301
                                            sqlite3_version2070x86ad28
                                            sqlite3_vfs_find2080x6625da
                                            sqlite3_vfs_register2090x66264c
                                            sqlite3_vfs_unregister2100x66269f
                                            sqlite3_vmprintf2110x670153
                                            sqlite3_vsnprintf2120x662e00
                                            sqlite3_vtab_config2130x67c6d0
                                            sqlite3_vtab_on_conflict2140x65d7de
                                            sqlite3_wal_autocheckpoint2150x690e8d
                                            sqlite3_wal_checkpoint2160x68f2d4
                                            sqlite3_wal_checkpoint_v22170x68f237
                                            sqlite3_wal_hook2180x65ebb7
                                            sqlite3_win32_is_nt2190x657cae
                                            sqlite3_win32_mbcs_to_utf82200x6634e2
                                            sqlite3_win32_set_directory2210x6856ff
                                            sqlite3_win32_sleep2220x657ca3
                                            sqlite3_win32_utf8_to_mbcs2230x663557
                                            sqlite3_win32_write_debug2240x657c2c
                                            Language of compilation systemCountry where language is spokenMap
                                            EnglishUnited States
                                            No network behavior found

                                            Click to jump to process

                                            Click to jump to process

                                            Click to dive into process behavior distribution

                                            Target ID:0
                                            Start time:11:00:51
                                            Start date:01/11/2024
                                            Path:C:\Users\user\Desktop\m6tly2Aqw4.exe
                                            Wow64 process (32bit):true
                                            Commandline:"C:\Users\user\Desktop\m6tly2Aqw4.exe"
                                            Imagebase:0x50000
                                            File size:4'594'535 bytes
                                            MD5 hash:51D4E15FA77CF644EE90F42269BCED3B
                                            Has elevated privileges:true
                                            Has administrator privileges:true
                                            Programmed in:Borland Delphi
                                            Reputation:low
                                            Has exited:true

                                            No disassembly